Privacy Policy
Last updated: 3 July 2026
This Privacy Policy explains how RaffWorks ("we", "us", "our") handles your information when you use AES Automated Email Sender ("the Software") and our website and services at raffworks.com.my.
1. Information We Collect
When you purchase a license or register a trial:
- Your name and email address: to generate and deliver your license key
- Payment information: processed securely by BillPlz; we never store your card or bank details
- A hashed device identifier (machine ID): used to lock your license to your device
When you use the Software:
- License key validation requests: your license key and machine ID are sent to our server to verify your license status
- No email content, no recipient lists, no attachments: these never leave your device
When you visit our website:
- Standard web server logs (IP address, browser type, pages visited): retained for up to 30 days for security and debugging
2. Your Email Credentials
Your Gmail App Password or SMTP credentials are encrypted using Fernet symmetric encryption and stored locally on your device only in a config.ini file beside the application. We have no access to these credentials at any point.
3. How We Use Your Information
- To generate, deliver, and validate your license key
- To process payments via BillPlz
- To send transactional emails (license key delivery, portal login links) via Resend
- To provide customer support when you contact us
- To detect and prevent abuse (e.g. trial system anti-abuse checks)
4. Third-Party Services
We use the following third-party services, each with their own privacy policies:
- BillPlz: payment processing (billplz.com/privacy)
- Resend: transactional email delivery (resend.com/privacy)
- Supabase: database hosting in Singapore region (supabase.com/privacy)
- Render: server hosting (render.com/privacy)
5. Data Retention
- License and order records are retained for the duration of your license plus 7 years for accounting purposes
- Trial registration records are retained to enforce the one-trial-per-device policy
- Portal session tokens expire after 15 minutes and are deleted automatically
- You may request deletion of your data by contacting us: subject to legal retention requirements
6. PDPA Compliance (Malaysia)
We are committed to complying with Malaysia's Personal Data Protection Act 2010 (PDPA). Your personal data is collected for the purposes stated above, processed lawfully, and is not sold or shared with third parties except as described in Section 4.
You have the right to access, correct, or request deletion of your personal data held by us. To exercise these rights, contact us at the address below.
7. Security
We use industry-standard security practices including encrypted connections (HTTPS), hashed identifiers, and access-controlled databases. However, no system is 100% secure: please keep your license key and device secure.
8. Children's Privacy
AES is a business productivity tool not directed at children under 13. We do not knowingly collect personal data from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the date at the top of this page. Continued use of the Software or our services after changes constitutes acceptance.
10. Contact Us
Questions about this Privacy Policy or your personal data?