Official document
Privacy Policy
How Rampoeng collects, uses, and protects your personal data — aligned with Indonesia's Personal Data Protection Law.
Translation for convenience
This English text is provided to help you understand the document. The binding version is the Indonesian one: Rampoeng is operated by an Indonesian company for users in Indonesia, and Indonesian law requires agreements with Indonesian parties to be made in Indonesian. Where the two versions differ, the Indonesian version prevails. Baca versi Indonesia →
Last updated: 1 August 2026
1. Introduction and Data Controller
1.1 This Privacy Policy (the “Policy”) explains how PT Titian Rampoeng Nusantara (“We”, “Rampoeng”), a limited liability company established under the laws of the Republic of Indonesia and domiciled in Kabupaten Tangerang, Banten, collects, uses, stores, shares, and protects your personal data (“User”, “you”) in connection with your use of the Rampoeng application and services (Pekerjaan Ringan dan Dinamis Online) (the “Platform”).
1.2 In processing personal data under this Policy, We act as the Personal Data Controller as defined in Law Number 27 of 2022 on Personal Data Protection (the “PDP Law”).
1.3 This Policy forms an inseparable part of the Terms & Conditions (the “T&C”). Capitalised terms not defined here have the meanings given to them in the T&C. By creating an account and/or using the Platform, you confirm that you have read and understood this Policy.
2. Personal Data We Collect
We collect the following categories of personal data, depending on the features you use:
a. Identity and verification (KYC) data. Full name, phone number, email address, profile photo, and gender (optional). For higher-level verification: your national identity number (NIK) and the data on your national identity card (KTP), and — where the feature is enabled — a selfie photo and the results of face-matching/liveness checks. Biometric data, where processed, is specific personal data and is treated with heightened protection (see Section 4).
b. Account and credential data. The sign-in methods you have linked (phone number, Google, Apple, or email) and session tokens. We do not store the passwords of your third-party accounts.
c. Job and transaction data. Details of Jobs you post or take on, the history of offers and negotiations, completion status, ratings and reviews, dispute history, and data relating to your Wallet/Balance, escrow, top-ups, withdrawals, and the bank account used for payouts.
d. Location data. For Jobs at a physical location (particularly daily-rate Jobs), We collect GPS coordinates only at the moment of check-in and check-out, in order to verify attendance. Location data is not collected continuously.
e. User Content and communications. The contents of chats, photos and attachments you send, evidence submitted in a dispute, and reports you make.
f. Device and technical data. IP address, device type and identifier, operating system, notification tokens, activity logs, and signals used to detect fraud or abuse and for Continuous Monitoring (including indications of duplicate accounts and unusual activity patterns).
g. Referral programme and tax data. Referral codes and links, the link between a Referrer and a Referred User, and your NIK and/or tax number (NPWP) at the point of withdrawing Referral Commission, in order to meet tax obligations.
h. Data from third parties. Verification results from e-KYC providers, anti-fraud service providers, and transaction status confirmations from Our Payment Partner.
3. Purposes and Legal Bases for Processing
We process your personal data for the following purposes, on the bases permitted under the PDP Law:
- Creating and managing accounts, authentication, and identity verification (KYC) — performance of a contract; compliance with a legal obligation.
- Matching Posters with Workers, and enabling Jobs, chat, escrow, the Wallet, and payouts — performance of a contract.
- Verifying physical attendance through GPS check-in/check-out — the Worker's consent.
- Selfie/liveness photos for face matching, where enabled — valid and explicit consent (specific data).
- Content moderation, fraud detection, Continuous Monitoring, and Platform security — legitimate interests; compliance with a legal obligation.
- Withholding and reporting tax on Referral Commission — compliance with a legal obligation.
- Developing and training artificial-intelligence recommendation features, using aggregated and/or anonymised data — legitimate interests.
- Service notifications, customer support, and dispute resolution — performance of a contract; legitimate interests.
- Cooperation with law enforcement on lawful request — compliance with a legal obligation.
- Sending promotional or marketing information, where applicable — consent, which may be withdrawn at any time.
4. Specific Personal Data
Biometric data (facial photographs and liveness results) and children's data are classed as specific personal data. We process them only on the basis of valid consent and/or another basis permitted by the PDP Law, with additional safeguards, limited retention, and restricted access. We do not sell your personal data.
5. Sharing and Disclosure
We do not share your personal data other than with:
a. Other Users on the Platform — only as far as a particular Job requires (for example name, profile photo, rating, and Job information). Sensitive data such as your NIK or KTP is not shown to other Users.
b. Our Payment Partner (Doku or its successor) — for escrow, the Wallet, top-ups, payouts, and account validation; subject to the privacy policy of that Payment Partner, which is licensed by Bank Indonesia.
c. Service providers (Data Processors) acting on Our behalf — including cloud infrastructure and database providers, authentication and notification services, e-KYC providers, anti-fraud providers, and email service providers. These parties are bound by confidentiality obligations and process data only on Our instructions.
d. Law enforcement, courts, or competent authorities — where required by law or on a lawful request, for the purposes of investigation, crime prevention, or law enforcement, while still applying the principle of data minimisation.
e. In the course of a corporate transaction — for example a merger or acquisition, still subject to this Policy.
6. Transfers Outside Indonesia
Some of Our service providers may process or store data on servers outside Indonesia. Where a cross-border transfer takes place, We ensure an equivalent level of protection as required by the PDP Law, including through contractual requirements imposed on those providers.
7. Storage and Retention
We retain personal data for as long as your account is active and for as long as it is needed for the purposes in Section 3, or for as long as the law requires (for example transaction and tax records). Once it is no longer needed, or upon a valid deletion request, data is deleted or anonymised. To preserve the integrity of transaction history, ratings, escrow, and legal obligations, some records may be retained in anonymised form.
8. Data Security
We apply reasonable technical and organisational measures to protect personal data, including transport encryption (HTTPS), storing credentials in secure device storage, role-based access control, and security monitoring. No system is entirely free of risk; you also bear responsibility for keeping your account credentials confidential. In the event of a personal data breach, We will notify you and the authorities in accordance with the PDP Law.
9. Your Rights as a Data Subject
Under the PDP Law, you have the right to: (a) access and obtain a copy of your personal data; (b) correct or update your data; (c) end the processing of, delete, and/or destroy your personal data; (d) withdraw consent; (e) object to decisions made solely by automated means that produce legal effects; (f) suspend or restrict processing; (g) obtain and/or transfer your personal data (portability); and (h) lodge an objection.
You can exercise these rights through features in the Platform (for example privacy settings or account deletion) or by contacting support@rampoeng.com. Exercising some rights may affect the availability of the service (for example, deleting your KYC data may render the account unusable) and is subject to identity verification and to the exceptions permitted by law.
10. Age Limit
The Platform is intended for users aged 18 and above. We do not knowingly collect children's data. Where We become aware of it, such data will be deleted.
11. Cookies and Similar Technologies (Website)
The rampoeng.com website may use cookies and similar technologies that are essential to basic functionality. We favour the most privacy-preserving option and do not use cross-site tracking for advertising without consent.
12. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified through the Platform and/or your registered channels, and take effect on the date specified.
13. Contact Us
For questions, data subject requests, or complaints regarding personal data protection:
- Personal Data Controller: PT Titian Rampoeng Nusantara
- Domicile: Kabupaten Tangerang, Banten
- Email: support@rampoeng.com
Requests relating to personal data protection may be sent to the email address above. You also have the right to lodge a complaint with the competent personal data protection authority under applicable regulations.
— PT TITIAN RAMPOENG NUSANTARA · RAMPOENG.COM —
