Last updated: 15 September 2026
Privacy Policy
This policy explains what personal data CV Mandiri Digital Integrasi ("Bizkita", "we") processes through the Bizkita POS app for Android, the servers behind it, the admin console our team uses, and the bizkita.com website — why, where it is stored, which providers are involved, for how long, and what your rights are. It is written with reference to Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, "the PDP Law").
1. Who we are
Bizkita is a brand of CV Mandiri Digital Integrasi, an Indonesian limited partnership (CV) based in Bandung, West Java. For anything about personal data, contact info@bizkita.com or WhatsApp +62 815-1417-4883.
2. Our role
- We are the controller for merchant user accounts (owners, admins, staff and cashiers), a business’s person-in-charge details, people who buy a plan on bizkita.com, and people who contact us.
- For the data a merchant records about its customers, outlet employees and sales, the merchant is the controller and we process it on the merchant’s behalf. The merchant decides what is recorded and must have a lawful basis for it.
3. The data we process
This table lists the data Bizkita’s systems actually store.
| Category | Data | Source |
|---|---|---|
| User accounts | Name, email, role, outlets they may access, active status, password (stored as a bcrypt hash), optional 6-digit PIN (PBKDF2 hash). | The Bizkita team or the business owner |
| Business and outlets | Business and legal entity name, business type; outlet name, address, phone, Instagram and TikTok; receipt logo and settings; tax rates; the content of the outlet’s static QRIS sticker (merchant name, NMID, city). | The merchant and the Bizkita team |
| Person in charge | Full name, name as on their ID card, position, phone number, email. The ID card number itself is not stored. | The merchant |
| Plan | Plan, limits, features, next payment date, and internal notes by the Bizkita team. | The Bizkita team |
| Catalogue and stock | Products, categories, prices, cost prices, product photos, stock, and stock movements with their reasons. | The merchant |
| Sales and cash | Sales and their items, receipt numbers, discounts, points, payments (method, brand, amount — no card or account numbers), cashier name, the employee who served, void reasons, shifts, cash in and out with reasons, commission. | The merchant, through the app |
| Merchants’ customers | Name, phone number (required), email and notes (optional), points, member tier, point adjustments with reasons, purchase history. | The merchant |
| Outlet employees | Name, phone number (optional), outlets worked at, commission rates. | The merchant |
| Devices | A random 4-character device code, app version, last user, last sync time. No IMEI, serial number or advertising ID. | The app |
| Rows the server rejected | Table name, code, reason, the user who sent it, and a full copy of the row as sent — which can contain customer data. | The app, while syncing |
| Monthly report recipients and delivery status; password reset codes and links (stored as hashes) with their expiry. | The merchant and the system | |
| Crash reports | Error trace, device model, Android version and Firebase installation ID. For sync errors the report includes the server’s message, which can contain a customer phone number or a sale amount. | The app, through Firebase Crashlytics |
| Server logs | IP address, the address requested, device or browser type, time; error messages that can contain a name or phone number. | Our servers |
| Plan purchases | Name, business name, email, WhatsApp number, plan and period, account status; from Xendit: payment status, amount, method and time. | The buyer on bizkita.com, and Xendit |
| Admin console | An audit log of every change a Bizkita operator makes: operator name, action, organisation and details of the change. | The system |
- What we do not collect: ID card (KTP/NIK) numbers, payment card or bank account numbers, location, phone contacts, microphone audio and advertising IDs. The app uses no analytics or ads.
4. Data on the Android device
- Business data is kept in the app’s internal storage. The local database is not separately encrypted by the app, so its protection depends on the device and its screen lock. The sign-in session and the data used for offline sign-in are encrypted with the Android Keystore.
- Every device signed in to an organisation, for any role including cashiers, holds a copy of that organisation’s customer records, employee records (including phone numbers), and its users’ names, emails and PIN hashes.
- Product photos and the receipt logo are sent to the server and to the organisation’s other devices.
- Signing out removes business data from the device once it has been sent, or after you agree to delete sales that have not been sent. Signing in to a different organisation on the same device removes the previous organisation’s data. Android’s automatic backup is turned off.
- Permissions used: Bluetooth for printers that are already paired (never for location), the camera to scan the QRIS sticker (the image is processed on the device and only the code’s content is sent), and internet. Files for import and export are chosen through Android’s file picker.
5. Purposes and legal bases
| Purpose | Basis (PDP Law, Article 20(2)) |
|---|---|
| Providing the service: storing and syncing data, computing reports, printing receipts, sending the monthly report a merchant has switched on. | Performance of a contract |
| Creating and managing accounts, including password resets. | Performance of a contract |
| Processing plan purchases, activating plans and contacting buyers about their order. | Performance of a contract |
| Helping merchants when asked, and maintaining the system. | Performance of a contract; legitimate interest |
| Keeping the service secure, preventing misuse and diagnosing faults through logs, crash reports and rejected rows. | Legitimate interest |
| Bookkeeping and tax for subscription invoices. | Legal obligation |
- We do not sell personal data, use it for advertising, or make automated decisions with legal effect on you.
6. Providers and where data is processed
Data is processed by these providers on our instructions:
| Provider | What for | Data they receive | Location |
|---|---|---|---|
| The Constant Company, LLC (Vultr) | Application server, managed database and its automatic backups | All service data | Singapore |
| Google LLC — Google Workspace | Password reset and monthly report emails; plan order notifications for our team | Recipient addresses and email content, including report attachments (cashier, customer and employee names); plan buyers’ contact details | Outside Indonesia |
| Google LLC — Firebase Crashlytics | App crash and error reports | Crash report content (section 3) | Outside Indonesia |
| Vercel Inc. | Hosting bizkita.com and the admin console, DNS, and the invoice-creating function | Technical visit logs; checkout form data while it is processed | Function in Singapore; site on a global network |
| PT Sinar Digital Terdepan (Xendit) | Plan payments | Name, email, WhatsApp number, business name, plan, amount | As set out in Xendit’s privacy policy |
- Because our servers are in Singapore and some providers are outside Indonesia, personal data is transferred outside Indonesian jurisdiction. We do so with regard to Article 56 of the PDP Law.
- Bizkita’s operations team can access an organisation’s data for support and maintenance, including copies of rejected rows.
- QRIS payments from a merchant’s customers go through the merchant’s own QRIS provider; Bizkita receives no payer account details. WhatsApp links open WhatsApp, which has its own privacy policy.
7. The bizkita.com website
- No cookies, analytics or trackers. Fonts are self-hosted, so opening the site sends no request to Google Fonts.
- The interactive demo runs entirely in your browser and sends no data.
- The contact form stores and sends nothing from the site; the message opens in your WhatsApp.
- The checkout page sends the order to our function on Vercel, which creates an invoice at Xendit. Orders are not stored in our database; the data sits on the Xendit invoice and in the notification to our team.
- The hosting provider keeps technical visit logs, such as IP addresses, for security.
8. Security
- The app and the website connect over HTTPS, and the server uses HSTS. The database can only be reached from our server, over an encrypted connection.
- Passwords are stored as bcrypt hashes, PINs as PBKDF2 hashes, and a merchant’s payment gateway credentials — if entered — are encrypted with AES-256-GCM.
- Menus and data are limited by role, and the server re-checks outlet access and recalculates totals for every row it receives.
- Administrative server access uses SSH keys. Every change an operator makes through the admin console is written to an audit log.
- Offline sign-in in the app locks for a while after 7 wrong passwords.
No system is free of risk. If a personal data breach occurs, we notify you and the competent authority in writing within 3 × 24 hours, as Article 46 of the PDP Law requires.
9. How long we keep data
- Account and business data is kept for as long as the merchant’s organisation uses the service. The system does not delete data automatically today.
- Deleting a customer in the app marks the record as deleted so it disappears from every device. The name, phone number, email and notes stay on the server, and that phone number cannot be used for another customer in the same organisation. Permanent deletion is done on request (section 11).
- Deleting a user or an employee deactivates them: the record stays and the user can no longer sign in. A session already running on a device ends within 100 hours.
- Voided sales stay on record with their reason, as part of the financial records.
- The database provider takes automatic backups, and our team keeps weekly backup copies (the last four at most) for recovery and for testing system updates. Deleted data can remain in a backup until that copy is replaced.
- Server logs rotate by size, so old logs are deleted automatically. The admin console audit log and the record of rejected rows are kept without a time limit.
- Crash reports are kept according to Firebase Crashlytics’ retention policy.
- Subscription invoices and their payment data are kept for as long as bookkeeping and tax rules require, up to 10 years.
10. Your rights
Under the PDP Law you may be informed about how your data is processed; access it and obtain a copy; complete and correct inaccurate data; have processing ended and your data deleted or destroyed; withdraw consent; object to decisions based solely on automated processing; have processing delayed or restricted; receive your data in a commonly used format; and sue for and receive compensation for breaches in processing your data.
Owners and admins can export business data to Excel straight from the app (Standard plan and up). A merchant’s customers or employees should contact that merchant first; we help the merchant fulfil the request.
11. Making a request or closing an account
Email info@bizkita.com with the subject "Personal Data Request" from your registered email address, or contact WhatsApp +62 815-1417-4883. Include your business name and what you are asking for — for example a copy of your data, a correction, or deleting your account and organisation data.
We verify the requester’s identity, then handle the request manually and respond within the time the PDP Law sets. The app does not yet have a delete-account button.
Before an account is closed, make sure every device has synced and export anything you want to keep. Data the law requires us to keep, such as subscription invoices, is not deleted.
12. Children
Bizkita POS is a business tool and is not intended for anyone under 18. If a merchant records customers who are children, the merchant is responsible for obtaining a parent’s or guardian’s consent as the PDP Law requires.
13. Changes to this policy
We may update this policy. We announce material changes by email or on this site before they take effect, and the last-updated date appears above.
14. Contact
CV Mandiri Digital Integrasi · Bandung, West Java, Indonesia · Email: info@bizkita.com · WhatsApp: +62 815-1417-4883