Privacy Policy
Last updated: April 2026
1. Introduction
G8Stack, G8Connect, G8Shield, and G8Monitor (collectively "the Platform") are products of Developers Hub Sdn Bhd (Company No. 202001011498 / 1367505-A), registered in Malaysia ("we", "our", "us").
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our websites (g8stack.com and related subdomains), use our platform, or interact with any of our products. This policy applies to all G8Stack products and services.
2. Information We Collect
We may collect the following types of information:
2.1 Information You Provide
- Contact information: Name, email address, company name, and phone number when you contact us, request a demo, or join a waitlist.
- Account data: Login credentials, profile information, and role assignments when you create an account on any G8Stack product.
- Payment information: Billing details for enterprise customers, processed through secure third-party payment providers. We do not store credit card numbers.
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, time spent, browser type, device information, and referring URLs.
- Log data: IP address, access times, and API request metadata for security and operational purposes.
- Cookies: We use essential cookies for authentication and session management. Analytics cookies are used only with your consent.
2.3 Data Source Information (G8Connect)
When you use G8Connect to connect data sources, your database credentials are encrypted at rest and never logged. G8Connect accesses your data sources in read-only mode for schema introspection. We do not store, copy, or transmit your source data beyond what is necessary for schema analysis and API spec generation.
2.4 Security Intelligence Data (G8Shield)
G8Shield analyses API traffic metadata and patterns for security threat detection. It processes traffic logs, request patterns, and response metadata. Sensitive data detected in API responses (PII, credentials) is flagged but not stored — only the alert metadata (endpoint, field name, data type) is retained.
3. How We Use Your Information
- To provide, operate, and maintain the G8Stack platform and all associated products
- To authenticate users and manage access control
- To generate API specifications and manage governance workflows (G8Connect)
- To detect security threats, assess compliance, and generate security reports (G8Shield)
- To monitor API performance and health (G8Monitor)
- To respond to your inquiries and support requests
- To send product updates, security advisories, and relevant communications
- To improve our products and develop new features
- To comply with legal obligations and regulatory requirements
4. Data Sharing & Third Parties
We do not sell your personal information. We may share data in the following circumstances:
- Service providers: Trusted third parties who assist in operating our platform (hosting, email delivery, analytics), subject to confidentiality agreements.
- API gateway integration: G8Stack communicates with your API gateway (e.g., Kong) via its Admin API to manage routes, plugins, and policies. This data stays within your infrastructure.
- Legal requirements: When required by law, regulation, or legal process.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected users.
5. Data Security
We implement appropriate technical and organisational measures to protect your data:
- All data transmitted over the network is encrypted using TLS
- Database credentials and sensitive configuration are encrypted at rest
- Role-based access control (RBAC) is enforced across all products
- Full audit trail on all data access and administrative actions
- Regular security assessments and code reviews
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy, or as required by law. API traffic metadata used for security analysis is retained for a configurable period (default 90 days). You may request deletion of your data at any time.
7. Your Rights
Under the Malaysia Personal Data Protection Act 2010 (PDPA) and applicable data protection laws, you have the right to:
- Access your personal data held by us
- Correct inaccurate or incomplete personal data
- Delete your personal data (subject to legal retention requirements)
- Withdraw consent for data processing where consent was the basis
- Data portability — request your data in a structured, machine-readable format
To exercise any of these rights, contact us at [email protected].
8. Cookies
We use essential cookies for authentication and session management. Optional analytics cookies help us understand how visitors use our site. You can disable non-essential cookies through your browser settings. Our platform will function without analytics cookies.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. If material changes are made, we will notify you via email or a prominent notice on the platform.
10. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at: