Skip to main content
WarisanNusantara

Legal

Privacy Policy

What data we collect, why, how long we keep it, and the rights you have over it.

Effective: 27 June 2026 ยท Last updated: 27 June 2026

1. Our commitment

Warisan Nusantara ("we", "us", "our") respects your privacy. This policy explains what data we collect, why, how long we keep it, and the rights you have over it. We have written this in plain language because legal jargon helps no one. If anything is unclear, email [email protected] and a human will respond within 5 business days.

2. Data controller

The data controller for warisannusantara.com is: SCALEUP CRM PTE. LTD. Singapore Email: [email protected] For EU/UK residents, we are the controller under the GDPR. For Singapore residents, we are the organization under the PDPA. Our Data Protection Officer can be reached at [email protected].

3. What data we collect

We collect four categories of data, and only the minimum needed to run the service: 1. Account data (only if you sign in): Your name, email, profile photo, and OAuth provider ID (Google). Stored encrypted at rest. You can delete your account at any time from /account/settings. 2. Usage data (local to your device): Your favorites, ratings, reviews, visited destinations, and saved trips are stored either in our backend (if signed in) or in your browser's localStorage (if not signed in). We do not use third-party tracking cookies. 3. Content you create: Reviews, ratings, comments, and uploaded photos. Linked to your account, deletable by you, never shared without consent. 4. Server logs: IP address, browser type, page requested, timestamp. Retained for 30 days for security and debugging. We do not sell logs, do not share them with advertisers, and do not use them to profile you. 5. Booking data (only if you book): When you book via our affiliate links, the booking partner (Booking.com, Agoda, etc.) receives your booking details directly from you. They become the controller for that data. We receive only a confirmation reference and commission amount โ€” not your name, payment details, or itinerary.

4. Cookies and similar technologies

We use the minimum cookies possible: - Authentication cookie (httpOnly, secure, signed): identifies you to the admin panel. Required for the service. - Country preference cookie (wn_country): remembers your country selection. Not used for tracking. - Theme preference cookie (wn_theme): remembers light/dark mode. Not used for tracking. - Affiliate partner cookies (set by Booking.com, Agoda, etc. when you click their links): they track conversions so we can earn commissions. See our [Affiliate Disclosure](/affiliate-disclosure) for full details. We do not use Google Analytics, Facebook Pixel, or any third-party analytics or advertising cookies. See our [Cookie Policy](/cookies) for the full inventory.

5. How we use your data

We use your data only to: - Provide the service you signed up for (favorites, trip planning, newsletter) - Authenticate you across devices and sessions - Respond to your support requests - Send you the newsletter you opted into (you can unsubscribe at any time) - Detect and prevent abuse (fraud, spam, scraping) - Comply with legal obligations (e.g., tax records) - Improve the service through aggregated, anonymized analytics We do not use your data for: - Behavioral advertising (we don't do any advertising) - Selling to third parties (we never sell) - Profiling for automated decisions with legal effect (e.g., credit, employment) - Training AI models on your private data

6. Who we share data with

We share data only with: - Cloud infrastructure providers (AWS, Cloudflare, Google Cloud, DigitalOcean) for hosting, storage, and delivery - Authentication providers (Google, Apple, Appwrite) when you sign in with them - Email service providers (Resend, Postmark) to send you the newsletter - Payment processors (Stripe, when premium features launch) to handle paid subscriptions - Affiliate booking partners (Booking.com, Agoda, Klook, etc.) when you complete a booking - Analytics providers (Plausible Analytics, self-hosted) for aggregated, cookieless page-view stats - Customer support tools (Help Scout, when live) for support tickets - Law enforcement, only with valid legal process (subpoena, court order, valid MLAT). See our Transparency Report. We require all processors to have GDPR-compliant data processing agreements. None of these providers are permitted to use your data for their own purposes.

7. International data transfers

We use cloud providers in multiple regions. Specifically: - Singapore (primary): our production database and most user data - United States (fallback): CDN edge cache and some backups - European Union (when required by EU customers): EU-only data residency for EU users When data is transferred internationally, we rely on: - EU Standard Contractual Clauses (SCCs) for transfers from the EU - Singapore PDPA-recognized transfer mechanisms for transfers from Singapore - Equivalent safeguards for transfers from other jurisdictions You can request a copy of the relevant clauses by emailing [email protected].

8. How long we keep your data

Account data: Until you delete your account, plus 30 days for backup rotation. User-generated content (reviews, photos): Until you delete it or delete your account. After account deletion, content is removed from active systems within 7 days and from backups within 90 days. Server logs: 30 days, then automatically deleted. Booking data: 7 years for tax and accounting compliance. Newsletter subscription: Until you unsubscribe. We honor unsubscribes immediately; we do not "re-confirm" opt-ins. Aggregated analytics: 24 months, after which data is anonymized to country-level only.

9. Your rights

You have the right to: - Access the personal data we hold about you (we'll send you a copy in a portable format) - Rectify inaccurate or incomplete data - Erase your data ("right to be forgotten") - Restrict or object to processing in certain circumstances - Data portability โ€” receive your data in a machine-readable format - Withdraw consent at any time, where processing is based on consent - Lodge a complaint with your local data protection authority To exercise any of these rights, email [email protected]. We respond within 30 days, typically much sooner. If you are in the EU/UK, you can also complain to your national supervisory authority. A list is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. If you are in Singapore, you can complain to the PDPC at https://www.pdpc.gov.sg.

10. Children's privacy

Warisan Nusantara is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you are a parent and believe your child has provided us data, email [email protected] and we will delete it within 7 days. For EU/UK users, we comply with the age of digital consent in your country (13-16 depending on jurisdiction).

11. Security

We protect your data with: - TLS 1.3 for all data in transit - AES-256 encryption for sensitive data at rest - HSTS, secure cookies, and same-site cookie protection - Role-based access controls (only staff with a business need can access personal data) - Regular security audits and penetration testing - 30-day log retention with restricted access If we ever have a data breach affecting your personal data, we will notify you by email within 72 hours of discovery, in line with GDPR Article 33-34. We will also notify the relevant supervisory authority.

12. Automated decision-making

We do not make automated decisions about you that have legal or similarly significant effects, except: - Fraud detection: We use automated checks to detect fraudulent signups and bookings. If we believe your account is fraudulent, we may suspend it automatically. You can appeal to [email protected]. - Trip planner recommendations: The AI trip planner makes recommendations based on your inputs. These are suggestions, not decisions; you choose whether to follow them. We do not use your data for credit, employment, insurance, or other decisions that would have a significant legal effect on you.

13. AI and your data

We do not use your private data (your reviews, your private trips, your search history) to train AI models. We do use anonymized, aggregated patterns (e.g., "X% of users searching for Bali in October") to improve our recommendations. When you use the AI trip planner, your prompt is sent to OpenAI or Anthropic to generate a response. These providers have their own privacy policies; we use their APIs under data processing agreements that prohibit them from retaining or training on your prompts.

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be: - Announced on our blog - Communicated by email to account holders at least 30 days before they take effect - Indicated by a "Last updated" date at the top You can always see the version history at /legal/privacy-history.

15. Contact

Privacy questions: [email protected] Data Protection Officer (DPO): [email protected] Data Subject Access Requests: [email protected] Postal mail: See our [Imprint](/legal/imprint)