Toos
Privacy policy
Last updated 30 September 2026. Applies to the Toos app for Android and the service behind it.
In short
- Toos is a food-discovery app for Malaysia. You need an account (email and password) to save places, write reviews, add places or claim a shop; the rest of the app works without signing in.
- What you share — reviews, places you add, edits you suggest and, if you turn it on, your saved places — is public, shown with your display name.
- Your location is used only to find places near you and to check shop-owner claims. It is not stored as a history and never shown to other users.
- There are no ads, no analytics or tracking SDKs, and we do not sell or rent your data.
- You can delete your account, and everything tied to it, from Settings in the app or via this page.
1. Who is responsible
Toos is operated by Toos The Place Store in Malaysia (“we”). For anything about your data, write to [email protected]. We handle personal data under Malaysia's Personal Data Protection Act 2010 and, where it applies to you, the data-protection law of your own country.
2. What Toos collects, and why
| Data | Why | Who sees it |
|---|---|---|
| Account — email address, password, date the account was created. | Signing you in, confirming your email, resetting a lost password. The password is stored only as a hash by our authentication provider; we never see it. | Only you and us. Your email is never shown in the app. |
| Profile — display name and the area you enter. | Shown next to everything you share. A profile photo you set stays on your phone only; it is not uploaded. | Public. |
| Reviews — star rating, text, tags, photos, time posted. | The purpose of the app: telling other diners about a place. | Public, with your display name and contributor badge. |
| Places you add — name, category, address, description, opening hours, tags, price band, photos and map position. | Adding a place to the Toos directory. | Public, with your display name as the person who added it. |
| Saved places — which places you tapped the heart on, with the place's map position. | Your own list, and the “From your saved places” strip on your home screen. | Private by default. If you turn on Settings › Sharing › Show my saved places, people within a few kilometres can see which places you saved, with your name. |
| Suggestions — corrections you send for a place, a note, or marking it closed. | Keeping the directory accurate. | Applied to the place; the note is visible to us. |
| Shop-owner claims — a photo of a business document, a photo of the shopfront taken in the app, the distance between your phone and the shop when you took it, and an optional note. If approved: the changes you make as owner (hours, menu, photos, tags) and your replies to reviews. | Checking that you really run the place before you can edit its listing. | The proof photos are stored in a private area readable only by us, and are deleted as soon as the claim is approved or rejected. Your owner edits and replies are public, marked as the owner's. |
| Location — your phone's position while the app is open, precise or approximate as you allow in Android. | Finding and sorting places near you, and the distance check above. Each nearby search sends your position to our server, which answers and does not keep it; the only stored trace is the claim distance. | Never shown to other users. Never collected in the background. |
| Photos — pictures you choose from your gallery or take with the camera for a review, a place or a claim. | Illustrating places; proving a claim. | Review and place photos are public. Photos are uploaded as your phone provides them, so a gallery photo may still carry the metadata your camera embedded (such as the time and place it was taken) — strip it first if you would rather not share it. The shopfront photo for a claim is always taken in the app, never picked from the gallery. |
| Contributor points — a score worked out from the reviews, places and photos you contribute. | The rank badge (Newcomer to Food Legend) next to your name. | Public, as the badge. |
| Technical logs — when the app talks to our server, the hosting provider records the IP address, time and request as standard server logs. | Keeping the service running and secure. | Only us and the hosting provider, for a short period. |
Everything you write or save is also kept on your phone so the app works offline. You can wipe it with Settings › Data › Clear my data, or by clearing the app's data in Android.
3. What Toos does not do
- No advertising, and no advertising identifiers.
- No analytics, crash-reporting or tracking SDKs. We do not profile you.
- No access to your contacts, calendar, microphone, files beyond the photos you pick, or location while the app is closed.
- No marketing email. The only emails you receive are the account emails you trigger: confirming your address and resetting a password.
- No selling, renting or trading of personal data. Ever.
4. Who else handles your data
We use a small number of service providers, each only for the job described. They process data on our instructions and under their own published privacy terms.
Supabase (hosting)
Our database, sign-in, file storage and server functions run on Supabase, on servers in Seoul, South Korea (Amazon Web Services, ap-northeast-2). Everything in section 2 is stored there. Account emails are sent through Supabase on our behalf.
Google Maps Platform
The map is drawn by the Google Maps SDK for Android, and Google's Places API supplies the Google rating, price level and photos shown for places in Search. When you view a place, its name and area are sent to Google to look it up; the map and Places SDKs also send Google standard device information as described in Google's privacy policy. Your Toos account details are not sent to Google.
OpenStreetMap (Overpass API)
Places in Search come from OpenStreetMap. Usually the app reads them from our own copy on Supabase; when you search an area we have not mirrored, the app asks a public Overpass API server directly, which then receives your search position and IP address. See the OSM Foundation privacy policy.
Resend (email delivery)
When you file a shop-owner claim, an email to us is delivered by Resend so we can review it. It carries your display name and area, the place, the distance check and your note — not your email address or the proof photos.
Beyond these, we disclose personal data only if the law requires it or to protect the rights and safety of Toos and its users.
5. Where your data lives
Your account and everything you share are stored in South Korea (see Supabase above). Google and OpenStreetMap servers may be in other countries. By using Toos you agree to your data being processed in these places.
6. How long we keep it
- Account, profile, reviews, saved places, suggestions, claims, owner edits: for as long as your account exists. Deleting your account removes them immediately.
- Claim proof photos: until the claim is approved or rejected, or your account is deleted — whichever comes first.
- Places you added: these stay in the directory after you delete your account, without your name, so other people can still find them. Their photos stay with them. Delete a place yourself first if you do not want that.
- Server logs: a short period, measured in days.
- Backups: routine encrypted backups expire within 30 days of a deletion.
7. Your choices and rights
- Location: grant precise or approximate location, or none, in Android's app settings at any time. Without it, the app measures from a fixed default position in Petaling Jaya and you can search any area by typing an address.
- Saved places: private unless you switch on Show my saved places; switching it off hides them again at once.
- Correct or remove what you shared: edit your profile under Me; delete your own reviews and places from their pages.
- Delete your account: Me › Settings › Delete account removes your account and its data straight away, or ask us via the account-deletion page.
- Access, correction, withdrawal of consent, complaints: under the PDPA and similar laws you can ask us what we hold about you, have it corrected, or object to how it is used. Write to [email protected]; we answer within 21 days.
8. Security
All traffic between the app and our servers is encrypted (TLS). Every database table is protected by row-level access rules, so a user can only ever write their own data and read what is meant to be public. Claim proofs sit in a private bucket that no other app user can read. Passwords are hashed, never stored in the clear.
9. Children
Toos is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has created an account, tell us and we will delete it.
10. Changes to this policy
If Toos starts collecting or sharing something new, this page changes first and the “Last updated” date moves. Check back here; the app links to this page from Settings › About.
Questions or requests: [email protected]