Privacy Policy
Our commitment to protecting, maintaining confidentiality, and responsibly managing your personal information and transaction data.
1. Introduction
Welcome to QRISU ("we", "our", or "platform"). This Privacy Policy outlines how we collect, use, store, process, and protect personal information of Users (Merchants and Customers) when accessing our website, merchant dashboard, and QRISU payment APIs.
By accessing or using QRISU services, you confirm that you have read, understood, and agreed to all provisions described in this Privacy Policy.
2. Information We Collect
We may collect the following information necessary to provide payment transaction services:
- Merchant Account Information: Full name, business email address, phone/WhatsApp number, business/store name, encrypted password, and legal identification documents required by regulatory KYC.
- Payment Transaction Data: Billing/transaction amount, payment reference IDs, payment status, transaction timestamp, chosen payment method (Dynamic QRIS, E-Wallet, etc.), and invoice details.
- Technical & Log Information: IP address, browser type, operating system, device identifiers, API request logs, and network diagnostic information for fraud prevention.
- Sensitive Payment Data: We do NOT store personal banking PINs or card CVVs. All QRIS processing is routed through official Bank Indonesia licensed switching networks.
3. How We Use Information
We use collected data strictly for the following operational and security purposes:
Processing Transactions
Generating dynamic QR codes, validating payment states, and triggering instant webhooks.
Security & Anti-Fraud
Detecting anomalous activity, preventing money laundering, and safeguarding merchant credentials.
Service Improvement
Optimizing API response speeds, debugging routing issues, and enhancing merchant dashboard features.
Regulatory Compliance
Fulfilling reporting obligations mandated by Bank Indonesia and national financial supervisory bodies.
4. Information Sharing & Third Parties
We do not sell personal data to third parties. We share transaction information only with licensed financial partners strictly required to complete payments:
- National QRIS switching operators and partner banks authorized by Bank Indonesia.
- Licensed cloud infrastructure and database service providers operating under strict confidentiality NDAs.
- Law enforcement or government regulatory authorities when formally required by Indonesian legal statutes.
5. Data Security & Storage
All transmission of transaction data is encrypted using TLS 1.3 standards. Secret keys and credentials are stored in secure hardware security modules (HSM) with SHA-256 HMAC integrity checks. We conduct regular penetration tests and vulnerability audits.
6. User Rights & Data Protection (UU PDP)
In compliance with Indonesia Law No. 27 of 2022 on Personal Data Protection (UU PDP), merchants and customers have the right to request access, correction, or deletion of personal data not required for statutory financial audits.
7. Contact & Data Protection Officer
For questions, requests, or privacy concerns, reach out to our Data Protection Officer at privacy@qrisu.com or via our official contact channels.