legal

Privacy

What we collect, why we are allowed to, how long we keep it, and what you can make us do about it. Written to be read, not to be survived.

This policy follows Indonesia’s Law No. 27 of 2022 on Personal Data Protection.

Who is responsible

ALL AROUND FADED decides what personal data is collected through this shop and why, which makes us the data controller ("Pengendali Data Pribadi") for it under Law No. 27 of 2022 on Personal Data Protection. If you want to ask about anything on this page, or exercise any of the rights described below, the contact details on our info page reach a person, not a queue.

What we collect

When you create an account: your name, email address, and phone number. Your password is never stored as you typed it — only a one-way hash, which cannot be turned back into the original. When you place an order: the delivery address you enter, the contents of the order, the courier and tracking reference, and the payment status reported back to us by the payment provider. We do not receive or store your card number; that stays with the payment provider. When you use the shop: your bag, your wishlist, your language and currency choice, and the sessions you are signed in on (with the device and IP address that created each one, so you can recognise and revoke them). When you talk to us: the messages you send through the chat widget or WhatsApp, and the name and email you gave to start that conversation. If you allow it: analytics and advertising identifiers, described in full in the cookies section of our info page. Nothing in that category is set before you agree.

Why the phone number is required

A phone number is required to register because deliveries fail without one. Couriers in Indonesia call before and during delivery, and an order with no reachable number is an order we cannot complete. Under Article 20(2)(b) of the PDP Law this is processing necessary to perform a contract with you — not something we ask your permission for, because you cannot buy from us and refuse it at the same time. Being asked for "consent" to something that is not optional would be misleading, so we do not frame it that way. Sending you promotions on that same number is a different matter entirely. It is a separate purpose, it rests on your explicit consent under Article 20(2)(a), the checkbox is unticked by default, and you can buy from us for years without ever ticking it. If you do tick it, we record the moment you did, and you can withdraw it at any time under Article 9 — from your account settings or by replying STOP. Withdrawing stops the promotions and changes nothing about your orders.

Our lawful basis

Article 20(1) requires a controller to have a basis for every kind of processing. Ours: Performing your contract — Article 20(2)(b). Your account, your orders, delivery, returns, and the phone number and address needed to complete them. Your explicit consent — Article 20(2)(a). Marketing by email or WhatsApp, and the analytics and advertising cookies. Each is asked for separately and each can be withdrawn on its own. Legal obligation — Article 20(2)(c). Tax and accounting records for completed sales, which we are required to keep whether or not you would prefer we did not. Legitimate interests — Article 20(2)(f). Fraud prevention, keeping the shop secure, and preventing abuse of the chat and signup forms.

Your rights

Chapter IV of the PDP Law gives you rights we are obliged to honour, and this shop is built to honour them: Be told what we hold and why (Article 5). This page, kept accurate. Correct anything wrong (Article 6). Your name, phone, and addresses are editable in your account. Get a copy of your data (Article 7). Ask us and we will send it. Have it deleted (Article 8) and have processing stopped. Note that where the law requires us to keep a completed sale's records, we keep those and delete the rest. Withdraw a consent you gave (Article 9). Marketing and cookie choices, at any time, without losing access to the shop. Object to purely automated decisions about you (Article 10). We do not make any; the chat assistant answers questions and never decides anything about your account. Receive your data in a portable format (Article 13). Seek compensation for a breach (Article 12). To use any of these, contact us. We will not make you explain why.

How long we keep things

Your account and its contents stay for as long as the account exists. Close it and we delete what we are not legally required to keep. Completed orders and their invoices are kept for as long as tax and accounting law requires, counted from the transaction, because Article 20(2)(c) obliges us to. Chat conversations are kept for one year, then deleted. The live session behind the chat widget expires after 24 hours of inactivity on its own. Sign-in sessions expire on their own schedule and can be revoked by you sooner from your account. Article 43 also requires us to delete personal data once it is no longer needed for the purpose it was collected for, once you withdraw consent, or when you ask — whichever comes first.

Who else sees it

Only the parties that make an order work, and only the part each of them needs: Couriers get the delivery name, address, and phone number, because that is what a delivery is. The payment provider gets what it needs to take the payment. We never see your full card details. Our hosting and email providers process data on our instructions as processors ("Prosesor Data Pribadi"), not for their own purposes. The chat assistant reads your conversation and, when you are signed in, your own order and account details, in order to answer you. It does not see other customers' data. If you allowed analytics or advertising cookies, the providers named in our cookie policy receive the identifiers described there. Some of these providers operate outside Indonesia, which makes those transfers subject to the cross-border rules in Chapter VIII. We do not sell your personal data. There is no arrangement under which anyone pays us for it.

How it is protected

Passwords are hashed, never stored in readable form. Traffic between you and the shop is encrypted in transit. Access to customer data is limited to the people who need it to run the shop, and administrative access is separate from customer accounts. If a breach occurs that puts your data at risk, Article 46 requires us to notify you and the supervisory authority within 3x24 hours. We will tell you what happened and what to do about it, rather than a notice written to say as little as possible.

If you are outside Indonesia

The shop ships internationally, so some visitors are covered by their own country's rules as well as ours — the GDPR for visitors in the EU and UK, among others. Where those rules give you a stronger right than the one described above, we will honour the stronger one. Cross-border transfers of personal data out of Indonesia are governed by Chapter VIII of the PDP Law, which requires the destination to offer an adequate level of protection or appropriate safeguards to be in place.

Changes to this policy

When we change how we handle personal data, we change this page, and Article 21(2) requires us to tell you before the change takes effect where the processing rests on your consent. We will not quietly widen what we do with data you already gave us.