Privacy Policy

Effective: 11 August 2026 · Last updated: 11 August 2026

This English version is provided for convenience only. In the event of any discrepancy, the Indonesian version prevails.

Quick summary

  • We collect account data, identity verification (KYC) data, trip participant data, and transaction data.
  • We do not sell your personal data to third parties.
  • Participant national identity numbers (NIK) are stored encrypted.
  • Payments are processed by Xendit — we never store your card details.
  • You can access, correct, and delete your account and data at any time.

1. About This Policy

This Privacy Policy explains how PT Kumbaya Indonesia Grup ("Kumbaya", "we", "us") collects, uses, stores, shares, and protects your personal data when you use the kumbaya.id website and application (the "Platform").

PT Kumbaya Indonesia Grup acts as the Personal Data Controller for the processing described in this Policy.

Kumbaya is a platform that connects trip organizers ("Vendors") with hiking and outdoor participants ("Participants"). This Policy applies to Vendors, Participants, Vendor staff, and visitors to the Platform.

We process personal data in accordance with Law Number 27 of 2022 on Personal Data Protection (the "PDP Law") and its implementing regulations.

By registering for or using the Platform, you confirm that you have read and understood this Privacy Policy.

2. Data We Collect

2.1 Account data

  • Name, email address, phone/WhatsApp number, and password (stored as a one-way hash, never in plain text).
  • Username, brand name, business description, bio, profile photo, and operating location (Vendors only).
  • If you sign up or sign in with Google: your Google account identifier, name, email address, and profile photo.

2.2 Identity verification data (KYC)

  • Photo of your national ID card (KTP) and a selfie photo.
  • Social media profile links and other supporting documents, depending on the verification tier.
  • Verification status, submission time, approval time, and rejection reason (if any).

KYC data is used solely to verify Vendor identity and to prevent fraud.

2.3 Financial data

  • Bank name, account number, and account holder name, used for Vendor payouts.
  • Booking, payment, invoice, payout, refund history, and any transfer receipts you upload.

We do not store your credit/debit card number, CVV, PIN, or mobile banking credentials. All card, virtual account, and e-wallet payments are processed directly by a licensed payment provider (Xendit).

2.4 Trip participant data

For hiking safety and to comply with conservation area requirements, the Platform processes the following Participant data — whether entered by the Participant or by the Vendor:

  • Full name, gender, phone number, address, place and date of birth.
  • National identity number (NIK), stored in encrypted form.
  • Blood type, allergies, and relevant medical conditions.
  • Emergency contact (name, relationship, and phone number).
  • Hiking experience, selected schedule and meeting point, and on-site check-in status.

Blood type, allergies, and medical conditions are specific personal data under the PDP Law. We process them based on your consent and to protect the vital interests of Participants during an activity.

2.5 Technical and usage data

  • IP address, device and browser type, operating system, and pages visited.
  • Access times, error logs, and significant account activity (for example, settings changes or access to sensitive data).
  • Cookies and local storage — see Section 7.

2.6 Data from optional Vendor integrations

  • Instagram content import: if a Vendor links or imports Instagram posts, we retrieve the public content of those posts (images, captions, dates) to display as trip material on the Platform.
  • WhatsApp AI assistant: if a Vendor enables this feature, our assistant service processes WhatsApp numbers and the content of conversations between the Vendor and their customers in order to generate automated replies and the Vendor's knowledge base. The feature is optional and can be disabled; deleting a Vendor account also triggers deletion of the corresponding data in the assistant service.

3. Purposes and Legal Bases

  • Providing the service — creating accounts, listing trips, processing bookings, issuing e-tickets and receipts. Basis: performance of a contract.
  • Verification and security — verifying Vendor identity, preventing fraud and account abuse. Basis: legitimate interests and legal obligation.
  • Payments and payouts — processing invoices, payments, refunds, and disbursements. Basis: performance of a contract and legal obligation.
  • Activity safety — preparing participant manifests, field check-in, and emergency response. Basis: consent and protection of vital interests.
  • Communication — sending transactional notifications, reminders, and service information by email, WhatsApp, or in-app notification. Basis: performance of a contract and consent.
  • Product improvement — aggregate usage analytics to improve features and performance. Basis: legitimate interests.
  • Compliance — meeting tax and accounting obligations and responding to lawful requests from competent authorities. Basis: legal obligation.

4. Data Sharing

We do not sell your personal data. We share data only with the following parties, and only as far as necessary:

  • Vendors operating the trip — receive the data of Participants who book their trips, for registration with area authorities, manifests, and safety purposes.
  • Payment providers (Xendit) — to process payments, refunds, and payouts.
  • Infrastructure and supporting service providers — hosting, databases, file storage, transactional email delivery, and analytics (including Google Firebase Analytics).
  • Conservation area / national park managers and public authorities — where required for hiking permits, emergency response, or lawful requests under applicable law.
  • Professional advisers — auditors or legal counsel, bound by confidentiality obligations.

Some of our service providers are located, or store data, outside Indonesia. Where personal data is transferred across borders, we ensure the recipient applies a level of protection equivalent to that required by the PDP Law.

5. Storage and Retention

  • Account data is retained for as long as your account remains active.
  • Transaction data and financial records are retained for at least 5 (five) years to meet tax and accounting obligations, even after an account is deleted.
  • KYC documents are retained while a Vendor is active, and are deleted or anonymised once the retention obligation ends.
  • Participant data is retained as long as needed to operate the trip and to handle claims and disputes.
  • Technical logs are generally retained for a short period for security and troubleshooting purposes.

6. Data Security

  • All Platform traffic is encrypted using HTTPS/TLS.
  • Passwords are stored as one-way hashes; Participant NIK is encrypted at rest.
  • Internal access is restricted by role (role-based access control), and access to sensitive data is recorded in audit logs.
  • KYC documents and payment proofs are kept in private storage, accessible only through time-limited signed links.

No system is entirely free of risk. In the event of a personal data protection failure, we will notify you and the relevant authority no later than 3 x 24 hours after becoming aware of it, as required by the PDP Law.

7. Cookies and Similar Technologies

We use cookies and browser local storage to:

  • Essential cookies — maintain your login session and protect forms against CSRF attacks. These cannot be disabled without breaking Platform functionality.
  • Preference cookies — remember your display settings and onboarding progress.
  • Analytics cookies — measure feature usage through Google Firebase Analytics.

You can delete or block cookies through your browser settings.

8. Your Rights

Under the PDP Law, you have the right to:

  • Be informed about and access your personal data.
  • Correct or complete inaccurate data.
  • Erase your personal data and end its processing.
  • Withdraw consent for processing that relies on consent.
  • Object to automated decision-making that produces legal effects for you.
  • Obtain a copy of your data in a commonly used format.
  • Lodge a complaint and seek compensation for personal data protection violations.

You can exercise most of these rights yourself from Profile → Account Settings, including updating your data and deleting your account. For any other request, contact us at [email protected]. We will respond no later than 3 x 24 business hours after the request is received and verified.

For Participant data entered by a Vendor, the Vendor determines the processing of that data. Requests concerning Participant data may be submitted to the relevant Vendor or through us, and we will forward them.

9. Account Deletion

You can delete your account at any time from the Profile page. After deletion, your profile data and content are deleted or anonymised, including data held in the WhatsApp AI assistant service if that feature was ever enabled. Transaction data that we are required to retain under tax and accounting rules is kept in accordance with Section 5, in the most minimal form possible.

Deleting your account does not cancel bookings in progress or outstanding payment obligations.

10. Children and Underage Participants

The Platform is intended for users aged 18 and over. Participants under 18 may only be registered by a parent or guardian who consents to the processing of that child's personal data. If we learn that an account was created by a child without guardian consent, we will delete the account and its data.

11. Third-Party Links and Services

The Platform may contain links to third-party sites, including Vendor social media profiles and payment pages. Third-party privacy policies govern any data you provide on their sites, and we are not responsible for those privacy practices.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification before they take effect. The date of the most recent update is always shown at the top of this page.

13. Contact Us

Questions, requests to exercise Personal Data Subject rights, or privacy complaints can be sent to:

If you consider our response inadequate, you have the right to lodge a complaint with the competent personal data protection authority in Indonesia.