Synctappy by Synvora Teknologi Indonesia
Privacy Policy
- Effective Date:
- To be announced at launch
- Last Updated:
- October 1, 2026
This document is a draft pending legal review. Contact details, address, third parties and retention periods will be finalized before launch. In case of any difference, the Indonesian version prevails.
Welcome to Synctappy, a physical-to-digital engagement platform developed and operated by Synvora Teknologi Indonesia.
This Privacy Policy explains how we collect, use, store, protect, disclose and manage Personal Data when you use the Synctappy website, applications, dashboard, NFC/QR devices, services and features.
We are committed to keeping Personal Data secure and confidential and to processing it responsibly, transparently and in accordance with applicable law, including Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”).
By using Synctappy, you confirm that you have read and understood this Privacy Policy.
1. About Synctappy
Synctappy is a platform that lets businesses and organizations create and manage physical-to-digital touchpoints using QR codes and NFC technology. Synctappy services may include:
- QR codes and NFC;
- Google Review destinations;
- multi-link profiles;
- website and social media links;
- digital menus, WhatsApp and booking;
- campaigns and promotions;
- analytics and a business dashboard;
- device management and design templates;
- subscriptions, billing, proposals and quotations;
- and other services made available from time to time.
Synctappy may connect users to third-party services. Activity that happens after a user leaves Synctappy may be subject to those third parties’ privacy policies.
2. Responsible Party
For Personal Data processed by Synctappy to provide and operate the platform, Synvora Teknologi Indonesia acts as the party that determines the purposes and means of processing, in the role applicable under the law.
- Name
- Synvora Teknologi Indonesia
- Product
- Synctappy
- Privacy email
- privacy@synctappy.biz.id
- Support email
- support@synctappy.biz.id
- Address
- To be published before launch
Where Synctappy processes Personal Data on behalf of a business customer and on its instructions, the parties’ relationship and responsibilities may be set out further in an agreement or the applicable terms of service. The PDP Law distinguishes between a Personal Data Controller and a Personal Data Processor based on who determines the purposes and control of processing.
3. Data We Collect
We collect Personal Data in a limited, specific, lawful and transparent way that fits the purpose of processing, in line with the PDP Law.
3.1 Account Data
When you create a Synctappy account, we may collect:
- name;
- email address;
- phone number;
- password, stored securely (hashed);
- company or organization name;
- job title or role;
- other account information you provide.
4. Business Profile Data
If you use Synctappy as a business user, you may provide:
- business name, address, phone number and email;
- website, logo, photos and business description;
- opening hours;
- social media, Google Maps, WhatsApp, booking and marketplace links;
- a digital menu and information about products or services;
- location or branch information;
- campaign content;
- and other information you choose to display through your Synctappy profile.
This data may be public if you choose to publish it through a Synctappy page.
5. NFC and QR Device Data
Each Synctappy device may have unique identifiers such as a Device ID, QR Code ID, NFC Tag ID, workspace ID, device location, destination URL, linked campaign, device status, activation date and configuration change dates.
We use this data to:
- activate devices and link them to an account;
- manage destinations;
- provide analytics;
- detect misuse;
- provide technical support;
- and keep the platform secure.
6. User Interaction Data
When someone scans a QR code or taps an NFC tag that leads to Synctappy, the system may record certain technical and interaction information, for example:
- access time and date;
- the device/touchpoint used;
- interaction type (QR or NFC);
- the page or destination opened;
- the related campaign;
- browser, operating system and device type;
- network information needed for security;
- approximate location, where that feature is used and permitted;
- and other technical data needed to provide and secure the service.
We aim not to collect Personal Data that is not needed for the service.
7. Analytics
Synctappy provides analytics to business customers, which may show the number of taps, scans, visits and clicks; the most visited destinations; the devices with the most interactions; interaction times; campaign and location performance; and other usage statistics. Analytics help customers understand how their physical-to-digital touchpoints perform.
8. Transaction and Payment Data
When you purchase a subscription, hardware, add-ons or other Synctappy services, we may process the customer name, company name, billing address, email, phone number, selected plan, subscription period, invoices, transaction ID, payment status and, where required, tax information.
For payment card details or other sensitive payment data, Synctappy may use a third-party payment gateway. We do not intend to store full payment card details where they can be processed directly by the payment gateway.
9. Communication Data
If you contact us by email, support ticket, live chat, WhatsApp, contact form or another channel, we may keep that communication to provide support, resolve issues, process requests, improve the service, maintain security and keep a service history.
11. Purposes of Processing
We may process Personal Data to:
- create and manage accounts;
- provide the Synctappy service;
- activate QR and NFC;
- manage devices;
- provide dynamic links;
- provide multi-link profiles;
- provide analytics;
- provide campaigns;
- process subscriptions;
- process payments;
- send service notifications;
- provide customer support;
- prevent misuse;
- keep our systems secure;
- troubleshoot;
- improve the product;
- analyze usage in aggregate;
- meet legal obligations;
- resolve disputes;
- and other purposes we have told you about.
Processing of Personal Data must have an appropriate legal basis. The PDP Law lists, among others, consent, performance of a contract, legal obligation, vital interests, public interest and legitimate interests as bases for processing.
12. Legal Bases
Depending on the context, Synctappy may process Personal Data on the basis of:
Consent
Where processing requires the user’s consent.
Performance of a contract
For example, to provide a subscription or service you have purchased.
Legal obligation
Where required by laws and regulations.
Legitimate interests
For specific purposes such as security, fraud prevention and service improvement, as long as this complies with applicable rules and does not override users’ rights.
13. Use of Data for Marketing
We may send product information, service updates, new features, subscription information, promotions, campaigns and other marketing communications. Where marketing requires consent, you can choose not to receive it.
Communications that are essential to operating the service, such as password changes, account security, payments, invoices, service changes or security notices, may still be sent because they relate to the service you use.
14. Sharing Data with Third Parties
Synctappy may use third-party service providers to support its operations, such as cloud hosting, databases, object storage, payment gateways, email delivery, analytics, monitoring, customer support, security and other infrastructure services.
These third parties may only receive data to the extent needed to provide the relevant service and in line with the applicable relationship and terms.
15. Third-Party Services
Synctappy may direct users to third-party services such as Google, Google Maps, Instagram, WhatsApp, TikTok, Facebook, marketplaces, booking platforms and others. When you leave Synctappy and use those services, your data may be processed by those third parties. We recommend reading each service’s privacy policy.
Synctappy is not responsible for the privacy practices of third parties outside our control.
16. Google Review
Synctappy may provide a feature that makes it easier to open a business’s Google review page. Synctappy:
- does not guarantee that a review will be published;
- does not determine users’ ratings;
- does not change the content of users’ reviews;
- does not ask users to give a particular rating;
- and does not treat a click as a successfully published review.
Users are free to write reviews that reflect their own experience, subject to Google’s policies.
17. Data Security
We apply reasonable technical and organizational measures to protect Personal Data, which may include encryption in transit (HTTPS/TLS), password hashing, authentication, role-based access control, access limitation, audit logging, rate limiting, backups, monitoring, vulnerability management and incident response procedures.
The PDP Law requires Personal Data Controllers to protect Personal Data against unauthorized access, disclosure, alteration, misuse, destruction or loss. However, no electronic system can guarantee absolute security.
18. Data Retention
We keep Personal Data for as long as needed to provide the service, fulfil the purposes of processing, meet contractual and legal obligations, resolve disputes, maintain security or for other legitimate purposes.
When data is no longer needed, we may delete, destroy or anonymize it, or take other action in line with the law and our internal retention policy. The PDP Law requires Personal Data to be deleted or destroyed when the retention period ends or at the data subject’s request, unless other rules apply.
19. Your Rights
Subject to applicable law (including Articles 5–15 of the PDP Law), you may have the right to:
- obtain information about the processing of your Personal Data;
- access and obtain a copy of your Personal Data;
- correct and update your Personal Data;
- request deletion or destruction of your Personal Data;
- withdraw consent;
- request restriction of processing;
- object to certain processing;
- and exercise other rights granted by laws and regulations.
20. How to Submit a Request
To submit a request about your Personal Data, contact privacy@synctappy.biz.id with the email subject:
Personal Data Request – Synctappy
Requests may cover data access, correction, deletion, withdrawal of consent, restriction of processing, or questions about how your Personal Data is processed. We may ask for additional information to verify the requester’s identity before fulfilling a request, so that Personal Data is not disclosed to unauthorized parties.
21. Account Deletion
You may request deletion of your account through the official channels available. Once the request is verified, we will process it in line with the law, operational needs and applicable retention obligations.
Some information may be retained where required by law or needed for security, fraud prevention, dispute resolution, transaction records or compliance with legal obligations.
22. Business Customers’ Data
If you use Synctappy to collect or process Personal Data of your own customers (for example names, phone numbers, emails, bookings or feedback), you are responsible for ensuring that this use has an appropriate legal basis. In that case your business may be responsible as the party determining the purpose of that processing.
In certain situations, Synctappy may act as a Personal Data Processor on the business customer’s instructions.
23. Children’s Data
Synctappy is not intended to knowingly collect children’s Personal Data without a lawful basis and appropriate mechanism. If we learn that children’s Personal Data has been collected inappropriately, we may take steps to delete it or restrict its processing in line with applicable rules.
24. Data Transfers
To provide the service, Personal Data may be processed by infrastructure or service providers located outside Indonesia. Where cross-border transfer or processing occurs, Synctappy will take the necessary steps to ensure it is carried out in accordance with applicable law.
25. Incidents and Data Breaches
We have procedures for handling security incidents. If a Personal Data protection failure occurs that meets the notification criteria under applicable law, we will notify the parties required by regulation, including information about the data disclosed, when and how the incident happened, and the handling and recovery steps taken.
26. Changes to This Privacy Policy
We may update this Privacy Policy from time to time due to changes in features, technology, services, third parties, data processing practices or laws and regulations.
If a change is material, we may notify you through the website, dashboard, email or another appropriate method. The “Last Updated” date shows the latest version.
27. Relationship with the Terms of Service
This Privacy Policy forms part of the terms of use of Synctappy. Use of Synctappy is also subject to the Terms of Service, Acceptable Use Policy, Subscription Terms, Refund Policy, Cookie Policy, Hardware Warranty and other applicable terms.
28. Governing Law
This Privacy Policy is governed by the laws of the Republic of Indonesia. Any dispute will be resolved according to the mechanism set out in the Terms of Service and applicable law.
29. Contact Us
If you have questions about this Privacy Policy or the processing of your Personal Data, please contact:
- Company
- Synvora Teknologi Indonesia
- Product
- Synctappy
- Privacy
- privacy@synctappy.biz.id
- Support
- support@synctappy.biz.id
- Address
- To be published before launch