Privacy Policy

Last updated: 27 August 2026

Most Kitdeka Free tools are designed to run in your browser. This policy explains the information that reaches our systems when you create an account, buy Pro, save work, use a dynamic QR code, contact us, or otherwise use a server-backed feature. For personal data processed for the Kitdeka service, IA Tech Digital is the data controller unless another party is independently responsible for its own processing.

Who you are dealing with

Kitdeka is operated by IA Tech Digital, an individual business (usaha perorangan) based at Jl. Cepit Raya, Jatimulya, Cilodong, Depok, Jawa Barat 16413, Indonesia — a sole trader, not an incorporated company. Where this document says “we” or “Kitdeka”, it means that business.

1. What we collect

Account information

When you create an account, we process information such as your name, your email address, email-verification and account status information, and your password in hashed form rather than plaintext.

Purchase and subscription information

When you buy Pro, we receive information needed to record and verify the purchase, such as PayPal transaction and order identifiers, amount and currency, purchase date, Pro activation status, and Pro start and expiry dates. We do not receive your full card number from PayPal.

Saved Pro workspace information

When you choose to save work in Pro, we may store the content needed to provide those features, including QR designs and configuration, brand kits and reusable assets, business profiles, projects, dynamic QR identifiers and destinations, dynamic QR status, destination-change history, and available scan analytics associated with your dynamic QR codes.

Dynamic QR scan analytics

When someone opens a Kitdeka dynamic QR redirect, Kitdeka records a scan event, not a person profile. Depending on what is available from the request and our hosting infrastructure, a scan event may include the timestamp, a broad device category, the operating-system family, the referring-site host when supplied, a two-letter country code supplied by infrastructure when available, and a coarse human/machine classification used to distinguish likely automated traffic from ordinary scans.

We do not create an estimated unique visitor identity from these events. A dashboard count means scans or link openings, not necessarily different people.

Server and security logs

Our hosting and infrastructure providers may process ordinary technical logs, which can include IP addresses and request metadata, for security, reliability, abuse prevention, and troubleshooting. Kitdeka’s own scan-analytics records are deliberately designed not to store the scanner’s raw IP address.

Messages you send us

If you contact support or send us an account, refund, security, or privacy request, we process the information in that message and the information needed to respond.

2. What we deliberately do not collect for QR analytics

Kitdeka does not use dynamic QR scans to build advertising profiles.

For our first-party scan analytics, we do not intentionally store:

  • raw scanner IP addresses;
  • device fingerprints;
  • advertising identifiers;
  • tracking-cookie identifiers;
  • estimated unique-person identifiers; or
  • cross-site browsing histories.

We do not sell personal data.

We also design application logs to avoid recording sensitive QR payload content such as Wi-Fi passwords, message bodies, phone numbers, contact details, destination URLs, raw QR payloads, or plaintext API keys where those values are not needed for the log.

3. Why we process personal data

Perform our contract with you

This includes creating and securing your account, activating and administering Pro, storing the workspace you ask us to save, providing dynamic redirects while the service is active, showing first-party scan analytics, providing exports, API access, and other requested Pro features, and handling purchases and account requests.

Comply with legal obligations

We may retain or process records when required for tax, accounting, consumer-protection, law-enforcement, dispute, or other legal obligations.

Pursue legitimate interests

Where permitted by applicable law and balanced against your rights, we may process limited data for service security, fraud and abuse prevention, maintaining reliable redirect infrastructure, troubleshooting, protecting old printed QR identifiers from being reassigned to another customer, resolving disputes, and retaining an expired Pro workspace for a limited period so that you can renew, restore eligible QR service, export your data, or delete it before scheduled deletion.

Consent

Where applicable law requires consent for a particular processing activity, we will ask for it first and allow you to withdraw it. Kitdeka currently does not use advertising cookies or third-party behavioural analytics cookies.

4. Who processes data with us

We use service providers to operate Kitdeka. Based on the current service architecture, these include:

  • Vercel — application hosting and related infrastructure;
  • Supabase — database hosting, currently using a Singapore region;
  • PayPal — payment processing; and
  • Hostinger — transactional email delivery.

We disclose or make data available only as needed for the relevant service.

Some providers, particularly payment providers, may also process information under their own legal obligations and privacy terms. This Privacy Policy does not replace a third party’s own privacy policy for processing it independently controls.

We do not sell personal data and do not use a third-party advertising network or behavioural analytics provider.

5. International processing and transfers

Kitdeka is operated from Indonesia, while some service providers process or store data outside Indonesia. In particular, saved account and workspace data may be hosted in Singapore through Supabase.

Where Indonesian personal-data law applies to a transfer outside Indonesia, we take the steps required by applicable law for the transfer and the protection of the data, including relying on appropriate provider safeguards, contractual protections, or another lawful transfer mechanism as applicable.

6. How long we keep data

We do not intend to keep ordinary workspace data indefinitely.

Active Pro

While your Pro Annual Pass is active, we retain the account and saved data needed to provide the service.

After Pro expires

When Pro expires, Pro editing and paid actions are paused; existing dynamic redirects continue for a 30-calendar-day grace period; the retained account and Pro workspace remain available in a limited or read-only form for up to 365 days after the pass expiry date, unless you renew or delete them earlier; and available historical scan analytics are retained with the workspace during that retention period.

During this retention period, you may use available account controls to view retained information, export available data, request deletion, delete your account, or buy another Pro Annual Pass. If you renew before the 365-day retention period ends, the scheduled deletion is cancelled and eligible retained Pro data can be used again.

Scheduled deletion after one year

If you do not renew, we schedule the account and Pro workspace for deletion 365 days after the Pro expiry date. Deletion includes ordinary account and workspace information that is no longer needed, including saved QR configurations, dynamic destinations, destination history, brand and workspace content, and retained scan analytics, subject to the exceptions below. Where required by applicable law, we will notify you about deletion or destruction of personal data.

Records kept longer for legal reasons

Certain purchase, accounting, and tax records may need to be retained after account deletion. Indonesian tax rules can require books, records, and supporting documents to be retained for 10 years. We keep only the records reasonably necessary for those obligations and related legal claims. We may also retain limited security, fraud-prevention, dispute, or abuse records for as long as reasonably necessary and permitted by law.

Dynamic QR tombstones

After a dynamic QR’s workspace data is deleted, we may retain a non-identifying tombstone or reserved identifier so that an old printed QR code is not later reassigned to a different customer. That tombstone is not intended to retain your previous destination, workspace content, or scan history and is not used to reconstruct your deleted profile.

Server logs

Infrastructure and server logs are retained according to operational and provider retention settings and are rotated or deleted when no longer needed, subject to security or legal requirements.

7. Your choices and rights

Subject to applicable law, you may have rights to:

  • obtain information about how your personal data is processed;
  • access personal data we hold about you;
  • correct or update inaccurate information;
  • obtain a copy of data you provided in an available format;
  • withdraw consent where consent is the processing basis;
  • request restriction, termination, deletion, or destruction of processing where applicable;
  • object to certain processing where applicable; and
  • complain to the competent authority or pursue other legal remedies.

Kitdeka provides account controls for available self-service actions. You may also write to hello@kitdeka.com.

We may need to verify that a requester is the account holder before providing, changing, exporting, or deleting account data.

Deletion rights may be limited where a record must be retained under applicable law, including tax or accounting rules.

8. Account deletion

You can delete your account using the account controls made available by Kitdeka. We may require confirmation by email or another reasonable verification step before destructive deletion is completed.

Account deletion removes saved workspace data and stops associated Kitdeka-hosted dynamic redirects, except for information that must or may lawfully be retained as described in section 6.

If you do not manually delete an expired account, automatic deletion is scheduled after the 365-day post-expiry retention period described above.

9. Security

We use technical and organisational measures intended to protect information against unauthorised access, alteration, disclosure, or destruction.

No system can guarantee absolute security. If a personal-data protection failure occurs, we will provide notices required by applicable law. Indonesian personal-data law may require written notice to affected data subjects and the competent institution no later than 3 × 24 hours after a qualifying personal-data protection failure.

10. Cookies and similar storage

Kitdeka uses only the cookies needed for sign-in and session functionality and remembering language preferences, as described in the Cookie Policy.

Kitdeka’s dynamic QR scan analytics do not require an advertising or analytics cookie.

The first-visit legal and cookie notice may remember dismissal in browser local storage so that the notice does not repeatedly appear.

11. Children

Kitdeka is not intended to knowingly collect personal data from children in circumstances where parental or guardian consent or another legal requirement is necessary and has not been satisfied.

If you believe a child has provided personal data to Kitdeka improperly, contact us so we can review and, where appropriate, delete it.

12. Changes to this Privacy Policy

If this Privacy Policy changes, we will update the date at the top.

If a change materially affects how we use, retain, transfer, or delete account-holder personal data, we will provide reasonable notice to affected account holders rather than relying only on a silent page update.

Contact

Questions about this document go to hello@kitdeka.com, or by post to IA Tech Digital, Jl. Cepit Raya, Jatimulya, Cilodong, Depok, Jawa Barat 16413, Indonesia. Please include the email address on your Kitdeka account so we can find you.