Last Updated: January 1, 2025
Effective Date: January 1, 2025
Version: 2.1

1. Introduction

Welcome to Loprutis.com ("we," "our," or "us"). This Privacy Policy explains how Loprutis collects, uses, discloses, and safeguards your information when you visit our website loprutis.com, use our mobile application, or interact with our services.

We are committed to protecting your privacy and ensuring the security of your personal information. This policy applies to all users of our services, including customers, website visitors, newsletter subscribers, and social media followers.

Quick Summary: We collect information to provide better plant care services, process orders, and improve your shopping experience. We never sell your personal data to third parties, and you have full control over your information.

By using our services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.

2. Information We Collect

We may collect information about you in various ways when you interact with our services:

2.1 Personal Information

  • Account Information: Name, email address, phone number, date of birth
  • Contact Details: Shipping address, billing address, emergency contact
  • Payment Information: Credit card details, bank account information (processed securely through third-party payment processors)
  • Identity Verification: Government ID numbers when required for large orders or business accounts

2.2 Plant & Preference Data

  • Plant Preferences: Favorite plant types, care level preferences, indoor/outdoor preferences
  • Home Environment: Lighting conditions, space size, climate information
  • Care History: Plants you've purchased, care questions asked, success stories
  • Wishlist Data: Plants you're interested in, saved items, comparison lists

2.3 Technical Information

  • Device Data: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, time spent, click patterns, search queries
  • Location Data: General location for delivery estimates and local plant recommendations
  • Performance Data: Page load times, error reports, app crashes

2.4 Communication Data

  • Customer Service: Chat logs, email correspondence, phone call records
  • Reviews & Feedback: Product reviews, ratings, testimonials, suggestions
  • Social Media: Comments, mentions, shared content, social media profiles
  • Survey Responses: Feedback forms, satisfaction surveys, market research participation
Data Minimization: We only collect information that is necessary for providing our services and improving your plant care experience. You can always opt out of non-essential data collection.

3. How We Use Your Information

We use the collected information for various legitimate business purposes:

3.1 Service Provision

  • Processing and fulfilling your plant orders and delivery
  • Providing customer service and technical support
  • Managing your account and subscription services
  • Facilitating returns, exchanges, and warranty claims
  • Scheduling plant care consultations and workshops

3.2 Personalization & Recommendations

  • Personalizing your shopping experience and plant recommendations
  • Sending customized plant care tips based on your plants
  • Providing location-specific plant advice and seasonal care guides
  • Suggesting complementary products and accessories

3.3 Communication

  • Sending order confirmations, shipping updates, and delivery notifications
  • Providing plant care reminders and maintenance schedules
  • Sending promotional emails about new plants and special offers (with consent)
  • Notifying you about policy changes, service updates, and important announcements

3.4 Business Operations

  • Improving our website, mobile app, and overall user experience
  • Conducting market research and analyzing customer trends
  • Preventing fraud, ensuring security, and protecting against abuse
  • Complying with legal obligations and regulatory requirements
  • Managing inventory, supply chain, and business analytics
Marketing Communications: We will only send you marketing emails if you have explicitly opted in. You can unsubscribe at any time using the link in our emails or by contacting us directly.

4. Information Sharing and Disclosure

We respect your privacy and do not sell, trade, or rent your personal information to third parties. However, we may share your information in the following limited circumstances:

4.1 Service Providers

  • Delivery Partners: JNE, J&T Express, GoSend, and other logistics companies for order fulfillment
  • Payment Processors: Banks, credit card companies, and payment gateways (Midtrans, OVO, GoPay, etc.)
  • Technology Partners: Cloud hosting providers, analytics services, customer support platforms
  • Marketing Partners: Email marketing services, SMS providers (only with your consent)

4.2 Legal Requirements

  • When required by Indonesian law or government regulations
  • To respond to legal processes, court orders, or government requests
  • To protect our rights, property, or safety, or that of our users
  • To investigate potential fraud, security breaches, or policy violations

4.3 Business Transfers

  • In the event of a merger, acquisition, or sale of company assets
  • During business restructuring or reorganization
  • As part of bankruptcy proceedings or similar legal processes

4.4 With Your Consent

  • When you explicitly agree to share information with specific third parties
  • For joint marketing campaigns or partnerships (with opt-in consent)
  • When participating in contests, surveys, or promotional activities
Data Processing Agreements: All our service providers are bound by strict data processing agreements that require them to protect your information and use it only for specified purposes.

5. Data Security

We implement comprehensive security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:

5.1 Technical Safeguards

  • Encryption: SSL/TLS encryption for all data transmission
  • Secure Servers: Data stored on secure, regularly updated servers
  • Firewalls: Advanced firewall protection and intrusion detection systems
  • Regular Updates: Continuous security patches and system updates
  • Backup Systems: Secure, encrypted data backups with disaster recovery protocols

5.2 Administrative Safeguards

  • Access Controls: Limited access to personal information by authorized personnel only
  • Employee Training: Regular privacy and security training for all staff members
  • Background Checks: Thorough screening of employees with access to sensitive data
  • Incident Response: Comprehensive data breach response and notification procedures

5.3 Physical Safeguards

  • Secure Facilities: Physical security measures at our offices and data centers
  • Access Logs: Detailed logging of all physical and digital access to systems
  • Equipment Security: Secure disposal of hardware and storage devices
Security Limitations: While we implement industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but commit to promptly addressing any security incidents.

6. Cookies and Tracking Technologies

Our website uses cookies and similar technologies to enhance your browsing experience and provide personalized services:

6.1 Types of Cookies We Use

  • Essential Cookies: Required for website functionality, shopping cart, and user authentication
  • Performance Cookies: Help us analyze website usage and improve performance
  • Functional Cookies: Remember your preferences and provide personalized features
  • Marketing Cookies: Used for targeted advertising and measuring campaign effectiveness (with consent)

6.2 Third-Party Cookies

  • Google Analytics: Website traffic analysis and user behavior insights
  • Facebook Pixel: Social media advertising and conversion tracking
  • Payment Processors: Secure payment processing and fraud prevention

6.3 Managing Cookies

You can control cookies through your browser settings:

  • Accept or reject all cookies
  • Delete existing cookies from your device
  • Set preferences for specific types of cookies
  • Receive notifications when cookies are being set
Cookie Consent: We use a cookie consent banner to obtain your permission for non-essential cookies. You can update your preferences at any time through our cookie settings page.

7. Your Rights and Choices

Under Indonesian data protection laws and our commitment to privacy, you have the following rights regarding your personal information:

7.1 Access Rights

  • Request copies of all personal information we hold about you
  • Obtain information about how we collect, use, and share your data
  • Receive data in a structured, commonly used format

7.2 Correction Rights

  • Request correction of inaccurate or incomplete information
  • Update your account information and preferences
  • Modify your communication preferences

7.3 Deletion Rights

  • Request deletion of your personal information
  • Close your account and remove associated data
  • Withdraw consent for data processing activities

7.4 Portability Rights

  • Request transfer of your data to another service provider
  • Receive your data in a machine-readable format
  • Transfer data directly to another controller where technically feasible

7.5 Communication Preferences

  • Opt out of marketing communications at any time
  • Choose specific types of communications you want to receive
  • Set frequency preferences for newsletters and updates

Exercise Your Rights

To exercise any of these rights, contact us at [email protected] or call +62 21 7890 1234. We will respond to your request within 30 days.

Contact Privacy Team

8. Children's Privacy

Protecting children's privacy is important to us. Our services are not intended for children under 13 years of age, and we do not knowingly collect personal information from children under 13.

8.1 Age Restrictions

  • Users must be at least 13 years old to create an account
  • Users between 13-17 years old need parental consent
  • We may request age verification for certain services

8.2 Parental Rights

  • Parents can review their child's personal information
  • Request deletion of their child's account and data
  • Refuse further collection of their child's information

8.3 Educational Programs

For our educational plant care programs involving minors, we:

  • Obtain explicit parental consent before collecting any information
  • Limit data collection to what's necessary for the program
  • Provide parents with ongoing access and control
  • Delete information when the program ends
Parents Notice: If you believe your child under 13 has provided us with personal information, please contact us immediately at [email protected] so we can delete the information.

9. International Data Transfers

Your information may be transferred to and processed in countries other than Indonesia. We ensure that such transfers comply with applicable data protection laws:

9.1 Transfer Safeguards

  • Standard contractual clauses approved by data protection authorities
  • Adequacy decisions recognizing equivalent protection levels
  • Certification schemes and codes of conduct
  • Binding corporate rules for intra-group transfers

9.2 Countries We May Transfer To

  • Singapore: Cloud hosting and data processing services
  • United States: Analytics, marketing, and technology services
  • European Union: Payment processing and customer support

9.3 Your Rights Regarding Transfers

  • Object to transfers to specific countries
  • Request information about transfer safeguards
  • Obtain copies of relevant transfer agreements

10. Data Retention

We retain your personal information only as long as necessary for the purposes outlined in this Privacy Policy:

10.1 Retention Periods

  • Account Information: Until account deletion or 3 years of inactivity
  • Purchase History: 7 years for tax and warranty purposes
  • Communication Records: 3 years for customer service quality
  • Marketing Data: Until consent withdrawal or 2 years of inactivity
  • Technical Logs: 12 months for security and performance analysis

10.2 Deletion Criteria

  • Purpose for collection is no longer relevant
  • Legal retention period has expired
  • User requests deletion (subject to legal obligations)
  • Consent is withdrawn and no other legal basis exists

10.3 Secure Deletion

  • Complete removal from active systems
  • Secure deletion from backup systems
  • Physical destruction of storage media when necessary
  • Verification of deletion completion

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors:

11.1 Notification Process

  • Email notification to registered users for material changes
  • Prominent notice on our website homepage
  • In-app notifications for mobile app users
  • Social media announcements for significant updates

11.2 Types of Changes

  • Minor Changes: Clarifications, contact information updates, formatting improvements
  • Material Changes: New data collection practices, sharing arrangements, or user rights
  • Legal Changes: Updates required by new laws or regulations

11.3 Your Options

  • Continue using our services under the new policy
  • Contact us with questions or concerns about changes
  • Exercise your deletion rights if you disagree with changes
  • Request a copy of previous policy versions
Stay Informed: We recommend reviewing this Privacy Policy periodically. The "Last Updated" date at the top indicates when the policy was most recently revised.

12. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

12.1 Privacy Officer

  • Email: [email protected]
  • Phone: +62 21 7890 1234 (ext. 101)
  • WhatsApp: +62 812 3456 7890
  • Response Time: Within 48 hours for urgent matters, 5 business days for general inquiries

12.2 Mailing Address

Loprutis Privacy Department
Jl. Raya Kebayoran No. 123
Jakarta Selatan 12560
Indonesia

12.3 Business Hours

  • Phone Support: Monday-Friday 9:00 AM - 6:00 PM WIB
  • Email Support: 24/7 monitoring, responses within business hours
  • In-Person Consultations: By appointment only

12.4 Data Protection Authority

If you believe we have not addressed your privacy concerns adequately, you have the right to lodge a complaint with the Indonesian Data Protection Authority:

  • Ministry of Communication and Information Technology
  • Website: kominfo.go.id
  • Email: [email protected]

13. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Indonesia:

13.1 Applicable Laws

  • Law No. 19 of 2016 on Information and Electronic Transactions
  • Government Regulation No. 71 of 2019 on Electronic Systems and Transactions
  • Ministry Regulation No. 20 of 2016 on Personal Data Protection
  • Upcoming Personal Data Protection Law (when enacted)

13.2 Dispute Resolution

  • Good faith negotiations as the first step
  • Mediation through recognized Indonesian mediation services
  • Arbitration under Indonesian Arbitration Board (BANI) rules
  • Litigation in Jakarta District Court as the last resort

13.3 International Compliance

While governed by Indonesian law, we also strive to comply with international privacy standards:

  • GDPR principles for EU customers
  • CCPA guidelines for California residents
  • PIPEDA standards for Canadian users
  • PDPA compliance for Singapore customers
Legal Updates: As Indonesia develops its comprehensive data protection framework, we will update our practices and this policy to ensure full compliance with new regulations.

Questions About Your Privacy?

Our privacy team is here to help. Contact us anytime for clarification about our data practices or to exercise your privacy rights.

Get Privacy Support