Privacy Policy
How Swipe POS collects, processes, and protects your personal data in accordance with Indonesian law.
PT Swipe Pay Indonesia ("Company", "we") is committed to protecting the Personal Data of every user of our products and services — Swipe Pay, Swipe Online, Swipe GO, and Swipe POS ("Service"). This policy explains how we collect, use, store, disclose, transfer, and protect your Personal Data, and your rights as a Data Subject.
1.Introduction
Swipe POS is integrated point-of-sale software connected to cashless acceptance via Swipe GO. This policy governs Personal Data processed when you register for, activate, and operate Swipe POS — including cashier, staff, inventory, promotion, and sales-report data.
This Privacy Policy applies to: (a) prospective Users and Users (including Merchants and their management, beneficial owners, and personnel); (b) Buyers/Payers whose data is processed for payment transactions; (c) visitors to our website and app; and (d) other parties whose data we process in operating the Service.
For operating the Service, the Company acts as Data Controller. For the merchant’s own customer data managed within Swipe POS, the Merchant acts as Data Controller and the Company acts as Data Processor, processing that data only on the Merchant’s instructions.
Payment channels operate under an aggregator model together with acquiring partners licensed by Bank Indonesia — currently PT Bank Rakyat Indonesia (Persero) Tbk for the APMK channel and PT Bank Nationalnobu Tbk for the QRIS channel. For data the acquiring partners process on their own systems, each acquiring partner acts as a separate Data Controller subject to its own privacy policy.
2.Definitions
3.Personal Data We Collect
3.1 General Personal Data
- Identity data: full name, place/date of birth, gender, nationality, photo, and ID document data (KTP/passport).
- Contact data: address, email address, and phone number.
- Business data: business name, type/category, address, legal documents (NIB, deeds, permits), NPWP, management and beneficial-owner data.
- Transaction data: reference number, amount, time, payment channel, status, settlement data, and history.
- Technical data: IP address, device type/version, OS, device identifiers, activity logs, location (if enabled), and cookies.
- Communication data: correspondence, complaint records, and customer-service interactions.
3.2 Specific Personal Data
- Financial data: bank account number, payment-instrument data (processed encrypted/tokenised per industry standards, incl. PCI DSS for card data).
- Biometric data (where used for electronic identity verification, e.g. face/liveness), processed with stricter protection under the PDP Law.
For Swipe POS we also process cashier/staff account data (access rights, activity logs, shifts) and any customer data the Merchant chooses to record in the POS. The Merchant, as Data Controller of that customer data, must have a lawful basis and comply with the PDP Law.
4.How We Obtain Personal Data
- Directly from you — at registration, form completion, use of the Service, transactions, or communication with us.
- Automatically through use of the Service, website, and app (system logs, cookies, and similar technologies).
- From lawful third parties — banks, switching operators, issuers, partners, identity-verification bodies, and official sources (e.g. Dukcapil), per applicable rules.
5.Legal Basis for Processing
Under Article 20 of the PDP Law, we process Personal Data on one or more of the following bases:
- Valid explicit consent for one or more specified purposes (e.g. marketing).
- Performance of a contract, or a pre-contract request (e.g. account opening and transaction processing).
- Compliance with legal obligations, incl. CDD/EDD and AML-CFT-CPF reporting, BI regulations, and tax rules.
- Protection of the vital interests of the Data Subject.
- Performance of a task in the public interest or exercise of authority under law.
- Other legitimate interests, balanced against the Data Subject's rights (e.g. fraud prevention, system security).
6.Purposes of Processing
7.Disclosure to Third Parties
We do not sell or rent your Personal Data. We may disclose it in a limited manner to:
- Acquiring/payment-system partners: BRI (APMK) and Bank Nobu (QRIS), plus switching, clearing/settlement institutions, issuers, and principals — for registration (NMID/MID), due diligence, processing, settlement, and dispute handling.
- Support-service providers (Data Processors) bound by written data-protection agreements.
- Competent authorities: BI, PPATK, tax authorities, law enforcement, and courts, on legal obligation or lawful request.
- Auditors, legal counsel, and professional advisers bound by confidentiality.
- Other parties based on your consent.
8.Processing in Indonesia & Cross-Border Transfer
In accordance with Bank Indonesia rules, domestic payment processing and payment-system data are handled within Indonesia.
Where transfer of Personal Data outside Indonesia is required (e.g. international card processing), it is carried out under Article 56 of the PDP Law — ensuring an equal/higher level of protection, adequate binding safeguards, or the Data Subject's consent.
9.Storage & Retention Period
Personal Data is stored as long as needed for the processing purpose and our legal obligations. Transaction, CDD/EDD, and payment-system records are retained for at least the period required by law — including a minimum of 5 (five) years under AML-CFT-CPF rules — or longer where required.
After the retention period ends, Personal Data is securely erased or destroyed, unless still needed for legal proceedings or otherwise required by regulation.
10.Data Security
We apply appropriate technical and organisational measures, including:
- Encryption in transit and at rest, and tokenisation of payment-instrument data.
- Compliance with card-data security (PCI DSS) and BI information-security standards.
- Role-based access control, layered authentication, and audit-trail logging.
- Periodic security testing (incl. penetration testing), monitoring, and incident management.
- Need-to-know employee access with confidentiality agreements; BCP/DRP.
11.Data Breach Notification
In the event of a Personal Data protection failure, under Article 46 of the PDP Law we provide written notification within 3 × 24 hours to affected Data Subjects and the data-protection authority, stating the data disclosed, when/how, and the handling and recovery measures taken. We also report the incident to Bank Indonesia per applicable rules.
12.Your Rights as a Data Subject
Submit requests through the Forms Center or the contact below. We respond within 3 × 24 hours from a complete request where that period applies, or within another reasonable period. Certain rights may be excepted where regulated by law.
13.Cookies & Similar Technologies
Our website and app use cookies and similar technologies to support functionality, security, analytics, and user-experience improvement. You can manage preferences via browser/device settings; disabling certain cookies may affect functionality.
14.Children's Personal Data
Our Service is intended for businesses and adults. We do not knowingly collect children's Personal Data. Where necessary, processing is done only with parental/guardian consent under Article 25 of the PDP Law. If we learn we have processed a child's data without a lawful basis, we will delete it.
15.Changes to This Policy
We may update this Privacy Policy from time to time. Material changes are notified via website, app, and/or registered email before taking effect. The latest version date appears at the top of this document.
16.Contact & Data Protection Officer
For questions, requests to exercise your rights, or complaints about Personal Data, please contact: