Privacy Policy
How Indovia collects, uses, shares, protects, retains, and responds to rights requests involving buyer, seller, visitor, transaction, shipping, communication, device, security, and compliance data.
Data follows marketplace purpose
Indovia uses personal data to operate accounts, orders, payments, shipping, support, safety, compliance, and improvement.
Public contact leakage is restricted
Private phone, WhatsApp, email, bank, identity, and address details should not appear on public buyer-facing pages.
Controlled service-provider access
Payment, hosting, shipping, email, security, analytics, and professional providers receive data needed for their role.
Rights requests available
Users may request access, correction, deletion, restriction, withdrawal, objection, or other applicable rights through support.
1. Scope and who this policy covers
This Privacy Policy applies to Indovia websites, marketplace accounts, buyer and seller consoles, checkout, messages, support, Trust and Help pages, and related services that link to it.
It covers visitors, registered buyers, invited seller applicants, verified sellers, seller staff, recipients, support contacts, reviewers, and other persons whose data enters the marketplace. It also covers information supplied by another user, such as recipient details entered by a buyer or staff information submitted by a seller.
Indovia determines why and how core marketplace data is processed for platform operation. A seller can separately determine certain processing when using buyer information for lawful fulfillment or compliance. PayPal, card issuers, banks, POS, DHL, customs authorities, hosting providers, and other parties may act independently under their own legal duties and privacy policies.
Where a separate notice, consent, onboarding statement, cookie preference, contract, or legally required disclosure applies to a specific activity, that notice supplements this policy. Mandatory personal-data rights under applicable law remain available.
2. Categories of personal data
Indovia processes different information depending on whether a person browses, buys, sells, communicates, or requests support.
Account and identity data can include name, username, email, password hash, role, language, country, account status, verification state, invitation information, profile image, and security settings. Seller verification can include business name, entity type, registration information, tax or licensing information, responsible person, beneficial ownership, identity documents, signatures, business address, production location, bank-account evidence, and review notes where necessary.
Order and transaction data can include products, variations, quantities, price, discounts, shipping, currency, billing and delivery details, recipient contact, order status, payment method, transaction reference, paid date, refund, dispute, chargeback, seller balance, payout request, and reconciliation information. Indovia does not need to display a complete card number to operate ordinary marketplace records.
Product and store data can include store identity, seller story, product content, images, stock, SKU, origin, weight, dimensions, certifications, categories, policies, FAQ, reviews, ratings, sales indicators, and moderation history. Communication data can include Q&A, chat, order messages, complaint files, support tickets, announcements, email delivery records, and moderation actions.
Technical and usage data can include IP address, device and browser information, operating system, timestamps, URLs, referral, session identifiers, cookies, preference data, login events, errors, performance, security signals, and interaction with marketplace features. Approximate location can be inferred from IP or destination data; precise location is not normally required unless a feature clearly requests it.
3. How Indovia receives personal data
Data can come directly from the person, another transaction participant, a connected provider, or marketplace use.
Users provide data when creating an account, accepting an invitation, completing seller onboarding, publishing a store or product, placing an order, entering a recipient, selecting shipping, paying, messaging, uploading evidence, leaving a review, changing account settings, requesting payout, or contacting support.
Connected providers can supply payment status, transaction references, shipping quotes, courier eligibility, tracking, delivery events, email delivery, security, hosting, analytics, or other service information. Sellers can provide buyer-related fulfillment evidence; buyers can provide seller-related complaint evidence. Public registries, sanctions lists, brand owners, regulators, or professional advisers can provide compliance information where lawful and relevant.
Indovia automatically generates logs and derived records, such as sales counts based on confirmed paid orders, account-risk signals, complaint holds, finance states, audit trails, moderation indicators, and performance measures. Derived records are reviewed and corrected when source information changes.
4. Purposes of processing
Indovia processes data only for defined marketplace, safety, legal, and improvement purposes.
Core purposes include creating and securing accounts; verifying buyers or sellers; reviewing seller invitations; publishing stores and products; providing search, recommendations, cart, checkout, payment, shipping estimates, order management, tracking, communication, reviews, complaints, refunds, finance, and payout workflows; and delivering transactional messages.
Indovia also uses data to prevent fraud, payment bypass, counterfeit sales, unsafe listings, account compromise, spam, harassment, privacy leakage, review manipulation, fake sales, chargeback abuse, prohibited products, sanctions violations, and other misuse. Logs and communications can be reviewed to investigate incidents and enforce policies.
Data supports customer service, dispute resolution, accounting, tax, audit, legal claims, regulatory response, security testing, backup, business continuity, debugging, performance improvement, accessibility, content quality, and product development. Aggregated or de-identified information may be used for marketplace analysis where individuals are not reasonably identifiable.
Marketing messages are sent only where permitted. Transactional messages about accounts, security, orders, payment, shipping, complaints, policy changes, or service administration are not optional marketing when needed to operate the relationship.
5. Grounds for processing
The applicable ground depends on the data, person, purpose, and law.
Indovia may process data because it is necessary to provide requested marketplace services or perform a contract; comply with legal obligations; protect a person's vital interests; carry out tasks in the public interest where authorized; pursue legitimate interests that do not override individual rights; establish, exercise, or defend legal claims; or act on consent where consent is required.
Legitimate interests can include marketplace security, fraud prevention, service improvement, network protection, record integrity, dispute resolution, seller curation, moderation, and understanding service use. Indovia considers necessity, proportionality, reasonable expectations, and safeguards before relying on those interests.
Where processing relies on consent, the request will identify the relevant purpose and consent can be withdrawn for future processing. Withdrawal does not affect processing already lawfully performed and does not require deletion where another lawful ground or retention obligation applies.
6. Public marketplace information and private information
Marketplace transparency does not justify exposing unnecessary personal contact or financial details.
Public information can include store name, seller display identity, general location, seller story, product content, ratings, reviews, public Q&A, sales indicators, and other information intentionally published for marketplace use. Search engines or third parties can index public pages. Removing content later may not erase copies held outside Indovia.
Private seller phone numbers, WhatsApp details, personal email, bank information, identity documents, and non-public addresses must not appear on product pages, store pages, images, descriptions, FAQ, seller policy, or story. Buyer delivery addresses, payment references, private messages, complaint files, and account details are not public.
Indovia may detect, mask, remove, or moderate contact details and payment instructions to prevent off-platform transactions and privacy leakage. Users should not upload another person's information unless they have authority and it is necessary for the marketplace purpose.
8. International data processing
A global marketplace can require data to be processed outside the user's country.
Buyers can be located worldwide, sellers are primarily based in Indonesia, and payment, hosting, security, email, shipping, analytics, and professional providers can operate in multiple countries. Personal data may therefore be accessed, stored, transmitted, or otherwise processed across borders.
Where applicable law requires protection for an international transfer, Indovia uses appropriate contractual, organizational, technical, consent-based, adequacy, or other lawful safeguards. The level of legal protection and government access rules can differ by country.
Users should avoid placing unnecessary sensitive information in free-text fields or attachments. Indovia can restrict a provider or transfer when legal, security, or operational risk becomes unacceptable, but cannot promise that every transaction can be completed without international processing.
10. Data retention and deletion
Indovia retains data for as long as necessary for the purpose, legal duties, security, disputes, and reliable marketplace records.
Account data can remain while an account is active and for an appropriate period afterward. Orders, payments, refunds, payouts, tax, accounting, shipping, complaint, audit, fraud, and legal-claim records may need longer retention. Seller verification data can remain while seller access or related obligations continue and afterward where risk or law requires.
Retention periods consider legal limitation periods, consumer and payment dispute periods, tax and accounting duties, carrier and customs needs, safety, fraud patterns, backups, litigation holds, and whether data can be de-identified. Different record categories can have different periods.
Deletion from active systems may not immediately remove secured backups. Backup copies are protected and removed or overwritten according to normal cycles unless preservation is required. Indovia may retain a minimal suppression or enforcement record to honor opt-outs, prevent re-registration abuse, or document prior legal action.
11. Security and incident response
Indovia uses reasonable technical and organizational safeguards, but no online service can promise absolute security.
Safeguards can include access control, authentication, role separation, encryption in transit, secure hosting, logging, backups, monitoring, review of high-risk changes, provider controls, staff confidentiality, restricted public exposure, and incident procedures. Specific controls can change as threats and technology evolve.
Users must protect passwords, email, payment accounts, devices, and recovery channels; avoid credential reuse; verify domains; and report suspicious activity. Sellers should remove access promptly when staff leave or roles change. Indovia may lock accounts, revoke sessions, require verification, or reset credentials after suspected compromise.
If a personal-data incident occurs, Indovia investigates scope, risk, affected systems, containment, recovery, and required notice. Indovia will notify affected persons and authorities when applicable law requires it. Notices will explain available facts and protective steps without exposing security-sensitive details.
12. Personal-data rights
Rights depend on applicable law and can be limited when another person's rights, legal duties, security, or claims require protection.
Applicable rights can include information about processing; access to personal data; correction or completion; withdrawal of consent; objection to certain processing; restriction, suspension, or cessation; deletion or destruction; data portability; complaint; compensation; and review of decisions based solely on automated processing that create significant effects.
Indovia may need to verify identity and account control before acting. A request can be clarified, limited, or refused where it is manifestly unfounded, excessive, conflicts with law, exposes another person's data, would undermine fraud prevention or security, or concerns records that must be retained. Indovia will explain the basis where required.
Users can correct many account fields directly. Order, payment, audit, review, moderation, and complaint records may be preserved as historical records while an inaccurate current fact is corrected or annotated. Deleting an account does not cancel unresolved orders, refunds, payouts, disputes, legal duties, or enforcement records.
A buyer asks to delete an account with an active order and complaint.
Indovia may restrict the account but retain and process data needed to complete the order and resolve the case.
A seller corrects a business address.
Indovia may update current data while retaining prior audit records needed for past orders and compliance.
A request would reveal another user's private message or security signal.
Indovia may redact or withhold that portion while providing the requester's accessible data.
13. Analytics, profiling, and automated support
Indovia can use rules and technical signals to prioritize review, protect accounts, and improve services.
Rules or models can identify unusual login, payment risk, spam, contact leakage, prohibited content, duplicate accounts, fake sales, listing quality problems, shipping anomalies, or support priority. These tools can produce a score, flag, recommendation, restriction, or request for human review.
Indovia does not rely solely on an automated result for a legally significant decision where applicable law requires meaningful human review. Users may request explanation or review of a significant automated decision to the extent required by law, subject to protection of confidential fraud and security methods.
Aggregated analytics can be used to understand categories, search, conversion, delivery, complaints, performance, and reliability. Indovia seeks to reduce identification where individual-level data is unnecessary.
14. Children and persons without legal capacity
Indovia accounts and seller access are intended for persons able to enter binding marketplace transactions.
Users should be at least 18 years old or the age of legal majority required for the transaction, unless a parent or lawful guardian acts and applicable law permits. Seller applicants must have authority to represent the business. Indovia does not knowingly invite children to operate seller accounts.
If Indovia learns that a child's data was submitted without valid authority, it may restrict the account and delete or limit the data, subject to order, safety, legal, and record-preservation needs. Parents or guardians can contact support@indovia.net with enough information for verification without sending unnecessary documents initially.
15. Privacy requests, complaints, contact, and changes
Use a clear request that identifies the account and right without exposing more sensitive data than necessary.
Privacy requests can be sent to support@indovia.net with the subject line Privacy Request. Include the account email, relationship to Indovia, request type, and relevant context. Do not email passwords, complete payment credentials, or full identity documents unless Indovia provides a secure, necessary verification method.
Indovia may ask for reasonable verification, especially for access, deletion, account takeover, seller identity, or payment-related requests. Authorized agents must show authority. Indovia will respond within the period required by applicable law, subject to permitted extension, complexity, verification, and preservation obligations.
Individuals may complain to the relevant personal-data authority or pursue other legal remedies where available. Indovia encourages direct contact first so records can be identified and corrected promptly, but direct contact is not a waiver of external rights.
Indovia may update this policy for new features, data categories, providers, security practices, legal requirements, or organizational changes. The effective date will be revised and material changes will receive an appropriate notice where required. If consent is required for a new purpose, Indovia will request it rather than rely only on continued use.