Hukum
Privacy Policy
Exactly what personal data Maleo Sites holds, why we hold it, how long we keep it, and the rights you have over it under UU PDP.
- Effective
- 23 August 2026
- Version
- 1.0
1. Who we are, and the two hats we wear
maleosites.com is operated by Bima Saputra, an individual sole proprietor trading as Maleo Labs, from Jl. Raya Palembang-Betung KM 18, Palembang, Sumatera Selatan, 30961, Indonesia. In this documentwe and us mean the operator, and you means the person who holds a Maleo Sites account. The full operator identity is published at /legal.
We handle two different kinds of personal data, under two different roles, and it matters which one your question is about.
Data about you, the account holder — we are the controller
When you sign up, build a site, pay us, and connect a domain, we decide what is collected and why. In the language of UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (UU PDP) we are the pengendali data pribadi — the controller. Everything in this policy is about that data.
Data collected by the websites you publish — we are the processor
When someone visits yourbusiness.maleosites.com or your custom domain and fills in your booking form, that visitor's data belongs to your relationship with them, not ours. You are the controller (pengendali) of it; we only store and move it on your instructions, which makes us the prosesor data pribadi (processor). The terms of that arrangement are in the Data Processing Agreement, not here.
If you are a visitor to a business's website hosted on Maleo Sites and you want to know what that business does with your name and phone number, or you want it deleted, contact the business itself — it is their record, and they control it. If you cannot reach them, write toprivacy@maleosites.com and we will pass the request on to the site owner.
2. What we collect, and why
2.1 Your account
- Name, email address, whether that email has been verified, your profile picture URL, and your language preference, plus the dates the account was created and last changed. This is what identifies your account and where we send anything we have to send you.
- If you sign in with email and password: a one-way hash of your password. We never store the password itself and cannot read it.
- If you use "Sign in with Google": the access token, refresh token, ID token, and granted scope that Google issues to us, so we can confirm it is you at each sign-in. Google also gives us your name, email address, and profile picture. We do not read your Gmail, Drive, or contacts, and we do not ask for permission to.
- Short-lived tokens for email verification and password resets. They expire quickly and are then useless.
2.2 Your sessions — including your IP address
Every time you sign in we create a session record holding a session token, its expiry, the IP address the sign-in came from, and the User-Agent string your browser sends (which reveals your browser and operating system). We keep those two because they are how anyone — you or us — can tell a legitimate sign-in from a stolen one. They are attached to your account and are not anonymous. Signing out ends the session.
2.3 Your sites and your business details
Whatever you put into the editor: your text and headings, the design you chose, your slug, whether the site is published, and the business details you enter about yourself — business name, address, phone number, WhatsApp number, and opening hours. Some of that is personal data about you, and when you press Publish you are making it public on purpose. Photos and other files you upload are stored as objects in Cloudflare R2.
2.4 Payments
For each order and subscription we record the plan, the billing cycle, the amount, the payment status, and the transaction and subscription IDs given to us by the payment provider, along with the webhook events the provider sends us about them. We keep these to give you the plan you paid for, to issue receipts, and to file our taxes.
2.5 Your own custom domain
If you connect a domain you own through your Cloudflare account, we store an OAuth refresh token for that Cloudflare account. We use it for one thing: creating and updating the DNS records that point your domain at your site. It is stored because DNS has to be re-checked and repaired after the initial setup, not just once. You can revoke it from your Cloudflare account at any time, and disconnecting the domain in Maleo Sites deletes our copy.
2.6 Abuse prevention
We keep short-lived counters, keyed by a value derived from the requester's IP address, that count how many times a given action has been attempted in a short window. That is how sign-in brute force, signup floods, and form spam get stopped. The counters hold numbers and a key, not a browsing history, and they expire on their own.
2.7 Data your published sites collect from visitors
Listed here for completeness; you control it, and the DPA governs it.
- Form submissions: the visitor's name, WhatsApp phone number, and free-text note. Each submission is forwarded to your WhatsApp and stored so you can find it again in your dashboard.
- Analytics events: a pseudonymous visitor hash, country and city as reported by Cloudflare's request headers, device type derived from the User-Agent, the page path, the referring domain, time on page, which page sections scrolled into view, and clicks on WhatsApp, phone, map, and link buttons. Traffic identified as bot traffic is discarded rather than recorded. Seesection 5 for how the hash works.
3. What we do not collect
- Card numbers, CVV codes, and bank credentials never reach us. Payment details are entered on pages hosted by Mayar or Dodo Payments. We receive a transaction ID and a status; that is the whole of it. We could not leak your card number if we tried.
- No advertising, no ad networks, no marketing pixels, and no cross-site tracking — not on maleosites.com and not on the sites you publish. We do not sell personal data, we do not share it with data brokers, and we do not build advertising profiles.
- No third-party analytics service. The statistics you see are computed by our own code from our own database.
- We do not ask for your national identity number, date of birth, religion, health information, biometrics, or any other data UU PDP treats as specific personal data, and there is nowhere in the product to enter it.
4. Legal bases under UU PDP
UU PDP requires us to have a lawful basis for each purpose. Here they are, purpose by purpose.
| What we do | Basis under UU PDP |
|---|---|
| Create your account, host and publish your site, store your media, take your payments | Performance of the contract between you and us |
| Send service email: verification, password reset, billing and expiry notices, and notices of outages or important changes | Performance of the contract |
| Keep session IP and User-Agent, run rate limiting, block abuse and fraud | Legitimate interest in keeping the Service and your account secure |
| Produce aggregate, pseudonymous statistics for the site owner | Legitimate interest of the site owner in understanding their own visitors, with no visitor identifier retained beyond the day |
| Optional communications: product announcements and tips you asked to receive | Consent, which you can withdraw at any time without losing the Service |
| Keep invoices and accounting records; answer a lawful order from a court or authority | Compliance with a legal obligation |
Where we rely on legitimate interest, we have weighed it against your interests and limited what we keep and for how long accordingly. If you disagree with that balance in your case, you can object — seesection 12.
5. Analytics on the sites you publish
Site statistics are the one place where a privacy policy usually stops being specific, so here is exactly how ours works.
No cookie is set on the visitor. Nothing is written to their browser and nothing is read from it. There is no identifier stored on the visitor's device at all.
To count how many different people visited rather than how many page loads happened, we need a way to recognise the same visitor twice in one day. We do it with a one-way hash. Each day we generate a new random salt. The visitor identifier is the SHA-256 hash of that day's salt combined with the visitor's IP address, their User-Agent, and the ID of the site they are on. The IP address itself is never written to the analytics tables — only the hash is.
Two consequences follow, and they are the point of the design:
- We cannot follow a visitor from one day to the next. Tomorrow the salt is different, so the same person produces a completely different hash. The old salt is deleted within two days, after which yesterday's hashes cannot be recomputed or reversed by anyone, including us.
- We cannot follow a visitor from one site to another. The site ID goes into the hash, so the same person visiting two Maleo Sites websites on the same day appears as two unrelated identifiers.
Location is recorded as country and city only, taken from the headers Cloudflare adds to the request — not from GPS and not from any device permission. Device type is "phone", "tablet", or "desktop", derived from the User-Agent; the raw User-Agent string is not stored in the analytics tables. Requests we identify as bots are discarded, not counted.
After 90 days the individual events are deleted and only the daily totals remain, and those totals contain no visitor identifier of any kind.
6. Cookies
We set two cookies. That is the complete list.
| Cookie | What it does | Lifetime |
|---|---|---|
| Authentication session cookie | Keeps you signed in to your dashboard. Without it you would have to log in on every page. | Until the session expires or you sign out |
ms_lang | Remembers whether you want the interface in Indonesian or English. | One year |
Both are strictly necessary for the Service to work as you asked, which is why there is no cookie banner asking permission for them. The websites you publish set no tracking cookies at all— no analytics cookie, no advertising cookie, nothing.
7. Who else touches your data
We do not sell personal data and we do not share it for anyone else's marketing. Data reaches other companies only where they perform part of the Service for us, as sub-processors bound to use it only on our instructions. The current list, with the data each one actually touches, is at/legal/subprocessors; it is summarised here.
| Provider | What they do for us | Where |
|---|---|---|
| Cloudflare, Inc. | Application hosting, database (D1), object storage (R2), CDN, and DNS | Global edge network, including data centres in Singapore and the United States |
| Resend, Inc. | Transactional email (email verification, password reset, notifications) | United States |
| PT Mayar Kernel Supernova | Payment processing for customers paying in Indonesian rupiah | Indonesia |
| Dodo Payments | Merchant of record and payment processing for customers paying in currencies other than Indonesian rupiah | India and the United States |
| Google LLC | Optional "Sign in with Google" authentication | Global |
Beyond that list, we disclose personal data only in two situations:
- Legal process. When we are required to by Indonesian law, or by a valid court order or a lawful request from an authorised government body. We check that a request is valid and properly issued before answering it, we give no more than what is asked for, and we tell you unless the law forbids us from doing so.
- A business transfer. If the Service is ever sold, merged, or transferred, account data would move with it. We will tell you before that happens and you will be able to delete your account first. Any buyer is bound by this policy until you are given notice of a new one.
8. International transfers
The Service runs on Cloudflare's global network, so your data is processed at whichever data centre is closest to the request — for Indonesian visitors that is usually Singapore or Jakarta, but it is not guaranteed to stay inside Indonesia. Transactional email goes through Resend in the United States, and non-rupiah payments through Dodo Payments in India and the United States. Mayar, which handles rupiah payments, is Indonesian.
UU PDP allows personal data to be sent outside Indonesia when the destination country's level of protection is equivalent or higher, or when adequate and binding safeguards are in place, or with your consent. We rely on the contractual data protection terms in each provider's data processing agreement, which bind them to protect the data and to process it only on our instructions. We do not claim any certification or adequacy decision beyond that.
9. How long we keep things
These periods are not aspirations. They are the numbers the deletion job actually uses, read from the same constant this page is generated from.
| Data | Kept for | Why that long |
|---|---|---|
| Raw analytics events on published sites | 90 days | Long enough to see a season of traffic, then deleted event by event. |
| Daily analytics aggregates (counts per site, per day) | 25 months | Lets you compare this month with the same month last year. Contains no visitor identifier. |
| Daily visitor salt used to compute the pseudonymous hash | 2 days | Discarded almost immediately. Once it is gone, the hashes it produced cannot be reversed. |
| Account, sites, uploaded media, and form submissions | For as long as your account is open | This is the thing you are paying us to keep. You can delete any of it yourself at any time. |
| Account data after you ask us to delete the account | 30 days, then permanently deleted | A grace period so an accidental or hijacked deletion can be undone. |
| Encrypted backups | 35 days, rolling | Deleted data survives here briefly until the backup that contains it expires. |
| Orders, invoices, and payment records | 10 years | Indonesian tax law requires accounting records to be kept this long. We cannot shorten it. |
| Sessions and rate-limit counters | Until the session expires or the counter window closes | Both are short-lived by design and expire without anyone doing anything. |
Things get deleted sooner than the table says when:
- you delete a photo, a page, a site, or a form submission yourself — it goes when you press delete, subject only to the backup window;
- you close your account — see section 13;
- you disconnect a custom domain — the Cloudflare refresh token is deleted with it;
- you ask us to erase data and no legal obligation requires us to keep it.
10. Security
- All traffic to maleosites.com and to every published site is served over HTTPS, with certificates issued and renewed automatically. There is no unencrypted route in.
- Passwords are stored as one-way hashes, never as recoverable text.
- Data at rest sits in Cloudflare D1 and R2, encrypted by the platform.
- Administrative access to the production database is limited to the operator, protected by multi-factor authentication, and used only when something has to be fixed.
- Rate limiting on sign-in, signup, password reset, and public forms blunts brute-force and spam.
- Every query is parameterised and user-supplied content is escaped when rendered, so content one customer writes cannot execute in another's site.
No system is perfectly secure, and we will not pretend otherwise. A determined attacker, a flaw in a dependency, or a stolen password on your side can all defeat good engineering. Use a password you use nowhere else, and tell us at abuse@maleosites.com the moment something looks wrong with your account.
11. If there is a data breach
If personal data we hold is exposed, lost, or accessed without authorisation, UU PDP gives us3×24 hours to act, and we will use them. Within that window we will notify the affected users in writing and notify the supervisory authority, telling both what data was involved, what happened, what we have done about it, and what you should do — for example change a password or revoke a token. We will not delay notice while we finish investigating; you get what we know when we know it, and an update afterwards.
12. Your rights under UU PDP
As a subjek data under UU PDP you have the right to:
- Be informed about what we hold and why — this document, and a fuller answer on request.
- Access your personal data and get a copy of it.
- Correct anything inaccurate or incomplete. Most of it you can edit yourself in account settings.
- Erase your personal data, subject to records we are legally required to keep.
- Withdraw consent for anything you consented to, at any time. Withdrawal applies from that point forward and does not make earlier processing unlawful.
- Object to processing based on legitimate interest, including to automated processing that produces a profile of you.
- Restrict or suspend processing while a dispute about accuracy or lawfulness is being resolved.
- Portability — receive your data in a structured, commonly used, machine-readable format, and have it sent to another provider where that is technically feasible.
- Claim compensation for damage caused by a breach of UU PDP.
- Lodge a complaint with the supervisory authority for personal data protection in Indonesia. You do not have to come to us first, though it is usually faster.
How to exercise them
Write to privacy@maleosites.com from the email address on your account and tell us plainly which right you are exercising. We answer within 30 days. If a request is unusually complex we will tell you inside those 30 days why it is taking longer and when to expect it.
We may need to verify who you are before acting — not to obstruct you, but because handing someone's data to the wrong person is itself a breach. Usually replying from the account email is enough; for a deletion or an export we may ask you to confirm from within your signed-in account. We charge nothing, unless a request is repetitive or clearly excessive, in which case we will say so before doing any work.
If your request is about data held by a business whose website we host, we are the processor and must pass the request to that business — see section 1.
13. Deleting your account
You can close your account from your account settings, or by asking us. Concretely, here is what happens.
- Immediately: your published sites go offline. Both the
slug.maleosites.comaddress and any custom domain stop serving your site, your forms stop accepting submissions, and any Cloudflare refresh token we hold for your domain is deleted. Your subscription is cancelled and you are not billed again. - Uploaded media is removed from object storage, so your photos stop being reachable by URL.
- For the next 30 days the account sits in a grace period. Sign in or write to us within that window and we can restore it, which is exactly why the window exists — a deletion made in anger, by mistake, or by someone who got into your account should be reversible.
- After 30 days the account, its sites, its content, its form submissions, and its analytics are permanently deleted. This cannot be undone. Copies inside encrypted backups age out within a further 35 days.
- What survives: orders, invoices, and payment records, kept for 10 years because Indonesian tax law requires it. These hold your name, email address, and what you paid — not your site content. They are used for accounting and nothing else.
Deleting your account does not delete the personal data of your own customers from anywhere you exported it to. If you downloaded your form submissions, that copy is yours to handle, and you are the controller of it.
14. Children
Maleo Sites is a tool for running a business, and it is not directed at children. You must be at least 18, or old enough to enter a binding contract under Indonesian law with the consent of a parent or guardian, to hold an account. We do not knowingly collect personal data from children.
UU PDP requires the consent of a parent or guardian before a child's personal data may be processed. If you believe a child has given us personal data, or that a site published through us is collecting data from children through its forms, tell us at privacy@maleosites.com and we will delete it. If you collect data from children through a site you publish, obtaining that consent is your responsibility as the controller.
15. Changes to this policy
When what we do changes, this document changes with it. Every version carries an effective date and a version number, shown at the top of this page.
- Substantive changes — a new category of data, a new purpose, a new sub-processor, a shorter or longer retention period — are announced by email to the address on your account and in the dashboard, at least 30 days before they take effect.
- Corrections that do not change meaning, such as a typo or a clearer sentence, are made without notice and without bumping the version.
- If a change means we would process data you already gave us for a genuinely new purpose that needs your consent, we ask for it rather than assuming silence is agreement.
- If you do not accept a change, you can delete your account before it takes effect. A refund, if one is due, follows the Refund Policy.
16. Contact
For anything in this document — a question, a data subject request, or a complaint — write toprivacy@maleosites.com. It is read by the operator personally. General support goes to support@maleosites.com, and security problems or abuse to abuse@maleosites.com.
We have not appointed a data protection officer. As a sole proprietor, the person responsible for personal data here is the operator, named below.
| Controller | Bima Saputra, an individual sole proprietor trading as Maleo Labs |
|---|---|
| Service | Maleo Sites, https://maleosites.com |
| Address | Jl. Raya Palembang-Betung KM 18, Palembang, Sumatera Selatan, 30961, Indonesia |
| Privacy contact | privacy@maleosites.com |
The full operator identity, including registration details as they are issued, is published at/legal, alongside the other documents that govern your use of the Service.
Questions about this document? Write to support@maleosites.com.