Legal
Privacy Policy
Apple Review Sandbox ("we", "us", or "our") operates this website and online ordering service (the "Service"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have over your data.
By using the Service you agree to the collection and use of information in accordance with this policy.
1. Information we collect
Account and contact information
Your name, phone number, email address (if provided), and delivery addresses. We use your phone number to communicate with you via WhatsApp, SMS, or voice call about your orders.
Order and transaction data
Items ordered, order times, delivery or pickup location, notes or special requests, and price paid.
Payment information
Payments are processed by Xendit, a licensed payment service provider. We do not store your full card number, CVV, or bank credentials. For saved cards, we store only a tokenized reference along with masked details (brand and last four digits) to enable repeat purchases.
Messaging data
When you contact us over WhatsApp we receive messages via Meta's WhatsApp Business Platform. Inbound and outbound messages, media, delivery receipts, and read receipts are retained in our systems so we can respond to you and maintain service quality.
Automatically collected data
IP address, browser and device information, pages viewed, referring URL, and timestamps. With your permission we may also collect approximate location in your browser to help you find the nearest location.
Cookies and similar technologies
We use cookies and local storage to keep you signed in, remember your cart, and measure site usage. You can disable cookies in your browser, but parts of the Service may stop working.
2. How we use your information
- To process, fulfill, and deliver your orders.
- To send order confirmations, status updates, and receipts.
- To process payments and prevent fraud.
- To provide customer support and respond to your inquiries.
- To send occasional marketing messages where you have consented; you can opt out at any time.
- To comply with tax, accounting, and other legal obligations.
- To improve the Service, including through aggregated and anonymized analytics.
3. How we share your information
We do not sell your personal data. We share it only with the following categories of recipients, and only to the extent necessary:
- Payment providers — Xendit — to authorize and capture payment.
- Messaging providers — Meta Platforms Ireland (WhatsApp Business Platform) — to deliver messages to you.
- Mapping and location providers — including Google Maps — to display locations and calculate delivery distances.
- Delivery partners — to complete delivery orders where applicable.
- Cloud infrastructure providers — including Amazon Web Services — which host our systems.
- Legal and regulatory authorities — where required by law, court order, or to protect the rights, property, or safety of our customers, our team, or the public.
4. Data retention
We retain your personal data for as long as your account is active and afterward for the period required by applicable law. In Indonesia this is typically up to ten (10) years for tax and accounting records. Data that is no longer required for a legitimate purpose is deleted or anonymized.
5. International transfers
Your data may be processed on servers located outside Indonesia. When we transfer data internationally we take reasonable steps to ensure appropriate contractual and technical safeguards are in place.
6. Security
We use administrative, technical, and physical safeguards — including TLS in transit, encryption at rest, access controls, and regular reviews — to protect your information. No system is perfectly secure, and we cannot guarantee absolute security of information you transmit to us.
7. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data (see our Data Deletion Policy).
- Receive a portable copy of your data.
- Withdraw consent at any time where processing is based on consent.
- Opt out of marketing communications.
- Lodge a complaint with a data protection authority.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by notifying you directly.
10. Contact us
To exercise your rights or ask questions about this policy, contact us at:
Apple Review Sandbox