Privacy Notice

Draft, pending review by a practitioner. This notice was written from how the site and the business actually work, not from a template. It has not yet been reviewed by a lawyer qualified in Indonesian data protection law, and it should be before anyone relies on it. Two points in particular need a professional eye: whether China’s Personal Information Protection Law applies alongside Indonesia’s UU PDP given that we operate from Shenzhen, and whether the cross-border section below is complete.

Who we are

Roammate is a travel concierge service operating in Shenzhen, Guangzhou and Hong Kong, based in Shenzhen and Jakarta. We decide what personal data is collected here and why, which under Indonesia’s Personal Data Protection Law (UU No. 27 of 2022) makes us the data controller.

You can reach us about anything on this page:

What we collect

When you message us. If you contact us on WhatsApp, WeChat or email, we hold what you send: your name or profile name, your phone number or WeChat ID, your email address, and the contents of the conversation. This is the only way to book with us at the moment.

When you use the booking form. The booking form is not published yet. When it is, this notice applies to it from the moment it goes live, and it will collect:

  • your full name;
  • your WhatsApp number, stored in international format;
  • your email address;
  • the services you selected;
  • the cities you want to visit;
  • your estimated dates and whether they are flexible;
  • the number of travellers;
  • any logistics help you asked for, such as Alipay or WeChat Pay set-up, visa preparation, airport pickup or a local data plan;
  • anything else you chose to tell us in the free-text field;
  • the fact that you ticked the consent box, and when;
  • how you arrived at the site, meaning the referring page and any campaign tags in the link you followed.

We also generate a booking reference and a timestamp, and we record the status of your request as we work on it.

We do not ask for and do not want your passport number, your date of birth, your payment card details, or anything about your health, religion, politics or family. If you send any of it to us anyway, we will not store it in our records.

Why we collect it

To answer your enquiry, to plan and price your trip, to arrange the guide and the logistics you asked for, and to keep a record of what was agreed. For the booking form, the legal basis is your consent, given by ticking the box, together with what is necessary to perform the service you asked us for.

You can withdraw consent at any time. Withdrawing it does not undo anything we did before you withdrew it, and if you withdraw it while a trip is being arranged we may not be able to continue arranging it.

Where it is kept

Booking requests are stored in a database on Cloudflare’s infrastructure, which is also where this website is hosted. The form posts to this same website; it does not hand your details to a third-party form service.

When a request comes in we email ourselves a copy so we notice it. That email goes through Zoho Mail. Messages you send us on WhatsApp, WeChat or email stay in those services, on the phone and in the accounts we run the business from.

Crossing borders. We operate from Shenzhen and Jakarta and our hosting is a global network, so your data will be handled outside Indonesia. UU PDP allows this where the receiving country offers an adequate level of protection or where adequate safeguards are in place. This is one of the points a practitioner should confirm.

How long we keep it

Twenty-four months after we last hear from you, then we delete it. If you ask us to delete it sooner we will, unless we are required to keep something to settle a dispute or a refund claim that is still open — in which case we keep only what that requires, and only until it is closed.

Who else sees it

  • The guide assigned to your trip, who is told your name, how to contact you, and what the trip involves. Nothing more.
  • Cloudflare, which hosts the site and the database.
  • Zoho, which carries our email.

That is the whole list. We do not sell your data, we do not share it for advertising, and we do not use it to build a profile of you.

Cookies and analytics

This site sets no cookies and runs no analytics. There is no tracking pixel, no advertising tag, and no third-party script of any kind. There is nothing here to consent to, which is why you were not asked.

If we ever add anonymous, cookieless visitor counting, we will say so here first.

Your rights

Under UU PDP 27/2022 you can:

  • ask what personal data we hold about you and get a copy of it;
  • have it corrected or completed if it is wrong or out of date;
  • have it deleted or destroyed;
  • withdraw your consent;
  • object to how we are using it, and ask us to restrict that use;
  • ask us to send your data to another provider where that is technically possible;
  • be told if your data is ever exposed in a breach;
  • seek compensation for harm caused by unlawful handling of your data.

To use any of these, message us on any of the channels at the top of this page. We will reply within seven working days. We may ask you something only you would know about your booking, so that we do not hand your details to someone else.

Complaints

If we have not handled your data properly, tell us first and we will try to fix it. You also have the right to complain to the Indonesian data protection authority.

Changes

If this notice changes we will publish the new version here and change the date below. Material changes will be pointed out rather than slipped in.

Version 1, drafted 10 August 2026.

Bahasa Indonesia
Book Now ID