This policy explains how PT Travel Blue Indonesia ("we") processes personal data through the travel-blue.co.id website and the Travel Blue Indonesia mobile app for employees. We process personal data under Indonesian Law No. 27 of 2022 on Personal Data Protection (UU PDP).
1. Data controller
PT Travel Blue Indonesia, Cyber 2 Tower, Lt. 18, Jl. H.R. Rasuna Said Blok X-5 Kav. 13, Jakarta Selatan 12950, Indonesia. Email: privacy@travel-blue.co.id. Phone: +62 21 5799 8751.
2. The travel-blue.co.id website
- The website has no forms, user accounts or tracking cookies.
- We use Cloudflare Web Analytics for visit statistics. It sets no cookies and does no device fingerprinting. We only see aggregated data such as pages viewed, country, browser type and referring site.
- The website is hosted on Cloudflare, which logs technical data such as IP address and access time to deliver pages and protect the site from attacks. This data may be processed outside Indonesia.
- If you email us, we process your name, email address and message to reply.
- Links to marketplaces and social media take you to other services with their own privacy policies.
3. The Travel Blue Indonesia app (for employees)
The app is only for employees of PT Travel Blue Indonesia. Accounts are created by a company administrator; there is no public sign-up. Data processed:
| Data | When it is collected | Purpose |
|---|---|---|
| Name, work email, role and employee record | When an administrator creates your account and when you sign in | Sign-in and deciding which features you can use |
| Precise location (GPS) and its accuracy | Only when you tap check-in, check-out or start an audit, while the app is open. There is no background tracking. | Confirming you are at the intended store or office |
| Camera photos | When you take a uniform verification photo or a photo of damaged items | Visit verification and stock audit records |
| Work data: store visits, stock counts, attendance, leave requests | When you use those features | Store operations, HR administration and payroll |
| Device operating system version | At check-in and check-out | Recording the device used for attendance |
| Sign-in token | After sign-in | Keeping you signed in. Stored in the device's secure storage and deleted when you sign out. |
- The app does not open your photo library, only the camera.
- Barcode scanning is processed on the device. Camera images used for scanning are not sent to our servers.
- The app contains no advertising, analytics SDKs or third-party trackers. We do not sell personal data.
4. Legal basis
Under Article 20 of UU PDP, we process personal data on the basis of:
- performing the employment contract, for attendance, leave and store operations;
- complying with legal obligations, for employment and tax law;
- legitimate interests, for system security, abuse prevention and aggregated website statistics.
5. Automated checks
The app automatically rejects a check-in when your location is outside the store or office radius. If you think a rejection is wrong, contact your supervisor or HR for a human review.
6. Storage and recipients
- App data is stored on our server in a Tencent Cloud data center in the Jakarta region, Indonesia. App data is not transferred outside Indonesia.
- Data is only accessed by HR, your direct supervisor, system administrators and the IT vendor that helps us run the system. The vendor is bound by confidentiality and data protection obligations.
- We do not share data with anyone else unless the law requires it.
7. Retention
- Your account and work data are kept for as long as you are employed. After that, attendance, leave and payroll records are kept only as long as employment and tax law require (for example up to 10 years for tax documents).
- Verification photos and location history are kept as long as needed for verification and audit, then deleted.
- Actions not yet sent while offline stay on the device for up to 6 hours, then are discarded.
- Server backups rotate, so deleted data also disappears from backups.
8. Security
- All connections use HTTPS.
- Sign-in tokens are stored in the iOS Keychain or Android Keystore. On Android, app data is excluded from device backups.
- Photos are stored as private files, and access is limited by user role.
- If a personal data breach occurs, we notify you and the competent authority within 3 x 24 hours, as required by Article 46 of UU PDP.
9. Your rights
Under Articles 5 to 13 of UU PDP, you have the right to:
- be informed about how your personal data is processed;
- complete, update or correct inaccurate data;
- access and get a copy of your data;
- end processing, and have your data deleted or destroyed;
- withdraw consent you have given;
- object to decisions based solely on automated processing;
- delay or restrict processing;
- sue and receive compensation for unlawful processing;
- obtain and transfer your data in a commonly used format.
Send requests to privacy@travel-blue.co.id. We respond within 3 x 24 hours after the request is received and your identity is verified. How to request account deletion is on the Delete Data page.
10. Children
The website and app are not directed at children under 18. The app is used by employees only.
11. Changes
If this policy changes, we update this page and the date above. We tell employees about significant changes by work email or in the app.
12. Contact
PT Travel Blue Indonesia, Cyber 2 Tower, Lt. 18, Jl. H.R. Rasuna Said Blok X-5 Kav. 13, Jakarta Selatan 12950, Indonesia. Email privacy@travel-blue.co.id, phone +62 21 5799 8751.
