Privacy & Cookies

Privacy and Cookies policy


Version 1.0. Effective as of 27th August, 2018

At Tesco, we’re working hard to serve shoppers a little better every day. Looking after the personal data you share with us is a hugely important part of this. We want you to be confident that your data is safe and secure with us, and understand how we use it to offer you a better and more personalised shopping experience.


What this policy covers

We, Tesco Stores (Malaysia) Sdn. Bhd. (referred to in this policy as “we”, “us” or “Tesco”), are committed to doing the right thing when it comes to how we collect, use and protect your personal data. That’s why we’ve developed this privacy and cookies policy (“Policy”), which:

  1. sets out the types of personal data that we collect;
  2. explains how and why we collect and use your personal data;
  3. explains when and why we will share personal data within the Tesco Group and with external partners; and
  4. explains the rights and choices you have when it comes to your personal data.

We offer a wide range of products and services, so we want you to be clear about what this Policy covers. This Policy applies to you if you use our services (referred to in this Policy as “our Services”).

Using our Services means:

  1. shopping with us in our stores, or by using Grocery Home Shopping, or otherwise using any of the websites (“our Websites”) or mobile applications (“Our Mobile Apps”) where this Policy is posted;
  2. being a member of the Clubcard/Clubcard Biz loyalty programme (“Clubcard”);
  3. signing up for electronic direct marketing communication such as newsletter you receive from us via e-mail or SMS; or
  4. signing up for membership in our customer clubs, or take part in surveys, competitions or events organised by us.

This Policy also applies if you contact us or we contact you about our Services.


Parts of this Policy also apply to our store CCTV systems where they capture footage of you.


Some parts of our business and other Tesco Group Companies may need to collect and use personal data to provide you with their products and services and for certain other purposes. They have their own privacy policies that explain how they use your personal data when you interact with them or use their products or services.

Our Websites or Mobile Apps may contain links to other websites operated by other organisations that have their own privacy policies. Please make sure you read the terms and conditions and privacy policy carefully before providing any personal data on a website as we do not accept any responsibility or liability for websites of other organisations. 

We process your personal data in accordance with the Personal Data Protection Act 2010.

Personal data we collect

This section tells you what personal data we may collect from you when you use our Services and what other personal data we may receive from other sources.


All information requested is obligatory to be provided by you unless stated otherwise. Should you fail to provide the obligatory information we may be unable to:

  1. provide you with our Services; or
  2. process your request.
When you register for our Services, you may provide us with:
  1. Your personal details, including your postal and billing addresses, email addresses, phone numbers and date of birth and title. This list is not exhaustive and may include other relevant personal details (depending on the nature of the transaction).
  2. Information relating to your membership of any of our clubs, such as Clubcard.
  3. The location of your closest or favourite Tesco store.
  4. Your account login details, such as your username and the password that you have chosen.
When you shop with us by using Grocery Home Shopping or browse our Websites or use our Mobile Apps, we may collect:
  1. Information about your online purchases (for example, what you have bought, when and where you bought it and how you paid for it)
  2. Information about your online browsing behaviour on our Websites and Mobile Apps and information about when you click on one of our adverts (including those shown on other organisations’ websites)
  3. Information about any devices you have used to access our Services (including the make, model and operating system, IP address, browser type and mobile device identifiers, date and time of your access to our Services, address of website you were re-directed from to our website, other data transmitted through standard HTTP(s) request headers, data used to maintain online session after logging in)
When you use Clubcard to shop with us, or use Clubcard vouchers or coupons, or any reward or benefits, we may collect:
  1. Transaction information, including the in-store and online purchases you earn Clubcard points for and how you use your Clubcard coupons and vouchers within us, the Tesco Group or with our Clubcard Partners
When you contact us or we contact you or you take part in promotions, competitions, surveys or reviews about our Services, we may collect:
  1. Personal data you provide about yourself anytime you contact us about our Services (for example, your name, username and contact details, your Clubcard number), including by phone, email or post or when you speak with us through social media
  2. Details of the emails and other digital communications we send to you that you open, including any links in them that you click on (for example those that enable us to know whether and when you opened that communication).
  3. Your feedback and contributions to customer surveys or reviews
When you visit our stores
  1. Footage of you may be recorded by our CCTV equipment and kept in on our CCTV systems together with date and time of your visit and details about Tesco store you visited
When you participate in charity or CSR events we organise or when we support other entities, to run them
  1. Personal data you provide about yourself or your family members (which may include also data about your children), for example, name, username and contact details (including phone number, email or postal address) as well as other information about your or your family personal (including health) situation, according to separate terms & conditions based on which these events are organised
  2. Your feedback and contributions to surveys or reviews

We may also use personal data from other sources, such as specialist companies that supply information or online media channels (which include websites, social media sites, pay TV providers and any other channels that become available to us) (“Online Media Channels”). For example, this other personal data helps us to improve and measure the effectiveness of our marketing communications, including online advertising.


How and why we use personal data

This section explains in detail how and why we use personal data.


We use personal data to This means that processing your personal data allows us to Why do we process your personal data in this way?
Make our Services and membership rewards benefit available to you Manage the accounts you hold with us, including your Clubcard and Grocery Home Shopping account. Process your orders and refunds. Personal data you provide about yourself or your family members (which may include also data about your children), for example, name, username and contact details (including phone number, email or postal address) as well as other information about your or your family personal (including health) situation, according to separate terms & conditions based on which these events are organised

We need to process your personal data so that we can manage your customer accounts, provide you with the goods and services you want to buy and help you with any orders and refunds you may ask for.

We also need to process your personal data so that we can provide you with the Clubcard statement, with your Clubcard points, vouchers and/or coupons you earned while being our loyal customer.

Manage And improve our day-to-day operations Manage and improve our Websites and Mobile Apps We use cookies and similar technologies on our Websites and Mobile Apps to improve your customer experience.

Some cookies are necessary so you should not disable these if you want to be able to use all the features of our Websites and Mobile Apps. You can disable other cookies but this may affect your customer experience. For more information about cookies and how you can disable them, see the Cookies section below.
Help to develop and improve our product range, services, stores, information technology systems, know-how and the way we communicate with you We rely on the use of personal data to carry out market research and internal research and development, and to improve our information technology systems (including security) and our product range, services and stores. This allows us to serve you better as a customer.
Detect and prevent fraud or other crime It is important for us to monitor how our Services are used to detect and prevent fraud, other crimes and the misuse of services. This helps us to make sure that you can safely use our Services in line with applicable terms and conditions.
Personalise your Tesco experience Use your online browsing behaviour as well as your in-store and online purchases (including Clubcard and/or Grocery Home Shopping transactions) to help us better understand you as a customer and provide you with personalised offers and services. Looking at your browsing behaviour and purchases allows us to personalise our offers (in terms of our product range, promotions, prices etc.) and services for you. This helps us meet your needs as a customer.
Provide you with relevant marketing communications (including by email, SMS, post, online advertising or social media platforms or WhatsApp communication or delivered to you at the till when you shop in our stores), relating to our products and Services, including Clubcard or Grocery Home Shopping, and those of our suppliers, Tesco Partners and the Tesco Group.

As part of this, online advertising may be displayed on websites across the Tesco Group and on other organisations’ websites and (including for example through Google AdWords). We may also measure the effectiveness of our marketing communications and those of our suppliers and Tesco Partners.
We want to ensure that we provide you with marketing communications, including online advertising, that are relevant and personalised to your interests. To achieve this we also measure your responses to marketing communications relating to products and services we offer, which also means we can offer you products and services that better meet your needs as a customer.

You can change your marketing choices, both when you register with us, and at any time after that.

You also have choices when it comes to online advertising. We set out below your choices when it comes to cookies, and how you can control your online behavioural advertising preferences.
Invite you to take part in and manage customer surveys, reviews and other market research activities carried out by the Tesco Group and by other organisations on our behalf. We carry out market research to improve our Services as well as tailor personalised offers and promotions for you. However, if we contact you about this, you do not have to take part in the activities. If you tell us that you do not want us to contact you for market research, we will respect this choice. This will not affect your ability to use our Services or your Clubcard.
Contact and interact with you Contact you about our Services, for example by phone, email or post or social media platforms or by responding to social media posts that you have directed at us. We want to serve you better as a customer so we use personal data to provide clarification or assistance in response to your communications as well as to inform you about the changes we made or are going to make to our Services that affects you (such as changes to this Policy or to the terms & conditions of our Services).
Manage promotions and competitions you take part in, including those we run with our suppliers and Tesco Partners. We need to process your personal data so that we can manage the promotions and competitions you choose to enter.
Invite you to take part in and manage customer surveys, reviews and other market research activities carried out by the Tesco Group and by other organisations on our behalf. We carry out market research to improve our Services as well as tailor personalised offers and promotions for you. However, if we contact you about this, you do not have to take part in the activities. If you tell us that you do not want us to contact you for market research, we will respect this choice. This will not affect your ability to use our Services or your Clubcard.
Disputes, complaints or claims In order to resolve complaints, legal claims or disputes involving you or us. For example if you are not satisfied with the products you bought from us or you have any accident or there is an incident at our stores. In some cases this could include medical reports.
CCTV To monitor the safety of our stores in order to prevent and detect crime and anti-social behaviour. In order to protect our business, the local community, customers and our employees.

To help us to better understand you as a customer and to be able to provide you with services and marketing communications, including online advertising, that are relevant to your interests we also combine personal data we collect when you make purchases in-store using Clubcard with personal data collected from our Websites or Mobile Apps.

Sharing personal data within the Tesco Group (within or outside of Malaysia)

This section explains how and why your personal data may be shared with other companies within the Tesco Group. We may share with other entities in the Tesco Group the personal data we collect or we receive such data from other Tesco Group entities. For example, we share personal data with the following Tesco Group companies in order to help us provide you with our Services:


Tesco Lotus (Thailand)

Tesco Lotus carries out certain functions on our behalf, helping us with providing our Services to our customers. It includes, for example, support in managing IT systems used for operating Clubcard, Grocery Home Shopping and electronic direct marketing, such as Tesco newsletters, which helps us to improve our services and make our marketing communications more relevant to you. Tesco Lotus will process only the data which is necessary to carry out these functions and according to our documented instructions.


Dunnhumby

Dunnhumby, part of the Tesco Group, is also one of our main service providers. dunnhumby help us to use encrypted personal data to help improve our understanding of customers and personalise your customer experience. For more information about dunnhumby, please visit: https://www.dunnhumby.com/malaysia


Sharing personal data with Tesco Partners and Service Providers (within or outside of Malaysia)

This section explains how and why we share personal data with Tesco Partners and Service Providers. When we share personal data with these companies we require them to keep it safe, and they must not use your personal data for their own marketing purposes, unless you separately gave them your consent for it.


Tesco Partners We work with a number of Tesco Partners who offer their products or services in cooperation with us, and/or offer the ability to earn points through Clubcard. We only share personal data that enable our Partners to provide their services. You can find more information about the way in which Tesco Partners use your data in their privacy and cookies policies.
Service Providers

We work with carefully selected Service Providers that carry out certain functions on our behalf. These include, for example companies that provide us with:


  1. technology services (for example support our Websites, Mobile Apps and other business systems we use to provide you with our Services);
  2. storing, combining and analysing data services;
  3. processing of payments on our stores or in Grocery Home Shopping;
  4. delivery services;
  5. direct marketing companies who send electronic communication, including Tesco newsletters, on our behalf
  6. printing and delivering our postal communications, including Clubcard statements, we send to our customers,
  7. legal or other professional services; as well as companies that operates our contact centres or manage and maintain CCTV in our stores.

We only share encrypted personal data that enable our Service Providers to provide their services.


Some of the Service Providers we work with operate Online Media Channels, and they place relevant for our products and services, as well as those of our suppliers, on those online media channels on our behalf.

Sharing personal data with other organisations

This section explains how and why we share personal data with other organisations.

We may share personal data with other organisations in the following circumstances:


  1. if the law or a public authority says we must share the personal data or for the administration of justice;
  2. if we need to share personal data in order to establish, exercise or defend our legal rights (this includes providing personal data to others for the purposes of preventing fraud); or
  3. where we restructure, sell or transfer our business (or a part of it). For example in connection with a takeover or merger.

How we protect personal data

We know how important it is to protect and manage your personal data. This section sets out some of the measures we have in place.


These include:


  1. We use computer safeguards such as firewalls and data encryption, and we enforce physical access controls to our buildings and files to keep this data safe. We only authorise access to employees who need it to carry out their job responsibilities.
  2. We protect the security of your information while it is being transmitted by encrypting it using Secure Sockets Layer (SSL).
  3. We enforce physical, electronic and procedural safeguards in connection with the collection, storage and disclosure of personal data. We may occasionally ask for proof of identity before we share your personal data with you.
  4. We will reveal only the last four digits of your credit card number when confirming an order.

However, whilst we take appropriate technical and organisational measures to safeguard your personal data, please note that we cannot guarantee the security of any personal data that you transfer over the internet to us.


The personal data that we collect from you may be transferred to, and stored at, a destination outside Malaysia. It may also be processed by companies operating outside Malaysia who work for us or for one of our service providers. If we do this we ensure that your privacy rights are respected in line with this Policy.


How long we use personal data for

We will not keep your personal data longer than we need to, how long this is depends on several factors, including:


  1. Why we collected it in the first place;
  2. How old it is;
  3. Whether there is a legal/regulatory reason for us to keep it; and
  4. Whether we need it to protect you or us.

Marketing and market research

This section explains the choices you have when it comes to receiving marketing communications and taking part in market research.


We will send you relevant offers and news about our products and services in a number of ways including by email, but only if you have previously agreed to receive these marketing communications. When you register with us we will ask if you would like to receive marketing communications, and you can change your marketing choices at anytime online, over the phone or by clicking the ‘unsubscribe’ link in any email communication that we send you.


We will then stop sending any further marketing emails, however please note that you may continue to receive such communications for a short period after changing your preferences until our systems are fully updated.


We also like to hear your views to help us to improve our Services, so we may contact you for market research purposes. You always have the choice about whether to take part in our market research.


Cookies

We and our partners use cookies and similar technologies, such as tags and pixels (“Cookies”), to personalise and improve your customer experience as you use our Websites and Mobile Apps and to provide you with relevant online advertising . This section provides more information about Cookies, including how we use them and how you can exercise your choices about our use of Cookies.

How we use Cookies

Cookies are small text files containing a unique identifier, which are stored on your computer or mobile device so that your device can be recognised when you are using a particular website or mobile app. They can be used only for the duration of your visit or they can be used to measure how you interact with services and content over time. Cookies help to provide important features and functionality on our Websites and Mobile Apps, and to improve your customer experience.


When you consent to cookies on our services, these may be used to do the following:


Improve the way our Websites and Mobile Apps work Cookies allow us to improve the way our Websites and Mobile Apps work so that we can personalise your experience and allow you to use many of their useful features. For example, we use Cookies so we can remember your preferences and the contents of your shopping basket when you return to our Websites and Mobile Apps.
Improve the performance of our Websites and Mobile Apps Cookies can help us to understand how our Websites and Mobile Apps are being used, for example, by telling us if you get an error messages as you browse. These Cookies collect data that is mostly aggregated and Anonymous (information which does not relate to an identified or identifiable natural person)
Deliver relevant online advertising, including via social media We use Cookies to help us deliver online advertising that we believe is most relevant to you on our Websites, on other organisations’ websites and using social media. Cookies used for this purpose are often placed on our Websites by specialist organisations.

Cookies used for this purpose are often placed on our Websites by organisations providing specialist services to us. These Cookies may collect information about your online behaviour, such as your IP address, the website you arrived from and information about your purchase history or the content of your shopping basket. This means that you may see our adverts on our Websites and on other organisations’ websites. You may also see adverts for other organisations on our Websites.

To help us to deliver online advertising that is relevant to you, we may also combine data we collect through Cookies in the browser of your desktop computer or other devices with other data that we have collected, for example your use of Clubcard and in-store purchases.
Measuring the effectiveness of our marketing communications, including online advertising Cookies can tell us if you have seen a specific advert, and how long it has been since you have seen it. This information allows us to measure the effectiveness of our online advertising campaigns and control the number of times you are shown an advert. We also use Cookies to measure the effectiveness of our marketing communications, for example by telling us if you have opened a marketing email that we have sent you.

Third parties operating through our Websites and Mobile Apps

Our key partners are listed below with information about the services they provide to us. This list is not exhaustive but it does include those partners with whom we have an established relationship and whose cookie technologies are most frequently deployed through our Services.


[Category] [How used] [Example(s) of partner]
Measurement & Personalisation To analyse how our services are used, including to test different content versions. This data may also be used to enable us to personalise our services and the marketing of our services.] Adobe, Google, Facebook, Instagram
Product Recommendation To enrich your shopping experience by delivering personalised recommendations to you on some of our websites Sizmek, Google, Facebook, Instagram
Online marketing To personalise Tesco adverts shown to you via Tesco and on other websites based on your interactions with Tesco. Facebook, Instagram, YouTube, Sizmek
Social Media To market to you via social media platforms and to enable social sharing and engagement on our websites. These companies may use your data for their own purposes, including to profile and target you with other advertising. Facebook, Instagram, YouTube

Your choices when it comes to Cookies

You can use your browser settings to accept or reject new Cookies and to delete existing Cookies. You can also set your browser to notify you each time new Cookies are placed on your computer or other device. You can find more detailed information about how you can manage Cookies through your browser’s help function and at www.allaboutcookies.org.

If you choose to disable some or all Cookies, you may not be able to make full use of our Websites. For example, you may not be able to add items to your shopping basket, proceed to checkout, or use any of our products and services that require you to sign in. You can also manage advertising related Cookies used on our Services by opting-out through the Service Providers listed in the table above.

Cookies work differently on Mobile Apps as they are coded into the App itself and will use a unique identifier created by your mobile device for use for advertising activities. You can turn off or reset this advertising identifier through your mobile device’s privacy settings.


Accessing and correcting your information

You have the right to see and correct the personal data we hold about you. If you would like a copy of the personal data we hold about you, or would like to amend your personal data, please contact our helpline on: 1300 13 1313.

How to contact us

If you have any questions about how we collect, store and use personal data please contact us.

Phone: 1300 13 1313

Write to us at:
Tesco Stores (Malaysia) Snd. Bhd. Kepong Village Mall, 3, Jalan 7A/62A, Bandar Menjalara, 52200 Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur

Email: tescohelpline@tesco.com.my

We reserve the right to change this Policy at any time, so please check back regularly to keep informed of updates to this Policy.

This Policy version 1.0 is effective as of 27th August 2018.

Last updated: n/a