Skip to main content
IDEN

Last updated: August 5, 2026

Privacy Policy

This page explains how we manage and protect information when you use SiberPOS services.

Privacy Policy

Privacy Policy

1. Introduction

Welcome to SiberPOS!

This privacy policy explains how PT. Dunia Siber Teknologi ("We", "Us", or "Dusitek") collects, uses, processes, stores, and protects your personal information.

This policy applies to all users of our services ("You", "Client", "User", or any entity you represent) who use our platform, website, dashboard, applications, or services.

By registering for or using our services, you are deemed to have read, understood, and agreed to this policy.

This policy may change from time to time. Changes will be notified through your account.

2. Personal Information

Personal information is data that can identify an individual, including but not limited to:

  • Name
  • Address
  • Date of birth
  • Email address and phone number
  • Bank account information for disbursement purposes
  • Identification documents (National ID card, driver's license, or passport)
  • Gender and occupation

Not all of the data above is relevant to every user; the types of data we collect depend on your role (business owner, cashier, merchant customer, or partner).

We only collect and use this data in accordance with applicable law and with your consent.

3. Purposes of Data Use

We use personal information to:

  • Manage user accounts
  • Process transactions and payments
  • Provide service notifications and updates
  • Respond to questions and feedback
  • Improve service quality
  • Analyze platform usage
  • Provide technical support
  • Manage reward points
  • Conduct research and development
  • Prevent illegal activity

A. Merchant Information

We collect:

  • Identity information (National ID card, name, and company)
  • Business address and type of business
  • Email address and phone number
  • Bank account information for disbursement purposes
  • Device data: IP address, device identifiers (Android ID on Android or identifierForVendor on iOS), notification tokens (Firebase Cloud Messaging), device model, operating system version, and application version

Used for:

  • Account verification and management
  • Identifying registered cashier devices
  • Sending order and payment notifications
  • Processing payments
  • Diagnosing application failures
  • Fraud prevention
  • Platform analysis and development

B. Merchant Customer Information

We collect:

  • Customer names and email addresses
  • Phone numbers
  • Transaction and payment details
  • Device and IP data
  • Order records

Used for:

  • Processing transactions
  • Supporting your business operations
  • Providing better services

C. Partner / Third-Party Information

We collect:

  • Name and company
  • Email address and phone number
  • Payment information
  • Web activity data

Used for:

  • Business collaboration
  • Service development
  • Marketing and research activities

D. Website Visitor Data and Cookies

This section applies to our websites and marketing pages, not to the SiberPOS cashier application. The cashier application does not display advertisements or track your activity within the application or on other websites.

We collect:

  • IP address
  • Browser and device information
  • Website activity history

Used for:

  • Personalizing your website experience
  • Analyzing website usage

5. Data Retention

  • Data is stored while the business account is active and for as long as necessary for business purposes
  • After an account is deleted, personal data is deleted within 3 business days, except for data that must be retained under applicable law
  • Anonymous and aggregated data may be retained for analysis

6. Third Parties

We may share limited data with service providers that help operate the platform:

  • Google Firebase (Cloud Messaging, Crashlytics): sending notifications and reporting application crashes. The data processed includes notification tokens, device identifiers, and technical crash information
  • Payment gateway providers: processing payments, including QRIS
  • Infrastructure and storage providers: hosting services and storing data

Each of these third parties, including our parent entities, subsidiaries, or affiliates that have access to user data, must provide the same or equivalent level of data protection described in this policy and may not use the data for any other purpose.

We do not sell your personal data to anyone.

7. Data Security

We protect your data through:

  • Encryption of data in transit through HTTPS/TLS
  • Encrypted storage of session credentials on devices (Keychain on iOS and Keystore on Android)
  • Role-based access controls
  • Regular security audits

Card payments are processed by PCI DSS Level 1-certified payment gateway partners. Our applications and systems do not store card numbers.

However, no method of transmission over the internet is completely secure.

8. International Data Transfers

Some service providers we use may process data outside Indonesia, such as Google's notification and crash-reporting services.

For each such transfer, we ensure that:

  • Processing is subject to Law No. 27 of 2022 on Personal Data Protection
  • There is a legal basis for the transfer in the form of a data processing agreement or standard contractual clauses with the service provider
  • The service provider provides a level of protection equivalent to that described in this policy

9. Your Rights

You have the right to:

  • Access your personal data
  • Update your data
  • Delete your data
  • Restrict the use of your data
  • Withdraw your consent to data processing

A. Cashier Accounts in the SiberPOS Application

Cashier accounts are created, managed, and deleted by the business owner through SiberPOS Backoffice (web). The cashier application does not provide account registration, and cashiers cannot delete their accounts from the application because the account belongs to the business, not to the individual cashier.

B. How to Submit a Request

  • Business owners: manage or delete cashier accounts directly through SiberPOS Backoffice
  • Cashiers: submit requests to the business owner for whom you work
  • Deletion of the entire business account and its data: submitted by the business owner to our support team through the official channel listed in the Contact section

Each deletion request is verified first to ensure that the requester is authorized to act on the account, and is then processed within 3 business days. We will send confirmation after the deletion is complete.

Consent to data processing may be withdrawn by disabling notifications through your device settings or by submitting a request through the channel listed in the Contact section. Withdrawing consent to data required to operate the service means that the account can no longer be used.

C. Data That Remains Stored

We may retain certain data after an account is deleted when required by applicable law, such as transaction records for tax and audit purposes. That data is retained for the legally required period and then deleted.

Restrictions on data may affect the services you receive.

10. Contact

For questions regarding this policy, data access requests, or data deletion requests, contact us through:

  • Email:siberpos@dusitek.com
  • WhatsApp:+6282156310062
  • Address:PT Dunia Siber Teknologi, Jl. HM Suwignyo, Ruko Citra Andalas No. 1-5, 4th Floor, Sungai Jawi, Pontianak, West Kalimantan, Indonesia

We respond to requests within 3 business days at the latest.

Everything You Need Under One Control Center

POS, Table Service, QR Dine-In, and other tools to support your F&B business.