Pesanle
Privacy policy
What personal data the platform handles, why, who else touches it, and what you can ask us to do with it. Written for two audiences: the sellers who use Pesanle, and the buyers who order from a shop running on it.
In effect from September 14, 2026. Last updated September 14, 2026.
1. Two roles, and which one applies to you
Pesanle handles personal data in two different capacities, and which rules apply depends on whose data it is.
- For a seller’s own account data — the person who signs up and runs a shop — we are the controller. We decide what is collected and why, and this policy governs it.
- For a shop’s customer data — the people who place orders with that shop — the seller is the controller and we are the processor. We hold and process that data on the seller’s instructions, for the purpose of running their shop.
If you ordered something from a shop on this platform and want your data corrected or removed, contact that shop. If they cannot resolve it, contact us and we will help.
2. What we collect
From sellers, when you create an account and run a shop:
- Account details: name, email address, and the password you set (stored only as a hash — we never see it).
- Shop details: the shop’s name, address, contact details, logo and banner, and the trade you selected.
- Billing records: the plan you are on, invoices issued, and any payment proof you upload.
From a shop’s buyers, on that shop’s instructions:
- Order details: what was ordered, in what quantity, and for how much.
- Contact and delivery details: name, phone number or email, and delivery address.
Automatically, when anyone uses the platform:
- Technical data needed to serve a request and to keep the service secure and working: IP address, browser and device type, and the pages requested.
- A small number of functional cookies — the session cookie that keeps you signed in, and preferences such as your chosen language and light or dark mode.
We do not collect payment card numbers. Where a payment gateway is used in future, the card details go to that provider and never pass through our systems.
3. What we use it for
- Providing the service: running your shop, serving your storefront, processing orders and counting stock.
- Authenticating you and keeping accounts secure.
- Billing: issuing invoices, recording payments and enforcing plan limits.
- Support: answering your questions and investigating problems you report.
- Keeping the platform working: diagnosing faults, preventing abuse, and meeting our legal obligations.
We do not sell personal data, and we do not use a shop’s customer data for our own purposes.
4. Our basis for processing
We process personal data where it is necessary to perform our agreement with you, where we have a legitimate interest in keeping the platform secure and functioning, where the law requires it, and — for anything beyond that — where you have consented.
Where Indonesian personal data protection law (Law No. 27 of 2022) applies, we process personal data in accordance with it. Where a seller’s buyers are in a jurisdiction with its own rules, the seller as controller is responsible for meeting them.
5. Who else handles it
We use a small number of service providers to run the platform. Each processes data only to provide its service to us:
- Appwrite — the database, authentication and file storage behind the platform.
- Netlify — hosting and content delivery for the dashboard, the storefronts and this site.
We may also disclose data where the law requires it, or to establish or defend a legal claim. We will not hand over data in response to an informal request.
If we ever transfer the business, personal data may transfer with it; you will be told before that happens.
6. Where the data is held
Platform data is stored in the Singapore region (ap-southeast-1) of our infrastructure providers. Requests are served through a content delivery network with points of presence in several countries, which means technical data such as an IP address may be handled outside Indonesia in the course of serving a page.
We do not move customer data outside the approved region for any other purpose.
7. Separation between shops
Each shop’s data is isolated from every other shop’s. Every record belongs to its own shop’s team, the underlying tables grant no access by default, and the dashboard independently re-checks ownership on every read and every write.
The two checks are deliberate and independent: a leak between two shops would require a mistake in both layers at the same time.
8. How long we keep it
- Account and shop data: for as long as the account is open, and for a short period afterwards so that an accidental closure can be undone.
- Order and billing records: for as long as we are required to keep them for tax and accounting purposes.
- Technical logs: for a limited period, then deleted or aggregated.
When a shop is closed, its catalogue, customer records and files are deleted on the same schedule.
9. Your rights
Subject to the law that applies to you, you can ask us to:
- tell you what personal data we hold about you
- correct anything that is wrong
- delete data we no longer have a reason to keep
- give you a copy of your data in a portable form
- stop processing where our basis was your consent, which you can withdraw at any time
Most of this you can do yourself in the dashboard. For anything you cannot, write to us at the address in the footer and we will respond within the period the law allows.
10. Security
Traffic is encrypted in transit. Passwords are stored only as hashes. Access to production systems is limited to the people who need it. Access to a shop is granted by membership of that shop’s team and by nothing else, and each member’s role determines what they may see and change.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as the law requires.
11. Cookies
We use cookies that are necessary for the platform to work: the session cookie that keeps you signed in, and preference cookies that remember your language and your light or dark mode.
We do not use advertising cookies, and we do not track visitors across other websites.
12. Children
The platform is for businesses and is not directed at children. We do not knowingly collect personal data from a child; if you believe we have, tell us and we will delete it.
13. Changes to this policy
We may update this policy. The effective date at the top of this page always reflects the version in force, and material changes will be notified before they take effect.
14. Contact
Questions about this policy, or a request about your own data, can be sent to the address in the footer of this site.