Privacy Policy Web App

Privacy Policy

Online Shop — E-commerce web application (Laravel)

Effective August 6, 2026 · Last updated August 6, 2026

Buying something online means handing over an address and paying for it. This policy sets out what the shop keeps, what goes to the payment gateway, and what goes to the shipping-cost service — and what never leaves the shop.

Summary
  • Collects account details, shipping address, order history, and payment status.
  • Payments go through Midtrans; card and bank details never touch the shop’s server.
  • Shipping cost lookups send only district-level destination and weight to RajaOngkir — never your name or street address.
  • Functional cookies only — no advertising or tracking pixels.

1. Who this policy applies to

Online Shop is software that an organization installs and runs on its own infrastructure. The store owner operating a given installation decides what data is entered into it and is the data controller for that installation. This page documents what the application itself collects and processes by design; it is the reference policy for the software, and an operator may publish additional terms on top of it. As the developer, I have no access to any production database unless an operator explicitly grants it for maintenance.

2. Data we collect

DataWhy
Account dataName, email, phone number, and a hashed password — for login, order history, and order notifications.
Shipping addressRecipient name, phone, full address, and region — needed to calculate shipping and to deliver the parcel.
Cart and order dataProducts, quantities, prices, shipping method, and order status history.
Payment statusMidtrans order ID, amount, method, and status. Card numbers, CVV, and bank credentials are never received or stored.
Reviews and wishlistYour rating, comment, and saved products — reviews are shown publicly with your display name.
Technical logsIP address, user agent, and timestamps — for security, fraud prevention, and debugging.

3. Third-party services

ServiceWhat it does
Midtrans (PT Midtrans)
Privacy policy ↗
Processes payments (QRIS, virtual account, e-wallet, card). Card and banking details are entered on Midtrans’ own page — this application never sees or stores them.
RajaOngkir
Privacy policy ↗
Shipping cost lookup. Only the destination province/city/district and package weight are sent — never the recipient’s name, full street address, or phone number.
Email delivery (SMTP provider)Sends order confirmation and status emails. The provider receives the recipient email address and the message content.

4. Payments and shipping

At checkout you are handed to Midtrans to pay. Midtrans collects the payment credentials directly; the shop receives back only a reference and a status. This is why the shop can never leak a card number — it never has one.

Shipping cost is calculated by sending the destination region and package weight to RajaOngkir. Your name, street address, and phone number are not part of that request; they go only to the courier once a parcel is actually shipped.

5. Cookies and sessions

The application uses cookies only for functionality:

There are no advertising cookies, no third-party analytics or tracking pixels, and no cross-site profiling. Clearing cookies simply logs you out.

6. Email notifications

Transactional emails (order confirmation, payment received, shipment) are sent automatically because they are part of the order. The shop does not add you to a marketing list without your explicit consent, and any marketing email includes an unsubscribe option.

7. Retention and deletion

Order records are kept for as long as the store’s bookkeeping and warranty obligations require. You can ask the store to delete your account; your profile and address book are then removed, while completed orders remain in the accounting records in anonymised form.

8. Data security

The application applies standard protections: passwords are stored as one-way hashes (never in plain text), access is limited by role, and all traffic between client and server is expected to run over HTTPS/TLS.

No system is perfectly secure. Server hardening, backups, and access management for a live installation are the responsibility of the organization operating it.

9. Children

The shop is not directed at children under 13 and requires a valid payment method to complete an order.

10. Your rights

You have the right to ask for access to, correction of, or deletion of your personal data, and to object to certain processing.

Because your data lives in the installation run by the organization you deal with, address those requests to that organization first — they hold the data and can act on it. If you cannot reach them, or you believe the application itself is at fault, contact the developer at mhdlutfidev@gmail.com and I will assist technically.

11. Changes to this policy

If this policy changes, the “Last updated” date at the top of this page will be revised. Material changes will be reflected in the application release notes.

12. Contact

Questions, complaints, or privacy requests about this application:

mhdlutfidev@gmail.com

I aim to respond within 7 business days.