PRIVACY POLICY
Privacy Policy
Last updated: 28 August 2026
This policy describes what happens to your information when you visit this website, create an account, place an order, or contact PSWD. The controller of that data is PT Sandi Maulana Juhana, an Indonesian company, trading as PSWD.
- 01
Reading This Site
Reading the public pages — home, services, work, about, contact, and these legal documents — sets no cookie, stores nothing in your browser, and contacts no server other than our own. There is no analytics, no advertising, and no third-party tag of any kind. Fonts are served from this domain rather than from Google.
You do not have to take our word for it. Open your browser's network panel, load any of those pages, and look at the list of hosts.
- 02
Creating An Account
An account is only needed to place and follow an order. We ask for your name, your email address, and a password. Nothing else, and there is no newsletter attached to it.
Sign-in is handled by Firebase Authentication, a Google service. When you submit the form your browser contacts identitytoolkit.googleapis.com directly, and Google processes your email address and password in order to authenticate you. We never see or store your password: it is verified by Firebase and reaches our servers at no point.
Firebase also writes two small databases into your browser's storage (firebaseLocalStorageDb and firebase-heartbeat-database) so that a sign-in survives a page reload. They are cleared when you sign out.
- 03
Cookies
One cookie, and only after you sign in: pswd_session. It holds your signed-in session, it is httpOnly — script on the page cannot read it — it is SameSite=Lax, and it expires after seven days. Signing out deletes it.
That cookie exists to keep you signed in. It is not used to track you, it is not shared with anyone, and there are no advertising, analytics, or profiling cookies on this site.
- 04
The Password Breach Check
When you choose a password we check whether it appears in known public breaches, using the Have I Been Pwned service. Your password is never sent anywhere. It is hashed inside your browser and only the first five characters of that hash leave — a prefix shared by many thousands of passwords, which is not enough to identify yours.
That request also goes through our own server rather than direct from your browser, so your IP address is not disclosed to the service either.
- 05
Placing An Order
When you place an order we record it: an order reference, the package you chose, the price and currency, the payment amounts and their status, the approval code the order was authorised with, your name and your email address, and the timestamps.
We keep this because it is the record of a commercial agreement between us. It is what an invoice, a receipt, a refund, and a tax return are all produced from.
- 06
Paying
Payments are processed by Xendit. When you pay, we send Xendit the amount, the currency, your name, your email address, and the order reference, and you are handed to Xendit's own hosted page to complete the payment.
Your card number, CVV, bank credentials, and e-wallet PIN are entered on Xendit's page and never reach this site. We are told the outcome, the amount, and a payment reference. Xendit is an independent controller of what it collects on its own page, under its own privacy policy.
- 07
Email We Send You
We send transactional email only: address confirmation, password resets, and order and payment notices. There is no marketing email, so there is no list to unsubscribe from.
These are delivered through a third-party SMTP provider, which necessarily processes your address and the content of the message in order to deliver it.
- 08
Rate Limiting And Abuse Prevention
Repeated approval-code attempts are counted so that a code cannot be guessed by brute force. The counter is keyed to your account, not to your IP address, and it holds nothing but a number and an expiry.
- 09
Who Else Processes Your Data
Vercel hosts the site and processes ordinary request data — IP address, user agent, and the URL requested — in order to serve pages and defend against abuse. Google, through Firebase, handles authentication and stores account and order records. Xendit processes payments. Our email provider delivers transactional mail. Have I Been Pwned answers the hashed-prefix breach query.
Each of these is used for the purpose named and nothing else. We do not sell your data, we do not share it for advertising, and we run no profiling on it. Some of these providers operate servers outside Indonesia, which means your data is processed abroad.
- 10
When You Contact Us
If you write to us by email or WhatsApp, we keep what you send: your name, your contact details, and whatever you tell us about your project. We use it to answer you and to prepare a proposal, and for nothing else.
WhatsApp is operated by Meta. Messages you send through it also pass under their terms and their privacy policy, which we do not control.
- 11
Data We Handle During A Project
During an engagement you may give us access to your accounts, and through them to data belonging to your business and your customers. In that data we act on your instructions, as a processor rather than a controller.
We use that access only for the work agreed. Credentials are returned or destroyed at handover, and we do not copy your customer data out of your systems.
- 12
How Long We Keep It
An account and its orders are kept while the account exists. Ask us to delete the account and we will, except for the records attached to a paid order: Indonesian tax and company law requires those to be retained, and that is an obligation rather than a preference.
Correspondence is kept for as long as the working relationship needs it, and then deleted.
- 13
Security
Sessions are carried by an httpOnly cookie that script cannot read and that is checked against Firebase on every request, so signing out everywhere takes effect immediately. Input is validated at every boundary before it reaches storage. Secrets are compared in constant time. Amounts are always recalculated on our server — a price sent by a browser is ignored.
No system is beyond compromise, and anyone claiming otherwise is selling something. If a breach affects your data we will tell you and the authority, rather than wait to be asked.
- 14
Your Rights
Under Law No. 27 of 2022 on Personal Data Protection you may ask what we hold about you, ask us to correct it, ask us to delete it, ask for a copy of it, withdraw consent, and object to how it is used.
Write to sandi@maulanajuhana.com and we will answer. If you are not satisfied with the answer, you may complain to the supervisory authority.
- 15
Children
This site is for businesses commissioning development work. It is not directed at children, and we do not knowingly collect data from anyone under eighteen.
- 16
Changes To This Policy
This policy describes the site as it works today, and the date at the top is the day it was last checked against the code. When what the site does changes, this document is rewritten rather than quietly amended.
If you have any questions about this policy, or want to exercise any of the rights above, write to us at sandi@maulanajuhana.com.