Privacy Policy
This is a summary of a legal document, please read it in full below. The English version is authoritative and prevails in case of any conflict with the Bahasa Indonesia translation.
1. Who we are
HOSPOPS is owned and operated by Supper Social Pte. Ltd., a company incorporated in Singapore (UEN [Singapore UEN placeholder]), and licensed to PT Supper Social Group (registration [Indonesia registration placeholder]) for operations in Indonesia. In this policy "we", "us" and "HOSPOPS" refer to these entities together.
This policy covers venue owners, general managers, managers, staff users, and visitors to our marketing website. Where a venue enters personal data about its staff, please also read clause 5 below.
2. Data we collect
The main categories of personal data we process:
- Account data. Name, email, WhatsApp number, password hash, role, MFA enrolment state, and account preferences (e.g. UI language).
- Staff records entered by venues. Names, contact numbers, primary role, pay rates and contract terms, national/BPJS or tax identifiers where the venue chooses to enter them, and clock-in PIN. The venue is the controller of this data — see clause 5.
- Operational data. Rosters, shifts, daily closes (revenue and cost figures), attendance and QR clock-in timestamps, tasks and checklists, reviews and internal notes, uploaded documents where features require them.
- Device and log data. IP address, user-agent, approximate location derived from IP, session tokens, error logs, and Platform usage events used for security and diagnostics.
- Payment data. Billing contact and receipts. Card payments are processed by Xendit; we do not store card numbers. We receive limited data from Xendit (last four digits, brand, status) to record the transaction.
- Support data. Messages, screenshots and metadata you send us when raising a ticket or chatting with in-app support.
3. Purposes and legal bases
We process personal data for:
- Providing the Platform to your venue — performance of contract.
- Billing, tax and record-keeping — legal obligation and performance of contract.
- Security, fraud prevention and abuse investigation — legitimate interest and legal obligation.
- Product analytics and improvements, using aggregated/de-identified data — legitimate interest.
- Communication about the service (transactional notices, invites, receipts) — performance of contract.
- Marketing to prospective customers where allowed — consent, which you can withdraw at any time.
In Indonesia we rely on the lawful bases in the Personal Data Protection Law (Law No. 27 of 2022) (the "PDP Law"). In Singapore we rely on the corresponding bases in the Personal Data Protection Act (PDPA). Where we act as processor on a venue's instructions, the venue is the controller and is responsible for the underlying lawful basis and consent (see clause 5).
4. Subprocessors and hosting
We share personal data with a small set of subprocessors that help us run the Platform:
- Supabase — managed database, authentication and file storage.
- Lovable — hosting and deployment infrastructure.
- Xendit — payment processing for Indonesian billing.
- WhatsApp / Meta — when a user or venue chooses to share content via a WhatsApp link, the content leaves our control at the moment of sharing.
- Email and messaging providers — for transactional and support messages [full subprocessor list to be confirmed].
- Product analytics and error monitoring — used sparingly and configured to avoid capturing sensitive fields [tooling to be confirmed].
International transfers. Some subprocessors host data outside Indonesia (typically in Singapore or other supported regions). Where required by law we put appropriate safeguards in place, and Venues remain able to instruct us on the processing.
5. Staff data — controller/processor split
When a venue enters data about its staff into the Platform (names, contact numbers, pay rates, contracts, attendance, clock-in PIN, etc.), the venue is the data controller of that data. HOSPOPS is a data processor acting on the venue's instructions.
Staff data rights. Staff members who want to access, correct or delete their personal data should first contact their venue (their employer), which is the controller. HOSPOPS will assist the venue in fulfilling those requests within reasonable time. Where applicable law gives staff a direct right against us (as processor), we will respond in accordance with that law and, where appropriate, in coordination with the venue.
6. Retention
- Active account and venue data are retained while the account is active.
- When a venue closes or terminates, the venue can export its data for 30 days. After that, we delete or de-identify Venue Data within 90 days [confirming with counsel].
- Backups cycle out within 30 days [confirming with counsel] and, when a deletion request has run, backup copies are overwritten in the ordinary course.
- Records we are required by law to keep (e.g. financial records for tax) are retained for the period the law requires, even after deletion of live data.
- Aggregated, de-identified statistics may be kept indefinitely for product analytics.
7. Security
We take reasonable technical and organisational measures to protect personal data, honestly described:
- Encryption in transit (HTTPS) and encryption at rest via our hosting provider.
- Row-level access controls (database RLS) and role-based permissions inside the Platform.
- Optional two-factor authentication for accounts; venues may require it for senior roles.
- Audit logging of sensitive operational changes.
- Limited internal access on a need-to-know basis and administrative access controls.
No system is perfectly secure, and we do not promise absolute security. Please use a strong unique password and keep your credentials confidential.
8. Cookies and local storage
The Platform uses cookies and browser localStorage for functional purposes only: keeping you signed in, remembering your language preference, and remembering the venue you have selected. We do not use advertising cookies or cross-site tracking cookies inside the Platform. Our marketing website may use minimal analytics; when it does we will list the tools here.
9. Children
The Platform is not directed at persons below the applicable working age in their jurisdiction. Venues are responsible for ensuring that any staff data they enter into the Platform relates to persons lawfully employed under local law.
10. Breach notification
If we become aware of a personal data breach that affects Venue Data, we will notify affected Venues (as controllers) without undue delay and, where required, within the timelines set by the PDP Law and other applicable laws. We will provide information necessary for the Venue to meet its own notification obligations to staff and regulators.
11. Contact and complaints
For privacy questions, data requests, or complaints please contact us at [contact email placeholder]. You also have the right to lodge a complaint with the relevant supervisory authority — in Indonesia, the authority designated under the PDP Law, and in Singapore, the Personal Data Protection Commission (PDPC).
12. Language
This policy is provided in English and Bahasa Indonesia for convenience. In case of any conflict the English version prevails.