Privacy Policy
Last Updated & Effective Date: 27 September 2026
1. Data Controller & System Scope
The application Marketplace Hub (hereinafter referred to as the "System") is owned, maintained, and operated privately by PT Rumah Komunitas Indonesia, located at Jl. Kemang Raya No. 10, Mampang Prapatan, Jakarta Selatan, DKI Jakarta 12730 (Contact Email: support@rumahkomunitas.com).
This System operates exclusively as an internal group enterprise integration hub and is not a publicly accessible or commercial Software-as-a-Service (SaaS). It strictly processes data from official marketplace stores owned and authorized by brands belonging to the PT Rumah Komunitas Indonesia group.
2. Categories of Data Processed
In order to fulfill and monitor commercial shopping transactions across authorized marketplace channels, the System processes the following data categories via official platform APIs:
- Store Authorization Credentials: Marketplace Store IDs, shop names, encrypted access tokens, and refresh tokens issued by Shopee and TikTok Shop.
- Order & Transaction Records: Order identification numbers (Order SN / Order ID), purchased product line items, quantities, variant selections, transaction prices, buyer purchase remarks, payment status, and fulfillment tracking events.
- Buyer & Recipient Personal Identifiable Information (PII): Recipient names, contact telephone numbers, physical shipping delivery addresses, sub-districts, cities, provinces, and postal codes as provided by the marketplace.
- Customer Support Conversations (Chat): Text dialogue history and uploaded customer service images exchanged between buyers and official store seller accounts to resolve customer inquiries.
- Reviews & Returns: Buyer product ratings, feedback commentary, return/refund requests, proof photos/videos, and dispute resolution records.
- Internal Operator Records: Staff credentials, role assignments (RBAC), and technical activity audit logs (IP addresses and user agents).
3. Legal Basis & Processing Purposes
All gathered data is processed strictly for legitimate operational purposes:
- Fulfillment & Shipping: Coordinating pickup/dropoff logistics parameters and generating shipping air waybills (AWB / shipping labels).
- Customer Service: Responding promptly to buyer questions, resolving logistics delays, and managing returns/refunds.
- Downstream Brand System Integration: Securely relaying order updates to internal brand Warehouse Management Systems (WMS) and ERPs via isolated API keys and webhooks.
- Financial Reconciliation & Audit: Internal bookkeeping, fee escrow verification, and operational reporting.
Non-Commercialization Principle: We do not sell, rent, lease, or monetize customer personal information to third parties, advertising brokers, or marketing networks for profiling or commercial targeting.
4. Data Storage Infrastructure & Security Measures
All data is hosted securely at: Jakarta, Indonesia (NEO Cloud / Data Center Tier 3).
Security protections enforced in the System include:
- Strong Cryptographic Encryption: Marketplace authorization tokens and sensitive keys are encrypted in the database using industry-grade AES-256-CBC.
- Brand-Level Data Isolation: Every brand API request is strictly scoped and validated using SHA-256 hashed API keys. Cross-brand data leakage is prevented at the database query layer.
- Webhook Signature Verification: Inbound marketplace webhooks undergo cryptographic HMAC-SHA256 signature verification before any job execution.
5. Data Retention Schedule
Data is retained only as long as necessary for technical operations and legal compliance:
| Data Category | Retention Period | Post-Retention Action |
|---|---|---|
| Inbound Webhook Payload Logs | 30 Days | Automatically pruned by scheduled cron |
| Technical Synchronization Logs | 60 Days | Automatically pruned by scheduled cron |
| Temporary Shipping Label PDFs | 7 Days | Deleted from local disk storage |
| Historical Order & Financial Records | 365 Days | Retained for corporate accounting and statutory tax audits |
6. Store Deauthorization & Automated Data Deletion
Sellers can revoke application authorization at any time directly through their respective Shopee or TikTok Shop Partner Center console.
-
Immediate Disconnection: Upon receiving the deauthorization webhook (Shopee code 1/2 or TikTok
SELLER_DEAUTHORIZATION), the store's status is immediately updated toREVOKED, halting all API background synchronization jobs. - Automated PII Anonymization & Purge: Customer identifiable information (recipient names, telephone numbers, and street delivery addresses) and raw API payloads associated with revoked stores are automatically anonymized within 30 days by an automated daily system scheduler command.
- Manual Deletion Inquiries: Data subjects or platform compliance officers may request early data erasure by contacting support@rumahkomunitas.com with the subject line "Data Erasure Request". All verified requests are addressed within 3 business days.
7. Official Third-Party Marketplace Partners
The System interacts directly with the following authorized third-party platforms:
- Shopee Open Platform: Data source for Shopee store orders, logistic parameters, chat messages, and reviews.
- TikTok Shop Partner Center: Data source for TikTok Shop / Tokopedia package management, order statuses, and returns.
8. Data Subject Rights & Contact Details
To exercise your privacy rights or submit queries regarding our data protection practices, please contact our Data Protection Officer at: