Privacy Policy

Last updated: May 04, 2023

Effective date: May 05, 2023


We care about your privacy and are committed to protecting your personal data. This privacy statement will tell you how we handle your personal data, your privacy rights and how the law protects you. Please read this privacy statement carefully before using our Services.

In this privacy statement:

Service means every product, service, content, feature, technology or function, and all related websites, applications and services offered to you by us.

Platform means our website, mobile application, mobile site or other online things through which we offer our Services.

Who are we?
The main controller of your data for our international service purposes is TokoJS, a company located in Indonesia. TokoJS is a holding company of the TokoJS group entity that provides services to you in accordance with our Terms & Conditions , (hereinafter referred to as " TokoJS ", " we ", " us " or " ours " in this privacy statement). These TokoJS group entities are also considered data controllers for the local services they offer.



What data do we collect about you?
2.1.1 Data is provided through direct interaction

Registration and other account information

When you register to use our services, we may collect the following information about you:

if you register using your Google account: first name, last name and email address;
if you register using your Facebook account: we collect your first and last name as they appear on your Facebook account and Facebook ID. If you have given permission to Facebook through the privacy options in their application (which appear just before you register on our Platform), we may collect your gender, age or email depending on the permission granted by you; and
if you register using your mobile number: mobile number.
Depending on the choices you make during the login to our Services or during the process involving our Services, you can choose to provide the following additional personal data:

Your name;
Email address;
Phone number;
Your credit card details if you want to buy our paid service as defined in our Terms & Conditions .
Communication via chat features on our Platform

When you use our chat feature to communicate with other users, we collect information that you choose to give to other users through this feature.

2.1.2 Data that we collect automatically when you use our services

When you interact with our Platform or use our Services, we automatically collect the following information about you:

Device Information

We collect device-specific information such as operating system versions, unique IDs. For example, the name of the cellular network you are using. We associate device identifiers with your TokoJS account.
Location information

Depending on your device's permission, if you post a thing / item on our Platform, we automatically collect and process information about your actual location. We use various technologies to determine location, including IP address, GPS, Wi-Fi access points, and cell towers. Your location data allows you to see user items near you and helps you post things / items in your location. If we need your location data, we will first display a pop-up that will ask you to choose whether or not to allow us to access your location data. If you do not allow us to have access to your location data, you can still use our services but with limited functionality. If you allow us to access your location data, you can always change it afterwards by opening the settings on our website or our platform application and deactivating permissions related to location sharing.

Client and Log data

Technical details, including your device's Internet Protocol (IP) address, time zone and operating system. We will also save your login information (date of registration, date of the last password change, date of the last successful login), type and version of your browser .
Clickstream data

We collect information about your activities on our Platform which includes sites from which you access our Platform, date and time stamp of each visit, searches that you have done, listings or advertisements that you click, your interactions with such advertisements or listings , duration of visits You and the order in which you visited content on our Platform.
Cookies and Similar Technologies

We use cookies to manage our user sessions, to save your preferred language preferences and send you relevant advertisements. " Cookies"is a small text file that is transferred by a web server to your device's hard drive. Cookies can be used to collect the date and time of your visit, your search history, your preferences, and your username. You can set your browser to reject all or some cookies , or to alert you when a website sets or accesses cookies.If you disable or reject cookies, please note that some parts of our Service / Platform may become inaccessible or malfunctioning.For more information about the cookies we use , please see our Policy on Cookies and Similar Technologies .
2.1.3 Data from third parties or data available from public sources.

We receive personal data about you from various third parties and public sources as stated below:

Specific technical and usage information from analytics providers such as Google, Facebook and Optimizely;
Cookes information from advertising networks such as Criteo and Props.


Do we collect data from children?
Our services are not intended for children under 18 years of age and we do not knowingly collect data from anyone under the age of 18. If we find out that people under the age of 18 have given us their personal data, we will delete it immediately.



Why do we process your personal information?
We will only use your personal data when the law allows us. Generally, we will use your personal data in the following situations:

Where we need to enter into contracts that we will enter or have followed with you.
Where necessary for our legitimate interests to improve our Services and to provide you with a safe and secure platform.
Where we must comply with legal or regulatory obligations.
In certain circumstances, we may also process your personal data based on your agreement. If we do this, we will notify you the purpose and category of personal data that will be processed when we ask for your approval.

We have explained below a description of how we use your personal data, [and from which legal basis we use it to do so. We have also identified what our legitimate interests are in the right place].

4.1 To provide access and provide services through our platform

If you log in using your mobile number or your email ID, we use your first and last name, mobile number and / or e-mail address to identify you as a user and provide access to our Platform.
If you log in using your Facebook account, we use your first and last name from your Facebook profile and Facebook email address to identify you as a user on our Platform and give you access to our Platform.
The log information above is also used by us to send our services to you in accordance with our Terms & Conditions .
We use your e-mail address and your mobile number (via SMS) to make suggestions and recommendations to you about our services that may be of interest to you.
We process the information above for the good performance of our agreement with you and on the basis of our legitimate interests in conducting marketing activities to offer services that may be of interest to you.

4.2 To improve your experience on the Platform

i. We use clickstream data to:

offering customized content, such as giving you more relevant search results when using our Services.
to determine how much time you spend on our Platform and in what way you navigate through our Platform to understand your interests and to improve our Services based on this data. For example, we can give you suggestions about content that you can visit based on the content that you click on.
to monitor and report on the effectiveness of campaign deliveries to our business partners and for internal business analysis.
ii. We use your location data for the following purposes:

to collect anonymous and aggregate information about the characteristics and behavior of TokoJS users, including for the purposes of business analysis, segmentation and anonymous profile development.
to improve the performance of our services and to personalize the content that we point to you. For example - with the help of location data we display a list of advertisements that are around you to improve your purchasing experience. For this purpose, the Google Maps service is integrated into our Platform. Google Maps is provided by us and Google acts as an independent controller. This means Google and we are responsible for processing your location data in the context of Google Maps. However, we will not process your location data for purposes other than those described in this Privacy Statement. However, Google may process these location data for their own purposes as described in the Google Privacy Policy which can be reviewed here.
to measure and monitor your interactions with third party banner advertisements that we place on our Platform
iii. With the help of your login information which includes your email id and telephone number, we map the different devices (such as desktops, mobile phones, tablets) used by you to access our Platform. This allows us to associate your activities on our Platform across devices and help us provide a good experience no matter what device you use.

We process the information above based on our legitimate interests to improve your experience on our Platform and for adequate performance of our contracts with you.

4.3 To provide you with a safe and secure platform

We use your mobile number, log data and unique device identifiers to manage and protect our platform (including troubleshooting, data analysis, testing, fraud prevention, system maintenance, support, reporting and data hosting).
We analyze your communication made through our chat feature for fraud prevention and to improve security by blocking spam or abusive and bad messages that may have been sent to you by other users.
We process the information above for adequate performance of our contracts with you, to improve our services and on the basis of our legitimate interests to prevent fraud.



How will we notify you of changes in our privacy statement?
We may change this privacy statement from time to time. We will post changes on this page and will notify you by e-mail or through our Platform. If you don't agree with the changes, you can close your account by going to account settings and selecting delete account.



Your rights
In certain circumstances, you have rights under data protection laws relating to your personal data.

If you wish to exercise any of the rights set forth below, please open your account / privacy settings or contact us using the Contact Form / privacy email id: jasaappandroid@gmail.com

The right to request access to your personal data (commonly known as "subject data access requests"). This allows you to receive a copy of the personal data we hold about you and to check that we are legally processing it.

The right to request corrections for any data we have about you . This allows you to have incomplete or inaccurate data that we have about you to correct, although we may need to verify the accuracy of the new data that you provide to us.

The right to request restrictions on the processing of your personal data . This allows you to ask us to suspend processing of your personal data in the following scenarios: (a) if you want us to establish the accuracy of the data; (b) if the use of our data is not valid; (c) where you need us to store data even if we no longer need it when you need it to establish, execute or defend legal claims; or (d) you object to our use of your data, but we need to verify whether we have ruled out a valid reason for using it.

The right to request the deletion of your personal data. This allows you to ask us to delete or delete personal data for which there is no compelling reason for us to continue processing it. You also have the right to ask us to delete or move your personal data where you have successfully exercised your right to refuse processing (see below), where we may have processed your information illegally or where we were asked to delete your personal data to comply with local law. Please note that for certain purposes we may be legally obliged to retain your data. Please see section 10.

The right to refuse processing of your personal data on which we rely on legitimate interests (or from third parties) and there is something about your particular situation that makes you want to refuse processing on this basis because you feel it impacts on your basic rights and freedoms. You also have the right to refuse where we process your personal data for direct marketing purposes. In some cases, we can show that we have enforced legitimate reasons for processing your information that overrides your rights and freedoms.

The right to request the transfer of your personal data to you or to third parties. We will give you, or the third party you choose, your personal data in a structured format, generally used, machine readable. Note that this right only applies to automatic information that you originally gave our consent to use or where we used the information to contract with you.

The right to withdraw your consent to process your personal data at any time. This does not affect the legality of any processing that we have done based on prior approval.

No fees are usually required : You do not need to pay fees to access your personal data (or use other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repeated or excessive. Or, we may refuse to comply with your request in this situation.

Deadline to respond : We try to respond to all legitimate requests within one month. Sometimes it takes us more than a month if your request is very complicated or you have made several requests. In this case, we will notify you and inform you of this development.

In addition, you have the right to submit a complaint at any time to the data protection authority that is responsible for you as described in article 13.

However, before you file a complaint with the data protection authority, we will appreciate the opportunity to address your concerns in the first instance, please contact our Privacy Office at Menara Sentraya, 19th Floor, Jl. Iskandarsyah Raya No. 1A Melawai, South Jakarta 12160.



Communication and marketing
We will communicate with you via email, SMS or application notification in connection with our Service / Platform to confirm your registration, to notify you if your advertisement list has become live / expired and for other transactional messages in connection with our Services. Because it is very important for us to give you transactional messages like that, you might not be able to opt out of those messages.

However, you can ask us to stop sending you marketing communications at any time by clicking the opt-out link in the email or SMS sent to you or by changing the communication settings in your account. If there are problems with changing these settings, contact us through the Connection Form .

You can receive marketing communications from us if you:

has requested such information from us;
use our Platform or Service;
give us details of your data when you enter the competition; or
registered for promotion.


Who do we share your data with?
We may have to share your personal data with the parties specified below for the purposes set out in section 4 above.

Company affiliation - we can share your data with other TokoJS group companies located within and outside the EEA and assist us in providing business operations services such as product improvement, customer support, and fraud detection mechanisms. Any sharing of personal data in an TokoJS group of companies located outside the European Economic Area (" EEA ") will always be the subject of protection as described in section 9 or in the data transfer agreement that clearly defines the obligations of the parties and ensures appropriate technical and steps organizational steps to protect your data.

Third Party Service Providers : We use third party service providers to help us provide certain aspects of our services, for example, cloud storage facilities such as Amazon Web Services and Microsoft Azure. Service providers can be placed inside or outside the " EEA ".

We conduct checks on our third party service providers and require them to respect the security of your personal data and treat it according to law. We do not allow them to use your personal data for their own purposes and only allow them to process your personal data for certain purposes and in accordance with our instructions.

Advertising and analytics providers : To improve our services, we will sometimes share your information with analytic providers who can help us analyze how someone uses our Platform / Services. For the most part, we provide your information to them in an indefinable form to monitor and report on the effectiveness of sending campaigns to our business partners and for internal business analysis. This information will usually include the cookie ID, IP address (short), referral URL and browser and device information. We partner with advertising providers regulated under the Interactive Advertising Bureau (IAB) and registered here: https://advertisingconsent.eu/vendor-list/. To control and manage the settings for advertising, you can access the settings through the link in the footer of our website. For more information about our advertisers and analytics providers, please see our Policy on Cookies and Similar Technologies .

Law enforcement officials, regulators, and others : We may disclose your personal data to law enforcement, regulators, government, or public bodies and other relevant third parties to comply with any legal or regulatory requirements.

We can choose to sell, transfer or merge parts of our business or our assets. As an alternative, we might try to get other businesses or join them. If changes occur to our business, then the new owner can use your personal data in the same way as stated in this privacy statement.

Publicly available information : When you post an item for sale using our service, you can choose to make certain personal information visible to other TokoJS users. This might include your first name, last name, your e-mail address, your location and your contact number. Please note, any information that you provide to other users can always be shared with them with others, so please be wise in this matter.



International Transfers
Every time we transfer your personal data from EEA, we ensure the same level of protection is given to him by ensuring that at least one of the following safeguards is applied:

We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission . For further information, see European Commission: Adequacy of the protection of personal data in non-EU countries.
Where we use certain service providers, we may use certain contracts approved by the European Commission that provide personal data protection similar to those in Europe. For further information, see European Commission: Adequacy of the protection of personal data in non-EU countries.
Where we use service providers based in the United States, we can transfer data to them if they are part of the Privacy Shield which requires them to provide the same protection to personal data shared between Europe and the United States. For further information, see European Commission: Adequacy of the protection of personal data in non-EU countries.
You can receive a copy of the relevant and applied protection by contacting us through   the Connection Form . .



Where do we store your data and for how long?
The data we collect about you will be stored and processed inside and outside the EEA on a secure server to provide the best user experience possible. For example - to build websites or mobile applications quickly.

We will only retain your personal data for as long as necessary to fulfill the purposes we collect, including for the purpose of meeting any legal, accounting or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purpose for which we process your personal data and whether we can achieve these goals through other means, and applicable legal requirements.

If there is no activity on your account for a period of longer than 24 months, we will delete your account including all personal data stored in your account which means that you will no longer be able to access and use it.

If you have questions regarding your data retention period, please contact us at jasaappandroid@gmail.com



Technical and organizational actions & security processing
All information we receive about you is stored on a secure server and we have implemented appropriate technical and organizational steps to protect your personal data. TokoJS continues to evaluate its network security and the adequacy of its internal information security program designed to (a) help secure your data from accidental or unlawful loss, access or disclosure, (b) identify reasonably predictable risks to TokoJS network security, and (c) minimize security risks, including through risk assessment and routine testing. In addition, we ensure that all payment data is encrypted using SSL technology.

Please note, even though we have taken the steps we have taken to protect your data, data transfer via the Internet or other open networks is never completely secure and there is a risk that your personal data can be accessed by unauthorized third parties.



Links to third party websites
Our platform may contain links to third-party websites or applications. If you click on one of these links, please note that each will have its own privacy policy. We do not control this website / application and are not responsible for these policies. When you leave our Platform, we encourage you to read the privacy notices of every website you visit.