Hi! How can we help you?

Privacy Policy

Privacy policy of Qelola for Qelola products, including data deletion (Forget Me) and Google Play compliance.

Introduction

Qelola ("we") respects your privacy and complies with Indonesia's Personal Data Protection (PDP) law. This policy explains how data is processed across Qelola products (Qelola Kasir, Qelola Kerja, Qelola Dashboard), including Android apps distributed through Google Play.

Data Controller

The controller is Qelola, Jl. Nipah No.6, RT.1/RW.1, Petogogan, Kec. Kby. Baru, South Jakarta 12170, Indonesia. Contact admin@qelola.id for privacy questions, data rights, or deletion requests.

Data We Collect

  • Account information (name, business, email, phone)
  • Biometric face data for attendance verification (Qelola Kerja)
  • Precise GPS location for attendance geofence
  • Watermarked attendance photos
  • Device identifiers (UUID derived from Android ID, manufacturer/model) to bind cashier/worker devices and support accounts
  • Notification tokens (FCM) for operational push messages
  • Offline app data on device (e.g. orders, stock, sync history in the local database) that is sent to the server during sync
  • Device and app-usage data

Mobile App Permissions

Qelola Android apps request the following permissions for core features:

Permission Product Purpose
Location (precise/coarse GPS) Qelola Kerja Attendance, geofence, location proof when checking in
Bluetooth Qelola Kasir Print receipts to thermal printers
Camera / storage Kasir & Kerja Attendance evidence photos, image uploads, receipt logos
Notifications Kasir & Kerja Operational reminders and updates
Device identifiers Kasir & Kerja Account security and technical support

Location permission is not used for advertising or third-party tracking.

Processing of biometric face data and precise GPS location is performed with explicit consent from users. You may withdraw consent at any time via your company admin or by contacting us at admin@qelola.id.

Purpose of Processing

Data is used to provide the service, verify attendance, generate reports, and support customers' business operations.

Retention

Data is retained during the subscription term and as legally required, then deleted or anonymized. Prospect ("leads") data in Firestore is used only for sales follow-up and deleted on request.

Data stored locally on your device (app cache, app database) is not automatically removed from our servers. Clearing app data or uninstalling the app removes the local copy via Android system settings.

Your Rights

Under Indonesia's PDP law you may access, correct, delete data, and withdraw consent. Send requests to admin@qelola.id.

Data Deletion / "Forget Me"

Google Play may require a user data-deletion option. Qelola does not currently provide an in-app "delete account" button. Requests are handled through the web form or email with manual follow-up by our team.

How to request

Primary — web form:

  1. Open Account Deletion Request
  2. Enter your login email (required) and optional supporting details
  3. Tick the consent checkbox and submit

The form notifies the Qelola team at admin@qelola.id and records the request for follow-up.

Alternative — manual email:

  1. Email admin@qelola.id
  2. Use subject: Data Deletion / Forget Me
  3. Include:
    • Full name
    • Email or phone number used to log in
    • Business / merchant name (if any)
    • Reason for deletion (optional)

Example email subject

Data Deletion / Forget Me — user@email.com

Who can request

  • The account holder, or
  • A merchant admin acting on behalf of an employee/cashier, naming the related employee data

What we delete or anonymize

After verification, we delete or anonymize on Qelola servers:

  • Related account data (name, email/phone, profile)
  • Related attendance records and evidence photos
  • Sync history tied to that account
  • Related notification tokens

We may retain data where required by law or for an active dispute; if so, we will explain the basis.

Local data on your device

Requests to admin@qelola.id delete data on Qelola servers. Local copies on your device (app database, image cache) are removed if you:

  • Clear app data from Android Settings, or
  • Uninstall the app

Manual handling and timelines

  1. Qelola receives the deletion request email
  2. We verify identity / merchant authorization (if needed)
  3. Internal action: delete or anonymize server data
  4. Completion confirmation is sent back to your email
  • Initial response: within 7 business days
  • Completion: within 30 business days, or longer if required by law

If a request is denied (e.g. insufficient authorization), we will explain why and the next options.

Children

Products are intended for business use; we do not knowingly collect data from children without guardian consent.

Sharing with Third Parties

We do not sell your personal data. To provide the service we process and store data using third-party service providers, including:

  • Google Firebase (Firestore, Cloud Storage, Authentication, Hosting, Cloud Messaging) for hosting and message delivery;
  • Analytics and crash-monitoring providers to keep the app stable;
  • Messaging providers (including WhatsApp) for business follow-up.

We vet partners to ensure they meet applicable data-protection standards. Data is not shared with others except as required by law or with your consent.

International Transfers

Some hosting services (including Firebase) may process data outside Indonesia. Where cross-border transfer occurs, we rely on the safeguards required by Indonesia's PDP law, including data-protection agreements and applicable standard clauses.

Security

We maintain reasonable technical and organizational measures — including encryption in transit (TLS) and at rest, role-based access controls, authentication, and periodic backups — to protect data from unauthorized access, disclosure, or misuse.

Cookies and Local Storage

Our web/PWA app uses cookies and local storage to maintain sessions, language preferences, and user experience. Mobile apps also store local data on your device (e.g. offline order queues). You can manage cookies through your browser settings; some features may be limited if cookies are disabled.

Google Play and Data Safety

This policy accompanies Google Play submissions and is the Privacy Policy URL listed in Play Console for Qelola Kasir (id.qelola.mobile.pos) and Qelola Kerja (id.qelola.mobile.work).

Aligned with the Play Data Safety section, the apps may collect:

  • Account information
  • Precise location (Qelola Kerja)
  • Photos
  • On-device face biometrics (Qelola Kerja)
  • Device identifiers
  • App interactions / offline data
  • Notifications (FCM token)

Face biometric data is not used for advertising or third-party machine-learning model training. Personal data is not sold.

Deletion in Play Console: the supported method is the web form at qelola.id/hapus-akun/ or email to admin@qelola.id as described in Data Deletion / "Forget Me" above (manual handling; not an in-app button).

Changes

We may update this policy; the latest version is published on this page. The effective date of the last change is shown at the top of the page.

Updated: 2 October 2026