Our Policies & Terms

Privacy Policy

Your privacy, security, and rights matter. Review our policies to understand how we protect your data and ensure a trusted experience.

Privacy Policy

This page is used to inform visitors regarding our policies with the collection, use, and disclosure of Personal Information for those who decide to use our Service.

If you choose to use our Service, then you agree to the collection and use of information in relation to this policy. The Personal Information that we collect is used for providing and improving the Service. We will not use or share your information with anyone except as described in this Privacy Policy.

The terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, which is accessible at Joyee App unless otherwise defined in this Privacy Policy.


Information Collection and Use

For a better experience while using our Service, we may require you to provide us with certain personally identifiable information, including facial recognition data for attendance purposes. The information that we request will be retained securely and handled in accordance with this Privacy Policy.

Types of Information We Collect:

  • Facial Recognition Data: For attendance verification purposes (see detailed section below)
  • Account Information: Name, email address, user IDs, student/staff ID, and other profile information
  • Contact and Identity Information: Phone number, home/mailing address, date of birth, and identity-document details captured during identity verification
  • Financial Information: Payment information such as bank account details shown on payment proofs you upload, purchase history (invoices, fees, receipts and payment records), and — for staff members only — payroll and salary records
  • Location Information: Precise device location, used for staff attendance clock-in/out verification and for live school-transport (bus) tracking
  • Messages: In-app chat messages exchanged between parents, teachers and school staff
  • Photos and Videos: Profile avatars, classroom and student photo walls, media you send in chat, and photographs of identity documents
  • Audio: Voice and sound recordings, including reading-practice recordings, chat voice notes, walkie-talkie / push-to-talk audio, and audio in video classrooms
  • Health Information: Student allergy and dietary/medical information recorded by the school
  • Files and Documents: Letters, homework, invoices and other attachments uploaded to or generated within the Service
  • App Activity: App interactions and other user-generated content you create in the app
  • Device Information and Identifiers: Device type, operating system, app usage data, device identifiers, and push-notification (Firebase Cloud Messaging) tokens

All of the information above is collected only to operate the Service for you and your school. All data is encrypted in transit.

We do not sell your personal information, and we do not share it with data brokers, advertising networks, or third-party analytics companies. Your data is processed and stored on infrastructure we control (Amazon Web Services, Asia Pacific — Singapore region).

We do, however, rely on a small number of platform service providers that are technically necessary to deliver the Service. These providers process only the limited data needed to perform their function on our behalf:

  • Firebase Cloud Messaging (Google) — to deliver push notifications to your device. This involves your device's push-notification token.
  • Google Sign-In (Google) — if you choose to sign in with a Google account, Google confirms your identity and provides your name and email address.
  • Google Maps and Places (Google) — to display maps, addresses and live transport tracking. Map and place requests may include location data.
  • Amazon Web Services — hosting, database and file storage (including Amazon SES for transactional email such as verification codes and notifications).

These providers act as our processors and are not permitted to use your information for their own advertising or profiling. Their use of information is also governed by their own privacy policies.


Facial Recognition and Attendance

Face Data Collection and Use

Our app collects and processes facial recognition data for the specific purpose of taking attendance in educational settings. This section explains how we collect, use, store, and protect this sensitive biometric information.

What Face Data We Collect

When you use the attendance feature, the app captures and processes the following face data:

  • Facial geometry and features: Mathematical representations of facial landmarks and patterns used to identify individuals for attendance purposes
  • Face images: Temporary captures of your face during the attendance check-in process
  • Facial recognition templates: Encoded biometric data derived from your facial features, converted into a unique identifier

How We Use Face Data

Face data is collected and used exclusively for the following purposes:

  • Attendance Verification: To accurately identify and record student or staff attendance in real-time
  • Security and Authentication: To ensure only authorized individuals are marked as present
  • Attendance Records: To maintain accurate attendance logs for educational and administrative purposes
  • System Improvement: To improve the accuracy and reliability of the facial recognition attendance system

Face data is never used for:

  • Marketing or advertising purposes
  • Sharing with third parties for commercial gain
  • Tracking user behavior outside of attendance functions
  • Any purpose other than attendance verification and system improvement

User Consent and Control

  • Explicit Consent: The app will request your explicit consent before collecting or processing any face data
  • Visual Indication: The app provides clear visual indicators when the camera is active and face data is being captured
  • Opt-Out Option: Users can choose not to use the facial recognition feature and may use alternative attendance methods
  • Data Access: You can request access to your facial recognition data at any time
  • Data Deletion: You have the right to request deletion of your face data at any time by contacting us

Data Sharing and Third Parties

Your face data is treated with the highest level of security and privacy:

  • No Third-Party Sharing: We do not sell, share, or disclose your face data to any third parties for any purpose
  • No Advertising Use: Face data is never shared with advertising networks or used for targeted advertising
  • Educational Use Only: Face data remains within the educational institution's system and is only accessible to authorized school administrators

Data Storage and Security

  • Secure Storage: All face data is encrypted and stored securely on our servers with industry-standard encryption protocols
  • Access Controls: Only authorized personnel with legitimate educational purposes can access face data
  • Storage Location: Face data is stored securely on AWS S3 servers in the Asia Pacific region (Singapore - ap-southeast-1), with appropriate security measures including encryption at rest and in transit
  • Isolated Storage: Face data is stored separately from other personal information and protected by multiple layers of security

Data Retention Period

  • Active Users: Face data is retained for the duration of the user's active enrollment or employment at the educational institution
  • Inactive Users: Face data is automatically deleted within 30 days after a user's account becomes inactive or upon graduation/termination of employment
  • User-Requested Deletion: Upon request, face data will be permanently deleted within 7 business days
  • Attendance Records: While face data is deleted, attendance records (without biometric data) are retained according to institutional record-keeping requirements

How to Delete Your Face Data

You can request deletion of your face data at any time by:

  1. Contacting us at joyeepreschool@gmail.com or raysonlim77@gmail.com
  2. Following the steps on our Account Deletion page, which also deletes your face data
  3. Submitting a written request to your educational institution's administrator

Upon receiving a deletion request, we will permanently delete all associated face data within 7 business days and provide confirmation of deletion.

Compliance with Privacy Laws

Our facial recognition practices comply with applicable privacy laws and regulations, including but not limited to GDPR, COPPA, and other relevant data protection legislation. We are committed to protecting your biometric privacy rights.

Changes to Face Data Practices

If we make any changes to how we collect, use, or store face data, we will update this section of our Privacy Policy and notify users via email or in-app notification at least 30 days before the changes take effect.


How We Use Other Categories of Data

Besides facial recognition data, the app collects the categories below. Each is collected only for the purpose stated, and none of them is sold, shared with data brokers, or used for advertising.

Personal and Contact Information

Name, email address, user ID, phone number, address, date of birth, and identity-document details are used to create and manage your account, to link parents/guardians with their children, to contact you about school matters, and — where the school requires it — to verify your identity before granting access to a child's records. Identity documents are used only for that verification and are stored with restricted access.

Financial Information

  • Payment information: When you upload a payment proof (for example a bank transfer slip), the image and the bank account details it shows are used solely to verify and reconcile your payment. We do not process card payments in the app and do not store card numbers.
  • Purchase history: Invoices, fees, receipts, and payment records are kept so that you and the school can view an accurate billing history and so the school can meet its accounting obligations.
  • Payroll information: For staff users only, salary, allowance, deduction and statutory-contribution records are processed to administer payroll and produce the statutory tax and contribution filings required in Malaysia.

Location Information

The app collects precise location for two features:

  • Staff attendance: When a staff member clocks in or out, the device location is recorded to confirm the clock-in took place at the school or approved work site.
  • School transport tracking: While a bus trip is in progress, the driver's device shares its location so that the school and parents can see the vehicle's live position and estimated arrival.

Location is collected only while these features are in use. Location is not collected in the background for any other purpose, is not used for advertising, and is not shared with third parties.

Messages

In-app chat messages between parents, teachers and staff — including text, media and voice notes — are stored so that conversations can be delivered and reviewed by their participants. Messages are visible only to the participants of a conversation and to authorised school administrators where the school's own policy requires oversight. We do not read messages for advertising or profiling.

Photos, Videos and Audio

  • Photos and videos: Used for profile avatars, classroom and student photo walls, media shared in chat, and identity-document verification. Photos on a student's photo wall may be face-tagged so the right child's photos reach the right family; this uses the same protections described in the facial recognition section above.
  • Voice and sound recordings: Reading-practice recordings are stored so teachers and parents can review a child's reading progress. Chat voice notes are stored as part of the conversation. Walkie-talkie (push-to-talk) and video-classroom audio is transmitted live to the intended participants.

Health Information

Student allergy and dietary or medical information is recorded by the school, or supplied by a parent/guardian, so that staff can keep the child safe at meal times and in an emergency. It is visible only to authorised school staff who need it for the child's care. It is never used for any commercial purpose.

Files and Documents

Letters, homework, invoices and other attachments uploaded to or generated by the Service are stored so that they can be delivered to and retrieved by the intended recipients within the school community.

App Activity and User-Generated Content

App interactions (such as which features are used and when) help us keep the app working correctly and improve it. User-generated content — posts, comments, homework submissions and similar contributions — is stored and shown to the audience you or the school selected.

Device Identifiers and Push Notifications

Device identifiers and Firebase Cloud Messaging tokens are used to deliver push notifications to the correct device and to keep your session secure. You can turn off push notifications in your device settings at any time.


Children's and Student Data

This is a school application. Accounts are created for parents/guardians and for school staff, and the app is not intended for independent use by children.

  • Most data about a student is entered by the school, or by that student's parent/guardian, and is processed by us on the school's behalf as its data processor. The educational institution remains responsible for deciding what student information is collected and who may see it.
  • Student information — including attendance, academic records, photos, allergy and dietary information — is accessible only to the school's authorised staff and to the student's linked parents/guardians.
  • We do not knowingly allow children to create their own accounts, and we do not use student data for advertising, profiling, or any purpose other than delivering the Service to the school and the family.
  • If you are a parent or guardian and you want to review, correct or delete information the school holds about your child in the app, please contact your school administrator, or contact us using the details below and we will act together with the school.

Data Retention

We keep personal information only for as long as it is needed for the purpose it was collected, or for as long as the law requires:

  • Financial and accounting records — invoices, payments, receipts, refunds, payroll and related ledger entries are retained for 7 years, as required by Malaysian statutory record-keeping obligations, and are purged after that period expires.
  • Account and profile data — deleted when your account is deleted, subject to the statutory records above. See our Account Deletion page for how to request deletion and exactly what is removed.
  • Facial recognition data — retained and deleted as described in the Facial Recognition section above.
  • Attendance and academic records — retained by the educational institution for its own record-keeping and regulatory obligations, with biometric data removed.
  • Backups — data may persist in encrypted system backups after deletion. All backups containing your data are rotated out and purged within 30 days of the deletion being completed.
  • Anonymised or aggregated data — data that can no longer be linked to you may be retained indefinitely.

Your Rights and Account Deletion

You may request access to, correction of, or deletion of the personal information we hold about you.

To delete your account and associated data, follow the steps on our Account Deletion page, which explains how to delete your account from inside the app or by email, what is deleted, and what must be retained for statutory reasons.


Log Data

We want to inform you that whenever you use our Service, in the case of an error in the app, we collect data and information (through third-party products) on your device called Log Data. This Log Data may include information such as your device's Internet Protocol ("IP") address, device name, operating system version, the configuration of the app when utilizing our Service, the time and date of your use of the Service, and other statistics.


Cookies

Cookies are files with a small amount of data that are commonly used as anonymous unique identifiers. These are sent to your browser from the websites that you visit and are stored on your device's internal memory.

This Service does not use these “cookies” explicitly. However, the app may use third-party code and libraries that use “cookies” to collect information and improve their services. You have the option to either accept or refuse these cookies and to know when a cookie is being sent to your device. If you choose to refuse our cookies, you may not be able to use some portions of this Service.


Service Providers

We may employ third-party companies and individuals for the following reasons:

  • To facilitate our Service;
  • To provide the Service on our behalf;
  • To perform Service-related services; or
  • To assist us in analyzing how our Service is used.

We want to inform users of this Service that these third parties have access to your Personal Information. The reason is to perform the tasks assigned to them on our behalf. However, they are obligated not to disclose or use the information for any other purpose.

The service providers we currently rely on are:

  • Amazon Web Services — server hosting, database and file storage (Asia Pacific, Singapore region), and Amazon SES for transactional email
  • Google — Firebase Cloud Messaging — delivery of push notifications
  • Google — Sign-In — optional sign-in with a Google account
  • Google — Maps and Places — maps, address lookup and live transport tracking

We do not use third-party advertising networks, and we do not sell or otherwise disclose your personal information to third parties for their own marketing or profiling purposes.


Security

We value your trust in providing us your Personal Information, including sensitive biometric data such as facial recognition information, and we strive to use commercially acceptable means of protecting it. We implement industry-standard security measures including:

  • Encryption: All data is encrypted in transit, and facial recognition data is additionally encrypted at rest
  • Access Controls: Strict access controls limit who can view or process facial data
  • Regular Security Audits: We conduct regular security assessments to protect your data
  • Secure Infrastructure: Data is stored on secure servers with multiple layers of protection

However, remember that no method of transmission over the internet or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security. We continuously work to improve our security measures to protect your sensitive information.


Links to Other Sites

This Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. Note that these external sites are not operated by us. Therefore, we strongly advise you to review the Privacy Policy of these websites. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.


Children’s Privacy

The app is designed for parents/guardians and school staff, not for independent use by children. We do not knowingly allow a child to create their own account or to provide us with personal information directly.

Information about a student is entered by the educational institution or by that student's parent/guardian, and is processed by us on the school's behalf, as described in the Children's and Student Data section above. If you are a parent or guardian and you believe a child has provided us with personal information directly, or you wish to review or remove information held about your child, please contact us and we will take the necessary actions together with the school.


Changes to This Privacy Policy

We may update our Privacy Policy from time to time. Thus, you are advised to review this page periodically for any changes. We will notify you of any changes by posting the new Privacy Policy on this page. For significant changes, especially those related to facial recognition data, we will provide advance notice via email or in-app notification.

This policy is effective as of 2021-05-11 and last updated on 2026-08-05.


Contact Us

If you have any questions or suggestions about our Privacy Policy, including concerns about facial recognition data collection and use, or if you wish to request deletion of your face data, do not hesitate to contact us at joyeepreschool@gmail.com or raysonlim77@gmail.com.

  • App name: 卓羿校园 (Joyous)
  • Package name: com.rayson.joyous
  • Developer: Rayson Lim

For face data deletion requests, please include:

  • Your full name and student/staff ID
  • The email address associated with your account
  • A clear statement requesting deletion of facial recognition data

To delete your entire account and its associated data, see the Account Deletion page.