inetbotdev

Privacy Policy

What we collect when you buy from us or open an account, why we hold it, and what you can ask us to do with it. It covers this site and everything under it.

Last updated9 September 2026

1. Who is responsible

inetbotdev is run as a sole proprietorship in Indonesia. For the purposes of Indonesia's Personal Data Protection Law (UU No. 27 of 2022) we are the controller of the data described here.

Anything you want to ask or change about your own data goes to the address at the bottom of this page.

2. What we collect, and when

Only what a purchase or an account actually needs. Nothing here is gathered speculatively.

  • Account — your name, email address, whether that email is verified, your preferred language, and a profile picture only if you signed in with Google.
  • Sign-in with Google — if you use it, Google tells us your name, email address and profile picture. Your Google password is never sent to us and we could not see it if we wanted to.
  • Sessions — while you are signed in we store a session token, the IP address and the browser user-agent that created it. Sessions expire after 30 days.
  • Orders — an order number, the items on it, the amount and currency, the payment channel you chose, and any instruction the gateway issued for it, such as a virtual account number or a QR code.
  • Payments — from the gateway we receive a transaction identifier, a status, an amount, the method used, and the notification message itself, which we keep as the record of what was paid.
  • Quote briefs — if you ask for a custom quote: the project name, the brief you write, any budget range and desired deadline, and how you prefer to be contacted.
  • Project threads — the updates and messages exchanged with you while work is under way.
  • Downloads — which files your purchase entitles you to, and when that access was granted.

3. What we never collect

There is no analytics on this site. No Google Analytics, no advertising pixel, no session recorder, no third-party tracker of any kind — you can confirm that from the page source. We do not build profiles, we do not do behavioural advertising, and we do not sell or rent personal data to anyone at any price.

We also never see your card number, CVV or bank credentials. Those are typed on the payment provider's own page. What comes back to us is a result, not an instrument.

4. Cookies

Two, both necessary, neither used for tracking:

  • A session cookie, set only after you sign in. It is httpOnly and, in production, secure — your browser will not hand it to scripts and will not send it over plain HTTP.
  • A language cookie, NEXT_LOCALE, remembering whether you chose Indonesian or English for a year so the site stops guessing.

Because we set no advertising or analytics cookies, there is no consent banner for you to click away.

5. Who else touches your data

Running the site means using a few services. Each gets only what its job needs:

  • Payment gateways — depending on the method you pick, one of Midtrans, Duitku, Xendit or Pakasir handles the payment and returns the result to us.
  • Database and hosting — the site runs on Vercel and on our own server, with the database at Neon.
  • File storage — purchased files sit in private object storage and are served through links that expire.
  • Email — receipts, quote replies and renewal notices go out over SMTP through Google's mail servers.
  • Google — only if you choose to sign in with it.

We do not add advertising or analytics vendors to this list, and we will not add one quietly: a new processor appears here before it is switched on.

6. Where your data is stored

Our database and hosting providers operate outside Indonesia, so your data is transferred and stored abroad, under those providers' own contractual safeguards. Indonesia's PDP Law gives you the right to know that, which is why it is stated plainly here rather than buried.

7. How long we keep it

  • Account data — for as long as your account exists. Ask us to delete it and we will.
  • Orders and payment records — kept as business and tax records even after an account closes, because we have to be able to show what was sold and what was paid.
  • Unpaid draft orders — expire on their own and are swept automatically.
  • Session records — expire after 30 days.

8. Your rights

Under UU No. 27 of 2022 you can ask us to show you what we hold about you, correct anything wrong, delete it, stop a particular use of it, or hand it over in a portable form. You can also withdraw consent where we relied on it.

If you are in the EU or the UK, the same requests are open to you under the GDPR. Same address.

Email us and we will answer within 30 days. There is no fee, and we will not ask you why.

9. How we protect it

  • Passwords are hashed, never stored as text, and must be at least 10 characters.
  • Session cookies are httpOnly and secure, so a script on a page cannot read them.
  • Download links are signed and expire in five minutes, so a leaked link stops working almost immediately.
  • Only a verified notification from the payment gateway can mark an order paid — a redirect back to your browser never can, which is what stops a forged “payment successful” page from unlocking anything.
  • Administrative actions on your data are logged, with who took them.

10. Children

This is a business service and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has given us data, tell us and we will remove it.

11. Changes to this policy

If this policy changes materially we update the date at the top, and where the change affects data we already hold we tell account holders by email. We will not change it retroactively to permit something you did not agree to.

Contact

A question about this page, or a request about your own data — write to us. A person reads it.

monkeythoughtdev@gmail.com

inetbotdev · sole proprietorship, Indonesia

Read the Terms of Service