Kesles Merchant
Privacy Policy
How we collect, use, store, and protect merchant data while you use the Kesles Merchant application and services.
Privacy & Data Security
This policy is governed by Indonesia's Law No. 27 of 2022 on Personal Data Protection (PDP Law). Effective May 2026.
1. Data We Collect
Kesles Merchant collects data necessary for merchant onboarding, account verification (KYC), device operation, transaction processing, operational support, regulatory compliance, and service improvement.
- Personal identity: full name, national ID number (NIK), ID card photo, selfie/liveness photo, WhatsApp number, email, date of birth.
- Business data: merchant name, business category, tax ID (NPWP for taxable merchants), outlet photo, product photo, outlet address.
- Financial data: bank account number, account holder name, transaction history (amount, time, payment method).
- Location data: outlet GPS coordinates (with explicit consent) for physical merchant existence verification and prevention of fake merchant QRIS fraud.
- Device data: model, OS version, unique identifier, FCM push token, IP address, security activity log.
- Interaction data: notification preferences, account status, support history, feedback you submit.
2. Purpose of Data Use
Data is used in a limited and proportionate manner to operate the service safely, accurately, and in line with merchant needs and regulatory requirements.
- Identity verification (KYC), merchant status management, and QRIS Plus service activation.
- Payment transaction processing, fund settlement, and fraud detection.
- Compliance with legal and regulatory obligations: Bank Indonesia, OJK, Directorate General of Taxes, PPATK.
- Sending transaction notifications, account status updates, promotions, and relevant operational messages.
- Anonymized internal analytics for service quality and security improvement.
3. Application Permissions (Android)
The app requests device permissions only for features you actively use. You can decline or revoke permissions anytime via your device settings, though related features may not function.
- Camera: capturing KYC photos (ID card, selfie, outlet, products) and scanning the QR serial number on QRIS Plus devices during pairing.
- Location (GPS): verifying physical merchant existence to prevent fake-merchant QRIS fraud (anti-fraud) — only with your explicit consent.
- Notifications: delivering incoming transaction alerts from QRIS Plus devices, settlement status, and operational information.
- Storage/Media: uploading product photos, outlet photos, or KYC supporting documents.
- Audio (output): announcing transactions via Text-to-Speech (TTS) — does not record audio from the microphone.
4. Data Sharing & Access
Access to data is restricted on a need-to-know basis. Data is shared only for service, compliance, security, or lawful purposes.
- Authorized internal Kesles teams: for verification, operational support, and service maintenance.
- Payment Service Providers (PSPs) and partner banks: for QRIS transaction routing and fund settlement.
- Cloud infrastructure providers (Indonesia-based data centers): hosting application, database, and messaging services.
- Analytics & monitoring service providers: technical data only, without personal identifiers.
- Regulatory authorities (Bank Indonesia, OJK, Tax Office, PPATK) or law enforcement: only when legally required.
- Kesles Merchant does not sell merchant personal data to third parties for commercial purposes.
5. Data Security & Retention
Kesles Merchant implements reasonable technical and operational safeguards to protect data from unauthorized access, improper alteration, leakage, or misuse.
- Data encrypted in transit (TLS 1.2+) and at rest (database encryption).
- System access protected by multi-factor authentication and audit logging of all data access activities.
- Transaction data retained minimum 5 years per Indonesia Law No. 28 of 2007 (KUP) Article 28 and Bank Indonesia regulations.
- Identity (KYC) data retained while the account is active and for 5 years after account closure for audit.
- Data is anonymized or securely deleted once retention periods expire.
- Merchants remain responsible for safeguarding their account credentials, OTP, PIN, and devices.
6. Your Rights Under the PDP Law
Under Indonesia's Law No. 27 of 2022 on Personal Data Protection, you have the following rights over your personal data:
- Right of access: request a copy of personal data we hold about you.
- Right to rectification: correct inaccurate or outdated personal data.
- Right to erasure: request deletion of personal data (subject to legal retention obligations).
- Right to restrict processing: limit data use under specific conditions.
- Right to portability: receive your data in a machine-readable format.
- Right to object: refuse data processing for marketing or profiling.
- Right to withdraw consent: anytime, without affecting the lawfulness of prior processing.
- Right to lodge a complaint with the data protection authority or relevant supervisory body.
- Submit requests to dpo@kesles.com; we respond within 30 working days.
7. Minors
Kesles Merchant services are intended for adult business operators aged 18 or older. We do not knowingly collect data from minors.
- If you become aware that a minor is using the service, contact us to remove the account and data.
- Age verification is performed during KYC onboarding.
8. Policy Updates & Contact
This policy may be updated to reflect regulatory changes or service improvements. The latest version is always available in the app and on this page.
- Update notices will be sent via the app, email, or push notifications at least 14 days before taking effect.
- Data Controller: PT Inti Kesles Nusantara, South Jakarta, Indonesia.
- Data Protection Officer (DPO): dpo@kesles.com.
- General privacy questions: merchantsupport@kesles.com / 0823-5551-7020.
- Effective version: May 2026.