Tubbu Logo

Privacy Policy

Last updated: May 2026

1. Introduction

PT Tubbu Wellness Indonesia ("Tubbu", "we", "us") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our platform, in accordance with Indonesian Law No. 27 of 2022 on Personal Data Protection (UU PDP).

2. Data We Collect

We collect the following personal data:

  • Identity data: Full name, email address, and profile photo — provided via Google OAuth at registration
  • Contact data: Phone number and bio, if you choose to complete your profile
  • Transaction data: Booking history, credit purchases, membership purchases, and payment records
  • Usage data: Session attendance, booking status, and recovery session records

We do not collect payment card details. All payment transactions are handled directly by Xendit.

3. How We Use Your Data

We use your personal data to:

  • Create and manage your account
  • Process bookings and payments
  • Send transactional emails (booking confirmations, payment receipts, membership updates)
  • Manage your credits and membership status
  • Improve and maintain the platform
  • Comply with applicable Indonesian law

4. Data Sharing

We do not sell your personal data. We share your data only with trusted third-party service providers necessary to operate the Service:

All third parties are contractually obligated to handle your data securely and only for the purposes specified.

5. Data Retention

We retain your personal data for as long as your account is active or as necessary to provide the Service. Transaction and booking records may be retained for up to 5 years for accounting and legal compliance purposes. You may request deletion of your account and associated data at any time (see Section 6).

6. Your Rights

Under UU PDP, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your personal data
  • Withdraw consent for data processing
  • Object to processing of your data

To exercise any of these rights, contact us at tubbudev@gmail.com. We will respond within 14 business days.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. All data is transmitted over encrypted connections (HTTPS/TLS).

8. Children's Privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a person under 18 without parental consent, we will delete that data promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page with an updated date. Your continued use of the Service after changes constitutes acceptance of the revised policy.

10. Contact Us

For any privacy-related questions or requests, please contact our Data Controller:

PT Tubbu Wellness Indonesia

Yogyakarta, Indonesia

Email: tubbudev@gmail.com