Privacy Policy
Last updated: January 20, 2026
At Indo Marketplace ("we," "us," or "our"), we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website indo-shop.com or make a purchase from us.
This policy is designed to comply with applicable privacy laws, including the General Data Protection Regulation (GDPR) for our European Union customers and the California Consumer Privacy Act (CCPA) for California residents.
1. Information We Collect
1.1 Personal Information You Provide
We collect information you voluntarily provide to us, including:
- Account Information: Name, email address, password, phone number
- Billing Information: Billing address, payment card details (processed securely through Stripe)
- Shipping Information: Delivery address, recipient name, contact details
- Communication Data: Messages you send us, customer service inquiries, reviews
- Marketing Preferences: Your choices regarding promotional communications
1.2 Information Collected Automatically
When you visit our website, we automatically collect certain information:
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages viewed, time spent on pages, links clicked, referring URLs
- Location Data: General geographic location based on IP address
- Cookies and Tracking: Information collected through cookies and similar technologies (see our Cookie Policy)
1.3 Information from Third Parties
We may receive information about you from:
- Payment processors (transaction confirmations)
- Analytics providers (website usage statistics)
- Social media platforms (if you connect your account)
2. How We Use Your Information
We use your personal information for the following purposes:
2.1 To Provide Our Services
- Process and fulfill your orders
- Send order confirmations and shipping updates
- Manage your account and provide customer support
- Process payments and prevent fraud
2.2 To Improve Our Services
- Analyze website usage and trends
- Develop new features and products
- Personalize your shopping experience
- Conduct research and analytics
2.3 To Communicate With You
- Send transactional emails (order confirmations, shipping updates)
- Respond to your inquiries and requests
- Send promotional communications (with your consent)
- Notify you about changes to our policies
2.4 To Ensure Security and Compliance
- Detect and prevent fraud or abuse
- Comply with legal obligations
- Enforce our terms of service
- Protect our rights and the rights of others
3. Legal Basis for Processing (GDPR)
For our EU customers, we process your data based on the following legal grounds:
- Contract Performance: Processing necessary to fulfill our contract with you (e.g., order processing)
- Legitimate Interests: Processing for our legitimate business interests (e.g., fraud prevention, analytics)
- Consent: Processing based on your explicit consent (e.g., marketing emails)
- Legal Obligation: Processing required to comply with applicable laws
4. How We Share Your Information
We may share your information with:
4.1 Service Providers
- Payment Processors: Stripe processes payments securely on our behalf
- Shipping Partners: Carriers who deliver your orders
- Email Services: Providers who help us send transactional and marketing emails
- Analytics Providers: Services that help us understand website usage
- Cloud Hosting: Infrastructure providers that host our platform
4.2 Legal Requirements
We may disclose information when required by law, court order, or government request, or when we believe disclosure is necessary to protect our rights or the safety of others.
4.3 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
4.4 With Your Consent
We may share your information in other ways with your explicit consent.
5. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. When we transfer data internationally, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.
6. Data Retention
We retain your personal information for as long as necessary to provide our services and fulfill the purposes described in this policy. Specifically:
- Account Data: Retained while your account is active and for 3 years after deletion
- Transaction Data: Retained for 7 years for tax and legal compliance
- Marketing Data: Retained until you withdraw consent or unsubscribe
- Analytics Data: Retained for 26 months in aggregated form
7. Your Rights
7.1 Rights for All Users
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your personal data
- Opt-Out: Unsubscribe from marketing communications
7.2 Additional Rights for EU Residents (GDPR)
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restriction: Request limitation of processing
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time for consent-based processing
- Right to Lodge a Complaint: File a complaint with your local data protection authority
7.3 Additional Rights for California Residents (CCPA)
- Right to Know: Request disclosure of data collected, used, or shared
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt-out of the sale of personal information (we do not sell your data)
- Right to Non-Discrimination: Not be discriminated against for exercising your rights
7.4 How to Exercise Your Rights
To exercise any of these rights, please contact us at support@indo-shop.com. We will respond to your request within 30 days (or sooner if required by law). We may need to verify your identity before processing your request.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL)
- Secure payment processing through PCI-compliant providers
- Access controls and authentication measures
- Regular security assessments and monitoring
- Employee training on data protection
However, no method of transmission over the internet is completely secure. We cannot guarantee the absolute security of your data.
9. Children's Privacy
Our Services are not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
10. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of these sites. We encourage you to read their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may also notify you by email.
12. Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
- Email: support@indo-shop.com
- Company: Indo Marketplace
- Data Protection Inquiries: support@indo-shop.com
For EU residents, you have the right to lodge a complaint with your local supervisory authority if you believe we have not adequately addressed your concerns.