Create an account in less than 5 minutes! Sign up now »

image/svg+xml

Privacy Policy

Last Updated: 28 August 2023 | Last Reviewed: 28 August 2023

Privacy and online safety are important to Us. PT Sinar Digital Terdepan, a limited liability company established under the laws of Indonesia (“Xendit”, “We”, “Us” or “Our”) offers payment platforms and services for running an online business. We collect data about businesses and their customers (“Data”) when they use the platform, the services, and Our websites (collectively, “Services”). This Privacy Policy describes how we collect, use and disclose Data.

In this Privacy Policy, we sometimes refer to “You”. “You” may be a visitor to one of Our websites, a user of one or more of Our Services (“User”), or a customer of a User (“Customer”). We’ll do Our best to clarify who we are referring to at various points in the policy. This policy does not apply to third-party websites, products, or services even if they link to Our Services, and You should consider the privacy practices of those third-parties carefully. If You disagree with the practices described in this Privacy Policy, You should immediately discontinue Your use of Our Services and take the necessary steps to remove cookies from Your computer after leaving Our website.

1. OVERVIEW

The Data we collect depends on how Our Services are used. Sometimes we receive Data directly, such as when a Xendit account is created, test transactions are submitted through Our website, the Xendit invoice form is used, or we receive an email. Other times, we get Data by recording interactions with Our Services by, for example, using technologies like cookies and web beacons. We also get Data from third parties, like Our financial partners or identity verification services.

The collection and use of data from a variety of sources is essential to Our ability to provide Our Services – and to help keep the Services safe. Data is critical in helping Us to increase the safety of Your online payments, and reduce the risk of fraud, money laundering and other harmful activity.

2. DATA WE COLLECT

  1. Personal Data. We call Data that (individually or when read with other data) identifies, or that could reasonably be used to identify, You as an individual “Personal Data”. We collect Personal Data in different ways. For example, we collect Personal Data when a business registers for a Xendit account, a Customer makes payments or conducts transactions through a User’s website or application, a person responds to Xendit emails or surveys, or when a Customer uses the “Remember Me” feature of Xendit Checkout. We also receive Personal Data from other sources, such as Our partners, financial service providers, identity verification services, and publicly available sources. Personal Data does not include Data that has been aggregated or made anonymous such that it can no longer be reasonably associated with a specific person. The Personal Data that we may collect includes:
    • Contact details, such as name, postal address, telephone number, email address;
    • Financial and transaction Data, such as credit or debit card number, and bank account information; and
    • Other Personal Data, such as date of birth, government issued identifiers
  2. Other Data. We call Data other than Personal Data “Other Data”. We collect Other Data through a variety of sources. One of Our sources for Other Data is cookies and other technologies that record Data about the use of Our websites, websites that implement Our Services, and the use of Our Services generally. Other Data that we may collect include:
    • Browser and device data, such as IP address, device type, operating system and Internet browser type, screen resolution, operating system name and version, device manufacturer and model, language, plug-ins, add-ons and the version of the Services You are using;
    • Transaction data, such as purchases, purchase amount, date of purchase, and payment method;
    • Cookie and tracking technology data, such as time spent on the Services, pages visited, language preferences, and other anonymous traffic data; and
    • Company data, such as a company’s legal structure, product and service offerings, jurisdiction, company records, and information submitted through the Xendit Atlas service.

(Personal Data and Other Data shall be collectively referred to as “Data”)

Should You wish to additionally avail of  the services provided by Our Affiliates (as defined below) whether in the same or other jurisdiction, We may collect, request and/or ask from You additional Data for and on behalf of Our respective Affiliate(s) in the said jurisdiction for the conduct of customer due diligence required by applicable laws, regulations,  the contractual commitments of such Affiliate with their respective bank and payment channel partners, and, in accordance with any terms and conditions and privacy policies of said Affiliate(s). Please note that once Your Data is received (collected) by our Affiliate(s), the use and processing of the Your Data shall be for such purposes as may be set out in Your relevant agreement with the Affiliate, or the Affiliate’s privacy policy or equivalent document which has been or will be communicated to You.

3. HOW WE USE DATA

  1. Personal Data. We, Our Affiliates, and/or Our service providers use Personal Data to: (i) provide the Services; (ii) detect and prevent fraud; (iii) mitigate financial loss or other harm to Users, Customers, and Xendit; and (iv) promote, analyze and improve Our products, systems, and tools. Examples of how we may use Personal Data include:
    • To verify an identity for compliance purposes;
    • To evaluate an application to use Our Services;
    • To conduct manual or systematic monitoring for fraud and other harmful activity;
    • To respond to inquiries, send service notices and provide customer support;
    • To process a payment with Xendit Checkout, communicate regarding a payment, and provide related customer service;
    • For audits, regulatory purposes, and compliance with industry standards;
    • To develop new products;
    • To send marketing communications;
    • To improve or modify Our Services; and
    • To conduct analysis and aggregation that enable Us to operate, protect, make informed decisions, and report on the performance of, Our business.
  2. Other Data. We may use Other Data for a range of different purposes, provided we comply with applicable law and Our contractual commitments. Where relevant, local regulations may require Us to treat some or all of Other Data as “Personal Data” under applicable data protection laws. Where this is the case, we will process Other Data only for the same purposes as Personal Data under this Privacy Policy.

(the data processing purposes set out in this Privacy Policy shall be referred to as the “Data Processing Purposes”)

We may, from time to time, appoint a data processor and/or sub-processor to carry out certain parts of the Data collection, processing, and storage in accordance with the Data Processing Purposes.

4. HOW WE DISCLOSE DATA

Xendit does not sell or rent Personal Data to marketers or unaffiliated third parties. We share Your Personal Data with trusted third parties, including, with:

  1. Affiliates. We share Data with entities worldwide that control us, are controlled by us, or are under Our common control (“Affiliates”), to provide Our Services. Xendit, Inc. is the party responsible for overall management and use of the Data by these affiliated parties;
  2. Service Providers. We share Data with service providers who help Us provide the Services (“Service Providers”). Service Providers help Us with matters like payment processing (e.g., banks, credit bureaus, payment method providers), website hosting, data analysis, information technology and related infrastructure, customer service, email delivery, Atlas, and auditing, among others;
  3. Our Users. We share Data with Users (such as merchants and application providers) as necessary to process payments or provide the Services. For example, we share Data with Users about purchases made by their Customers through the Xendit payment processing services;
  4. Authorized Third Parties. We share data with parties directly authorized by a User to receive Data, such as when a User authorizes a third party application provider to access the User’s Xendit account. The use of Data by an authorized third party is subject to the third party’s privacy policy;
  5. Third Parties. We will share Data with third parties (on a need-to-know basis) in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of Our business, assets or stock (including in connection with any bankruptcy or similar proceedings); and
  6. For Safety, Legal Purposes and Law Enforcement purposes. We use and disclose Data as we believe necessary: (i) under applicable law, or payment method rules; (ii) to enforce Our terms and conditions; (iii) to protect Our rights, privacy, safety or property, and/or that of Our affiliates, You or others; and (iv) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside Your country of residence.

Should You wish to additionally avail the services provided by Our Affiliates whether in the same or other jurisdiction, We will share Your Data to such Affiliate(s), and such Affiliate will store and process such documents, information and/or data for the purpose of providing the requested services and in accordance with any terms and conditions and privacy policies of said Affiliate. Please note that once Your Data is received (collected) by our Affiliate(s), the use and processing of the Your Data shall be for such purposes as may be set out in Your relevant agreement with the Affiliate, or the Affiliate’s privacy policy or equivalent document which has been or will be communicated to You.

You hereby acknowledge that some of our Affiliates and/or Service Providers to whom we disclose your Data for the Data Processing Purposes may be deemed as personal data controller under prevailing laws and regulations for the relevant data processing (including but not limited to, our bank partners, payment channel provider, and/or identity verification services). By agreeing to this T&C and continuing the use of the Service, you are deemed to have consented to any terms and conditions and privacy policy of such Affiliates and/or partner with respect to the processing of your Data for such purposes determined by the relevant Affiliates and/or partner.

5. SECURITY

We store all customer data encrypted in the database. Sensitive systems are physically and logically isolated to restrict access to authorized personnel only. We limit access to data based on job function.

We use reasonable organizational, technical and administrative measures to protect Personal Data within Our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If You have reason to believe that Your interaction with Us is no longer secure (for example, if You feel that the security of Your account has been compromised), please stop using Our Services and contact Us immediately.

6. ADVERTISING

We may use third-party advertising companies to serve advertisements regarding goods and services that may be of interest to You when You access Our websites, based on Data relating to Your access to and use of Our websites on any of Your devices, as well as Data received from third parties. To do so, these companies may place or recognize a unique cookie, or similar tracking technology, on Your browser (including the use of pixel tags). They may also use these technologies, along with data they collect about Your online use, to recognize You across the devices You use, such as a mobile phone and a laptop, and to make decisions about the advertisements You see. If You would like more information about this practice, and to learn how to opt out of behavioral advertising delivered by Network Advertising Initiative member companies in desktop and mobile browsers on the particular device on which You are accessing this Privacy Policy, please visit the Network Advertising Initiative and Digital Advertising Alliance. You may download the AppChoices app to opt out in mobile apps. In order to understand and improve the effectiveness of Our advertising, we may also use web beacons, cookies, and other technologies to identify the fact that You have visited Our website or seen one of Our advertisements, and we may provide that Data to one or more third party advertising networks. The Data we provide may include the time and date of Your visit to Our website, pages viewed, links clicked and other information that does not disclose your “real world” identity. Those advertising networks may recognize the web beacon or cookie associated with Your visit to Our website when You visit other websites on which they serve advertising, and they may make decisions about the advertisements You see based on it. We may choose to work with Google AdWords, Doubleclick, AdRoll or other advertising networks. Each of these companies has its own privacy policy, which we encourage You to review. For more information about advertising and tracking online, visit the Network Advertising Initiative. This website allows consumers to “opt out” of the behavioral advertising delivered by member companies. At present, there is no industry standard for recognizing Do Not Track browser signals, so we do not respond to them.

7. CHOICE AND ACCESS

You have choices regarding Our use and disclosure of Your Personal Data:
  1. Opting out of receiving electronic communications from Us. If You no longer want to receive marketing-related emails from Us on a going-forward basis, You may opt-out via the unsubscribe link included in such emails. We will try to comply with Your request(s) as soon as reasonably practicable. Please note that if You opt-out of receiving marketing-related emails from us, we may still send You important administrative messages that are required to provide You with Our Services.
  2. How You can access or change Your Personal Data. If You would like to review, correct, update or delete Personal Data that You have previously disclosed to us, You may do so by signing in to Your Xendit account or by contacting Us. Please take note that in the event that You request for Us to delete any Personal Data that You have previously disclosed to us, this may affect Our ability to provide any or all of the Services to You.
In emailing Us Your request, please make clear in the email what Personal Data You would like to have changed. For Your protection, we may only implement requests with respect to the Personal Data associated with the particular email address that You use to send Us Your request, and we may need to verify Your identity before implementing Your request. We will try to comply with Your request as soon as reasonably practicable.

8. RETENTION PERIOD

We will retain Personal Data for the period necessary to fulfill the Data Processing Purposes unless a longer retention period is required or permitted by law (a period of 5 (five) years under prevailing laws), or upon You sending a written request to Us for the deletion and disposal of Your Data.We may dispose Data by way of deletion, erasure, sanitization and overwriting (subject to the limitations in Our system) followed by a notification of Our completion of satisfying your request.  Your written request shall be acknowledgement that You will not hold Us liable or responsible for Our non-ability / non-performance to provide You future Service requests. In any event, we warrant that any Data we dispose of shall be put beyond use for any purpose whatsoever.

Please note that we have a variety of obligations to retain the Data that You provide to us, including to ensure that transactions can be appropriately processed, settled, refunded or charged-back, to help identify fraud and to comply with anti-money laundering and other laws and rules that apply to Us and to Our financial service providers. Accordingly, even if You close Your Xendit Account, we will retain certain Data to meet Our obligations. There may also be residual Data that may remain within Our databases and other records, which will not be removed to the extent the prevailing laws and regulations permits.

9. USE OF SERVICES BY MINORS

The Services are not directed to individuals under the age of thirteen (13), and we request that they not provide Personal Data through the Services.

10. JURISDICTION AND CROSS-BORDER TRANSFER

Our services are global and Data (including Personal Data) may be stored and processed in any country where we have operations or where we engage service providers, and we may transfer Data to countries outside of Your country of residence, including the United States, Philippines and Indonesia, which may have data protection rules that are different from those of Your country. However, we will take measures to ensure that any such transfers comply with applicable data protection laws and that Your Data remains protected to the standards described in this Privacy Policy. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries may be entitled to access your Personal Data.

11. XENDIT AS A DATA PROCESSOR

We may collect, use and disclose certain Personal Data about Customers when acting as the User’s service provider. Our Users are responsible for making sure that the Customer’s privacy rights are respected, including ensuring appropriate disclosures about Our and third party data collection and use. To the extent that we are acting as a User’s data processor, we will process Personal Data in accordance with the applicable law and/or the terms of Our agreement with the User and the User’s lawful instructions.

12. UPDATES TO THIS PRIVACY POLICY AND NOTIFICATIONS

We may change this Privacy Policy. The “Last updated” legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes are effective when we post the revised Privacy Policy on the Xendit website. It is your responsibility to periodically review this Privacy Policy; You are bound by any changes to this Privacy Policy by continuing to use the Service after such changes have been first posted.

We may provide You with disclosures and alerts regarding the Privacy Policy or Personal Data We collected by posting them on Our website or, if you are a User, by contacting You through your Xendit Dashboard, email address and/or the physical address listed in Your Xendit account, at Our discretion. You agree that electronic disclosures and notices have the same meaning and effect as if we had provided You with hard copy disclosures. Disclosures and notices in relation to this Privacy Policy or Personal Data shall be considered to be received by You within 24 hours of the time they are posted to Our website or, in the case of Users, sent to through one of means listed in this paragraph.

In the unlikely event of a security incident or personal data breach, We shall manage the incident or the breach in accordance with our internal policies consistent with the applicable data protection laws and regulations, and which may include, among others, sending of timely notifications to You and/or the relevant data protection authority.

13. CONSENT AND ACKNOWLEDGMENT

By accepting the Privacy Policy, You acknowledge that You have read and understood this Privacy Policy and you accept all of its terms. In particular, You agree and consent to Us collecting, using, sharing, disclosing, storing, transferring, or otherwise processing Your Personal Data in accordance with this Privacy Policy. In circumstances where You provide Us with Personal Data relating to other individuals (such as Personal Data relating to Your spouse, family members, friends, or other parties), You represent and warrant that You have obtained such individual’s consent for, and hereby consent on behalf of such individual to, the collection, storage, use, disclosure, processing and disposal of his/her Personal Data by Us.

HOW TO CONTACT US

If you have questions or concerns regarding this privacy policy, or any feedback pertaining to your privacy and the Xendit service that you would like us to consider, please email us at help@xendit.co.