Privacy
Privacy Policy
Terakhir diperbarui: 10 Agustus 2026
CariPembantu.id is a platform that connects employers with domestic workers. We collect as little data as possible to run this service safely.
The data we collect and why
- Account data (email, phone number, hashed password): for authentication and account security.
- Worker data (name, photo, description, service area, salary expectation, skills, experience): for discovery and matching. Some fields are shown publicly according to the Worker's visibility settings.
- Employer data (display or company name, contact details): for the account and for the contact process according to entitlement.
- Identity documents (for example a KTP national ID card, driver's license, or passport used for verification): private by default, held in private storage, and accessible only to authorized internal roles with access recorded in the audit log. Never shown to the public or to employers.
- AI interactions (conversations with the AI Assistant): to help with search. The AI only accesses the data permitted for that request and does not reveal phone numbers, email addresses, identity documents, private addresses, or internal notes.
- Payments (amount, method, gateway reference, invoice): for Employer Subscription billing and Worker promotion. We do not store card details; payment processing is handled by the payment provider.
- Analytics and logs (aggregate usage events, audit logs): for security, accountability, and service improvement.
- Cookies and consent: see Cookie Policy.
AI and privacy
The AI Assistant is subject to the same authorization rules as the rest of the platform. The AI never reveals phone numbers, email addresses, identity documents, private addresses, private verification information, or internal notes, and conversations are not indexed by search engines.
Identity documents and worker photos
Identity documents are always private and kept separate from public Profile photos. Public worker photos appear only under the worker visibility rules already in place. The two use different storage and access models and are never interchanged.
Data sharing
We do not sell personal data. A worker's contact information is released to an employer only when an entitlement (Subscription or credit) allows it, and the release is recorded in the audit log. Service providers (for example payments and storage) receive only the data their function requires.
Storage and security
Passwords are stored as hashes; session tokens are stored as hashes. Identity documents are held in private storage with audited access. We apply security headers, role-based access control (RBAC), and signature verification on payment webhooks. Retention details are set out in our internal documentation.
Your rights
You can access and update your account data, manage Profile visibility (for workers), change your cookie consent at any time, and submit privacy requests through the contact below. Authentication and authorization are always verified on the server — cookie consent is not proof of authorization.
Contact
Permintaan privasi: privacy@caripembantu.id.
This document is a technical foundation for privacy and compliance. It is not legal advice, and it is not a claim of full compliance with any particular regulation. A legal review may be required depending on the applicable jurisdiction and business operations.