Privacy policy

Last updated: August 2026

JastipPoint provides a management platform and marketplace for jastip (personal-shopper) businesses. This policy explains what we collect on our websites, the seller workspace, and buyer tracking pages, and how we use it.

1. Who we are

JastipPoint is operated from Blok FF2, Jl. Cut Nyak Dien II No.1, Jurang Mangu Barat, Kec. Pd. Aren, Kota Tangerang Selatan, Banten 15222. For anything in this policy you can reach us at [email protected] or 081233144516.

2. Information we collect

We collect account information you provide (store name, full name, email, phone number), business data you create in the workspace (trips, orders, customers, payments, shipments), and technical data needed to operate the service (device type, browser, approximate region, and product-usage events). Buyer tracking pages are designed for data minimization: a buyer only ever sees their own order projection, never other customers or internal seller data.

3. How we use information

We use information to provide and improve the service: syncing orders across your team, generating shopping lists and reports, computing true profit, delivering buyer tracking pages, processing payments and refunds, preventing abuse, and communicating with you about your account. We do not sell personal data, and we do not use your business data to advertise to your customers.

4. Payment data

Payments are processed by Midtrans, a licensed Indonesian payment gateway. Card numbers, CVV, and banking credentials are entered on the gateway's own page and never reach our servers or our database. We store only what an order needs: the amount, method, status, timestamp, and the gateway's reference number.

5. How we share information

We share data only with service providers that help us operate the platform (hosting, payment processing, transactional messaging, shipping couriers), each bound by contractual confidentiality and security obligations. We may disclose information where required by Indonesian law or to protect the rights and safety of our users. If the business is acquired, data may transfer under the same protections described here.

6. Data security & retention

Account access uses authenticated sessions and server-side authorization checks. Buyer portals use opaque, unguessable tokens, sensitive actions are re-authorized on the server, and payment proofs are served as private assets. Transaction records are retained for as long as Indonesian tax and accounting rules require; other personal data is deleted on request. No method of transmission is 100% secure, but we design for least exposure by default.

7. Cookies

We use strictly necessary cookies for authentication and security. We do not use third-party advertising cookies. Any future analytics cookies will be privacy-respecting and documented here before they are enabled.

8. Your rights & contact

You may access, correct, export, or delete your personal data at any time from your workspace settings or by contacting [email protected]. Sellers act as the data controller for their customers' information; buyers should contact the seller directly for order-related data requests, and we will assist where required. We respond to privacy requests within seven days. This policy may be updated from time to time; material changes will be announced in the workspace before they take effect.