Privacy Policy

Last updated 6 October 2026

This text describes how the service works today. The owner reviews it with a lawyer before launch, and this notice is removed once that is done.

Summary

We collect the minimum needed to run the store: your WhatsApp phone number or email address as account identity, a password stored hashed, order data, and session data. We do not sell your data. We use Google for Sign in with Google, Midtrans for payments, WhatsApp to send codes to a phone, Mailketing to send codes to an email, an email provider for the contact form, and UpCloud for hosting and storage.

Data controller

The data controller is Medtive Studio, an individual business based in Indonesia. Privacy requests are made via the Contact page.

What we collect

  • Account and identity data: your WhatsApp phone number or email address as account identity, a password stored only as an Argon2id hash so the plain password is never stored or logged, plus your name and any contact data you provide.
  • Order and payment data: products bought, amount in rupiah, order number, payment status, and licence key. Card or bank details are handled by Midtrans and never reach our server.
  • Session and security data: a session token per device stored hashed, user agent, IP address, and timestamps; records of sign-in attempts, one-time code sends, and admin actions, to prevent and investigate abuse.
  • Download data: download records with item, time, and IP address, to enforce the download limit.
  • Contact form: name, email, and the message you send.
  • Profile and account-security data: your display name, username (public handle), contact verification status, and, when you enable it, the two-factor secret stored encrypted plus hashed recovery codes.

Legal basis and purposes

  • Create and secure your account: phone, password, session data; basis is contract and consent.
  • Send verification and password-reset codes: phone and message; basis is contract.
  • Process payment: order number, amount, and email; basis is contract.
  • Send receipts and licence keys: phone and order data; basis is contract.
  • Prevent fraud and abuse: IP address, user agent, and security logs; basis is legitimate interest.
  • Accounting and tax obligations: order data; basis is legal obligation.
  • Answer privacy requests: relevant data; basis is legal obligation.

Recipients

  • Google processes Sign in with Google. If you use it, Google verifies your identity and gives us your Google account id and email address.
  • Midtrans processes payments. They receive the order amount and email, and handle your payment details directly.
  • WhatsApp sends verification and password-reset codes to your phone number. The phone number and message content go to the WhatsApp service, so data may be processed outside Indonesia.
  • Mailketing sends verification and password-reset codes and notices to your email address. The email address and message content go to the Mailketing service.
  • The email provider sends contact-form messages.
  • UpCloud hosts the app and stores files. Product files are stored in a private bucket, reachable only via a short-lived link issued to a signed-in buyer.
  • Law enforcement or regulators, where legally required.

We do not sell your personal data.

How long we keep it

  • Account and order data: while the account exists, and afterwards for 10 years per Indonesian accounting and tax rules.
  • One-time codes: single-use and expire in 10 minutes.
  • Session tokens: expire after 30 days or when the session is revoked.
  • Security logs: 12 months, then deleted or anonymised.

Your rights

You have the right to access and receive a copy of your data; to rectify inaccurate data; to erase data; to withdraw consent; to restrict or object to certain processing; to port your data; and to lodge a complaint with a supervisory authority, in Indonesia the PDP authority and in the European Union your local data-protection authority.

To exercise these, contact us via the Contact page. We respond within the period allowed by law. We may ask for proof of account ownership before complying.

Account deletion: you may ask for your account and personal data to be deleted. Order records we must keep for accounting remain, with personal data reduced to the legal minimum.

Cookies

We use session cookies needed to sign in and keep a cart, plus browser session storage for the anti-CSRF token and the checkout idempotency key. These are not used for advertising or third-party tracking.

Cookie list: ms_access, ms_refresh, csrf (session cookie, HttpOnly except csrf), and ms_cart (guest cart, HttpOnly).

International transfers

Because we use WhatsApp, Mailketing, Midtrans, and UpCloud with a European region, data may be processed outside Indonesia. For EU customers, transfers outside the EU rely on a lawful safeguard, such as the provider's Standard Contractual Clauses.

Security

Passwords are stored as Argon2id hashes, one-time codes are stored hashed, sessions use hashed tokens, product files are in a private bucket with short-lived links, and admin access uses two-step verification. No system is fully secure, but we take reasonable steps to protect your data.

Children

This service is not intended for anyone under 18. We do not knowingly collect children's data. If you believe a child provided data, contact us for deletion.

Data breaches

On a personal-data protection failure, we notify data subjects and the competent authority in writing within three times twenty-four hours (Indonesia PDP law), and the relevant supervisory authority as required by GDPR.

Changes

This policy may change. The date above shows the last change. Material changes will be notified on the site or account.

Contact

Privacy questions or requests via the Contact page.