Last updated 16 July 2026

Privacy Policy

Draft — pending legal review. This document describes how Protocol operates today, but it has not yet been reviewed by counsel. Do not rely on it as final; the published version may differ.

1. Scope

This policy explains how PT Soember Djaya Masyarakat (“Soedja”) handles data in Protocol, the payment tunnel for the Soedja ecosystem. It covers two kinds of people: the Merchants who hold Protocol accounts, and the customers whose payments flow through it.

For a customer’s personal data, the Merchant is the controller and Protocol acts on the Merchant’s behalf as a processor. For a Merchant’s own account data, Soedja is the controller.

2. What we collect

  • Merchant account — email address, business name, a website or social profile, an optional logo, and (for payouts) bank name, account number, and account holder name.
  • Transactions — the order reference, product name, and amount you send us on a charge, plus any customer details you choose to pass (first name and, optionally, email and phone).
  • Technical — request metadata, IP address, and logs needed to operate, secure, and audit the service.
  • No card data. We never receive raw card numbers. Cards are tokenised in the browser directly by our payment processing provider; other methods carry no card data at all.

3. How we use it

  • To create and settle payments, and to notify your server of the result.
  • To compute your balance, verify bank accounts, and make payouts.
  • To secure the service, prevent fraud and abuse, and keep an audit trail.
  • To send transactional email about your account, payouts, and bank status.

We do not sell personal data, and we do not use customer payment data for our own marketing.

4. Who we share it with

We share data only with the processors that make the service work:

  • Our payment processing provider (currently Midtrans) — to create and settle payments (the payment processor of record).
  • Supabase — our database and authentication provider.
  • Vercel — hosting for the application.
  • SendGrid — to deliver transactional email.

We may also disclose data where required by law, or to our payment processing provider and the networks as part of processing, dispute, or compliance obligations.

5. How we protect it

  • API keys are stored as a one-way hash plus an encrypted copy; webhook secrets and stored keys are encrypted at rest (AES-256-GCM).
  • Every Merchant’s data is isolated at the database layer — one Merchant can never read another’s transactions, balance, bank details, or credentials.
  • Sandbox and production are separated so test data and real money never share a table.
  • Access to the underlying systems is limited and audited.

6. Retention

We keep transaction and payout records for as long as needed to operate the service and to meet legal, tax, accounting, and audit obligations. Account data is kept while your account is active and for a reasonable period afterwards.

7. Your rights and choices

Subject to applicable law, you may request access to, correction of, or deletion of your Merchant account data, and you can update most of it directly in your dashboard. Requests about a customer’s personal data should be directed to the Merchant that collected it; we will assist that Merchant as their processor.

8. Cookies and international transfers

We use only the cookies required to keep you signed in — no advertising or third-party tracking cookies. Some of our processors operate outside Indonesia; where data is transferred internationally, we rely on those providers’ safeguards.

9. Changes and contact

We may update this policy; material changes will be communicated. Questions or requests: agie@soemberdjaya.com.