Data we collect
- Account data: name, email, hashed password, organization name, and language preference.
- Authentication data: session tokens, email verification status, IP address, user agent, and login time.
- Usage data: API key, endpoint, request count, status code, response time, and quota.
- Billing data: plan, invoice, payment status, transaction metadata, and payment provider reference.
- Support data: messages, attachments, support topics, and communication history.
How we use data
- Create accounts, secure sign-in, and provide dashboard access.
- Issue API keys, calculate quota, prevent abuse, and record technical activity.
- Process payments, taxes, invoices, refunds, and accounting needs.
- Answer questions, handle incidents, and send product or security notices.
- Meet legal duties in Indonesia or other relevant jurisdictions.
Google and other sign-in providers
If you sign in with Google or another identity provider, we may receive your name, email address, profile photo, and account identifier according to the permissions you approve on the sign-in screen.
We do not sell data from sign-in providers. We do not use Google data for ads, cross-app marketing profiles, or transfers to third parties outside service needs.
Google API Limited Use
API Indonesia use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. If requested Google scopes change, we will update this policy and ask for new consent when required.
Cookies and local storage
We use session cookies, CSRF tokens, theme preference, language preference, and other local storage for sign-in, security, and product settings. See the Cookie Policy for details.
Data sharing
- Infrastructure, hosting, email, monitoring, technical analytics, and payment providers.
- Professional advisers such as auditors, tax consultants, or legal counsel when needed.
- Public authorities when required by law, court order, or valid legal process.
- A recipient in a business transaction such as merger, acquisition, or restructuring, with reasonable safeguards.
Retention
Active account data is kept while the account exists. Technical logs are usually kept for up to 12 months, unless a longer period is needed for security, audit, disputes, or legal duties. Billing records may be kept for tax and accounting retention periods.
Your rights
- Request access, a copy, correction, or deletion of personal data.
- Withdraw consent for marketing messages.
- Request restriction or objection to certain processing when the law gives that right.
- Delete your account through the dashboard or by contacting hello@apiindonesia.id.
Security
We use TLS, password hashing, internal access limits, audit logs, and technical monitoring. No system is risk-free, so users must protect their API keys, passwords, and devices.
Privacy contact
For privacy questions, data requests, or complaints, contact hello@apiindonesia.id. For security issues, contact support@apiindonesia.id.