Privacy Policy
How we collect, use, and protect your personal data. Aligned with Indonesia’s PDP Law and GDPR.
Data Controller: PT Digital Kreatif Bangsa, Samudera Residence, Glasfin Cluster Block C5, Tajurhalang, Bogor Regency, West Java, Indonesia ("MoGerak", "we"). Privacy contact: privacy@mogerak.com.
1. Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, email, phone, avatar, hashed password | You at signup |
| Precise location (sensitive) | GPS coordinates during play, activity route history | Your device permission |
| Activity & gameplay | Distance, steps, duration, coins, missions, leaderboards | Automatic from use |
| Partner data (B2B) | Business name, tax ID, outlet address, ad creatives | You as partner |
| Transactions | Subscription history, Midtrans transaction IDs, payment status | Automatic / Midtrans |
| Device & technical | Device model/OS, app version, IP address, crash logs | Automatic |
We do not sell your personal data and only collect what the service requires.
2. Legal Bases (Indonesia PDP Art. 20 & GDPR Art. 6)
- Consent — precise location, push notifications; withdrawable anytime in device/app settings.
- Contract performance — gameplay, coins, subscriptions, reward fulfillment.
- Legal obligation — tax records, lawful authority requests.
- Vital interests — user safety emergencies.
- Legitimate interests — platform security, anti-fraud/anti-cheat, service improvement, balanced against your rights.
3. Purposes
- Core features: coin collection detection, AR, missions, leaderboards.
- Account management, payments, subscription handling, reward delivery.
- Security: GPS-spoofing/bot detection, fraud prevention, content moderation.
- Customer support and transactional communications.
- Aggregate/anonymized product analytics. Direct marketing only with opt-in consent.
4. Cookies & Local Storage
The website uses essential cookies and localStorage for preferences (theme, language, session).
Google advertising cookies. If we later display ads through Google AdSense or another Google advertising partner, third-party vendors including Google will set and read advertising cookies (such as the DoubleClick cookie) to serve ads based on prior visits to this or other websites. If that happens, this section will name the vendor, its purpose, and its data scope, and an "ads personalization" toggle will be provided alongside the existing consent banner. You may also opt out of personalized advertising at any time via Google's Ads Settings (https://adssettings.google.com), and you can review Google's own policy at https://policies.google.com/technologies/ads. Currently, we run no third-party advertising trackers on our properties; future changes will be reflected here.
5. Third-Party Disclosure
| Party | Purpose | Data Scope |
|---|---|---|
| Google Cloud Platform & Firebase | Hosting, database, storage, auth, crash reporting | Full infrastructure (encrypted) |
| Midtrans (PT Midtrans Payment) | Payment processing | Transaction data & tokens; cards are never stored by MoGerak |
| Reward merchants | Voucher/merch fulfillment | Minimum contact details you approve at redemption |
| Lawful authorities | Court/legal orders | As required by the order |
We never disclose personal data for third parties' own marketing. Under CCPA/CPRA we do not "sell" or "share" personal information as defined by those laws.
6. International Transfers
Primary servers are hosted in us-central1 (United States) on Google Cloud Platform. Cross-border transfers are safeguarded with contractual protections equivalent to Standard Contractual Clauses plus encryption in transit (TLS 1.2+) and at rest, consistent with PDP Arts. 55–56 and GDPR Chapter V.
7. Retention
| Data | Retention |
|---|---|
| Active account data | While the account exists |
| Transaction/tax records | 10 years (Indonesian tax law) |
| Gameplay location & routes | Max 24 months, then aggregated/anonymized |
| Security logs | 12 months |
| Deleted accounts | Anonymized within 30 days except legally required records above |
8. Security
- TLS everywhere; at-rest encryption for databases and object storage.
- Passwords hashed (bcrypt); role-based access control with least privilege; administrative audit logs.
- Production network isolation, routine patching, periodic security reviews.
9. Data Breach Notification
Under PP 71/2019 and the PDP Law, material personal-data breaches are notified to you in writing within 3×24 hours of becoming known, including risks, affected data and mitigation, alongside reports to the competent supervisory authority.
10. Your Rights
Under PDP Arts. 5–13 and GDPR Arts. 15–22 you may: access and copy your data; correct inaccuracies; request deletion (within legal retention limits); restrict processing or withdraw consent anytime; receive data in portable format; object to legitimate-interest processing; and lodge complaints with supervisory authorities (Komdigi in Indonesia; your local EU DPA).
Email privacy@mogerak.com from your registered address, or use Account Settings → Privacy. Response within 7 business days; free of charge.
Account deletion: App/Dashboard → Account Settings → Delete Account, or email privacy@mogerak.com — consistent with Google Play and App Store account-deletion policies.
California residents additionally hold CCPA/CPRA know/delete/limit rights and will not be discriminated against for exercising them.
11. Children
The service is intended for ages 13+. Users aged 13–17 require parental/guardian consent and supervision. We do not knowingly collect data from children under 13 without verifiable parental consent (COPPA and PDP children's-data principles). Contact us to remove any such data immediately.
12. Changes
Material changes are announced in-app/by email at least 7 days before taking effect; prior versions available on request via privacy@mogerak.com.