Privacy Policy
Last updated: Thursday, 24 September 2026
This translation is for convenience only. Where the two differ, the Indonesian text prevails.
In short
We keep your photos and your page's content because that is the product. We shrink the photos you send and remove their location data, then delete the file you sent once it has been processed. We never sell your data. Money from the digital gift envelope never passes through us. You can ask for a copy of your data, or for it to be deleted, at any time.
Invitation pages hold the most personal things: family photos, parents’ names, home addresses, and the phone numbers of hundreds of guests. This policy explains what we collect, why, for how long, and what you can ask of us.
1. Who we are
Harimu (harimu.id) is a Personal Data Controller within the meaning of Law Number 27 of 2022 on Personal Data Protection (UU PDP). This means we decide the purposes and the means of the personal data processing described below.
Questions about your data: privasi@harimu.id
2. The data we collect
From you, as the page’s creator
- Photos and media you upload
- Page content: names, parents’ names, dates, times, event locations, messages
- Bank account and QRIS details, if you turn on the digital gift envelope
- Name and email address when you sign in: from your Google account, or the email address you type. An account is needed to upload photos and publish a page
- Waitlist email address, if you signed up before the service opened
- Technical data: IP address and device type, to prevent abuse
- Page performance data: how fast a page opens and responds on your device, the type of device and browser, and the address of the page opened. An invitation’s address can contain names, for example harimu.id/rani-bayu. No cookies, and no tracking of who you are
From your guests
This is the part to pay attention to as a host. When guests reply to an invitation, we collect their name, contact details, number of people and message: people who never signed up for our service.
We process that data on your behalf. You decide who is invited and what the guest list is used for. We show a short notice on the reply form so guests know where their data goes.
What we do not keep
- Passwords. We have no passwords at all. You sign in with Google, or with a one-time code and link sent to your email
- Drafts before you sign in. Until you sign in, a draft page is kept only on your device. Nothing is sent to us until you sign in
- Your card or payment account details. Payments are processed by a licensed payment provider; we never see your card number
- Location from photos. EXIF data, including GPS coordinates, is removed before a photo is stored
3. Legal basis for processing
Under Article 20 of UU PDP, each kind of processing has its own legal basis:
| Purpose | Legal basis |
|---|---|
| Creating, storing and showing your page | Performance of a contract: this is the service you asked for |
| Creating an account and sending sign-in codes by email | Performance of a contract: an account is needed to publish a page |
| Collecting guests’ replies | Performance of a contract, on your behalf as the host |
| Sending photos to an AI provider outside Indonesia | Your consent, asked for separately |
| Using content to improve the service | Your consent, asked for separately |
| Telling you when the service opens (the waitlist) | Your consent, given when you filled in the form |
| Measuring page speed and performance on visitors’ devices | Legitimate interest. No cookies and no tracking of individuals |
| Preventing abuse and fraud | Legitimate interest |
Consent you give can be withdrawn at any time, as easily as it was given. Withdrawing consent to AI personalisation does not delete your page: the page keeps working without that feature.
4. Transfers of data outside Indonesia
Some processing happens outside Indonesia. Under Article 56 of UU PDP, we only do so when the destination country offers equal or higher protection, when adequate and binding safeguards are in place (such as a data processing agreement containing standard contractual clauses), or with your consent.
Storage. Our database is in Singapore (Neon). Photos are stored with Cloudflare in the Asia Pacific region, and served from Cloudflare’s network around the world so that pages open quickly wherever guests are. Singapore has a personal data protection law (PDPA), and both providers are bound to us by data processing agreements.
Email. Emails from us, such as sign-in codes, are sent through Resend. Resend processes email addresses and the contents of those emails in the United States; its sending servers are in Japan. This transfer rests on a data processing agreement with Resend containing standard contractual clauses.
AI personalisation, only for paid plans that turn it on, sends your photos to a model provider abroad. We ask for separate consent for this, and free pages never go through it.
Error reports. When something goes wrong in our systems, the technical report is sent to Sentry and stored in the European Union. Before a report is sent, we remove email addresses, phone numbers, IP addresses and form contents from it. This transfer rests on the equivalent protection in the European Union (GDPR) and a data processing agreement with Sentry.
5. How long we keep it
| Data | How long |
|---|---|
| The photo files you send | Deleted once processed, usually within minutes. Their location data is removed before the file is stored |
| Photos in your photo library | A reduced copy with no location data, and the sizes shown on the page, kept for as long as the photo is in your library. A photo you delete can be restored for 28 days, then it is permanently deleted |
| Account (name and email) | For as long as your account exists. An account you delete can be restored for 28 days, then it is permanently deleted |
| Published pages | Until you delete them. Invitation links are designed never to die. A page you delete can be restored for 28 days, then it is permanently deleted; its link will never be used by anyone else |
| Guest lists and replies | Deleted automatically 12 months after the event date |
| Digital gift envelope accounts | Follow the page; deleted with it |
| Transaction records | As required by applicable bookkeeping obligations |
| Waitlist emails | Deleted once the service has opened and you have been told, or whenever you ask |
| Technical logs and error reports | At most 90 days |
6. Your rights
Under Articles 5 to 13 of UU PDP, you have the right to:
- See the personal data we hold about you
- Correct data that is wrong
- Delete your data and your pages
- Withdraw consent at any time
- Take a copy of your data in a machine-readable format
- Object to certain processing
Send your request to privasi@harimu.id. We answer within 3 working days and complete the request within 30 days.
If you are a guest and want your reply data deleted, contact us directly. You do not need to contact the host.
7. Security
- Data is encrypted in transit and at rest
- Guests’ contact numbers are encrypted separately inside the database
- We never write photos, names, phone numbers or guest lists into logs
- There are no passwords to leak, because we do not keep any
- Each user’s and each partner’s data is kept apart, and that separation is tested automatically
8. If there is a data breach
Under Article 46 of UU PDP, if a failure of personal data protection occurs, we notify you and the relevant Ministry within 3 x 24 hours of becoming aware of it, explaining which data is affected and what you need to do.
9. Third parties that process data
We work with the providers below. Each is bound by a data processing agreement before it receives your data:
| Provider | What for |
|---|---|
| Cloudflare | Storing and processing photos, delivering pages, security, and cookieless page-performance analytics |
| Neon | Database, in Singapore |
| Xendit | Payments, licensed by Bank Indonesia |
| Resend | Email, such as sign-in codes. Processed in the United States |
| Sentry | Application error reports, stored in the European Union. Emails, phone numbers and IP addresses are removed before a report is sent |
| AI model provider | Only for paid plans that turn it on |
We do not sell personal data to anyone.
10. Digital gift envelope
If you turn on the digital gift envelope, the account number and QRIS you enter are shown publicly on your invitation page: that is what it is for. Make sure you really want to show them.
The money never passes through us. Guests transfer directly to your account. We do not hold, keep or deduct any money from the digital gift envelope.
11. Children
This service is meant for users aged 18 and over. Pages for children’s events (birthdays, khitanan, aqiqah) are made by a parent or guardian, and the child’s data in them is processed with their consent.
12. Changes to this policy
If there is a meaningful change, we tell you by email or with a notice in the service before the change takes effect. The date of the last update is always shown above.
13. Contact us
privasi@harimu.id for anything about personal data.
halo@harimu.id for general questions.
You also have the right to complain to the competent personal data protection supervisory authority.