Privacy Policy
Last updated: 6 October 2026
This policy explains what personal data Dezlio processes, why, who it is shared with, how long it is kept, and what rights you have. We try to write it to match what our systems actually do, and it refers to Indonesian Law No. 27 of 2022 on Personal Data Protection.
1. Who we are and our role
For your account data (name, email, password, sign-in history) we are the data controller.
For guest data that an accommodation enters, or that a guest fills in on a property’s booking form, the accommodation is the controller and we are the processor, acting on its behalf and its instructions. A guest who wants to use their rights over this data should contact the accommodation first; we help it meet them.
2. The data we process
- Account: name, email address, password (kept only as a one-way hash, which cannot be read back), when the email was confirmed, last sign-in, and your agreement to the Terms of Service with its version.
- Sessions and devices: a description of the device or browser (for example "Chrome on Windows") for your list of sessions, and a push notification token if you use the mobile app.
- Security: IP address and request identifier in security and audit logs and rate limiting, failed sign-in attempts, and a record of important actions (who did what, and when).
- Business data you enter: organizations, team members and roles, properties, rooms, rates, photos, API keys (kept as a hash), and sales-channel calendar links (kept encrypted).
- Guest data: name, email, phone number, stay dates, number of guests, booking notes, and the history of booking status and cancellation.
- Payments and payouts: amounts, status and payment references. Card numbers never pass through our systems; payments are processed by the payment provider. For payouts: bank code, account holder name, the last four digits of the account number, and the account number itself, which is stored encrypted.
- Communications: the service emails we send (confirmations, reset links, security notices, booking notices) and their delivery records (sent, failed, bounced).
3. Where the data comes from
From you; from guests who fill in a booking form on a property’s site; from the payment provider (payment status); from the email provider (delivery and bounce reports); and from our own systems (security and audit logs).
4. What we use it for, and on what basis
- To provide the service you ask for, including processing bookings, payments and payouts (performance of the agreement).
- To keep things secure and prevent fraud and abuse: rate limiting, account locking, audit logs (our legitimate interest and that of our users).
- To meet legal duties, including bookkeeping and lawful requests from authorities.
- To send the service emails needed to use an account. We send no marketing email without your consent.
- To keep the service reliable, for example monitoring technical failures without including personal content.
We do not sell personal data and do not use it for advertising or profiling.
5. Who it is shared with
- The accommodation: guest data goes to the property the guest booked, and team members’ data to the owners of the same organization.
- Our team: our operator staff can see account names and emails and the organization information needed for support, account approval and payouts; what they do is logged. For payouts, operators see the bank details needed for the transfer (the full number only after an extra password check, and each look is logged). They do not open a property’s booking contents or guest data as part of this work.
- Infrastructure and service providers who work for us: the server and database hosting provider; Amazon Web Services (sending email); Cloudflare (storing property photos); the payment provider (currently Midtrans); and device push notification services if you use the mobile app. They process data only to serve us.
- Google Fonts, only if a property’s website chooses a Google font in its WordPress plugin: the browser of that site’s visitor fetches the font from Google’s servers, and Google receives the visitor’s IP address. That is the choice and responsibility of that site; the plugin loads nothing from Google when no Google font is in use.
- Authorities, where the law requires; and whoever takes over our business, bound to protect this data at least as well.
6. Transfers outside Indonesia
Some of our providers may process data outside Indonesia. We choose providers that apply adequate protection and bind them with data processing agreements.
7. Cookies
The dashboard uses only two necessary session cookies to keep you signed in (httpOnly, unreadable by page scripts). We use no advertising, tracking or third-party analytics cookies. A property’s website that embeds our widget or plugin has its own cookie policy.
8. How long we keep it
- Account and business data: while your account is active.
- Sign-in sessions: end after 30 days of not being used or when you sign out; inactive push devices are removed after 90 days; notifications are deleted after 90 days.
- When you ask to delete your account or an organization: there is a grace period (30 days) that can be cancelled. After it the account is anonymised: name, email and password are replaced by empty values that cannot be restored. On deleting an organization, photos and files are deleted, guests and properties are anonymised, API keys are revoked, and invitations and notifications are deleted.
Records we must keep for bookkeeping, disputes and security (bookings and payments, amounts, status, audit records) remain for as long as the law requires, without your name. Some free-text content in them cannot yet be erased automatically and may still hold personal data: account holder names on past payouts, notes and reasons once written on bookings, and IP addresses in audit records. We are preparing a way to erase them at the end of the retention period; until then you may ask us through the contact below, and we will tell you whether and when it can be done.
9. Security
Connections to Dezlio use HTTPS. Passwords are stored as hashes (Argon2id); bank account numbers and calendar links are stored encrypted; API keys are stored as hashes. Access is limited by role, each organization’s data is separated at the database level, and important actions are logged. No system is perfectly secure; if a breach of personal data affects you, we tell you and the authorities within the time the law sets.
10. Your rights
Under the applicable law you may be informed about how your data is processed; access and obtain a copy of your data; correct what is wrong; ask for deletion or destruction; withdraw consent; object to or ask to restrict processing; and ask for your data in a common format where possible.
What you can do yourself today: download a copy of your account data (My account, "My data"), change your password, end sessions on other devices, and ask to delete your account or an organization. For anything else, contact us at the address below; we answer as soon as we can and within the time the law sets.
11. Children
Dezlio is for adult operators of accommodation. We do not knowingly collect children’s data for accounts. Children’s guest data that an accommodation enters is the accommodation’s responsibility as controller.
12. Changes to this policy
If this policy changes materially we tell you by email or in the dashboard before it applies. The version in force is the one dated above.
13. Language
This policy is made in Indonesian with an English translation. If they differ, the Indonesian version prevails.
14. Contact
The operator’s details and contact address are on dezlio.com.