Ringkasan (Bahasa Indonesia): TandaKit cuma mengumpulkan data yang dibutuhkan buat bikin halaman publik kamu, menghitung skor TandaCheck, dan menyalurkan brief dari brand ke inbox kamu. Kalau kamu menghubungkan akun Instagram, TikTok, atau YouTube, kami hanya membaca statistik publik (follower, engagement, kadensi posting) untuk skor kesiapan — kami tidak pernah memposting atas nama kamu dan tidak menjual data kamu. Kamu bisa cabut akses atau hapus akun & data kapan saja lewat halaman Hapus data.
1. Who we are
TandaKit ("TandaKit", "we", "us") operates the creator bio-link service at tandakit.id. TandaKitis the bio link that helps Indonesian creators get brand deals: a public page for your profile, proof, rate cards, open collaboration slots, and structured brief intake. This Privacy Policy explains what personal data we process, why, and the choices you have. It is written to comply with Indonesia's Personal Data Protection Law (UU No. 27/2022, "UU PDP") and the data requirements of the platforms we integrate with (Meta/Instagram, TikTok, and Google/YouTube).
For any privacy question or request, contact us at privasi@tandakit.id.
2. Data we collect
We collect only what each feature needs. The table below is our full personal-data inventory.
| Data | Subject | Purpose | Retention |
|---|---|---|---|
| Email, authentication identifier | Creator | Account creation and login | Life of the account |
| Name, photo, niche, bio, handle, location | Creator | Your public TandaKit page | Life of the account |
| Contact methods (WhatsApp / email) | Creator | Letting brands reach you | Life of the account |
| Connected social stats (followers, engagement, posting cadence) | Creator | Computing your TandaCheck readiness score | Until you disconnect the account or delete your account |
| Brand name, contact name & method, brief details | Brand visitor | Delivering the brief to the creator's inbox | Per plan limit, plus deletion on request |
| Anonymous session id, referrer, UTM | Visitor | Product analytics (aggregate) | Limited window, then aggregated |
3. Connected social accounts
Connecting a social account is optional. It powers TandaCheck — a deterministic readiness score computed from your publicaccount statistics. We connect only through each platform's official OAuth flow, we request the minimum scopes, and we never post, message, or take any action on your behalf. You can revoke our access at any time from the platform's own app settings or from your TandaKit dashboard.
Instagram (Meta)
We use the Instagram API with Instagram Login (for Business/Creator accounts) to read your basic profile and aggregated media insights (followers, engagement, posting cadence). Our use of Instagram and Meta platforms is also governed by the Meta Platform Terms and Instagram's terms. You can request deletion of the data we obtained from Instagram at any time — see Hapus data.
TikTok
We use TikTok Login Kit and the Display API to read your public profile and aggregated video statistics for your readiness score. Our use of TikTok developer tools is governed by the TikTok Developer Terms of Service. We store only the derived statistics needed for TandaCheck and you can revoke access from your TikTok account settings.
YouTube (Google)
We use the YouTube Data API v3 (via Google OAuth) to read your channel's public statistics. By connecting YouTube you agree to the YouTube Terms of Service, and Google's use of your data is described in the Google Privacy Policy. Where TandaKit displays YouTube data, YouTube is identified as the source.
Google API Services — Limited Use disclosure. TandaKit's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not transfer it except to provide or improve the connected feature (or as required by law), and do not allow humans to read it except with your consent, for security, to comply with law, or on aggregated/anonymized data.
4. How we use data
- Create and operate your account and your public TandaKit page.
- Compute and refresh your TandaCheck readiness score from connected-account statistics.
- Receive structured briefs from brands and deliver them to your inbox.
- Provide aggregate analytics (page views, link clicks, collab requests).
- Keep the service secure, prevent abuse and spam, and meet legal obligations.
We do not sell personal data, and we do not use connected-account data for advertising or profiling unrelated to TandaCheck.
5. Legal basis (UU PDP)
Under UU PDP we process personal data on the basis of your consent (e.g. connecting a social account, or a brand submitting a brief) and the performance of our agreement with you (operating your account and page). You may withdraw consent at any time; withdrawal does not affect processing already carried out.
6. How data is shared
- Brief details go only to the owning creator.A brand's contact details are never shown publicly — they are delivered to the creator's inbox for that collaboration only, not for resale or marketing lists.
- Service providers (processors). We use vetted infrastructure providers for hosting, database, storage, and email. They process data only on our instructions.
- Legal & safety. We may disclose data where required by law or to protect the rights, safety, and security of users and the public.
- No sale. We do not sell or rent personal data to third parties.
7. Cookies & analytics
We use strictly necessary cookies to keep you signed in and to secure the service, plus privacy-respecting, mostly first-party analytics to understand aggregate usage (page views, link clicks, collab requests). We do not use third-party advertising trackers. You can control cookies through your browser settings; disabling necessary cookies may break sign-in.
8. Retention
We keep account and page data for the life of your account. Connected-account statistics are kept until you disconnect the account or delete your account. Brief/inquiry data is retained per your plan limit and deleted earlier on request. Analytics are retained for a limited window, then aggregated. When you delete your account, we delete or anonymize personal data within 30 days, except where retention is required by law.
9. Your rights
As a data subject under UU PDP you can:
- Access the personal data we hold about you and request a copy.
- Correct inaccurate or incomplete data (most of it is editable in your dashboard).
- Delete your data and your account, and disconnect any social account.
- Withdraw consent and object to or restrict certain processing.
To exercise any right, email privasi@tandakit.id. We respond within the period required by UU PDP. If you believe we have not handled your data properly, you may lodge a complaint with the relevant Indonesian data protection authority.
10. Deleting your data
You can delete your account and associated data yourself from your dashboard, or request deletion by email. A brand who submitted a brief can also request its deletion. Full step-by-step instructions — including how to revoke each connected social account — are on our dedicated Hapus data page.
11. International transfers
Our infrastructure providers may process data on servers outside Indonesia. Where personal data is transferred abroad, we ensure an adequate level of protection consistent with UU PDP through appropriate safeguards and provider commitments. We prefer regions close to our users and document such transfers.
12. Security
We encrypt data in transit (HTTPS) and at rest, restrict access to personal data on a need-to-know basis, and log access to sensitive data. No method of transmission or storage is perfectly secure, but we maintain a breach-response process and will notify affected users and the authority where UU PDP requires.
13. Children
TandaKit is intended for creators aged 18 and over (or the age of majority in their jurisdiction). We do not knowingly collect data from children. If you believe a minor has provided us data, contact us and we will delete it.
14. Changes to this policy
We may update this policy as the product and legal requirements evolve. We will change the date at the top and, for material changes, notify you in-app or by email before they take effect.
15. Contact
Privacy & data requests: privasi@tandakit.id
General support: halo@tandakit.id
This policy is provided for transparency and is not legal advice. TandaKit will have Indonesian counsel review its final terms and data handling before public launch.