pullupJoin Waitlist

Legal · DAMAI GEMILANG VENTURES ENT

Privacy Policy

Effective date: July 28, 2026 · Applies to the Pullup mobile application, waitlist portal, and all associated services.

1. Introduction & Data Controller Identification

DAMAI GEMILANG VENTURES ENT ("Company," "we," "us," or "our"), the sole operator of the Pullup social platform, is the data controller responsible for all personal data collected, processed, and stored in connection with the Pullup mobile application, waitlist portal, and all associated services (collectively, the "Services").

We recognize that your privacy is a fundamental right. This Privacy Policy is designed to be transparent, comprehensive, and fully compliant with applicable data protection laws. It describes precisely what data we collect, why we collect it, how we use it, with whom we share it, how long we retain it, and the rights you hold over your information.

By accessing or using any Service, including by submitting your details to our waitlist, you acknowledge that you have read and understood this Privacy Policy and consent to the data practices described herein. If you do not agree, you must immediately cease all use of the Services.

For all data-related inquiries, contact our designated data point of contact at: pulluppteam@gmail.com.

2. Scope of This Policy

This Policy applies to all personal data processed by the Company in connection with the Services, regardless of how you access them. It covers:

  • Individuals who download, access, or use the Pullup mobile application;
  • Individuals who submit their contact information to the Pullup waitlist portal;
  • Individuals who communicate with the Company via email or other channels;
  • Individuals whose information is incidentally processed because they appear in User Content.

This Policy does not cover data practices of third-party services or platforms that you access via links or integrations within our Services. Those third parties maintain their own privacy policies.

3. Categories of Data We Collect

We collect data in the following categories, depending on how you interact with the Services:

3.1 Data You Provide Directly

  • Waitlist Registration: Phone number or email address, and any optional information you choose to provide.
  • Account Profile: Display name, photographs, date of birth (for age verification), and biographical information.
  • Event Content: Event titles, descriptions, dates, venue information, photographs, and associated media uploaded by Hosts.
  • Communications: Messages sent through in-app group channels, reports submitted to the Company, and emails or messages you send to our support team.
  • Identity Verification: Where required, government-issued identification or biometric-adjacent data processed solely for verification purposes.

3.2 Data Collected Automatically

  • Precise Location Data: Real-time GPS coordinates and network-inferred location, collected when the Application is active and you have granted location permissions. This data underpins core map-based features.
  • Device & Technical Data: Device type, operating system version, device identifiers (e.g., advertising IDs where applicable), browser type, IP address, and app version.
  • Usage & Telemetry Data: Features accessed, Events viewed or joined, tap patterns, session durations, crash logs, and error reports.
  • Network Data: Network type (WiFi, cellular), approximate connection quality, and related diagnostics used to optimize performance.

3.3 Data From Third Parties

  • Authentication Providers: If you authenticate via a third-party provider (e.g., phone number OTP via SMS gateway), we receive confirmation of your identity token from that provider.
  • Firebase Infrastructure: We use Google Firebase services for authentication, database, cloud functions, and storage. Firebase's own Privacy Policy governs data processed at the infrastructure level.

4. Purposes of Processing & Legal Bases

We process your personal data only for specified, explicit, and legitimate purposes. The following table outlines each processing purpose and its corresponding legal basis:

PurposeLegal Basis
Creating and managing your accountPerformance of a contract
Displaying live Events on the mapPerformance of a contract; Consent (location)
Facilitating Event group chatsPerformance of a contract
Sending waitlist and platform updatesConsent; Legitimate interests
Platform security, fraud prevention, and abuse detectionLegitimate interests; Legal obligation
Identity verification and age gatingLegal obligation; Legitimate interests
Improving and personalizing the ServicesLegitimate interests; Consent
Responding to support inquiries and reportsPerformance of a contract; Legitimate interests
Compliance with legal and regulatory obligationsLegal obligation
Crash diagnostics and performance monitoringLegitimate interests

5. Data Ephemerality, Minimization & Retention

Pullup is built on a strict data-minimization architecture. We collect only what is necessary for the purpose stated and retain it no longer than required. Specific retention periods are as follows:

Data CategoryRetention Period
Event group chat messages and mediaPermanently purged 7 days after Event conclusion
Identity verification artifactsSecurely destroyed immediately post-verification
Precise location dataNot persistently stored; used in real-time only
Account profile dataDuration of active account; deleted upon account closure
Waitlist registration dataUntil waitlist is dissolved or user withdraws consent
Usage telemetry and crash logsUp to 12 months, then anonymized or deleted
Safety and moderation recordsUp to 3 years, where required for legal or safety purposes
Transaction and legal compliance recordsAs required by applicable law (typically up to 7 years)

Following the applicable retention period, personal data is either permanently deleted or irreversibly anonymized so that it can no longer be associated with an individual.

6. Security Protocols & Data Integrity

The Company implements rigorous, layered technical and organizational security measures designed to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
  • Encryption at Rest: Sensitive data fields stored on our infrastructure are encrypted using AES-256 or equivalent standards.
  • Access Controls: Access to production systems and personal data is restricted on a strict need-to-know basis, governed by role-based access controls and multi-factor authentication.
  • Firebase Security Rules: Firestore and Firebase Storage rules enforce data isolation, ensuring users can only access data they are authorized to view.
  • Security Monitoring: We employ automated monitoring tools to detect and respond to anomalous access patterns, potential breaches, and abuse signals in real-time.
  • Secure Development Practices: Our engineering team follows secure software development lifecycle (SSDLC) principles, including regular code reviews and security testing.

Notwithstanding these measures, no system is perfectly impenetrable. The Company expressly disclaims liability for data breaches resulting from sophisticated cyber-attacks, zero-day exploits, or force majeure events beyond our reasonable control. In the event of a confirmed breach materially affecting your personal data, we will notify you in accordance with applicable legal requirements.

7. Disclosure of Your Data

We do not sell your personal data. Period.

We do not sell, rent, or trade your personal information to third-party data brokers, advertisers, or marketing entities. We may, however, share your data in the following limited circumstances:

7.1 Service Providers

We share data with trusted third-party service providers who perform functions on our behalf, including cloud hosting (Google Firebase / Google Cloud), push notification delivery, SMS authentication gateways, and crash analytics providers. These providers are contractually bound to use your data only as directed by us and in accordance with this Policy.

7.2 Other Users (By Design)

Certain information is inherently visible to other users as part of the platform's social functionality — specifically, your display name, profile photo, and Events you create or attend. You control and are responsible for what you choose to share publicly on the platform.

7.3 Law Enforcement & Legal Compliance

We may disclose your information to law enforcement agencies, regulatory authorities, courts, or governmental bodies when: (a) compelled by a valid subpoena, court order, or equivalent legal process; (b) we believe in good faith that disclosure is necessary to prevent imminent physical harm to any person; (c) disclosure is required to prevent fraud or illegal activity on the platform; or (d) disclosure is necessary to enforce our Terms of Service or protect our legal rights. We will, where legally permissible, notify you of such requests.

7.4 Business Transfers

In the event of a merger, acquisition, restructuring, asset sale, or similar corporate transaction involving the Company or its assets, your data may be transferred to the successor entity. We will provide notice if your data becomes subject to a materially different privacy policy.

7.5 With Your Consent

We may share your data in any other manner with your explicit, informed, prior consent.

8. Location Data — Special Notice

Precise location data is the cornerstone of Pullup's core functionality. When you use the Application, we collect your real-time GPS coordinates to display nearby Events on the map and to verify proximity to an Event venue.

Key facts about location data:

  • Real-time only: We do not build a persistent historical record of your location movements. Location is used in the moment, not stored indefinitely.
  • Opt-out available: You may disable location access for the Application in your device settings at any time. Doing so will disable map-dependent features.
  • Not sold: Your location data is never sold or shared with advertisers.
  • Visible to others by design: When you host or join an Event, your proximity to that Event may be inferred by other attendees as part of the platform's social mechanics. You consent to this visibility by participating in such Events.

9. Cookies & Tracking Technologies

Our Waitlist Portal may use cookies and similar tracking technologies (e.g., local storage, session tokens) to: (a) maintain session state; (b) analyze aggregate traffic and usage patterns; and (c) improve the user experience. These are functional and analytical in nature — not advertising-related. You may configure your browser to refuse cookies, though this may limit certain portal functionality.

We do not use third-party advertising trackers or cross-site tracking technologies.

10. Your Rights Over Your Data

Subject to applicable law and our ability to verify your identity, you may have the following rights with respect to your personal data:

  • Right of Access: Request a copy of the personal data we hold about you and information about how we process it.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data where there is no longer a lawful basis for us to retain it.
  • Right to Restriction: Request that we restrict our processing of your personal data in certain circumstances.
  • Right to Data Portability: Request that we provide your personal data in a structured, commonly used, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Where processing is based on your consent, withdraw that consent at any time without affecting the lawfulness of prior processing.
  • Right Not to Be Subject to Automated Decision-Making: Request human review of any automated decision that significantly affects you.

To exercise any of these rights, contact us at pulluppteam@gmail.com. We will respond to verified requests within 30 days. We may require proof of identity before processing your request.

11. Children's Privacy

The Services are strictly intended for users aged 18 and older. We do not knowingly collect, solicit, or process personal data from individuals under the age of 18. If we discover that we have inadvertently collected personal data from a minor, we will immediately delete such data from our systems. If you believe we have collected data from a person under 18, please notify us immediately at pulluppteam@gmail.com.

12. International Data Transfers

The Services are operated primarily from Malaysia. If you access the Services from outside Malaysia, you acknowledge that your personal data will be transferred to, processed in, and stored in Malaysia, where data protection laws may differ from those in your jurisdiction. By using the Services, you consent to such transfer, processing, and storage.

Where we use third-party services that process data outside Malaysia (e.g., Google Cloud infrastructure), we ensure that appropriate safeguards are in place, including standard contractual clauses or reliance on the third party's adequacy status.

13. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time. Material changes will be communicated by updating the "Effective Date" at the top of this document and, where practicable, by notifying you via the contact information you provided. Your continued use of the Services after the effective date of any revision constitutes acceptance of the updated Policy.

We encourage you to review this Policy periodically to stay informed about how we protect your personal data.

14. Contact & Data Inquiries

For formal privacy inquiries, data access requests, consent withdrawals, or concerns about our data practices, please contact:

Data Controller: DAMAI GEMILANG VENTURES ENT

Platform: Pullup

Email: pulluppteam@gmail.com

Response time: Within 30 calendar days

OPERATED EXCLUSIVELY BY DAMAI GEMILANG VENTURES ENT. ALL DATA PRACTICES ARE EXECUTED IN STRICT COMPLIANCE WITH APPLICABLE PRIVACY LAWS. LAST UPDATED: July 28, 2026.