Lewih Glow Privacy Policy

1. About This Policy

Glow is Lewih's salon-management product and is marketed as Lewih Glow. This policy explains how PT GUSSY INOVASI MANDIRI ("We"/"Us"), the business entity operating Lewih, collects, uses, stores, and protects personal data in connection with that service at glow.lewih.com and app.glow.lewih.com.

2. Our Role Over Data

  1. Account data (name, email, credentials of the Account Owner and Users): We act as the data controller.
  2. Tenant Data (salon customer data, employee data including payroll, transactions, inventory): the tenant (salon owner) is the data controller; We act as the data processor, processing that data solely to provide the service on the tenant's instructions.
  3. Tenants are responsible for obtaining any consent required from their customers and employees before entering their personal data into the service.

3. Data We Collect

Provided directly by Users:

Collected automatically:

We do not collect: payment card data (payment is made via manual bank transfer).

4. How We Use Data

We use data to:

  1. Provide and operate the service (authentication, Tenant Data storage, real-time sync, receipt printing).
  2. Verify registrations (email verification, anti-bot) and subscription payments.
  3. Send transactional email (account verification, subscription notices). We do not send marketing email without consent.
  4. Maintain security: rate limiting, access logs, abuse detection.
  5. Comply with applicable legal obligations.

We do not sell personal data, and do not use Tenant Data for any purpose beyond providing the service.

5. Storage & Data Transfers

  1. Application data is stored on Fly.io cloud infrastructure with servers located in Singapore. By using the service, Users understand that data is processed outside Indonesia with the protections described in this policy.
  2. Every tenant is isolated: all data carries a tenant identity and server-side access rules prevent tenants from accessing other tenants' data.
  3. Cross-role access (Owner, Manager, Cashier, Beautician, Finance) is restricted server-side according to role and branch assignment.
  4. Traffic is encrypted with TLS/HTTPS. Administrative access safeguards are applied according to the operating environment's configuration.
  5. We perform backups under the applicable operational policy and continue to test the recovery procedure.

6. Third Parties (Subprocessors)

7. Data Retention

  1. Tenant Data is kept while the tenant is active, including while a tenant sits on the Free plan after a subscription ends (features locked, data not deleted).
  2. Tenant deletion: the Account Owner may request tenant deletion via support@lewih.com. After identity verification, We will delete or anonymize Tenant Data from active systems and handle backup copies according to the backup rotation cycle and applicable legal obligations. We will confirm the request's scope and estimated completion time.
  3. Technical logs are retained only as long as needed for security, troubleshooting, incident investigation, and legal obligations. The operational retention period will be documented and reviewed before production launch.

8. Data Subject Rights

Under Indonesia's Personal Data Protection Law (Law No. 27 of 2022), data subjects may request access to, correction of, or deletion of their personal data, and may withdraw processing consent.

  1. For account data: contact support@lewih.com.
  2. For salon customer/employee data stored as Tenant Data: submit the request to the salon concerned as the data controller; We will assist the tenant in fulfilling it.

9. Children

The service is intended for business operators and is not directed at minors. We do not knowingly collect children's personal data.

10. Changes to This Policy

Material changes to this policy will be announced via the registered email or an in-app notice before taking effect, with an updated "last updated" date.

11. Contact

Privacy questions or requests: support@lewih.com