#StartupLokal

Privacy Policy

Effective August 12, 2026 · version 2026-08-12

This policy explains what #StartupLokal does with your personal data: what we collect, why, who else sees it, and what you can ask us to do about it. It is written to be read rather than to be survived, and the part most people are looking for is section 7 — what event sponsors receive.

1. Who is responsible for your data

PT Startuplokal, a limited liability company incorporated in Indonesia under business registration number (NIB) 8120214201198 and tax number (NPWP) 0313693574071000, with its registered office at Jl. Penjernihan Dalam No. 45, RT 002 / RW 007, Kelurahan Bendungan Hilir, Kecamatan Tanah Abang, Kota Administrasi Jakarta Pusat, DKI Jakarta 10210, is the controller of the personal data described here.

For anything in this policy, including a request to see, correct or delete your data, write to [email protected].

This policy is written against Indonesia's Personal Data Protection Law (Undang-Undang No. 27 of 2022).

2. What we collect

When you create an account: your email address, and either a password we store only as a bcrypt hash or the fact that you signed in with Google. If you sign in with Google we receive your name, email address and profile picture from them, and nothing else.

Your profile, all of it optional except your name: name, photograph, short bio, city, postcode, LinkedIn profile address, company, job title, and phone number.

Two of these are collected for a reason worth stating. Your postcode is used for one thing only — working out which upcoming meetups are near you. Your phone number doubles as a way to sign in, as the number we can reach you on about an event, and as one of the details given to sponsors.

When you register for an event: which event, when you registered, whether you attended, your answers to any questions on that event's form, and the record of your consent — the date, the language you read the terms in, and which edition of them was current.

When you contribute: photographs, articles and videos you upload, and which event they belong to.

When you pay: for ticketed events, Midtrans handles the payment and tells us its status. We never see your card number.

Automatically: our web server logs the IP address, browser and pages requested for every visit, which is ordinary server operation and is how we find faults and abuse. We use one cookie, for keeping you signed in. There is no advertising or third-party analytics tracking on this site.

3. Why we use it, and on what basis

What we doWhyBasis under UU 27/2022
Run your account and sign you inYou asked for an accountPerformance of a contract with you
Register you for an event and manage the rosterYou asked for a placePerformance of a contract with you
Send you booking confirmations, reminders and changesYou need to know the event movedPerformance of a contract with you
Give your contact details and answers to that event's sponsorsIt is how a free meetup gets paid forYour consent
Send you news and promotional messages about #StartupLokalKeeping the community togetherLegitimate interest, with an opt-out you control
Show your name, photo and bio on the site where you have chosen to appearYou filled the profile inYour consent
Keep the site secure and workingFaults and abuseLegitimate interest
Keep financial records for paid ticketsTax and accountingLegal obligation

4. Nobody has to give us everything

The only things we need are an email address and a name. Everything else is optional, and the site works without it — you will simply see less relevant suggestions and sponsors will get a shorter row.

The one exception is registering for a sponsored event, where the sharing in section 7 is a condition of the booking. You always have the option not to register.

5. Marketing messages, and how to stop them

We may send promotional messages about #StartupLokal — new meetups, write-ups and community news — by email, by WhatsApp or SMS to the number on your profile, and as push notifications if you have installed the app.

You can switch each of those three off independently, at any time, in Settings → Communication preferences. It takes effect immediately, and we do not ask you to justify it.

Some messages are not promotional and will still reach you: confirming a booking, telling you an event has moved or been cancelled, confirming your email address, and anything about the security of your account. Turning marketing off does not turn those off, and it should not — someone who asked not to be marketed at did not ask to stop being told that the meetup they registered for has changed venue.

These settings cannot stop a sponsor contacting you. Once your details have been shared, that sponsor is sending under its own policy from its own systems. See section 7.

6. Who else sees your data

We do not sell personal data, and we do not share it for anyone else's advertising.

Beyond the sponsors described in section 7, your data reaches these service providers, each only to the extent they need it:

WhoWhat they getWhat for
Amazon Web Services (SES, SQS)Your email address and the messageSending email, handling bounces
CloudflareYour IP address and request detailsServing and protecting the site
Cloudflare R2Photographs you uploadStoring images
GoogleYour Google account detailsSigning you in, if you use Google
MidtransYour name, email and the amountTaking payment for ticketed events
Meilisearch (our own server)Public listings onlySearch on the site

Our servers are in Indonesia and in Singapore, and email leaves Indonesia to reach AWS. Where data goes abroad we rely on the recipient operating to a standard of protection comparable to the one required here.

We will also disclose data where the law requires it, or to establish or defend a legal claim.

7. Event sponsors — the important part

Our meetups are paid for by sponsors: companies that provide the venue, the food, the prizes or the money. What they get in return is the attendee list.

When you register for an event, the sponsors of that event receive:

  • your name;
  • your email address;
  • your phone number;
  • your company and job title, if your profile has them;
  • your LinkedIn profile address, if your profile has it; and
  • your answers to any additional questions on that event's registration form.

Sponsors may add their own questions to the form, and where they have, the form tells you which sponsor is asking before you answer.

A few things follow from this, and they are the reason this section exists rather than a line in a table:

  • It happens because you agreed to it. The tick box on the booking form is a real consent, recorded with its date and the edition of the terms in force. It is not pre-ticked and the booking will not go through without it.
  • It only covers events you registered for. A sponsor of one meetup gets the list for that meetup and nothing else. Registrations recorded before this policy existed, imported lists and attendees added by hand have no consent behind them and are never included.
  • It cannot be undone once done. We can stop sharing your details in future, and we do the moment you stop registering for sponsored events. We cannot reach into a sponsor's CRM and remove what was already sent.
  • The sponsor then decides for itself. From the moment they receive it they are an independent controller under their own privacy policy. We ask them to use the list only to follow up about their own products and events. To stop hearing from them, unsubscribe from their message or write to them directly — our settings page has no reach there, and we would rather say so than pretend otherwise.

If you want to know which sponsors have your details, write to [email protected] and we will tell you which events you registered for and who sponsored them.

8. How long we keep it

WhatHow long
Your account and profileUntil you delete it
Event registrations and answersFive years, then anonymised — they are the record of the community's own history
Consent recordsFive years after the registration they belong to, as evidence of what was permitted
Payment recordsTen years, as Indonesian tax law requires
Server logs90 days
Photographs and articles you postedUntil you delete them

9. Your rights

Under UU 27/2022 you can ask us to:

  • tell you what data we hold about you and where it came from;
  • correct anything that is wrong or out of date — most of it you can edit yourself in settings;
  • delete your data (see section 10);
  • give you a copy of your data in a machine-readable form;
  • stop or limit a particular use;
  • withdraw a consent you gave, including the marketing switches, which takes effect from now rather than retroactively; and
  • object to a use we base on legitimate interest.

Write to [email protected]. We will reply within 30 days. If you are not satisfied you can complain to the Personal Data Protection authority in Indonesia.

10. Deleting your account

There is a button for it in Settings, and it takes effect immediately rather than filing a request.

It removes your name, photograph, bio, city, postcode, LinkedIn address, company, job title, email address and phone number, disables every way of signing in, and switches off all messages.

Two things stay, deliberately:

  • Your attendance record, with your identity stripped out. It becomes a row saying somebody attended, with no name attached. Meetup 121 having had 84 attendees is a fact about the event, not about you, and removing you from the count would falsify the community's own history.
  • The consent record. The date, the edition of the terms, and the language. This is the evidence that details already sent to a sponsor were sent with permission. Deleting it would leave us unable to show that, which protects neither of us.

Neither of these can be linked back to you once the account is anonymised.

If you would rather have everything removed including those records, write to [email protected] and we will discuss what we are able to do.

11. Keeping it safe

Passwords are stored as bcrypt hashes and never in a readable form. The site is served over HTTPS only. Access to the database and to attendee lists is restricted to the organisers who need it. Attendee rosters are never a public page and are not indexed by search engines.

No system is perfectly secure. If a breach affects your data we will tell you and the authority, as UU 27/2022 requires.

12. Children

The site is not for people under 17 and we do not knowingly collect their data. If you believe a child has created an account, tell us at [email protected] and we will remove it.

13. Changes to this policy

The version and date at the top of this page say which edition is current. The full history of changes is public in the repository the site is built from.

If we change what sponsors receive, or add a new recipient of your data, we will ask for your agreement again the next time you register for an event rather than treating your continued use as consent.

14. Contact

PT Startuplokal
Jl. Penjernihan Dalam No. 45, RT 002 / RW 007, Kelurahan Bendungan Hilir, Kecamatan Tanah Abang, Kota Administrasi Jakarta Pusat, DKI Jakarta 10210
[email protected]


This policy was written by the organisers of #StartupLokal and is not legal advice.