Privacy Notice
What personal data we process, why, and what your rights are. Version 2026-08-27.
Version 2026-08-27. The previous version still applies to anyone who has not accepted this one.
1. In short
- To read this site you do not have to give us anything.
- To have an account we store your email address. No phone number, no password. A name is yours to add if you want one, and yours to clear again.
- We do not sell personal data and we do not use it for targeted advertising.
- You can ask for a copy, a correction or a deletion at any time.
2. Who controls this data
Nisdos Estonia OÜ, Estonian Business Register 14349798, Sepapaja tn 6, 15551 Tallinn, Estonia — the data controller for sini.id.
Our company is registered in Estonia, so alongside Indonesian Law No. 27 of 2022 this processing is also subject to the EU General Data Protection Regulation. The two ask for nearly the same things here, and where they differ we follow whichever protects you more.
For anything to do with personal data, including exercising the rights below: privasi@sini.id.
3. What we collect
- Your email address — only if you create an account. With it we store when the account was created, when you last signed in, which version of the terms you accepted and when, and which interface language you used.
- A name — only if you type one on your account page. It is optional and it is not how you sign in. If you fill it in, that name is published as the author name on any review you write about a company and on any comment you write on a phone-number page, and nowhere else; both forms say so before you submit. You can change or clear it yourself at any time — cleared, what you have written appears without a name.
- Sign-in links — your email address and a hash of the one-time link, for as long as that link is valid. This is what lets the link be sent and be usable only once.
- Sessions — a hash of your session cookie, so you stay signed in. The cookie is called sid, is HttpOnly, and contains nothing about you.
- Server logs — IP address, time, the page requested and the browser type, recorded by our web server as is standard, for security and fault-finding.
- Approximate location — if you press the location button, your browser gives us rounded coordinates (about 110 metres) to order search results. We do not store them on the server; your browser keeps them for at most 30 minutes. We also use a coarse estimate from your network address, only to order results.
- Content you write — reviews, ratings, comments on phone numbers, and suggested corrections, with their timestamps. Reviews and comments are public.
4. Legal basis and purpose
Under art. 20(2)(b) of Law 27/2022, we process the account email address to perform our contract with you — providing the account and sending the sign-in link. We do not ask for separate consent for it, because consent is not the basis.
Server logs and rate limiting are processed on our legitimate interest in keeping the service secure and available.
If we ever want to send you something that is not part of the account — product news, say — we will ask for your consent separately, in its own unticked box, and you will be able to withdraw it at any time.
5. How long we keep it
- Account data: for as long as your account exists. When you delete your account its contents are deleted — your name among them — and the email address is kept so that signing up again works smoothly; for complete removal including the address, write to privasi@sini.id.
- Sign-in links: 15 minutes, or immediately once used — whichever comes first. An address that is never confirmed never becomes an account and goes with the link.
- Sessions: until you log out. A session renews itself for as long as you keep using the site; one on a device you never come back to ends 400 days after its last use.
- Server logs: 90 days at most.
- Reviews and ratings: for as long as they are shown, or until you or we remove them.
6. Who else processes it
- Our hosting provider, DigitalOcean, in Singapore — where this site and its database run.
- Our email provider, Resend, which delivers the sign-in link. They receive your email address and the content of that message.
- Google Analytics, for aggregate visit statistics. It receives your IP address and sets measurement cookies. We also record which pages are opened and what kind of action was taken on them — that a call button was pressed, say, or that a search was submitted. What you type is not sent to it: not the words you searched for, not a phone number, not an email address, not the text of a review.
- We do not sell personal data to anyone and do not use it for targeted advertising.
7. Processing outside Indonesia
Our servers and database are in Singapore, and our email provider processes messages outside Indonesia. So your personal data is processed outside the territory of the Republic of Indonesia.
Under art. 56(3) of Law 27/2022 we rely on contracts binding those providers to protect personal data adequately — not on a finding that a country’s level of protection is adequate, because no such finding exists in Indonesia.
Because the controller is in the European Union, the EU-to-Singapore leg additionally rides on Standard Contractual Clauses under art. 46 GDPR.
You can ask us about those safeguards at privasi@sini.id.
8. Your rights
Law 27/2022 gives you the following rights over your personal data. All of them go through one address, free of charge, and we will not ask why.
- To be informed about the processing of your data (art. 5).
- To access your data and receive a copy. We answer within 3x24 hours (art. 7 and art. 32(2)).
- To have inaccurate data corrected. We correct it and tell you the outcome within 3x24 hours (art. 6 and art. 30). Your name you can correct yourself, at any time, on your account page.
- To have processing stopped, and your data erased or destroyed (art. 8 and arts. 42–45).
- To withdraw consent, where consent is the basis (art. 9).
- To object to decisions made solely by automated means, and to profiling (art. 10). We do neither.
- To delay or restrict processing (art. 11).
- To claim compensation for a breach (art. 12).
- To obtain and transmit your data in a machine-readable form (art. 13).
9. Security and breach notification
We hold as little as possible: there is no password, and both the sign-in link and the session cookie are stored only as hashes, so a leak of the database gives nobody a way into your account. Traffic to this site is encrypted.
If personal data protection fails, we notify you and the competent authority in writing within 3x24 hours, stating the data exposed, when and how it happened, and how it is being handled — as art. 46 of Law 27/2022 requires.
10. Age
This service is for people aged 18 and over. We do not knowingly collect children’s data. If you are a parent or guardian and know that a child has created an account here, write to privasi@sini.id and we will delete it.
11. Cookies
- sid — the session cookie, present only when you are signed in, and gone when you log out. The account cannot work without it.
- Google Analytics measurement cookies, for aggregate visit statistics.
- We set no advertising cookies and do not follow you to other sites.
12. Changes to this notice
Every version of this notice is dated. If we change any of the above, we tell you before the change takes effect, as art. 21(2) of Law 27/2022 requires, and ask you to accept the new version of the terms at your next sign-in.
13. Complaints
If you are unhappy with how we handle your data, write to privasi@sini.id.
You also have the right to complain to the competent Indonesian personal data protection authority and — because the controller is established in Estonia — to Andmekaitse Inspektsioon, the Estonian Data Protection Inspectorate (aki.ee). We do not limit your right to go to court.