Last updated: August 28, 2026
Privacy Policy
This policy explains how the Sekolah Client platform ("we", "the Platform") collects, uses, stores, and protects your Personal Data when you use our services.
By creating an account, placing a shipment booking, using the tracking service, or accessing the Platform in any way, you are deemed to have read and agreed to this Privacy Policy. If you do not agree with this policy, please do not use our services.
1. Definitions
- Personal Data — any information relating to an identified or identifiable person, whether alone or combined with other information.
- User — an individual or business entity that registers for and/or uses the Platform's services.
- Tenant — a logistics company or partner that uses the Platform to manage its operations, including its own customer data.
- Services — all Platform features, including but not limited to shipment booking, receipt tracking, rate checking, online payments, support tickets, and the management portal.
2. Data We Collect
2.1 Account Data
When you register, we collect your username, email address, password (stored in hashed form and never readable in plain text), time zone, and language preference.
2.2 Shipment Data
When you place a shipment booking, we collect sender and receiver data, including: name, address, phone number, goods description and value, weight, dimensions/volume, service type, and any voucher code used.
2.3 Location Data (Geolocation)
We collect location data (latitude and longitude) on shipment tracking events and on Proof of Delivery (POD) photos, including location accuracy, to ensure accurate shipment position information.
2.4 Transaction & Payment Data
We record transaction data such as reference numbers, gateway transaction IDs, Virtual Account numbers, payment links, transaction amounts and currencies, as well as request/response data for audit and reconciliation purposes.
We do NOT store credit/debit card data. All payments are processed through the payment pages of third-party payment providers (redirect/hosted), so your card data never passes through or is stored on our servers.
2.5 Support & Communication Data
When you contact us through the contact form, chatbot, or support tickets, we collect your name, email address, subject, message content, and communication history to handle and resolve your requests.
2.6 Device & Technical Data
We collect technical data such as IP address, browser type and version, device type, and a device identifier used for offline data synchronization, security, and fraud prevention.
2.7 Company Data (Tenant)
For platform tenants (logistics companies), we collect company data such as legal name, display name, address, tax ID, logo, email, and company phone number, along with the operational data managed through the Platform.
3. How We Use Data
We use the data we collect for the following purposes:
- Providing, operating, and improving the Services, including shipment booking, receipt tracking, and rate checking;
- Processing payments and performing financial reconciliation;
- Sending important notifications via email, WhatsApp, or other channels you use, such as shipment status and transaction confirmations;
- Performing cross-device data synchronization (offline sync);
- Handling support tickets and user inquiries;
- Maintaining Platform security and preventing misuse, fraud, and illegal activity;
- Creating audit records for compliance and governance;
- Analyzing Services usage in aggregate and anonymous form to improve service quality;
- Complying with applicable laws and regulations.
4. Cookies & Similar Technologies
We use cookies and similar technologies to support the Services:
- Session cookies — to maintain your login session;
- Security (CSRF) cookies — to protect forms from cross-site attacks;
- Identity/auto-login cookies — to remember your login session on your device (httpOnly);
- Device identifier cookie (offline_device_id) — to identify your device for the offline synchronization feature; valid for 365 days, stored with httpOnly and SameSite=Lax attributes.
You can configure your browser to reject cookies or warn you before cookies are set. However, some features of the Services may not work properly without cookies.
5. Sharing Data with Third Parties
We do not sell your Personal Data. We only share data as necessary to provide the Services, with:
- Payment Service Providers — Midtrans, Xendit, PayPal, Stripe, DOKU, Duitku, Tripay, OY!, and iPaymu. Shared data is limited to customer name, payment amount, and transaction reference. Card data is never shared because payments are processed on the provider's pages.
- Data Synchronization Provider — a backend service (Supabase) that supports offline data synchronization across your devices.
- Cloud Storage Provider (S3/MinIO) — to store Proof of Delivery (POD) photos, document photos, attachments, and other shipment files.
- WhatsApp Notification Provider (Fonnte) — phone numbers and message content are transmitted to send shipment status notifications.
- Artificial Intelligence (AI) Service Providers — for the chatbot feature, your messages and conversation history may be processed by AI providers (e.g., OpenAI, Anthropic, Gemini) according to the tenant's configuration. Access credentials to AI providers are stored encrypted.
- Email Provider (SMTP) — to send verification emails, password resets, and notifications.
- Authorized Authorities — when required by law, regulation, or a valid court order.
Each platform tenant (logistics company) may operate its services on its own custom domain. In such cases, shipment data is managed under that company's own privacy policy and in accordance with the agreement between the company and its customers.
6. Data Security
We implement reasonable security measures to protect your Personal Data, including:
- Password encryption with a strong hashing algorithm (bcrypt);
- Encryption of sensitive credentials (e.g., gateway API keys) with AES-256 encryption;
- Identity cookies with the httpOnly attribute to prevent access from client-side scripts;
- Multi-tenant data isolation and role-based access control (RBAC);
- Activity logging (audit logs) for important data changes;
- Encrypted connections (TLS/HTTPS) for data transmission.
However, no method of transmission or storage is completely secure. We cannot guarantee absolute security of your data.
7. Data Storage & Retention
We retain your Personal Data for as long as necessary to provide the Services and fulfill the purposes described in this policy, or for as long as required by applicable laws and regulations (for example, tax and bookkeeping purposes). Once no longer needed, the data will be deleted or anonymized.
8. Your Rights
Under applicable laws (including the Indonesian Personal Data Protection Law), you have the right to:
- Request information about the processing of your Personal Data;
- Access and obtain a copy of your Personal Data;
- Request correction of inaccurate or incomplete data;
- Request deletion or cessation of processing, subject to certain limitations;
- Withdraw previously given consent;
- Object to the processing of your data;
- Submit a complaint to the competent authorities.
To exercise these rights, contact us via the details in Section 10. We will respond to your request within a reasonable period in accordance with applicable regulations.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Platform or other appropriate channels. By continuing to use the Services after changes take effect, you are deemed to accept the updated policy.
10. Contact
If you have questions, requests, or complaints regarding this Privacy Policy or the processing of your Personal Data, please contact us at:
- Legal entity name: [Company Legal Entity Name]
- Address: [Head Office Address]
- Email: [[email protected]]
- Phone/WhatsApp: [phone number]
Last updated: August 28, 2026. This document applies to all Services provided by Sekolah Client.