Privacy

What we collect, in plain terms.

English · Baca dalam Bahasa Malaysia →

Last updated 3 September 2026. Plaza is operated by DUOCODE TECHNOLOGY (registration no. LA0087244-A), a business registered in Malaysia ("we", "us"), and is part of the polyagent product family. Questions go to duocodetechu@gmail.com.

What we collect

A waitlist email. If you ask for early access, we collect the email address you submit. The form is delivered through Web3Forms, which passes the submission to our inbox on our behalf. That is the only thing you hand us directly.

Usage analytics. Every page — the marketing site and the product at /app alike, whether or not you are signed in — loads Umami, so we can see which parts of Plaza get used. It records page views, referrer, and a coarse country and device type derived from your IP address, which is not stored. It sets no cookie and gives you no identifier that persists between days, so there is no analytics cookie to accept or refuse. Our Umami instance is self-hosted on a DUOCODE TECHNOLOGY server at fluentdojo.com, so these page views go to us and to no advertising network. Vercel Analytics, which our host provides, records page views the same way. None of it is used to build advertising profiles, and Plaza shows no ads.

Until September 2026 this site also loaded Google Analytics 4, which did set an identifier cookie. It has been removed, and nothing here loads it any more.

A GitHub profile, if you sign in. Signing in is optional — everything except your own profile page works without it. When you do, we store what GitHub returns about your public profile: your GitHub numeric id and login, display name, avatar image URL, bio, the location text on your profile, and the links listed on it. That record is what other people see when Plaza matches you, and it is refreshed from GitHub each time you sign in.

Measurements of your public repositories. Alongside that profile we store what we measured from your public GitHub activity and the Trust Score we compute from it: per-repository language byte counts, repository topics, star counts and how recently each was pushed, plus the five components behind the score — account age, number of public repositories, followers, repositories pushed in the last 90 days, and stars on your own work. We keep these because every match Plaza shows cites the repositories and the arithmetic behind it, and a number nobody can check is not evidence. It is all measured from data GitHub already publishes; we read nothing private.

What you post. If you publish a need — a request for collaborators — we store its title, summary and the skills you list, along with which profile owns it.

Requests you send, and messages in them. To reach someone on Plaza you send a request: we store who sent it, who it was sent to, why you are reaching out (one of collaborate, hire, advice or contribute), the pitch you wrote, whether it is pending, accepted, declined or withdrawn, and when it was sent and last changed. If the person accepts, the two of you can write messages inside that request, and we store each message, its author and its time. Both people in a request can read it. Nobody else can, and we do not publish it. A message cannot exist without an accepted request, so nobody receives a cold approach they did not agree to; we also cap how many requests you can send in a day. Plaza never shows either of you the other's email address, because it does not hold one.

What we do not collect

No contacts, photos, files, health data, or payment details, and no password: sign-in goes through GitHub, so we never see your credentials. Plaza has no in-app purchases. The only location we hold is the free-text line you chose to put on your public GitHub profile; we do not read device location.

How we use it

To run the waitlist and let you know when Plaza opens; to build your public builder profile, rank it against the skills someone is searching for, and show the evidence behind each match; to carry requests and messages between the people who agreed to them and to enforce the limits that keep them from becoming spam; and to understand how the product is used so we can improve it. We do not sell your personal data, and we do not use it for advertising.

Who else touches it

Only the service providers that make Plaza work: GitHub (sign-in, and the public profile data it returns), Web3Forms (waitlist delivery), and Vercel (hosting and analytics). Our analytics instance is self-hosted by DUOCODE TECHNOLOGY rather than run by a third party. Each provider processes data solely to provide its service to us. Our database is hosted with Supabase, on servers in the United States, so running Plaza involves transferring your data outside Malaysia.

Deleting your account and data

Email duocodetechu@gmail.com from the address you signed up with, or naming your GitHub login, and say what you want removed. We delete on request and confirm by reply.

What gets deleted. Your Plaza profile — the GitHub id and login, display name, avatar URL, bio, location and links copied from your public GitHub profile, together with the repository measurements and Trust Score computed from them — along with any needs you posted, every request you sent or received and every message in them, and your waitlist entry, if you left one. Deleting a profile removes it from matching immediately. Nothing of yours is kept afterwards except what we are legally required to retain; we hold no payment or identity records, because Plaza collects neither.

Deleting only part of it. Ask for that instead and we will do it — for example removing a single posted need, or your waitlist entry, while leaving your profile in place.

Your other choices

Email the same address to see or correct what we hold, or to limit how we use it. Our analytics sets no cookie, so there is no analytics cookie to refuse; if you would rather not be counted at all, a browser tracker blocker stops it, and everything on the site keeps working.

How long we keep it

Waitlist entries stay until you ask us to remove them or the waitlist closes. Your profile, the measurements behind it, your posted needs and your requests and messages stay while your profile exists, and go when you ask us to delete it.

Your rights under Malaysian law

Plaza is operated from Malaysia and we handle personal data in accordance with the Personal Data Protection Act 2010. Under that Act you may ask us for a copy of the personal data we hold about you, ask us to correct it if it is wrong or incomplete, ask us to limit how we process it, and withdraw a consent you previously gave. Use the email address above; we reply to every request. If you are not satisfied with how we have handled one, you may complain to the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi), Malaysia.

This notice is published in English and in Bahasa Malaysia as required by section 7(2) of that Act. If the two versions disagree, the English version prevails. Baca notis ini dalam Bahasa Malaysia →

Children

Plaza is not directed at children under 13 and we do not knowingly collect data from them.

Changes

We will update this policy as the product changes; material changes show up in the date at the top.