Kiosku
Legal

Privacy Policy

Effective date: 3 October 2026

Contents

01Who We Are02What We Collect03How We Use It04Who We Share With05Data Storage06Data Retention07Your Rights08Security09Children10Changes
§1

Who We Are

Kiosku is an order-management platform for small businesses that sell through chat channels such as WhatsApp and Instagram DM.

Who controls your data depends on where your store is registered. For stores registered in Indonesia, the data controller is PT Wahana Ciptaka Digital, a limited liability company established under Indonesian law and domiciled in Jakarta Utara. For stores registered anywhere else, the data controller is Sebastian Arthur Chua, a sole trader based in Sydney, New South Wales, Australia. This affects which data protection law governs your rights — see §7.

If you have any questions about this policy or how your information is handled, please contact us:

PT Wahana Ciptaka Digital

Jl. Ruko The Plaza, Jl. Pantai Indah Kapuk Blok 9AG

Kelurahan Kapuk Muara, Kecamatan Penjaringan

Kota Administrasi Jakarta Utara, DKI Jakarta 14460, Indonesia

NPWP 10.000.000.8-456.163

sebastian.a.chua@gmail.com

Counterparty for stores registered in Indonesia.

Sebastian Arthur Chua

Sydney, New South Wales, Australia

sebastian.a.chua@gmail.com

Counterparty for stores registered outside Indonesia.


§2

What Personal Information We Collect

We collect different information depending on how you interact with Kiosku.

Merchant account information

When you sign up as a merchant, we collect your email address and, if you sign in with Google, your Google profile name and profile picture URL. We also store a hashed password if you use email and password sign-in.

Merchant business configuration

We store the information you enter to set up your store: your business name, contact details, operating hours, product catalogue, delivery zones, and payment configuration. This is business data you provide voluntarily to make Kiosku work for your store.

Merchant identity verification (stores in Indonesia)

If you apply to accept digital payments through DOKU, we are required to verify your identity and your business before your payment account can be created. For that purpose we collect:

  • Your full legal name and your national identity number (NIK), together with a photograph of your identity card (KTP)
  • A selfie photograph, used to check that it matches your identity document
  • Your contact email address and phone number
  • Your business category, a description of your business, your full business address (provinsi, kota/kabupaten, kecamatan, kelurahan/desa, kode pos, and street address), a photograph of your storefront, and links to the channels you sell through
  • A record of your acceptance of the cooperation agreement (Perjanjian Kerja Sama): the version you accepted, a digital fingerprint of the exact document shown to you, the date and time, and the IP address and browser user-agent used

Your NIK and your selfie are specific personal data under Indonesian law (UU No. 27 of 2022 on Personal Data Protection). We collect them only for merchant verification and anti-money-laundering compliance, only from merchants who choose to apply for digital payments, and never for advertising, profiling, or any other purpose. Providing them is voluntary — but without them we cannot create your payment account.

These documents are stored in a private, access-controlled location. They are not readable by other users of the platform, not readable by your own staff members, and not served publicly; only our reviewers can open them.

End-customer information

When your customers place orders — either through a checkout link you share or manually entered by you — we collect:

  • Name, phone number, and delivery address
  • Order details (items, quantities, special instructions)
  • Payment metadata (payment status, reference numbers). We do not store raw card numbers or full bank account details — those are handled directly by our payment processors.

This information is entered on behalf of, or directly by, your customers. As the merchant, you are responsible for ensuring you have the appropriate basis to share your customers' data with us.

Session and technical data

We use essential session cookies to keep you logged in. These are set by our authentication provider (Supabase) and contain only an encrypted session token — no personal details, no tracking identifiers. The Kiosku dashboard itself does not set analytics, advertising, or marketing cookies. The Kiosku home page, the welcome page, and our sign-up, login, and password-reset pages do set a first-party analytics cookie, which we read once when you create a store; see “Product analytics on the home, welcome, and sign-up pages” below.

Marketing pixels on storefronts

Individual merchants may choose to enable the Meta (Facebook) Pixel on their own storefront. This is off by default and entirely merchant-controlled — it loads only when a merchant has entered their Meta Pixel ID in their store settings. When enabled, the pixel runs in the visitor's browser on that merchant's storefront and reports a small set of standard shopping events to Meta: page views, viewing a product, adding an item to cart, starting checkout, and completing a purchase (including the order value and currency). This lets the merchant measure and target their Facebook and Instagram advertising. The pixel is not loaded on storefronts whose merchant has not enabled it, and never on the Kiosku dashboard. The data flows to Meta under Meta's own terms — see the Meta Privacy Policy.

Kiosku's own advertising pixel

We advertise Kiosku on Facebook and Instagram. To measure those ads, our own Meta Pixel runs on the Kiosku welcome page that our ads link to. It reports a visit to that page, a tap on the WhatsApp button, and a completed consult request to Meta. When you submit the consult form, our server also reports the request to Meta directly, so it is counted even if your browser blocks the pixel. That report includes your WhatsApp number and email address in hashed form (a one-way code Meta can match against its own accounts but cannot turn back into the original), your IP address, your browser type, and Meta's cookies from your visit. We also record the ad campaign details from the page link (such as the campaign name and Meta's click identifier) alongside your request, so we know which ad reached you. This pixel does not run on merchant storefronts or on the Kiosku dashboard.

If you arrive at any Kiosku page from an ad link, we keep that link's campaign details in a cookie for 30 days. If you then create a store, we record them against it, so we know which ad brought you to Kiosku. When any merchant creates a store, our server also tells Meta that a sign-up happened, including your email address in hashed form, your IP address, your browser type, and Meta's cookies from your visit, so Meta can credit the ad that reached you.

Product analytics on the home, welcome, and sign-up pages

To understand how people find and use our home, welcome, and sign-up pages, and where signing up goes wrong, we use PostHog, a product analytics service. PostHog runs only on the Kiosku home page (including its Indonesian and Australian versions), the welcome page, and our sign-up, login, and password-reset pages. It does not run on merchant storefronts, on our guides, or on the Kiosku dashboard, and we do not use it for advertising.

On those pages, PostHog sets a first-party cookie and a matching entry in your browser's storage (named ph_…_posthog) holding a random identifier, so it can tell that several page views came from the same browser. It records the pages you visit and the link that brought you there (including any ad campaign details in it), how far you scroll, the buttons and links you tap, your browser and device type, and whether you are using an app's built-in browser (such as Instagram's). It also records which sign-up method you choose and, if signing up fails, a general reason (such as “email already registered”) — never what you typed. PostHog uses your IP address to estimate your approximate location (country and city), then discards it; your IP address is not stored.

PostHog also makes session recordings: a replay of how the page looked and responded while you used it, so we can see where it confuses people or breaks. Everything you type into a form field is masked in your browser before the recording is sent, and the free consult form is left out of recordings entirely.

If you create a store, we link this activity to your Kiosku account, so we can see which visits led to a store. We use PostHog's European Union region, so this data is stored in the EU (see §5).


§3

Why We Collect It and How We Use It

We use personal information to:

  • Provide and operate the service — authenticate your account, display your orders, process payments, and deliver the features you sign up for.
  • Communicate with you — send transactional emails (password resets, order confirmations) when you or your customers trigger them.
  • Improve reliability — diagnose errors and maintain the platform's performance.
  • Comply with legal obligations — retain records as required under applicable law.

We do not sell personal information. We do not use it for behavioural advertising.


§4

Who We Share Information With

We use a small set of third-party service providers (sub-processors) to operate Kiosku. Each receives only the data necessary for their function:

ProviderPurposeData processed
SupabaseDatabase and authenticationAll personal data (stored in Singapore region)
VercelWeb hosting and serverless functionsRequest metadata (IP, headers) processed at edge
StripePayment processing (AU / global)Payment details for transactions
DOKUPayment processing and settlement (Indonesia; PT Nusa Satu Inti Artha). Merchant verification documents are shared with DOKU where needed to register and maintain your payment account.Payment details for transactions; merchant payout data; merchant identity and business verification documents
XenditPayment processing (Indonesia) — being retired; still processing for a small number of existing storesPayment details for transactions
MidtransPayment processing (Indonesia) — being retired; still processing for a small number of existing storesPayment details for transactions
Meta (Meta Platforms)Advertising analytics via Meta Pixel — on storefronts whose merchant has enabled it, and on the Kiosku welcome page our own ads link toStorefront shopping events (page views, add-to-cart, checkout, purchase value); welcome-page visits, WhatsApp taps, and consult requests and store sign-ups (with hashed WhatsApp number and email, IP address, and browser type)
PostHogProduct analytics and session recordings on the Kiosku home, welcome, sign-up, login, and password-reset pages (EU region)Page views and the link that brought you there (including ad campaign details), taps, scroll depth, sign-up method and a general failure reason, session recordings with typed input masked, browser and device type, and approximate location (estimated from your IP address, which is discarded and not stored); linked to your account once you create a store
Supabase

Database and authentication

All personal data (stored in Singapore region)

Vercel

Web hosting and serverless functions

Request metadata (IP, headers) processed at edge

Stripe

Payment processing (AU / global)

Payment details for transactions

DOKU

Payment processing and settlement (Indonesia; PT Nusa Satu Inti Artha). Merchant verification documents are shared with DOKU where needed to register and maintain your payment account.

Payment details for transactions; merchant payout data; merchant identity and business verification documents

Xendit

Payment processing (Indonesia) — being retired; still processing for a small number of existing stores

Payment details for transactions

Midtrans

Payment processing (Indonesia) — being retired; still processing for a small number of existing stores

Payment details for transactions

Meta (Meta Platforms)

Advertising analytics via Meta Pixel — on storefronts whose merchant has enabled it, and on the Kiosku welcome page our own ads link to

Storefront shopping events (page views, add-to-cart, checkout, purchase value); welcome-page visits, WhatsApp taps, and consult requests and store sign-ups (with hashed WhatsApp number and email, IP address, and browser type)

PostHog

Product analytics and session recordings on the Kiosku home, welcome, sign-up, login, and password-reset pages (EU region)

Page views and the link that brought you there (including ad campaign details), taps, scroll depth, sign-up method and a general failure reason, session recordings with typed input masked, browser and device type, and approximate location (estimated from your IP address, which is discarded and not stored); linked to your account once you create a store

We do not share personal information with any other third parties except where required by law (e.g., a lawful request from a government authority).


§5

Where Data Is Stored and International Transfers

Your data is stored primarily in Supabase's Singapore region (ap-southeast-1). This means your data is hosted in Singapore by Supabase.

Some of our sub-processors operate infrastructure in the United States (Supabase's control plane, Vercel's edge network, and Stripe's payment platform). By using Kiosku, you acknowledge that your information may be transferred to and processed in countries outside your own, including Singapore, the United States, and the European Union. PostHog, our product analytics provider, stores the data it collects in the European Union.

Merchant verification documents (§2) are stored in the same Singapore region, in a private storage bucket with no public access and no merchant-level read access — they are readable only by our reviewers through an authenticated, time-limited link. Where your verification data is transferred to DOKU, that transfer is to a recipient in Indonesia.

Where we transfer personal information internationally, we take reasonable steps to ensure it receives an equivalent level of protection. Our sub-processors are bound by their own privacy policies and applicable data protection laws.


§6

How Long We Keep Your Information

We retain your personal information for as long as your account is active. If you request account deletion, we will delete your account data within a reasonable period, subject to any legal obligations that require us to retain certain records for longer.

End-customer order data is retained as part of your merchant account and is deleted when you delete your account or when you manually remove individual records.

Merchant verification documents. Your KTP image, selfie, and the other verification material described in §2 are kept for as long as your payment account is active, and for a period after it closes, because anti-money-laundering and payment regulations require us to be able to evidence who we onboarded. After that period you can ask us to delete them, and we will unless the law requires us to keep them longer. Your record of accepting the cooperation agreement is kept for as long as that agreement could still be relied on by either of us.

To request deletion, contact us at sebastian.a.chua@gmail.com.


§7

Your Rights

Stores registered in Indonesia

Where PT Wahana Ciptaka Digital is the controller, your personal data is governed by Indonesian law, principally UU No. 27 of 2022 on Personal Data Protection (UU PDP). Under it you have the right to be informed about how your data is processed; to access and obtain a copy of it; to have inaccurate data corrected; to have your data erased or its processing ended; to withdraw a consent you previously gave; to object to certain processing; and to seek redress for a breach. Withdrawing consent to the verification data in §2 means we can no longer operate your payment account, but it does not affect your right to be paid out any balance in your sub-account.

Stores registered outside Indonesia

Where Sebastian Arthur Chua is the controller, your personal information is governed by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Under these, you have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to correct information that is inaccurate, out of date, or incomplete.
  • Complaint — if you believe we have mishandled your personal information, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

To exercise your access or correction rights, contact us at sebastian.a.chua@gmail.com. We will respond within 30 days.


§8

Security

We take reasonable steps to protect personal information from misuse, loss, unauthorised access, modification, or disclosure. Our security measures include:

  • Encrypted HTTPS connections for all data in transit
  • Cookie-based sessions with HTTP-only, Secure flags set by Supabase's SSR library
  • Row-level security (RLS) policies on our database, ensuring each merchant can only access their own store's data
  • Authentication handled by Supabase, which manages credential hashing and token rotation

No method of transmission over the internet is 100% secure. If you believe your account has been compromised, contact us immediately.


§9

Children

Kiosku is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us and we will delete it.


§10

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. If the changes are material, we will notify merchants by email.

Continued use of Kiosku after a policy update constitutes acceptance of the revised policy.

© 2026 PT Wahana Ciptaka Digital. All rights reserved.

PrivacyTermsBack to Kiosku