Version: 2026-09-25 • Effective Date: September 25, 2026 • Compliant with PDP Law & GDPR Standards
Clause 1 • Data Controller & Scope
This Privacy Policy details the policies and protocols of PT Go Travelist Asia ("GTA", "We", "Us", "Our") regarding the collection, transmission, processing, storage, and erasure of personal data when you interact with gotravelist.asia, associated subdomains, and decentralized booking interfaces.
GTA operates in strict compliance with the Indonesian Law No. 27 of 2022 on Personal Data Protection (UU PDP), the General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR), and applicable regional data protection legislations across member states of the Pan-Asian network.
Clause 2 • Categories of Information Collected
GTA adheres to the principle of data minimization. We only collect information strictly required to facilitate verified direct bookings and creator attribution:
Traveler Contact & Manifest Data: Legal full name, email address, and WhatsApp contact telephone number formatted in international standard (ITU-T E.164). For maritime/group journeys, participant names and special logistics requests (dietary/child requirements) are collected.
Payment Verification Media: User-uploaded bank transfer screenshots and deposit receipts processed through client-side HTML5 Canvas compression (< 800 KB Base64).
Partner Identification Data: For registered Tour Operators and Verified Creators: national identity numbers (KTP/Passport), business licenses (NIB), bank account settlement details, and business physical coordinates.
Technical Runtime Telemetry: Anonymized client timestamps (ISO 8601 Asia/Jakarta), coarse geographic zone filters, device user-agent strings, and security event signatures stored in volatile memory.
Clause 3 • Lawful Basis for Processing
GTA processes personal information strictly under the following lawful bases:
Contractual Necessity: Generating deterministic booking IDs (GTA-ORD-...), issuing electronic reservation vouchers (VCR-...), and routing essential traveler manifest details directly to operating vendor partners for activity fulfillment.
Legitimate Legal & Compliance Interest: Preventing fraudulent transactions, validating bank transfer proofs against unauthorized double-submissions, and resolving traveler-vendor disputes through the Master Admin Arbitration Center.
Explicit Consent: Voluntary subscription to notification channels, creator community participation, and localized language or currency preference persistence.
Clause 4 • Meta Instagram API & Social Embeds
The Travel Creator Hub (pages/travel-reel.html) embeds short vertical travel videos utilizing official Meta Instagram Graph API endpoints. GTA does not store raw video files on its servers.
When interacting with video reels via the centralized Instagram pop-up modal (#modal-ig-social), interactions (likes and comments) are registered directly on native Meta infrastructure. For users authenticating through Meta Instagram OAuth 2.0, GTA only accesses public profile identifiers (id, username) necessary to authenticate review submissions and display creator badges. We do not inspect private messages, friend lists, or non-public media.
Clause 5 • Google Identity Services (GIS) Flow
Travelers electing to access platform profiles through Google Identity Services transmit a secure cryptographic ID Token (credential) directly to GTA backend dispatcher functions.
Backend verification validates token integrity natively against Google public keys without external libraries. Profile fields obtained (full name, verified email, profile avatar URL) are utilized exclusively to instantiate the active session token (HMAC-SHA256 JWT) and synchronize locally saved trip wishlists (GTA_LOCAL_WISHLIST).
Clause 6 • Strict Zero-Data Selling Guarantee
GTA maintains a permanent, uncompromised commitment: We never sell, rent, monetize, lease, or trade personal information to third-party data brokers, advertising networks, or speculative marketers.
Personal information is transmitted solely to the verified local tour operator or property host who is bound to execute your specific reservation, and exclusively to the extent necessary to confirm bookings and verify traveler identity at activity meeting points.
Clause 7 • Payment Proof & Cloud Drive Security
Uploaded payment slips, bank transfer proofs, and partner compliance credentials undergo client-side image compression via HTML5 Canvas before network transmission, purging unnecessary EXIF metadata and geolocational tags.
Binary files are transmitted via secure POST envelopes without preflight leaks and stored in isolated, permission-locked Google Workspace enterprise storage. Sensitive verification files (KTP identification cards and bank transfer receipts) are configured with strict private access control (Access.PRIVATE), accessible solely by authorized compliance and finance controllers.
Clause 8 • Data Retention & Auto-Purge Policy
Active reservation records, communication tickets, and session tokens are retained in the primary production database only for the duration required to service your travel itinerary and audit fulfillment.
Pursuant to Technical Architecture T.8, completed, cancelled, or refunded transactions exceeding ninety (90) calendar days from fulfillment are automatically extracted by automated system triggers and migrated to isolated Cold Storage archives (GTA_ARCHIVE_DATABASE_PROD). Archived records remain strictly segregated to preserve high database throughput and are expunged in accordance with statutory accounting retention requirements.
Clause 9 • Data Subject Rights & Account Purge
In accordance with global data protection standards, travelers and partners hold comprehensive rights regarding their personal data:
Right to Access & Portability: You may inspect active bookings, reviews, and profile metadata directly via pages/profile.html.
Right to Rectification: You may edit and update display names, contact telephone numbers, and email credentials through the self-service profile settings module.
Right to Erasure (Right to be Forgotten): You may request permanent deletion of your account and personal records at any time. Upon verified confirmation, your user status is modified to DELETED, and personal identifying fields (full name, email, phone number) are replaced with irreversible anonymized hashes (ANON-XXXXX), terminating marketing telemetry while preserving immutable financial audit ledgers.
Clause 10 • Data Protection Officer (DPO) Inquiries
If you have inquiries, complaints, or requests concerning the processing of your personal data or wish to exercise your data subject rights, please contact our Data Protection Compliance Team through the encrypted support interface:
In accordance with platform anti-mailto safeguards, clicking the contact link directly opens the encrypted transmission modal without exposing email clients to unauthorized surveillance.