Privacy Policy
Terakhir Diperbarui: 1 September 2026 · Versi 2026-09-01
At Laksa, we value and are committed to protecting your personal information and business data. This Privacy Policy explains how we (LAKSA BUSINESS VISION) collect, use, store, disclose, and protect your information when you use the Laksa platform, in accordance with Law No. 27 of 2022 on Personal Data Protection (UU PDP).
1. Information We Collect
We collect information in order to provide the Service to you. This information includes:
- Account registration information: Full name, email address, phone/WhatsApp number, business/store name, business mode (small business or freelancer), and a password stored as a one-way hash (never stored in its original form).
- Business operational data: Product information, prices, stock inventory, POS transaction data, invoices, your customer data, expenses, shift and employee data, and the financial reports you enter into the app.
- Payment information: Your subscription payment transaction data (payment status, transaction ID, e-wallet or virtual account method). This information is processed directly by our official payment gateway partner, Xendit. We do not store your full credit card number, CVV, or PIN.
- Technical & security data: IP address, device type and operating system, app version, access time, and security activity logs (login attempts, two-factor verification, and changes to important settings). We need this data to detect misuse and protect your account.
- Consent records: When you accept the Terms of Service and Privacy Policy, we record the document version you agreed to and the time of your acceptance, as valid proof of consent as required by the UU PDP.
We do not request and do not intend to collect specific-category personal data (such as health data, biometric data, beliefs, or criminal records). Please do not enter such data into free-text fields in the app.
2. Use of Information & Legal Basis for Processing
We use the information we collect for the following purposes:
- Providing, operating, maintaining, and improving Laksa’s platform features (basis: performance of contract).
- Processing subscription payment transactions and sending invoices to your email (basis: performance of contract).
- Securely syncing data so your transactions are accessible across multiple web and mobile devices in real time (basis: performance of contract).
- Verifying your identity and protecting your account from unauthorized access, including sending email verification codes and two-factor codes (basis: legitimate interest and legal obligation).
- Sending important operational notifications, app updates, and responding to your technical support requests (basis: performance of contract).
- Presenting business analytics and insights (AI Insights) on your own store data, solely for you (basis: performance of contract).
- Fulfilling legal, tax, and official requests from competent authorities (basis: legal obligation).
We do not use your in-app transaction data or customer data to train general-purpose artificial intelligence models, and we do not use it to target advertising. The public Laksa Berita site serves third-party ads that use cookies; this is separate from your app data and is explained in Section 10.
3. Security & Data Protection
The security of your data is our priority. We implement technical and organizational security measures to protect data from unauthorized access, loss, alteration, or disclosure:
- All data traffic between your device and our servers is encrypted using TLS (HTTPS).
- Passwords are stored using one-way PBKDF2 hashing with 600,000 iterations; we can never read your password.
- Credentials on the mobile app are stored in the operating system’s encrypted storage (Android Keystore / iOS Keychain), not in plain storage.
- Accounts with the owner and admin role are required to enable two-factor authentication (2FA).
- Sensitive actions such as voiding and refunding transactions require a server-verified authorization PIN.
- Data is stored on Cloudflare’s cloud infrastructure with routine backups, point-in-time recovery, and internal access restrictions based on need.
No system is completely immune. You also play a part in keeping your account secure by using a strong, unique password, enabling 2FA, and never sharing a verification code with anyone — including anyone claiming to be part of the Laksa team. We will never ask for your password or OTP code by phone, WhatsApp, or email.
4. Disclosure to Third Parties
We do not sell, rent, or trade your personal information or business data to anyone for marketing purposes. We only share data as necessary with service providers that support the operation of the Laksa platform, namely:
- Xendit (payment processor): Receives the data necessary to securely process your subscription payments in compliance with Indonesian banking regulations.
- Cloudflare (compute & storage infrastructure): Stores and processes your application data on their database, object storage, and content delivery network services.
- Resend (email delivery): Receives your email address and transactional message content to send verification codes, invoices, and operational notifications.
- Google (optional authentication): If you choose to sign in with a Google account, we receive your name, email address, and profile photo from Google to create or match your account.
We may also disclose data when required by law, court order, or an official request from a competent authority, and when necessary to enforce our Terms of Service or protect the rights and safety of other users. In the event of a merger, acquisition, or business transfer, data may be transferred to the successor business while remaining subject to this Privacy Policy, and we will notify you before this takes effect.
5. Cross-Border Data Transfer
The Laksa platform runs on Cloudflare’s global cloud infrastructure. As a result, your data may be stored and processed in data centers located outside the Republic of Indonesia, following that infrastructure provider’s global network. The same applies to our email delivery partner (Resend) and, if you use it, Google authentication.
In accordance with Article 56 of the UU PDP, we carry out these transfers by ensuring the data recipient applies a level of personal data protection equal to or higher than what the UU PDP requires, through data processing agreements and binding security commitments with those service providers. By using Laksa, you understand and consent to this cross-border processing as an inseparable part of the Service being provided.
Your subscription payments are processed by Xendit, a Bank Indonesia–licensed payment service provider that processes payment data within Indonesia.
6. Data Retention Period
We retain your data only for as long as necessary for the purpose it was collected, as follows:
- Active accounts: Business and account data is retained for as long as your account remains active.
- After an account deletion request: The account is deactivated immediately, and personal and business data is deleted from production systems within 30 calendar days at the latest.
- Backups: Rotating backup copies may still contain your data for up to 90 calendar days after deletion, after which they are automatically purged following the backup rotation cycle.
- Inactive accounts: Free-plan accounts that have not been accessed for 24 consecutive months may be deleted by us, after prior notice to your registered email.
- Financial & tax records: Subscription payment records and related tax documents are retained for 10 years in accordance with Indonesian tax law obligations, even if your account has been deleted.
- Security records: Security and audit logs are retained for up to 12 months for incident investigation purposes.
7. Your Rights Over Your Personal Data
In accordance with the UU PDP, you have the following rights over your personal data:
- The right to obtain clear information about our identity, the legal basis, the purpose of the request, and the use of your personal data.
- The right to access and obtain a copy of your personal data. You can fulfill most of this right yourself via the data export feature in the app.
- The right to correct and update inaccurate data via Settings > Profile.
- The right to stop processing, delete, and/or destroy your personal data, via the Delete Account feature in the app.
- The right to withdraw consent to the processing of your personal data.
- The right to object to decisions made solely through automated processing.
- The right to claim and receive compensation for violations in the processing of your personal data in accordance with applicable law.
Requests regarding these rights can be submitted via [email protected] and will be acknowledged within 3x24 hours and resolved within 30 calendar days at the latest. We may request identity verification before processing a request, to ensure your data is not handed over to an unauthorized party.
8. Your Customer Data (Controller & Processor)
Two types of data within Laksa need to be distinguished, because the legal responsibility for each is different:
- Your account data: For your own registration and usage data, LAKSA BUSINESS VISION acts as the Data Controller.
- Your customer data: For data you enter about your buyers or clients (name, phone number, address, purchase history, loyalty points), you act as the Data Controller. Laksa only acts as a Data Processor processing that data on your instructions.
As the Controller, you are responsible for ensuring there is a lawful basis for processing your customer data, providing them with privacy notices, and responding to their rights requests. As the Processor, Laksa commits to only processing that data according to your instructions through the app’s features, not using it for our own purposes, applying the safeguards described in Section 3, and helping you fulfill rights requests from your customers when needed.
9. Data Breach Handling & Notification
In the event of a personal data protection failure (breach, unauthorized access, or data loss), we will send written notice within 3x24 hours of discovery to you as the affected data owner and to the competent authority, in accordance with Article 46 of the UU PDP.
That notice will include what personal data was exposed, when and how it happened, and the remediation and recovery efforts we are undertaking. If the incident involves your customer data, we will notify you without delay so you can fulfill your own obligations as a Data Controller.
11. Contact Us
If you have questions, complaints, or requests regarding your personal data and this Privacy Policy, please contact:
- Legal Entity: LAKSA BUSINESS VISION
- Office Address: Sukadami, RT 002 / RW 001, Kel. Sukadami, Kec. Cikarang Selatan, Kabupaten Bekasi, Jawa Barat 17530
- Data Protection Officer: [email protected]
- Support Email: [email protected]
- Support WhatsApp: +62 852-1187-0129
If you believe your complaint has not been handled properly, you have the right to lodge a complaint with the competent personal data protection authority in Indonesia.
© 2026 LAKSA BUSINESS VISION. Hak Cipta Dilindungi.