Current Exchange Rate $1 = RM3.10(Updated on 2026-06-01)

PRIVACY POLICY

Personal Data Protection Notice

Issued by

HANDAL INDAH SDN. BHD.

(Company No.: 287467-M / 199301002757)

Updated on: 25th May 2026

Compliant with the Personal Data Protection Act 2010 (Malaysia), as amended by the Personal Data Protection (Amendment) Act 2024

This Privacy Policy explains how Handal Indah Sdn. Bhd. and its related companies collect, use, store, disclose, share, transfer and otherwise process your Personal Data when you use the Manja Services and/or visit the Website. Please read this Privacy Policy carefully before providing any Personal Data to us. If you do not agree with any part of this Privacy Policy, please do not provide any Personal Data to us or use the Manja Services.

INTRODUCTION AND ABOUT US

  1. Handal Indah Sdn. Bhd. (Company No. 287467-M / 199301002757) (“HISB”, “we”, “us” or “our”) and, where applicable in respect of services provided in or relating to Singapore, ManjaLink Pte. Ltd. (Company Registration No. 201134172M) (“MPL”) (HISB and MPL together, the “Service Providers”), are committed to protecting and respecting the privacy of the Personal Data of users of our Manja Services and visitors of our Website.
  2. This Privacy Policy describes our practices in relation to the collection, use, storage, disclosure, sharing, transfer and other processing of Personal Data, and is issued pursuant to and in compliance with the Personal Data Protection Act 2010 of Malaysia, as amended (including by the Personal Data Protection (Amendment) Act 2024, with provisions phased into force on 1 January 2025, 1 April 2025 and 1 June 2025), and any subsidiary legislation, codes of practice, guidelines (including the Guidelines for Cross Border Personal Data Transfer issued by the Personal Data Protection Department of Malaysia) and orders issued thereunder (collectively, the “PDPA”).
  3. For the purposes of the PDPA, HISB is the “data controller” (a term which, under the PDPA Amendment, replaces “data user”) in respect of the Personal Data collected through the Manja Services and the Website. Where MPL is involved in services provided in or relating to Singapore, MPL acts in accordance with applicable Singapore data protection laws, which are not the subject of this Privacy Policy.
  4. This Privacy Policy applies to all individuals whose Personal Data we process, including users of the Manja Services (Card Holders, ManjaPay Account holders and ManjaRewards members), visitors of the Website, and any other person who provides Personal Data to us or whose Personal Data we otherwise collect (“you” or “your”).
  5. This Privacy Policy should be read together with our Terms of Use for ManjaLink, ManjaPay and ManjaRewards and our Website Terms of Use.

DEFINITIONS

In this Privacy Policy, unless the context otherwise requires:

  1. “Commissioner” means the Personal Data Protection Commissioner appointed under the PDPA.
  2. “Cross-Border Transfer” means the transfer of Personal Data from Malaysia to a place outside Malaysia.
  3. “Data Protection Officer” or “DPO” means the data protection officer appointed by us in accordance with Section 12 of the PDPA (as introduced under the PDPA Amendment Act 2024).
  4. “Manja Services” has the meaning given in our Terms of Use for ManjaLink, ManjaPay and ManjaRewards.
  5. “Personal Data” means any information that relates directly or indirectly to a data subject, who is identified or identifiable from that information or from that and other information in our possession, including any Sensitive Personal Data.
  6. “Sensitive Personal Data” means Personal Data consisting of information as to the physical or mental health or condition of a data subject, their political opinions, their religious beliefs or other beliefs of a similar nature, the commission or alleged commission by them of any offence, biometric data (as added by the PDPA Amendment Act 2024) or any other Personal Data as may be determined by the Minister responsible for personal data protection.
  7. “Website” has the meaning given in our Website Terms of Use.

PERSONAL DATA WE COLLECT

We may collect, use, store and otherwise process the following categories of Personal Data, depending on the Manja Services you use and the manner of your interactions with us:

(a) Identity and contact information:

full name, gender, date of birth, nationality, National Registration Identification Card (NRIC) or passport number (where required for verification), residential and mailing address, e-mail address and mobile/telephone number.

(b) Account and transactional information:

Manja Account username and (in encrypted/hashed form) password and PIN, ManjaLink Card serial/identification numbers, ManjaPay Account identifiers, Travel Credit balances, top-up records, transaction history, fare records (including journey origin, destination, route, date and time), rebate accumulation and redemption records, and refund and cancellation records.

(c) Payment and financial information:

designated bank account information (for the processing of refunds), records of payment instruments used for top-ups (such as type of card, last four digits, and bank name; we do not store full card numbers or CVV values), e-wallet identifiers, and payment transaction references.

(d) Device, technical and online information:

IP address, device identifiers (including IMEI, MAC and advertising identifiers), device type, operating system, browser type, language preferences, geo-location data (where you enable location services), application crash and diagnostic logs, cookies, pixel tags, web beacons, session and authentication tokens, and usage and interaction data with the Website and the LUGO App.

(e) Customer service and feedback information:

the content of any enquiry, complaint, support ticket, feedback, comment, review or other communication you submit to us, including any attachments and call recordings (where calls are made to our customer service line and you are notified of recording).

(f) Marketing and survey information:

marketing preferences, consents and opt-out elections, and responses to any survey, contest or promotional campaign that we conduct or in which you participate.

(g) Sensitive Personal Data:

where strictly necessary for a specified purpose (for example, biometric data, such as facial features or fingerprint templates, may be processed where you choose to authenticate to the LUGO App using your device’s biometric authentication, in which case the biometric data is typically stored on your device and not transmitted to us). We process Sensitive Personal Data only with your explicit consent or where otherwise permitted under the PDPA.

You may choose not to provide certain Personal Data. However, if such Personal Data is necessary for us to provide a particular Manja Service or to process your request, our inability to obtain that Personal Data may result in our being unable to provide that Service, process the request, complete a transaction or carry out the relevant activity. We will inform you, at the point of collection, which items of Personal Data are mandatory and which are optional.

SOURCES OF PERSONAL DATA

We collect Personal Data from the following sources:

  1. directly from you, when you register for or use any Manja Service, when you fill in any form (online or offline), when you interact with us through the Website, the LUGO App, the Manja Portal, social media, e-mail, telephone or in person, and when you participate in any survey, contest or promotion;
  2. automatically, when you use the Website or the LUGO App, through cookies, pixel tags, web beacons and similar tracking technologies, and through device-generated information;
  3. from Authorised Agents and our partners (such as ticketing offices, vending machine operators, e-commerce platforms, payment processors and banks) in connection with your transactions;
  4. from publicly available sources, where lawful (for example, public registers, social media profiles you have made public);
  5. from third parties such as credit reference agencies, fraud-prevention agencies, law enforcement and regulatory authorities, where lawful and necessary; and
  6. from referees or any other person who provides Personal Data about you to us with your consent or where lawful.

PURPOSES OF PROCESSING

We process Personal Data for one or more of the following purposes (each, a “Purpose”):

  1. to assess your eligibility for, and to register, issue, activate, maintain, manage and operate your Manja Account, ManjaLink Card, ManjaPay Account and ManjaRewards membership;
  2. to process top-ups, fare deductions, transactions, refunds, cancellations and other operations relating to the Manja Services;
  3. to administer the ManjaRewards Programme, including the calculation, accrual, crediting and redemption of rebates and member privileges;
  4. to verify your identity for fraud prevention, customer due diligence and anti-money laundering / countering the financing of terrorism (AML/CFT) purposes, including in compliance with the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 and Bank Negara Malaysia guidelines (where applicable);
  5. to provide customer service, respond to your enquiries, complaints and requests, and to investigate and resolve any disputes or issues;
  6. to communicate with you about the Manja Services, including service notifications, fare changes, route changes, maintenance windows, security alerts, account alerts, refunds and dormant account notifications;
  7. to operate, maintain, secure, administer, monitor, debug, improve, personalise and develop the Manja Services, the Website and the LUGO App, including conducting analytics, statistical analysis and research, and to develop new services and features;
  8. to detect, prevent, investigate and address fraud, security incidents, abuse, violations of our Terms of Use, infringement of intellectual property rights and other unlawful or harmful activity;
  9. where you have consented (or where otherwise permitted by law), to send you marketing communications about the Manja Services, our Bus Services, our other products and services, and (subject to your separate consent) the products and services of our partners; and to administer contests, lotteries, surveys and promotional campaigns;
  10. to comply with applicable laws, regulations, codes, guidelines and orders, and with requests from courts, regulators, government authorities or law enforcement agencies, including the PDPA, financial services laws and tax laws;
  11. to establish, exercise or defend our legal rights, including in legal or administrative proceedings;
  12. to enforce or apply our Terms of Use and other agreements with you, including for collection and recovery of amounts owed; and
  13. for any other purpose that is reasonably necessary in connection with the foregoing, or as otherwise notified to you at the point of collection.

LEGAL BASIS FOR PROCESSING

We process Personal Data on one or more of the following legal bases under the PDPA:

  1. your consent, where required (and, for Sensitive Personal Data, your explicit consent), which you may give expressly or which may be implied from your conduct (for example, by your continued use of the Manja Services after notice has been given);
  2. the performance of a contract with you (including our Terms of Use), or to take steps at your request prior to entering into such a contract;
  3. compliance with a legal obligation to which we are subject;
  4. the protection of your or another person’s vital interests;
  5. the administration of justice, the exercise of any function conferred on us by law, or the exercise of any function of a public nature; and
  6. (f)  the legitimate interests pursued by us or by a third party (such as fraud prevention, network and information security, and the maintenance and improvement of our services), except where such interests are overridden by your interests or fundamental rights.

 

CONSENT

  1. Where we rely on your consent to process Personal Data, you may withdraw that consent at any time by contacting us using the channels set out in Section 19 (Contact Us) below. Withdrawal of consent will not affect the lawfulness of any processing carried out on the basis of consent prior to the withdrawal.
  2. If you withdraw your consent in relation to Personal Data that is necessary for the provision of a particular Manja Service, we may be unable to continue providing that Service to you, and your Manja Account may be suspended or terminated, in accordance with our Terms of Use.
  3. Where the data subject is below the age of eighteen (18), consent must be given by the parent or legal guardian of the data subject. We do not knowingly collect Personal Data from children under the age of thirteen (13) without verifiable parental or guardian consent. If you believe that we have inadvertently collected Personal Data from a child under thirteen (13) without such consent, please contact us so that we may take appropriate steps.

DISCLOSURE OF PERSONAL DATA

We may disclose your Personal Data to the following categories of recipients, in each case subject to appropriate safeguards and only for the Purposes set out in this Privacy Policy:

  1. our subsidiaries, holding company, and other related and affiliated companies within our group (including those operating under the “Causeway Link”, “Handal Indah” and “BAS.MY” brands);
  2. MPL and its affiliates, in connection with cross-border services between Malaysia and Singapore;
  3. Authorised Agents, partners, ticketing offices, vending machine operators, e-commerce platforms (such as Shopee), kiosk operators and other parties involved in the operation of the Manja Services;
  4. service providers, vendors and contractors who perform services on our behalf, including hosting and cloud providers, IT and software providers, payment processors, banks, e-wallet operators, telecommunications operators, courier and logistics providers, fraud-prevention agencies, identity verification providers, marketing and advertising agencies, analytics providers (such as Google Analytics), customer service providers, professional advisers (legal, tax, accounting, audit) and insurers;
  5. courts, regulators, law enforcement, tax authorities, public authorities and other competent bodies, where required or permitted by law;
  6. actual or prospective purchasers, transferees, financiers or investors in connection with any actual or potential reorganisation, merger, sale, joint venture, assignment, transfer or other disposition of all or any part of our business, assets or shares; and
  7. any other person to whom you have consented to the disclosure, or to whom we are otherwise permitted or required to disclose under applicable law.

 

All third parties to whom we disclose Personal Data are bound by confidentiality obligations and are required to process the Personal Data only for the purposes for which it was disclosed and in accordance with applicable data protection laws.

CROSS-BORDER TRANSFER OF PERSONAL DATA

  1. Some of the recipients to whom we disclose Personal Data may be located outside Malaysia (including in Singapore, where MPL is located, and in any other jurisdiction where our service providers or affiliates operate). Where we engage in Cross-Border Transfer of Personal Data, we will do so in compliance with Section 129 of the PDPA and the Guidelines for Cross Border Personal Data Transfer issued by the Personal Data Protection Department of Malaysia (the “CBPDT Guidelines”).
  2. Cross-Border Transfers will only be made where one or more of the following conditions is satisfied: (a) the recipient jurisdiction has been specified by the Minister in the Federal Gazette as offering an adequate level of protection; (b) you have given your consent to the transfer (which, in accordance with the CBPDT Guidelines, may be supported by prior written notice in electronic format describing the proposed transfer); (c) the transfer is necessary for the performance of a contract between us and you, or for the implementation of pre-contractual measures taken at your request; (d) the transfer is necessary for the conclusion or performance of a contract between us and a third party in your interest; (e) we have taken all reasonable precautions and exercised all due diligence to ensure that the Personal Data will be protected in a manner equivalent to that under the PDPA; or (f) any other ground under Section 129 of the PDPA applies.
  3. Where we transfer Personal Data on the basis of contractual safeguards, we will put in place appropriate data transfer agreements containing protections equivalent to those required under the PDPA.

DATA SECURITY

  1. We have implemented and will maintain appropriate technical, physical and organisational security measures designed to protect Personal Data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, the Personal Data. These measures include encryption in transit and at rest (where appropriate), access controls and identity management, secure development practices, regular vulnerability assessments and penetration testing, staff training and awareness programmes, vendor risk management, and incident response and business continuity planning. 
  2. Notwithstanding the foregoing, no method of transmission over the Internet, or method of electronic storage, is 100% secure. While we strive to use commercially reasonable means to protect your Personal Data, we cannot guarantee absolute security. You are also responsible for protecting your own login credentials, devices and connections, and for notifying us promptly of any actual or suspected security incident.

PERSONAL DATA BREACH NOTIFICATION

  1. In compliance with Section 12B of the PDPA (introduced by the PDPA Amendment Act 2024 and in force from 1 June 2025), if a personal data breach occurs which causes or is likely to cause significant harm to a data subject, or which is of a significant scale, we will notify the Commissioner without undue delay and within the time period prescribed under the PDPA and any guidelines issued thereunder.
  2. Where the personal data breach causes or is likely to cause significant harm to you, we will also notify you without undue delay, using such means of communication as we consider most appropriate in the circumstances (which may include e-mail, SMS, push notification, in-app messaging or telephone). The notification will include, to the extent reasonably available at the time, the nature of the breach, the categories and approximate number of data subjects and Personal Data records concerned, the likely consequences, the measures taken or proposed to address the breach and mitigate its possible adverse effects, and the contact point from which further information can be obtained.
  3. We maintain an internal personal data breach register and have established incident response procedures consistent with the PDPA and applicable guidelines.

DATA RETENTION

  1. We will retain your Personal Data only for as long as is reasonably necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting, reporting or audit requirements, resolving disputes, enforcing our agreements, and protecting our legal interests.
  2. The criteria used to determine our retention periods include: (a) the duration of your relationship with us and the duration of your use of the Manja Services; (b) the nature and sensitivity of the Personal Data; (c) the potential risk of harm from unauthorised use or disclosure; (d) the purposes for which we process the Personal Data and whether we can achieve those purposes through other means; and (e) the applicable legal, regulatory, tax, accounting and other requirements.
  3. When Personal Data is no longer required to be retained, we will securely destroy, delete or anonymise it in accordance with our retention policy and applicable law.

YOUR RIGHTS UNDER THE PDPA

Under the PDPA, you have the following rights in respect of your Personal Data:

  1. Right of Access: you have the right to request access to, and a copy of, the Personal Data that we hold about you, together with information about how we process it.
  2. Right to Correction: you have the right to request correction of any Personal Data that is inaccurate, incomplete, misleading or out of date.
  3. Right to Withdraw Consent: you have the right to withdraw any consent that you have previously given to the processing of your Personal Data for any specific purpose, subject to Clause 7.2 above.
  4. Right to Prevent Processing for Direct Marketing: you have the right to require us, at any time, to cease processing your Personal Data for the purposes of direct marketing.
  5. Right to Prevent Processing Likely to Cause Damage or Distress: you have the right to require us, by notice in writing, to cease or not to begin processing your Personal Data on the ground that the processing is causing or is likely to cause substantial damage or substantial distress to you or another person.
  6. Right to Data Portability: in accordance with Section 43A of the PDPA (introduced by the PDPA Amendment Act 2024 and in force from 1 June 2025), where it is technically feasible and where data format compatibility permits, you have the right to request that your Personal Data be transmitted directly from us to another data controller of your choice. You may make such a request by giving notice in writing in electronic format using the channels set out in Section 19 below.
  7. Right to Lodge a Complaint: you have the right to lodge a complaint with us (using the contact details in Section 19 below) and/or with the Commissioner if you believe that our processing of your Personal Data infringes the PDPA. The Commissioner’s contact details are available at https://www.pdp.gov.my.
  8. How to exercise your rights: to exercise any of the above rights, please contact our Data Protection Officer using the details set out in Section 18 (Data Protection Officer) below. We will respond to your request within the timeframes required by the PDPA. We may need to verify your identity before fulfilling your request, and we may charge a reasonable fee where permitted by law (for example, for excessive or repetitive requests). In limited circumstances permitted by the PDPA, we may decline your request, in which case we will give reasons.

COOKIES AND TRACKING TECHNOLOGIES

The Website and the LUGO App use cookies, web beacons, pixel tags, SDKs and similar tracking technologies (collectively, “Tracking Technologies”) to recognise you when you visit, to remember your preferences, to provide you with a more personalised experience, to measure the effectiveness of our content and marketing, and to maintain the security of our services.

We use the following categories of Tracking Technologies:

  1. Strictly Necessary: essential for the operation of the Website and the LUGO App and the provision of the Manja Services, including authentication, session management and fraud prevention. These cannot be disabled without affecting core functionality.
  2. Performance and Analytics: collect information about how visitors use the Website and the LUGO App (for example, Google Analytics and Google Tag Manager). The information collected is generally aggregated and used to improve our services.
  3. Functional: enable enhanced features and personalisation, such as remembering language preferences.
  4. Advertising and Marketing: used to deliver more relevant advertising and to measure the effectiveness of our marketing campaigns, where permitted.

You can control or delete cookies through your browser or device settings. However, disabling certain Tracking Technologies may affect the functionality and user experience of the Website and the LUGO App.

THIRD-PARTY LINKS AND SERVICES

The Website and the LUGO App may contain links to third-party websites, applications, services and content (including the Apple App Store, Google Play Store, social media platforms such as Facebook and Instagram, e-commerce platforms such as Shopee, video platforms such as YouTube, and mapping services such as Google Maps). This Privacy Policy does not apply to such third-party websites, applications or services. We encourage you to review the privacy policies of any third party before providing them with any Personal Data.

CHILDREN

The Manja Services are not directed to children under the age of thirteen (13), and we do not knowingly collect Personal Data from children under that age without verifiable parental or guardian consent. If you are a parent or guardian and you believe that your child has provided us with Personal Data without your consent, please contact us so that we may take appropriate steps to delete the data.

CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, services or applicable law. We will post the updated Privacy Policy on the Website together with the effective date. Where the changes are material, we will use reasonable efforts to notify you (for example, by a prominent notice on the Website or, where appropriate, by e-mail or in-app notification) before the changes take effect. Your continued use of the Manja Services or the Website after the effective date constitutes acceptance of the updated Privacy Policy.

DATA PROTECTION OFFICER

  1. In accordance with Section 12 of the PDPA (introduced by the PDPA Amendment Act 2024 and in force from 1 June 2025), we have appointed a Data Protection Officer who is responsible for overseeing our compliance with the PDPA and addressing data protection enquiries.
  2. You may contact our Data Protection Officer in relation to any matter concerning this Privacy Policy or your Personal Data using the following details:

 

Data Protection Officer

Handal Indah Sdn. Bhd.

No. 23, Jalan Firma 2, Kawasan Perindustrian Tebrau IV, 81100 Johor Bahru, Johor, Malaysia.

E-mail: dpo@manjalink.com.my

Customer Support: https://support.causewaylink.com.my

CONTACT US

If you have any questions, comments, complaints or requests in relation to this Privacy Policy or your Personal Data, please contact us at:

Handal Indah Sdn. Bhd.

No. 23, Jalan Firma 2, Kawasan Perindustrian Tebrau IV, 81100 Johor Bahru, Johor, Malaysia.

Website: https://manja.my

Customer Service Page: https://manja.my/customer-service/

Customer Support Portal: https://support.causewaylink.com.my

 

If you are not satisfied with our response, or if you believe that we are not processing your Personal Data in accordance with the PDPA, you have the right to lodge a complaint with the Personal Data Protection Department of Malaysia at:

Personal Data Protection Department (Jabatan Perlindungan Data Peribadi)

Ministry of Digital, Malaysia

Website: https://www.pdp.gov.my

ManjaPay available route

(Scroll down for more info)

Bus Service No. From/To To/From
F100 JB Sentral KSL City Mall
F200 Terminal Bas Masai Bandar Seri Alam
F300 Terminal Kulai Taman Putri Kulai
T10 JB Sentral Terminal Bas Kota Tinggi (via Terminal Larkin)
T11 JB Sentral Terminal Seri Austin
T13 JB Sentral Larkin Sentral (via Kebun Teh)
T14 JB Sentral Toppen
T20 JB Sentral Terminal Pasir Gudang
T21 JB Sentral Permas Jaya
T22 Larkin Sentral Lotus Kota Masai
T30 JB Sentral Terminal Kulai
T31 JB Sentral Taman Pulai Mutiara
T32 JB Sentral Flat Taman Selesa Jaya
T33 JB Sentral Taman Tan Sri Yaacob
T40 Larkin Sentral Gelang Patah Sentral
T42 Terminal Gelang Patah Kampnd Pendas Baru
T44 Larkin Sentral Terminal Feri Puteri Harbour (via Bukit Indah)
T50 Larkin Sentral Terminal Pontian

Johor Bahru Bus Services

(Scroll down for more info)

Johor Bahru Bus Services

Bus Service No. From/To To/From
F100 JB Sentral KSL City Mall
F200 Terminal Bas Masai Bandar Seri Alam
F300 Terminal Kulai Taman Putri Kulai
T10 JB Sentral Terminal Bas Kota Tinggi (via Terminal Larkin)
T11 JB Sentral Terminal Seri Austin
T13 JB Sentral Larkin Sentral (via Kebun Teh)
T14 JB Sentral Toppen
T20 JB Sentral Terminal Pasir Gudang
T21 JB Sentral Permas Jaya
T22 Larkin Sentral Lotus Kota Masai
T30 JB Sentral Terminal Kulai
T31 JB Sentral Taman Pulai Mutiara
T32 JB Sentral Flat Taman Selesa Jaya
T33 JB Sentral Taman Tan Sri Yaacob
T40 Larkin Sentral Gelang Patah Sentral
T42 Terminal Gelang Patah Kampnd Pendas Baru
T44 Larkin Sentral Terminal Feri Puteri Harbour (via Bukit Indah)
T50 Larkin Sentral Terminal Pontian
JPO1 JB Sentral Johor Premium Outlets
AA1 JB Sentral Senai International Airport

Cross Border Bus Services

(Scroll down for more info)

Cross Border Bus Services

Bus Service No. From/To To/From
CWL Larkin CIQ 1st Link (Transit Point)
CW1 Larkin Kranji MRT Station
CW2 Larkin Queen Street Terminal
CW3 Perling Mall Jurong East
CW3S Taxi & Bus Terminal Taman Tun Ungku Tun Aminah / Sutera Mall CIQ 2nd Link (Transit Point)
CW3L Perling / Bukit Indah CIQ 2nd Link (Transit Point)
CW4 Pontian / Gelang Patah Terminal Jurong East
CW4G Gelang Patah Terminal CIQ 2nd Link (Transit Point)
CW4S Sutera Mall Jurong East
CW5 CIQ 1st Link Newton Circus
CW6 TF Value-Mart Nusa Bestari / Bukit Indah Boon Lay
CW7 CIQ 2nd Link Tuas Link
CW7L Hotel Ramada Meridin / CI Medini CIQ 2nd Link (Transit point)
52T Terminal Pontian Terminal Gelang Patah