Privacy Policy
Effective August 12, 2026 · version 2026-08-12
This policy explains what #StartupLokal does with your personal data: what we collect, why, who else sees it, and what you can ask us to do about it. It is written to be read rather than to be survived, and the part most people are looking for is section 7 — what event sponsors receive.
1. Who is responsible for your data
PT Startuplokal, a limited liability company incorporated in Indonesia under business registration number (NIB) 8120214201198 and tax number (NPWP) 0313693574071000, with its registered office at Jl. Penjernihan Dalam No. 45, RT 002 / RW 007, Kelurahan Bendungan Hilir, Kecamatan Tanah Abang, Kota Administrasi Jakarta Pusat, DKI Jakarta 10210, is the controller of the personal data described here.
For anything in this policy, including a request to see, correct or delete your data, write to [email protected].
This policy is written against Indonesia's Personal Data Protection Law (Undang-Undang No. 27 of 2022).
2. What we collect
When you create an account: your email address, and either a password we store only as a bcrypt hash or the fact that you signed in with Google. If you sign in with Google we receive your name, email address and profile picture from them, and nothing else.
Your profile, all of it optional except your name: name, photograph, short bio, city, postcode, LinkedIn profile address, company, job title, and phone number.
Two of these are collected for a reason worth stating. Your postcode is used for one thing only — working out which upcoming meetups are near you. Your phone number doubles as a way to sign in, as the number we can reach you on about an event, and as one of the details given to sponsors.
When you register for an event: which event, when you registered, whether you attended, your answers to any questions on that event's form, and the record of your consent — the date, the language you read the terms in, and which edition of them was current.
When you contribute: photographs, articles and videos you upload, and which event they belong to.
When you pay: for ticketed events, Midtrans handles the payment and tells us its status. We never see your card number.
Automatically: our web server logs the IP address, browser and pages requested for every visit, which is ordinary server operation and is how we find faults and abuse. We use one cookie, for keeping you signed in. There is no advertising or third-party analytics tracking on this site.
3. Why we use it, and on what basis
| What we do | Why | Basis under UU 27/2022 |
|---|---|---|
| Run your account and sign you in | You asked for an account | Performance of a contract with you |
| Register you for an event and manage the roster | You asked for a place | Performance of a contract with you |
| Send you booking confirmations, reminders and changes | You need to know the event moved | Performance of a contract with you |
| Give your contact details and answers to that event's sponsors | It is how a free meetup gets paid for | Your consent |
| Send you news and promotional messages about #StartupLokal | Keeping the community together | Legitimate interest, with an opt-out you control |
| Show your name, photo and bio on the site where you have chosen to appear | You filled the profile in | Your consent |
| Keep the site secure and working | Faults and abuse | Legitimate interest |
| Keep financial records for paid tickets | Tax and accounting | Legal obligation |
4. Nobody has to give us everything
The only things we need are an email address and a name. Everything else is optional, and the site works without it — you will simply see less relevant suggestions and sponsors will get a shorter row.
The one exception is registering for a sponsored event, where the sharing in section 7 is a condition of the booking. You always have the option not to register.
5. Marketing messages, and how to stop them
We may send promotional messages about #StartupLokal — new meetups, write-ups and community news — by email, by WhatsApp or SMS to the number on your profile, and as push notifications if you have installed the app.
You can switch each of those three off independently, at any time, in Settings → Communication preferences. It takes effect immediately, and we do not ask you to justify it.
Some messages are not promotional and will still reach you: confirming a booking, telling you an event has moved or been cancelled, confirming your email address, and anything about the security of your account. Turning marketing off does not turn those off, and it should not — someone who asked not to be marketed at did not ask to stop being told that the meetup they registered for has changed venue.
These settings cannot stop a sponsor contacting you. Once your details have been shared, that sponsor is sending under its own policy from its own systems. See section 7.
6. Who else sees your data
We do not sell personal data, and we do not share it for anyone else's advertising.
Beyond the sponsors described in section 7, your data reaches these service providers, each only to the extent they need it:
| Who | What they get | What for |
|---|---|---|
| Amazon Web Services (SES, SQS) | Your email address and the message | Sending email, handling bounces |
| Cloudflare | Your IP address and request details | Serving and protecting the site |
| Cloudflare R2 | Photographs you upload | Storing images |
| Your Google account details | Signing you in, if you use Google | |
| Midtrans | Your name, email and the amount | Taking payment for ticketed events |
| Meilisearch (our own server) | Public listings only | Search on the site |
Our servers are in Indonesia and in Singapore, and email leaves Indonesia to reach AWS. Where data goes abroad we rely on the recipient operating to a standard of protection comparable to the one required here.
We will also disclose data where the law requires it, or to establish or defend a legal claim.
7. Event sponsors — the important part
Our meetups are paid for by sponsors: companies that provide the venue, the food, the prizes or the money. What they get in return is the attendee list.
When you register for an event, the sponsors of that event receive:
- your name;
- your email address;
- your phone number;
- your company and job title, if your profile has them;
- your LinkedIn profile address, if your profile has it; and
- your answers to any additional questions on that event's registration form.
Sponsors may add their own questions to the form, and where they have, the form tells you which sponsor is asking before you answer.
A few things follow from this, and they are the reason this section exists rather than a line in a table:
- It happens because you agreed to it. The tick box on the booking form is a real consent, recorded with its date and the edition of the terms in force. It is not pre-ticked and the booking will not go through without it.
- It only covers events you registered for. A sponsor of one meetup gets the list for that meetup and nothing else. Registrations recorded before this policy existed, imported lists and attendees added by hand have no consent behind them and are never included.
- It cannot be undone once done. We can stop sharing your details in future, and we do the moment you stop registering for sponsored events. We cannot reach into a sponsor's CRM and remove what was already sent.
- The sponsor then decides for itself. From the moment they receive it they are an independent controller under their own privacy policy. We ask them to use the list only to follow up about their own products and events. To stop hearing from them, unsubscribe from their message or write to them directly — our settings page has no reach there, and we would rather say so than pretend otherwise.
If you want to know which sponsors have your details, write to [email protected] and we will tell you which events you registered for and who sponsored them.
8. How long we keep it
| What | How long |
|---|---|
| Your account and profile | Until you delete it |
| Event registrations and answers | Five years, then anonymised — they are the record of the community's own history |
| Consent records | Five years after the registration they belong to, as evidence of what was permitted |
| Payment records | Ten years, as Indonesian tax law requires |
| Server logs | 90 days |
| Photographs and articles you posted | Until you delete them |
9. Your rights
Under UU 27/2022 you can ask us to:
- tell you what data we hold about you and where it came from;
- correct anything that is wrong or out of date — most of it you can edit yourself in settings;
- delete your data (see section 10);
- give you a copy of your data in a machine-readable form;
- stop or limit a particular use;
- withdraw a consent you gave, including the marketing switches, which takes effect from now rather than retroactively; and
- object to a use we base on legitimate interest.
Write to [email protected]. We will reply within 30 days. If you are not satisfied you can complain to the Personal Data Protection authority in Indonesia.
10. Deleting your account
There is a button for it in Settings, and it takes effect immediately rather than filing a request.
It removes your name, photograph, bio, city, postcode, LinkedIn address, company, job title, email address and phone number, disables every way of signing in, and switches off all messages.
Two things stay, deliberately:
- Your attendance record, with your identity stripped out. It becomes a row saying somebody attended, with no name attached. Meetup 121 having had 84 attendees is a fact about the event, not about you, and removing you from the count would falsify the community's own history.
- The consent record. The date, the edition of the terms, and the language. This is the evidence that details already sent to a sponsor were sent with permission. Deleting it would leave us unable to show that, which protects neither of us.
Neither of these can be linked back to you once the account is anonymised.
If you would rather have everything removed including those records, write to [email protected] and we will discuss what we are able to do.
11. Keeping it safe
Passwords are stored as bcrypt hashes and never in a readable form. The site is served over HTTPS only. Access to the database and to attendee lists is restricted to the organisers who need it. Attendee rosters are never a public page and are not indexed by search engines.
No system is perfectly secure. If a breach affects your data we will tell you and the authority, as UU 27/2022 requires.
12. Children
The site is not for people under 17 and we do not knowingly collect their data. If you believe a child has created an account, tell us at [email protected] and we will remove it.
13. Changes to this policy
The version and date at the top of this page say which edition is current. The full history of changes is public in the repository the site is built from.
If we change what sponsors receive, or add a new recipient of your data, we will ask for your agreement again the next time you register for an event rather than treating your continued use as consent.
14. Contact
PT Startuplokal
Jl. Penjernihan Dalam No. 45, RT 002 / RW 007, Kelurahan Bendungan Hilir,
Kecamatan Tanah Abang, Kota Administrasi Jakarta Pusat, DKI Jakarta 10210
[email protected]
This policy was written by the organisers of #StartupLokal and is not legal advice.