Privacy Policy
Your privacy is fundamental to our editorial integrity. This policy outlines our data collection, anonymization protocols, and compliance with Indonesian Personal Data Protection Law (UU No. 27/2022) and international privacy frameworks.
1. Data Controller & Core Principles
BaliExpertGuide.com acts as the Data Controller (Pengendali Data Pribadi) responsible for personal information gathered through this website. We operate with strict data minimization principles: we only gather personal details strictly necessary to provide destination guides, dispatch airport transfers, personalize itinerary routes, or protect the integrity of our platform.
2. Indonesian PDP Law (UU No. 27/2022) & Global Framework
In compliance with the Republic of Indonesia Law No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Pribadi / UU PDP), we process personal data exclusively under legitimate legal bases:
- Explicit Consent: Granted when subscribing to dispatch advisories or submitting contact inquiries.
- Contractual Performance: Necessary to execute private airport transfer reservations or concierge dispatches.
- Legitimate Interests: Conducting cybersecurity monitoring, preventing bot fraud, auditing affiliate referral accuracy, and optimizing our destination infrastructure.
- Legal Compliance: Adhering to Indonesian fiscal, electronic transaction (UU ITE), and hospitality regulations.
3. Categories of Data We Collect
Depending on how you interact with BaliExpertGuide, we may collect:
👤 Information You Provide Directly
- • Full name & email address
- • WhatsApp or phone contact (transfer dispatch)
- • Flight arrival numbers & flight times
- • Property verification records (hotelier claim)
- • AI Concierge prompts and trip preferences
💻 Automatically Collected Telemetry
- • Browser user agent and device screen width
- • Active locale (en, fr, zh, ru, id)
- • Selected currency preference (IDR, USD, EUR, etc.)
- • Referring URLs and page interaction timestamps
- • Masked / one-way hashed IP address (MD5)
4. Outbound Affiliate Telemetry & Anonymization Standards
When you click to explore a property rate or tour on an external partner platform (such as Agoda, Klook, or Viator) via our /agoda/{hotelId} or /outbound/track endpoints:
Our system immediately computes a one-way cryptographic hash of your IP address (md5($clientIp)) and stores only this irreversibly anonymized fingerprint in transient Redis memory. Raw traveler IP addresses are NEVER logged or permanently preserved in our outbound click telemetry.
This telemetry enables us to accurately measure regional interest across destination hubs, detect bot traffic, and confirm affiliate referral commissions without compromising individual traveler privacy.
6. Purposes of Data Processing
We process your personal information strictly for the following objectives:
- Facilitating and confirming airport arrival transfers and private driver dispatch.
- Verifying hotelier ownership documentation in property claiming procedures.
- Responding to VIP concierge requests and bespoke itinerary inquiries.
- Maintaining real-time island safety radar telemetry and sending requested emergency notices.
- Preventing fraudulent requests, DDoS incidents, and unauthorized web scraping.
7. Third-Party Service Providers & Data Integrity
We collaborate only with vetted, reputable technical infrastructure providers:
- Payment Gateways: Midtrans (PT Midtrans) for Indonesian Rupiah/QRIS transactions and Stripe Inc. for international cards. Credit card credentials are tokenized directly with PCI-DSS Level 1 certified processors.
- Affiliate Booking Partners: Agoda Company Pte. Ltd., Klook Travel Technology, and Viator Inc. When you click outbound booking channels, partner referral tags and pseudonymous session IDs are transmitted to attribute your booking.
- Infrastructure & Security: Cloudflare Inc. for content delivery, DDoS prevention, and TLS encryption.
8. Security Protocols & Retention Schedule
We deploy industry-standard technical measures including TLS 1.3 encryption for all data in transit, strict database encryption at rest, role-based access controls, and regular vulnerability auditing.
Airport transfer logs and concierge dispatch records are retained for a maximum of 12 months for customer service fulfillment and Indonesian statutory accounting compliance, after which they are securely purged. Transient click telemetry stored in Redis expires automatically on a rolling 30-day schedule.
9. Your Rights as a Data Subject
Under Article 5 through Article 13 of the Indonesian Personal Data Protection Act (UU PDP) and relevant international legislation (such as GDPR Chapter III), you possess comprehensive rights:
10. Data Protection Desk & Inquiries
To exercise any of your data rights, report security concerns, or inquire about our data protection standards, contact our privacy compliance desk: