Legal

Privacy Policy

Last updated 11 May 2026

This Privacy Policy explains what personal data Protinku collects when you use protinku.com or place an order with us, how we use it, and the rights you have under Indonesian law.

1. Who is responsible for your data

The data controller is Protinku, NPWP 91.102.081.6906.000, Perumahan Griya Panji Asri Blok N 4, Sukasada, Buleleng, Bali, Indonesia. You can reach us at protinku.bali@gmail.com or by WhatsApp on the number shared after you place an order.

This Policy works alongside our Terms & Conditions and covers the website, our order flow, and our communication with you about your order.

2. What data we collect

Order data — when you check out, we collect the information you fill in: your full name, contact number (for delivery orders or where needed), delivery address and postal code (for delivery orders), any courier notes you add, the items in your order, your chosen fulfillment method, and your chosen payment method.

Communication data — when you contact us by WhatsApp or by email, we keep the content of that conversation as needed to handle your order, answer your question, or comply with the law.

Browser storage — your cart is saved in your browser's localStorage so the items stay there if you reload the page. This data lives on your device, not on our servers, and is cleared when you clear your browser storage.

Payment data — for QRIS payments, the payment data (such as the source account or wallet) is collected and processed by Midtrans (PT Midtrans), not by us. We only receive a payment status (success / pending / failed) and a reference for that transaction.

We do not use any web analytics, advertising pixels, third-party tracking cookies, or session-replay tools on this site.

3. Why we use your data

We use your data only for the following purposes:

To process, fulfill, and deliver your order, including coordinating pickup or sharing your address with a courier where delivery applies.

To communicate with you about your order — confirmations, payment updates, pickup readiness, delivery tracking, and after-sale issues such as a damaged item.

To keep records of sales and payments as required by Indonesian tax and accounting rules.

To prevent fraud and to protect the legitimate interests of our customers and our business.

To respond to legal requests where we are required to do so.

We do not use your data for marketing without your consent, and we do not profile you.

5. Who we share data with

We do not sell your data. We only share it with the parties below and only to the extent needed for the purpose:

Midtrans (PT Midtrans) — for processing QRIS payments. Midtrans receives the data needed to handle the transaction and processes it under its own privacy policy.

Couriers and delivery partners — when your order is delivered to an address, we share your name, contact number, address, and order details with the courier so they can deliver it.

WhatsApp / Meta — when we contact you via WhatsApp, the content of that conversation passes through and is stored by WhatsApp (operated by Meta), which may store data outside of Indonesia. WhatsApp's own privacy policy applies to that storage.

Hosting and infrastructure providers — the website is hosted on standard cloud infrastructure. These providers do not have access to identifiable customer data beyond what is needed to keep the site running.

Authorities — where we are required to disclose data under a valid legal request, we will do so.

6. Where data is stored and for how long

Order records (including invoices and basic customer details) are kept for as long as required by Indonesian tax and accounting law — typically up to 10 years from the date of the transaction.

WhatsApp and email conversations are kept only as long as we need them to handle your order and to handle any after-sale issue. After that we may delete them.

Your cart data, stored in your own browser's localStorage, stays there until you clear your browser storage or place the order; we do not have access to it.

Some of our service providers (such as WhatsApp / Meta and certain cloud services) may store data on servers located outside of Indonesia. When this happens, we rely on the safeguards provided by those providers and by Indonesian law.

7. Your rights

Under UU PDP, you have the right to:

Access the personal data we hold about you.

Correct or update your personal data if it is inaccurate or incomplete.

Delete your personal data, subject to our legal duty to keep certain order and tax records.

Withdraw any consent you have given (where consent is the legal basis we relied on).

Object to or restrict processing in certain cases.

Lodge a complaint with the relevant Indonesian data protection authority if you believe we have not handled your data correctly.

To exercise any of these rights, email us at protinku.bali@gmail.com from the address or phone number used for the order, so that we can verify your identity. We will respond within a reasonable time, and in any event within the time required by law.

8. How we protect your data

We use reasonable technical and organisational measures to protect your data, including HTTPS for all traffic to the website, limiting access to order data to people who need it, and using established providers (such as Midtrans for payments).

No method of transmission or storage is 100% secure. If we ever become aware of a personal data breach that puts your rights or freedoms at risk, we will notify you and the relevant authority as required by UU PDP.

9. Children's data

Our products are not directed at children. We do not knowingly collect personal data from anyone under 18 without the involvement of a parent or legal guardian. If you believe we have collected data from a minor, please contact us and we will take appropriate steps.

10. Changes to this Policy

We may update this Privacy Policy from time to time. The current version is always available at this URL, and the "Last updated" date at the top reflects when it last changed. Material changes will be communicated through the website.

11. Contact

If you have any question about this Policy or about how we handle your data, please reach out:

Protinku

Perumahan Griya Panji Asri Blok N 4, Sukasada, Buleleng, Bali, Indonesia

NPWP: 91.102.081.6906.000

Email: protinku.bali@gmail.com