Legal
Privacy Policy
What we collect, why, how long we keep it, and your rights under Indonesia's Personal Data Protection Law (Law No. 27 of 2022).
Last updated: 10 October 2026
1. Our role
For Customer account and billing data, Recco is the controller. For videos and shipping data recorded by the Customer (for example recipient names and addresses visible on labels), the Customer is the controller and Recco is a processor acting on the Customer's instructions.
2. Data we process
Account: name, email, password (stored as a hash), 2FA settings, billing details (business name, billing email, tax ID if provided).
Operations: operator names and PINs (hashed), AWB numbers, times, durations, statuses, station devices (type, browser, app version), activity logs.
Videos and return photos you record, including what is visible in them.
Payments: payment status and method from Xendit. We never store card or bank account numbers.
Evidence-link visitors: hashed IP address and access time, for security and an access log visible to the Customer.
3. Purposes and grounds
Providing the service under contract; security, fraud prevention and audit (legitimate interest); billing and legal obligations; service communication. We do not sell data and do not use your videos for advertising or to train AI models.
4. Storage and retention
Videos are stored in encrypted object storage for the plan's retention period and then deleted automatically; a void/deletion record (without the video) is kept as an audit trail. Account data is kept while the account is active and up to 30 days after it ends, except billing records that tax rules require us to keep.
Encrypted database backups are kept for 30 days.
5. Sub-processors and transfers
We use the third-party providers listed on the Sub-processors page, some outside Indonesia (e.g. object storage in Singapore). Transfers are protected by equivalent contractual and technical safeguards as required by the PDP Law.
6. Security
Encryption in transit (HTTPS) and at rest, database-level isolation between customers, mandatory 2FA for Recco staff, tamper-evident access logs, and least-privilege access. If a personal data breach occurs, we notify affected Customers within 3 × 24 hours of becoming aware of it.
7. Your rights
You may access, correct, obtain a copy of, delete, restrict and withdraw consent for your personal data. For data inside a Customer's videos, send your request to the Customer (seller/warehouse) that recorded it; we help them fulfil it. Deletion may be deferred while a video is evidence in an open claim, with the reason recorded.
Send requests to albertwirawan@recco.my.id. We respond within 3 × 24 hours and complete requests within the PDP Law's time limits.
8. Cookies
We only use cookies needed for sign-in and security (session, registered station). There are no advertising or third-party tracking cookies in the app.
9. Changes
Changes are published on this page and, if material, announced by email.