Skip to main content
Legal

Privacy policy

Last updated: 2026-05-02

This policy describes how TriaPay collects, uses, and protects information about you when you use our service.

1. Information we collect

We collect the data you provide when you register a tenant: organization name, email address, and password (stored as an Argon2id hash). When you process payments through TriaPay we record payment metadata: amounts, transaction hashes, timestamps, DHRU invoice references, and IP addresses tied to dashboard sessions. We do not collect or store cryptocurrency private keys, seed phrases, or wallet credentials of any kind.

2. How long we keep it

Tenant account data is retained for the lifetime of the account. Audit log entries are retained for 180 days. Payment metadata is retained for as long as required by Indonesian tax and accounting regulations. When you delete your tenant, account data and credentials are removed within 1 day; payment metadata may be retained in encrypted backups for up to 90 days.

3. Where your data lives

TriaPay infrastructure is hosted on commercial cloud and colocated providers; encrypted daily backups are kept with the same providers. We do not transfer personal data to processors outside our agreed region without prior notice.

4. Your rights

You may request access to the personal data we hold about you, request correction of inaccurate data, request deletion of your account and associated data, or request a portable export of your account and payment history. Send any such request via WhatsApp at https://wa.me/rbwtech from a number associated with your tenant. We respond within 1 day.

5. Cookies and local storage

We use a small number of first-party cookies: a session cookie for authentication, a locale preference cookie, and a theme preference cookie. We do not use third-party analytics or advertising trackers.