Lewih Glow Privacy Policy
Last updated: 19 July 2026
1. About This Policy
Glow is Lewih's salon-management product and is marketed as Lewih Glow. This policy explains how PT GUSSY INOVASI MANDIRI ("We"/"Us"), the business entity operating Lewih, collects, uses, stores, and protects personal data in connection with that service at glow.lewih.com and app.glow.lewih.com.
2. Our Role Over Data
- Account data (name, email, credentials of the Account Owner and Users): We act as the data controller.
- Tenant Data (salon customer data, employee data including payroll, transactions, inventory): the tenant (salon owner) is the data controller; We act as the data processor, processing that data solely to provide the service on the tenant's instructions.
- Tenants are responsible for obtaining any consent required from their customers and employees before entering their personal data into the service.
3. Data We Collect
Provided directly by Users:
- Registration data: name, email address, password (stored as a hash, never as plain text).
- Business profile data: salon name, locations/branches, operational settings.
- Tenant Data entered during use: customer data (name, phone number, optional email, visit history, loyalty points), transaction and payment data, inventory data, appointment data, and employee payroll data (salary, PPh21 withholding, BPJS enrollment).
- Subscription payment proofs uploaded from the Billing page.
Collected automatically:
- Reasonable technical data for security and operations: IP address, access times, and error logs.
- Login session tokens and preferences (e.g. language, active location) stored in the browser (cookies/localStorage) — used for application functionality, not ad tracking.
- Cloudflare Turnstile anti-bot verification on the registration page.
- Product analytics in the application (
app.glow.lewih.com) and registration-button click tracking on this site (glow.lewih.com): We use GoatCounter, an open-source analytics tool that We self-host on the same Fly.io infrastructure as the application — not a third party. This analytics does not use cookies, does not store full IP addresses (the IP is hashed with a salt that rotates and is discarded every 24 hours, solely to deduplicate unique visits within the same day), and never includes names, customer data, transaction data, or any free-text content — only anonymous counts such as registration button clicks, completed registration/onboarding steps, and application features used. Raw data is retained for a maximum of 12 months. The Account Owner may disable application analytics at any time via Salon Settings → Policies.
We do not collect: payment card data (payment is made via manual bank transfer).
4. How We Use Data
We use data to:
- Provide and operate the service (authentication, Tenant Data storage, real-time sync, receipt printing).
- Verify registrations (email verification, anti-bot) and subscription payments.
- Send transactional email (account verification, subscription notices). We do not send marketing email without consent.
- Maintain security: rate limiting, access logs, abuse detection.
- Comply with applicable legal obligations.
We do not sell personal data, and do not use Tenant Data for any purpose beyond providing the service.
5. Storage & Data Transfers
- Application data is stored on Fly.io cloud infrastructure with servers located in Singapore. By using the service, Users understand that data is processed outside Indonesia with the protections described in this policy.
- Every tenant is isolated: all data carries a tenant identity and server-side access rules prevent tenants from accessing other tenants' data.
- Cross-role access (Owner, Manager, Cashier, Beautician, Finance) is restricted server-side according to role and branch assignment.
- Traffic is encrypted with TLS/HTTPS. Administrative access safeguards are applied according to the operating environment's configuration.
- We perform backups under the applicable operational policy and continue to test the recovery procedure.
6. Third Parties (Subprocessors)
| Party | Function | Data touched |
|---|---|---|
| Fly.io | Application & database hosting | All application data |
| Cloudflare (Turnstile) | Anti-bot verification at registration | Technical browser signals on the sign-up page |
| ZeptoMail (Zoho) | Transactional email delivery | Email addresses, transactional email content |
7. Data Retention
- Tenant Data is kept while the tenant is active, including while a tenant sits on the Free plan after a subscription ends (features locked, data not deleted).
- Tenant deletion: the Account Owner may request tenant deletion via support@lewih.com. After identity verification, We will delete or anonymize Tenant Data from active systems and handle backup copies according to the backup rotation cycle and applicable legal obligations. We will confirm the request's scope and estimated completion time.
- Technical logs are retained only as long as needed for security, troubleshooting, incident investigation, and legal obligations. The operational retention period will be documented and reviewed before production launch.
8. Data Subject Rights
Under Indonesia's Personal Data Protection Law (Law No. 27 of 2022), data subjects may request access to, correction of, or deletion of their personal data, and may withdraw processing consent.
- For account data: contact support@lewih.com.
- For salon customer/employee data stored as Tenant Data: submit the request to the salon concerned as the data controller; We will assist the tenant in fulfilling it.
9. Children
The service is intended for business operators and is not directed at minors. We do not knowingly collect children's personal data.
10. Changes to This Policy
Material changes to this policy will be announced via the registered email or an in-app notice before taking effect, with an updated "last updated" date.
11. Contact
Privacy questions or requests: support@lewih.com