1. Scope & Data Controller Identification
PT GO TRAVELIST ASIA acts as the Data Controller governing all personal data collected through gotravelist.asia under Indonesian Law No. 27/2022 and regional privacy benchmarks.
2. Categories of Personal Data Collected
We collect essential traveler identities (name, email), ITU-T E.164 phone numbers, bank transfer receipts, and meta profile credentials upon authentication.
3. Lawful Bases for Processing
Data processing is conducted strictly to execute direct travel vouchers, satisfy statutory audit ledgers, and attribute creator referral commissions.
4. Zero-Data Selling & Direct Vendor Sharing
GTA never sells or monetizes personal data. Traveler contacts are transmitted strictly on a need-to-know basis to the specific verified operator fulfilling the service.
5. Data Retention & Automatic Purging
Completed transaction records are retained for five (5) fiscal years for tax compliance. Unsettled guest cart drafts are purged automatically after seven (7) days.
6. Client-Side Compression & Encryption
Uploaded bank mutation receipts and identity documents are scaled and compressed in-browser via HTML5 Canvas before TLS 256-bit transmission.
7. Web Storage Persistence
We utilize standard browser localStorage strictly for functional persistence: GTA_PREF_LANG, GTA_PREF_CURR, and GTA_LOCAL_WISHLIST.
8. Data Subject Rights (Right to be Forgotten)
Users hold enforceable rights to access, rectify, or request permanent profile erasure provided no active unsettled transactions remain.
9. Cross-Border Asian Data Transfers
Minimal logistical data may be processed across Asian boundaries to coordinate island pickups under binding contractual safety clauses.
10. Data Protection Officer (DPO) Inquiries
Statutory inquiries or erasure notices must be directed to our appointed DPO: dpo@gotravelist.asia.