Skip to content

MONEY GOLD · MG

Privacy Policy

Your information deserves a clear explanation. Here is how it is handled across the Money Gold platform.

Last updated: 27 September 2026

1. About this policy

This policy covers the Money Gold website at mgstack.my, the MG Agent app, the MG Customer app and the related MG administration workspace. Money Gold is also referred to as “MG”.

Money Gold provides the platform. The organisation that gives you an account or manages your loan controls the customer and business records in its workspace. Its own privacy notices and legal responsibilities also apply. You can contact us about the platform, or your organisation about a particular account or record.

2. Information we handle

The information used depends on your role and the features you or your organisation use:

  • Account and identity information: names, contact details, login identifiers, authentication information, roles, company/group assignments and, where entered for a customer or business, identity/passport numbers, registration details and director/owner associations.
  • Application and financial records: loan applications, supporting financial information, bank details, repayment schedules and receipts, balances, approval decisions, expenses, commissions and payout records.
  • Documents and communications: files you choose to upload, supporting evidence, payslips, notes, referral enquiries, staff notices, acknowledgements and support requests.
  • Staff attendance and activity: clock-in/out times, the time of deliberate activity in MG during an open shift, inactivity alerts and their resolution. This does not record the content of your keystrokes or activity in other apps.
  • Technical and security information: IP addresses, browser/device information, session and request identifiers, error information, access history and audit records. If you enable supported device notifications, we also handle installation identifiers and notification delivery tokens.

Information may be provided by you, by authorised staff acting for your organisation, or through actions you take in MG. A business record may include information about directors or owners supplied by an authorised user.

3. How information is used

We use information to authenticate users, apply access permissions, maintain customer and loan records, process the workflows selected by your organisation, show account information, provide notifications, resolve support requests and protect the service against misuse.

Customer identity enquiries retain an audit history and search counts. For staff, inactivity monitoring operates only during an open clocked-in shift and stops at clock-out. Selected managers and/or the staff member receive alerts according to the organisation’s settings. It is not location tracking.

Where an organisation enables document or report analysis, selected uploaded content may be processed by its configured analysis service to prepare information for authorised review. This is separate from routine customer searches and repayment recording.

4. Access and sharing

Information is available to authorised users according to company, group, role and record permissions. A match outside a user’s record access can indicate that a record exists without giving that user the private record. Customer accounts are limited to their permitted information.

We use service providers for infrastructure, document storage, security and, where enabled, message delivery or document analysis. They receive information needed for those functions. Optional device push notifications use Google Firebase Cloud Messaging and, on supported Apple devices, Apple’s notification service. Push notifications use generic messages; the user signs in to see protected details.

Information may also be disclosed where required by applicable law, a valid legal request, or to investigate fraud or protect legal rights. MG does not provide personal information to advertisers or sell personal information.

Infrastructure and service providers may process information outside your country. Contact us or your organisation for details about the services used for your account and the safeguards that apply.

5. Device permissions and local storage

MG uses an internet connection to communicate with the service. When you upload a document or image, the system file picker lets you choose the file to share; the app does not need unrestricted access to your files.

MG Agent requests notification permission only when you choose to enable device notifications on a supported, configured device. You can turn notifications off in the app or your device settings. The current apps do not request access to your contacts, SMS, microphone or device location.

The apps use protected local storage for login information and recovery of pending actions. The web workspace uses browser storage for essential session, language and workflow preferences. The public website does not use advertising cookies or third-party analytics.

6. Storage and security

MG uses HTTPS for connections, authenticated access and role/record permissions. Uploaded documents and supported sensitive local records use encryption, and business actions are recorded in an audit history. Access controls, backups and monitoring help protect availability and integrity.

No service can guarantee absolute security. Keep your account credentials private and contact your organisation or MG support if you believe your account has been accessed without permission.

7. Retention and deletion

Information is retained while needed to provide the service and for the purposes described in this policy. Retention also depends on the organisation’s configured policies and applicable financial, accounting, security, dispute-resolution and legal requirements. We do not apply one universal retention period to every record.

You can request deletion of your account and associated personal information. Requests are reviewed with identity verification and the organisation responsible for the records. Information no longer needed can be deleted or anonymised. Financial records, audit evidence or information subject to a legal obligation or hold may need to be retained; the response to your request will explain relevant exceptions.

Removing the app, signing out or disabling an account does not by itself delete server-side information. Deletion of an app account does not cancel a loan or other outstanding contractual obligation. Backup copies follow their retention and expiry process.

8. Your choices and requests

You can ask to access or correct your information, request account or data deletion, or raise a privacy concern. Depending on applicable law and the purpose of processing, you may also be able to object to or restrict processing, request a copy of your data or withdraw consent. Withdrawing optional permissions may make the related feature unavailable.

Use the support contact or deletion-request page. We may request information needed to verify that the account or record belongs to you. Please do not send passwords, verification codes or full identity documents in an initial email.

MG is designed for customers and authorised business users and is not directed at children. Contact us if you believe information about a child has been provided inappropriately.

9. Updates and contact

We may update this policy when the service or its data practices change. The current version and update date will be published here. Where a change requires additional notice or consent, that will be handled through the appropriate service or organisation.

For privacy enquiries, contact Money Gold using the support details below. Please name the app you use—MG Agent or MG Customer—and the organisation associated with your account.