Legal
Privacy Notice.
Last updated 5 August 2026
We are a restaurant group, not a data business. We would rather you spent your attention on the food. But you trust us with a few pieces of information when you book a table or send us a message, and you deserve a straight account of where that information goes. This notice is issued under Malaysia's Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727). Under that law we are a data controller — the term the Act used to call a "data user". It covers jibrilgroup.com and the ways you get in touch with us through it. It does not cover what happens on other companies' apps and websites once you leave ours, and it does not cover what happens inside our restaurants.
The short version
- We do not run our own booking system any more. Table reservations are handled inside UMAI, a booking platform we hire. Your booking details go to UMAI, and we read them there.
- We have no newsletter sign-up and no contact form on this site. If you want to reach us, you email, call, WhatsApp, or use the chat bubble.
- Four third parties receive something from your browser on every page you open here, whether or not you interact with anything: Google, UMAI, respond.io, and our host Vercel. The map on the homepage adds two more.
- One of those — a tag container we do not control — is an arrangement we are not comfortable with and are working to remove. We explain it below rather than bury it.
- We do not sell your personal data.
- If you want your data, want it corrected, or want us to stop — one email to hello@jibrilgroup.com does it.
Who we are, and how to reach us
JIBRIL Restaurant Group is operated by De Oratore Sdn Bhd (Company No. 201701047463 (1261639-H)), trading as JIBRIL Restaurant Group. We run five outlets: SS15 Subang Jaya, Publika, Bangi, Setapak, and Johor Bahru.
For anything about your personal data — questions, requests, complaints — write to hello@jibrilgroup.com.
What you have to give us, and what happens if you don't
Malaysian law asks us to tell you plainly whether giving us your personal data is voluntary or obligatory, and what follows if you don't. So:
- Booking a table: giving your name, a contact number and your party details is voluntary, but the booking cannot be held without them. There is nothing we can do about that — we need to know who to expect and how to reach you if the kitchen floods.
- Writing, calling or messaging us: entirely voluntary. Whatever you choose to put in the message is what we get.
- Applying for a job: voluntary, but we cannot consider an application with no way to contact you.
- Browsing the site: you are not asked for anything, but your browser sends technical information automatically, as described below. See "Your choices" for what you can switch off.
We also collect some information about you from somewhere other than you: booking details reach us through UMAI's platform rather than directly, and our analytics receive information from your browser rather than from anything you type.
Booking a table: UMAI
This is the biggest change since our last notice, so we will be clear about it.
Until August 2026 we ran our own reservation system, and your booking details landed in our own database. We do not do that any more. That system was retired on 3 August 2026.
Booking now happens inside a widget supplied by UMAI, a restaurant booking platform (you will see widget.letsumai.com and reservation.umai.io in your browser). Two things happen with UMAI, and they are worth separating.
First, the UMAI script loads on every page of this site, not only when you book. That means UMAI's servers receive the ordinary technical information any web request carries — your IP address, your browser and device type, and which page you were on — even if you never open the booking form.
Second, if you do open the form and book, the details you type go directly into UMAI's systems: your name, contact details, the outlet, the date and time, your party size, and anything you add in the notes or special requests box. They do not pass through a JIBRIL database on the way.
We are still responsible for that information. We hire UMAI to hold and handle your booking data for us, and we read it through the UMAI dashboard so we can hold your table, ring you if plans change, and know that it is your anniversary before you have to mention it. UMAI is also a business in its own right; where it uses data for its own purposes rather than ours, it is acting on its own account and its own privacy policy governs that. We would encourage you to read it.
If you would rather not use the widget at all, call the outlet or WhatsApp us and we will take the booking by hand.
The system we retired
Our old in-house booking system stored guest records — names, phone numbers, email addresses, notes and past bookings — in a database hosted in Singapore by Supabase, a cloud database provider.
The live website no longer reads from or writes to that database. What remains in it, and for how long, is something we are settling as part of this review: Records created by that system still sit in a database the website no longer connects to. We are closing it down, and until we have, access is limited to the people who administer it..
We would rather tell you the system exists and that we are dealing with it than let you assume it vanished when the booking page did.
Talking to us
Email, phone and WhatsApp. Our contact page gives you an email address, outlet phone numbers, and WhatsApp links. There is no form to fill in. When you email or message us we get whatever you send — your name, your number or address, and the contents of your message — and we keep the thread so we can pick up where we left off. Our mailbox is a Google Workspace account, so email you send us is stored on Google's systems. WhatsApp is run by Meta, and your use of it is governed by their terms and privacy policy, not ours.
Live chat. The chat bubble in the corner of the site is a webchat widget from respond.io (loaded from cdn.respond.io). Like the booking widget, the script loads on every page of the live site whether or not you click it, so respond.io receives the same basic connection information from every visitor. If you do open it, respond.io also handles the conversation for us — what you type, plus basic technical details about your visit — and our team replies from the respond.io console.
Applying for a job. Our careers page asks you to email us, so any CV, cover letter or portfolio you send arrives in that same inbox. If you are not successful we keep your application for twelve months in case something suitable opens up, and you can ask us to delete it sooner at any time.
Deposits for larger tables
For parties of five or more we may ask for a deposit, arranged with you over WhatsApp and deducted from your bill on the day.
The deposit is handled by the outlet team over WhatsApp or on the phone — this website cannot take payments and never sees a card or bank detail. Whatever the team needs to record a deposit is kept with the booking and used only to apply it to your bill.
When you are just looking around
The site is hosted on Vercel, which serves our pages from servers around the world. Like every web host, Vercel records standard server log information for each request — including your IP address, the page you asked for, the time, and your browser and device type. This is how the site gets delivered to you and how we spot abuse and outages.
One small clarification, since we name Google several times below: the fonts on this site are served from our own domain, not from Google's. Loading a page here does not send anything to Google's font servers.
The map on our homepage
The outlet map on our homepage is not a picture — it pulls its map tiles live from CARTO (basemaps.cartocdn.com), falling back to OpenStreetMap (tile.openstreetmap.org) if CARTO is unavailable. It starts loading as soon as the homepage opens, before you scroll to it or touch it.
That means those providers receive your IP address and can see roughly which part of the map is being displayed. We do not receive anything from them about you, and we never ask your browser for your location — the map does not request GPS permission at any point.
Our previous notice did not mention this at all. That was an omission, and this notice fixes it.
Analytics, and one thing we want to be straight with you about
There are two separate measurement systems running on this site. They are not the same thing and we are not going to pretend they are.
1. Our own analytics. We run a Google Analytics 4 property that belongs to JIBRIL, set up in August 2026, loaded from www.googletagmanager.com. It is not anonymous: it sets a cookie carrying a random ID for your browser, so repeat visits from the same device are recognised as the same visitor, and Google processes your IP address when it receives the data. We do not know your name from it and we do not try to work it out.
What it records is more specific than "pages viewed". As well as which pages you open, it records when you tap a phone number, a WhatsApp link, a directions link, an email address, the Oddle ordering link or a social link — and which outlet that link belonged to, and roughly where on the page you tapped it. We use this to see which outlets people are actually trying to reach and which parts of the site are getting in the way.
Two things we have deliberately switched off on our property: Google Signals, and ad personalisation. Our analytics data is not fed into advertising profiles by us.
2. A tag container that we do not control. The site also loads a Google Tag Manager container that was installed by a third party and is administered by them, not by us. It was kept when we rebuilt the site so that historical traffic figures stayed continuous, and we now think that was the wrong trade.
When the site was built in August 2026, that container loaded three further Google Analytics properties belonging to that third party, plus one obsolete tag. We cannot see the data in those properties, we cannot switch individual tags off from our side, and because the container is administered remotely its contents can change at any time without any change to this website and without anyone telling us. So we cannot promise that list is still complete as you read this.
We are telling you this because it is your data and you should know where it goes, even when the answer is unflattering. We are working to remove that container. Until it is gone, visiting jibrilgroup.com sends basic browsing information to a party we cannot identify to you.
Cookies and similar technologies
This site sets no cookies of its own. It stores nothing in your browser under our name — no first-party cookies, no local storage, nothing. Every cookie you will find on jibrilgroup.com was set by one of the third parties described above: Google for the analytics, respond.io for the chat, UMAI for the booking widget.
We want to be accurate about this: there is currently no cookie banner on jibrilgroup.com. Our previous notice said there was one. There was not, and saying so was wrong. At present the analytics, chat and booking scripts load when you open the site.
Your choices
Since nothing on the site is currently gated behind a consent prompt, here is what you can actually do:
- Block cookies and trackers in your browser. Most browsers can block third-party cookies outright, and privacy extensions can block the analytics, chat and booking scripts by name. Blocking them does not break the pages, the menu or the contact details; it will stop the chat bubble and the embedded booking form from working, in which case you can still book by phone or WhatsApp.
- Book by phone or WhatsApp instead of using the widget, if you would rather your booking details did not go through UMAI's form.
- Do not open the chat if you would rather not have a conversation stored with respond.io. Email or phone us instead.
- Email us at hello@jibrilgroup.com to ask us to stop processing your data, or to withdraw consent you gave earlier. See "Your rights" below.
One honest limitation: blocking scripts in your own browser is the only reliable way to stop the third-party tag container described above, because we cannot switch its tags off from our side.
What we use your information for
Short list, honestly kept:
- To hold your table and manage your booking, and to contact you about it.
- To answer you when you write, call or message us.
- To consider your job application.
- To run, secure, and improve the website.
- To understand how people use the site so we can make it less annoying.
- To meet obligations the law places on us — tax, accounting, food safety, licensing, and responding to lawful requests from the authorities.
Under Malaysian law we process your data with your consent, except where the Act allows processing without it — most often because it is necessary to perform the thing you asked us to do, such as holding your table, or because a law requires us to keep the record.
We do not currently run an email marketing list. If we start one, it will be opt-in, and unsubscribing will be one click.
Who else sees it
Our people. The outlet team and our operations, marketing and management staff, on a need-to-know basis.
Companies we hire to run parts of the operation:
- UMAI — reservations
- respond.io — live chat
- Vercel — website hosting and delivery
- Google — analytics for our own property, and the Google Workspace mailbox that receives your emails
- Supabase — the database behind our retired booking system
Third parties we do not control, described above: the third-party tag container and the analytics properties it loads, and the map tile providers CARTO and OpenStreetMap.
Authorities, regulators, insurers and our professional advisers, where the law requires it or where we need advice.
We do not sell your personal data, and we do not rent or trade it for marketing.
Links that take you somewhere else
Several buttons on our site hand you over to someone else's platform. Once you are there, you are on their turf and their privacy policy applies, not ours:
- WhatsApp (wa.me links) — operated by Meta
- Waze and Google Maps, for directions to an outlet
- Oddle (jibril.oddle.me) — pickup ordering
- Instagram, TikTok and Facebook — our social accounts
We get no personal data back from any of these. As described in the analytics section, our own analytics do record that a link of a given type, for a given outlet, was tapped — not who tapped it, and not what happened after you arrived.
Sending data outside Malaysia
Several of the companies above store or process data on servers outside Malaysia — our retired booking database sits in Singapore, and our host serves pages from wherever you happen to be. That is normal for cloud services, and Malaysian law permits it, but since April 2025 the rules have changed: instead of relying on a government-published list of approved countries, we now have to assess each destination ourselves and be able to show our working.
In practice that means we satisfy ourselves that the data is protected to the standard Malaysian law demands before we send it, and we hold each provider to that.
Several of the companies named in this notice are based outside Malaysia, and some of them process data on servers outside Malaysia. If you want to know where a particular one holds your information, ask us and we will tell you what we know.
How long we keep things
The principle is simple: we keep personal data only for as long as we actually need it for the purpose we collected it for, or for as long as the law requires us to, and then we delete it or strip out anything that identifies you.
We are not going to invent numbers here. We keep each thing only as long as we need it for the purpose we collected it for, and then we get rid of it. In practice that means a booking record stays while it is still useful to us as a restaurant, chat and email stay while the conversation is live and for a reasonable period after it closes, and job applications are kept for twelve months. Ask us to remove something sooner and we will, unless the law requires us to keep it.
Some records we have no choice about: accounting and tax records must be kept for the period Malaysian law prescribes, whatever our own preference would be.
Keeping it safe
We take reasonable technical and organisational steps to protect personal data: access is limited to the people who need it, connections to this site are encrypted, and the companies we hire are themselves now directly answerable under Malaysian law for the security of the data they process for us.
No website and no company can promise perfect security, and we are not going to pretend otherwise. What we can promise is that we treat it as our problem rather than yours.
If something goes wrong
Malaysian law now requires us to report serious personal data breaches. If a breach happens that causes, or is likely to cause, significant harm to anyone, we must notify the Personal Data Protection Commissioner as soon as practicable, and in any event within 72 hours of discovering it or being told about it. Where a breach affects a very large number of people, it must be reported to the Commissioner even if significant harm has not been established.
Where the law requires it, we will also tell the people affected without unnecessary delay, and in any event within 7 days of notifying the Commissioner — what happened, what data was involved, and what to do about it.
Your rights
Under the Personal Data Protection Act you can:
- Ask for a copy of the personal data we hold about you, and be told how we are using it. The Act gives us 21 days to respond to an access request.
- Ask us to correct it if it is wrong, out of date or incomplete.
- Withdraw your consent to processing you previously agreed to.
- Ask us to stop processing that is causing, or is likely to cause, you damage or distress.
- Tell us to stop using your data for direct marketing — at any time, no reason needed.
- Ask us to send your data directly to another organisation. This right came into force in June 2025 and applies where the transfer is technically feasible and the formats are compatible. Detailed official guidance on how it should work in practice has not been issued yet, so we will handle requests case by case and tell you honestly what we can and cannot do.
To use any of these, email hello@jibrilgroup.com and say what you want. We may need to check that you are who you say you are before we act — that protects you, not us.
For booking data, we may need to work with UMAI to fulfil your request. We will do that; you should not have to chase two companies.
The Act allows us to charge a fee for an access request. We do not.
If you are not happy with how we have handled your request, you can complain to the Personal Data Protection Commissioner, who heads the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi), at pdp.gov.my. We would rather you came to us first and gave us the chance to put it right.
If you are under 18
Our site is built for adults booking meals, but we know a seventeen-year-old might well book a birthday dinner.
Under Malaysian data protection rules, if you are under 18 we need the consent of your parent or guardian before we process your personal data. So if you are booking a table, sending us a message, or applying for a job with us and you are under 18, please make sure a parent or guardian is happy for you to give us your details.
If your child has given us information and you would rather we did not have it, write to hello@jibrilgroup.com and we will remove it.
What this notice does not cover
This notice is about the website. It does not cover what happens when you walk into one of our restaurants — the point-of-sale system, CCTV, guest WiFi, or anything else on the premises — or our own staff and payroll records. Those are handled separately.
Changes to this notice
We will update this notice when what we do changes — new tools, retired systems, new legal requirements. The date at the top always shows the current version. If a change is significant, we will say so on the site rather than quietly swapping the text.
The last substantial rewrite was this one, prompted by the move to UMAI and by the amendments to Malaysia's data protection law that took effect through 2025.
Contact
hello@jibrilgroup.com
JIBRIL Restaurant Group
De Oratore Sdn Bhd (Company No. 201701047463 (1261639-H))
Come and eat with us. We will look after both the table and the details.
Prepared on 5 August 2026 against the site as it actually stands. It has not yet been reviewed by a Malaysian lawyer, and a Bahasa Malaysia version is required alongside it. The terms of use were rewritten in the same release and agree with this notice on how bookings work. Open questions for counsel are tracked in the repository, not here.
