• 1 – Introduction
  • 2 – Who This Policy Applies To
  • 3 – How We Collect Your Personal Data
  • 4 – Types of Personal Data We Collect
  • 5 – How We Use Your Personal Data
  • 6 – Ideku’s Role in Processing Personal Data
  • 7 – Who We Disclose Your Personal Data To
  • 8 – Obtaining and Managing Consent
  • 9 – Cookies and Tracking Technologies
  • 10 – Transfer of Personal Data Outside Singapore
  • 11 – How We Retain Your Personal Data
  • 12 – How We Protect Your Personal Data
  • 13 – Accuracy of Personal Data
  • 14 – Access and Correction
  • 15 – Data Breach Notification
  • 16 – Contacting Us
  • 17 – Changes to This Privacy Policy

Privacy Policy

1 – Introduction

“We”, “Our” or “IDEKU” means Ideku Technology Solution Pte. Ltd. (Singapore company registration number 202214395M), PT IDE INOVASI NUSANTARA (Indonesia), and, where applicable, its related companies involved in providing the IDEKU Services.

We respect the privacy and confidentiality of the personal data of individuals who interact with us in the course of providing our services. We are committed to implementing policies, practices and processes to safeguard the collection, use, disclosure and processing of personal data in compliance with the Singapore Personal Data Protection Act (“PDPA”) 2012.

IDEKU is a technology platform providing point-of-sale (“POS”), QR ordering, kiosk ordering, loyalty and rewards management, customer relationship management (“CRM”), merchant management and related food and beverage (“F&B”) solutions to merchants and their customers.

We have developed this Privacy Policy to assist you in understanding how we collect, use, disclose, process, protect and retain personal data that is in our possession or control.

In this Policy, “personal data” refers to any data, whether true or not, about an individual who can be identified (a) from that data; or (b) from that data and other information to which we have or are likely to have access, but excludes “business contact information” as defined under the PDPA where it is used for business-to-business purposes.

2 – Who This Policy Applies To

Depending on your relationship with us, we may collect or process personal data from different groups of individuals, including:

  • Merchant owners and operators who subscribe to or use IDEKU’s platform and services
  • Merchant staff and authorised users who access and operate the platform on behalf of a merchant
  • End-customers of merchants who place orders, make payments or interact with a merchant’s services through Ideku’s platform, including via QR ordering, kiosk, POS or delivery channels
  • Loyalty programme members who enrol in a merchant’s loyalty or rewards programme administered through IDEKU’s platform
  • Suppliers and business partners who provide goods or services to IDEKU
  • Website visitors who access IDEKU’s website
  • Job applicants who apply for employment or internship opportunities with IDEKU

The type of personal data collected and the purposes for which it is processed may differ depending on your relationship with us and the nature of your interaction with IDEKU’s services.

3 – How We Collect Your Personal Data

We collect personal data when you:

  • Register for or use an IDEKU merchant account or platform
  • Onboard as a merchant or authorised user of the IDEKU platform
  • Place orders, make payments or interact with a merchant’s services through IDEKU’s QR ordering, POS, kiosk or related services
  • Enrol in a merchant’s loyalty or rewards programme administered through the IDEKU platform
  • Visit our website and submit information through our contact or inquiry forms
  • Communicate with us via email, written correspondence, telephone or chat
  • Respond to our direct marketing communications
  • Participate in surveys, promotions or events conducted by us or our business partners

We may also receive personal data from third-party platforms or integration partners, such as food delivery platforms, where such data is shared with us in the course of processing or fulfilling orders on behalf of merchants using our services. Such data is processed for purposes such as order fulfilment, transaction support, service support, troubleshooting, platform security, audit, reconciliation and other purposes necessary to provide and support the IDEKU Services.

We may also collect personal data from other third parties, such as business partners, referrals or publicly available sources, where permitted under applicable law.

4 – Types of Personal Data We Collect

Depending on the nature of your interaction with us, we may collect the following types of personal data:

From merchant owners and authorised users:

  • Name, business contact details, email address and telephone number
  • Business name, business registration details, business address, country and postal code
  • Account registration information, user role and access permissions
  • Authentication information, such as login credentials or password hashes
  • Billing contact details, invoice information, payment status and transaction references
  • Usage and activity records on the IDEKU platform; and
  • Technical support requests, communications and service records

From end-customers of merchants:

  • Name and contact details, such as email address and telephone number
  • Order details and transaction records
  • Delivery or collection details, including delivery address or collection location where applicable
  • Payment-related information, such as payment method, payment status, transaction reference, amount and currency, but not full payment card details unless expressly stated at the point of collection
  • Loyalty programme membership details, points balances and reward redemption records
  • Feedback, preferences and service-related communications; and
  • Device information and technical data relating to the use of ordering, payment or notification services, including device registration tokens used for push notifications where applicable

From loyalty programme members:

  • Name, gender, contact details and membership details
  • Date of birth, birth month or birthday information, where provided for birthday rewards, age-related eligibility or verification purposes
  • Transaction and points history
  • Communication preferences

From website visitors:

  • Technical information such as IP address, browser type, device identifiers, pages visited, referring website, approximate location derived from IP address, and information collected through cookies or similar technologies

We do not collect NRIC, passport or other national identification numbers unless required by law, or unless there is a clear and specific need to accurately establish or verify an individual’s identity to a high degree of fidelity. Where such collection is necessary, we will explain the reason at the point of collection.

5 – How We Use Your Personal Data

We use personal data for one or more of the following purposes:

Platform and service administration:

  • Merchant onboarding, account creation and account management
  • Providing, operating and supporting our POS, QR ordering, kiosk, loyalty, CRM and related services
  • Processing transactions, payments and billing
  • Sending service-related notifications, transactional communications and support updates

Loyalty and rewards:

  • Administering loyalty and rewards programmes on behalf of merchants
  • Tracking points, stamps and reward redemptions
  • Communicating rewards, promotions and programme updates to loyalty members where consent has been given

Improvement and analytics:

  • Analysing platform usage to improve functionality and performance
  • Conducting research, analytics and reporting to support service development
  • Troubleshooting technical issues and providing technical support

Compliance and security:

  • Complying with applicable legal and regulatory requirements
  • Detecting, investigating and preventing fraud, security incidents and other unlawful activity
  • Maintaining platform and data security

Marketing and communications:

  • Where we send marketing communications by telephone, SMS, messaging applications or email, we will comply with applicable consent, unsubscribe, Do Not Call and anti-spam requirements
  • Communicating with merchants, partners and website visitors about our services, updates and promotions

6 – Ideku’s Role in Processing Personal Data

Depending on the context, Ideku may collect, use and disclose personal data for its own business and operational purposes, such as account management, billing, technical support, platform administration, security, analytics and compliance.

Where merchants use Ideku’s services to collect or process personal data of their own customers, the merchant remains responsible for ensuring that it has provided appropriate notification and obtained any required consent from such individuals. Ideku will process such data in accordance with the merchant’s instructions, the applicable service configuration, our Terms of Use, this Privacy Policy and applicable law.

7 – Who We Disclose Your Personal Data To

We may disclose personal data to the following categories of recipients where necessary to provide, support or administer our services:

  • Cloud hosting and infrastructure providers, including cloud storage and computing services
  • Payment service providers, for the purpose of processing payment transactions, including order amounts, currency and payment method information
  • Delivery and logistics service providers, where delivery services are used, including customer name, contact details and delivery address
  • Messaging and communication service providers, including SMS, WhatsApp and email notification providers, for the purpose of sending OTP codes, order updates, transactional messages and announcements
  • Push notification service providers, for the purpose of delivering in-app and device notifications
  • Domain and network service providers
  • Integration partners, including food delivery platforms, through which we may receive order-related data for the purpose of order fulfilment on behalf of merchants
  • Accounting and financial service providers, which may receive invoice information, billing contact details, payment records, transaction summaries, and where appropriate, aggregated or anonymised financial summaries for accounting and reporting purposes.
  • Professional advisors, including auditors, lawyers and accountants
  • Regulatory authorities and law enforcement agencies, where required by applicable law

Where third parties process personal data on our behalf, we will take reasonable steps to ensure that they are subject to appropriate confidentiality, security and data protection obligations.

8 – Obtaining and Managing Consent

Before we collect, use or disclose your personal data, we will notify you of the purposes for which we are doing so. We will obtain your consent where required under the PDPA. We will not collect more personal data than is necessary for the stated purpose.

If you wish to withdraw your consent, you should notify us in writing with reasonable advance notice. We will advise you of the likely consequences of withdrawal. Your withdrawal of consent does not affect the lawfulness of processing that occurred before the withdrawal.

We may rely on deemed consent or exceptions to consent under the PDPA where applicable, including where collection, use or disclosure is required or authorised by law, necessary for legal proceedings, necessary to respond to an emergency, publicly available, or otherwise permitted under the PDPA.

9 – Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect information about your use of our website and platform. Cookies are small text files stored on your device that help us recognise you, remember your preferences and improve your browsing experience.

We may use the following types of cookies:

  • Functional cookies: necessary for the operation of our website and platform, including session management and user authentication
  • Analytics cookies: used to understand how visitors interact with our website and to improve its performance and content
  • Marketing cookies: used to understand the effectiveness of our marketing campaigns and to provide relevant content or advertisements, where permitted by applicable law. (Only if this is applicable).

Most session cookies are automatically deleted when you close your browser.

10 – Transfer of Personal Data Outside Singapore

IDEKU operates across multiple jurisdictions. Personal data collected through the IDEKU Services may be transferred to, stored or processed in countries other than the country in which it was collected, including in connection with cloud hosting, payment processing, messaging services, technical support or other third-party service providers. Where personal data is transferred outside Singapore, we will take reasonable steps to ensure that such personal data receives a standard of protection comparable to that provided under the PDPA, including by entering into contractual arrangements with the receiving party where required.

11 – How We Retain Your Personal Data

We maintain a data retention policy that sets out retention periods for personal data in our possession or control, including personal data stored in electronic systems, platform records and other records.

We will dispose of or destroy such documents containing your personal data in a proper and secure manner when the retention limit is reached.

In general, we retain personal data associated with user accounts and memberships for as long as the account or membership remains active and for a reasonable period thereafter, unless a specific retention period is required or permitted by applicable laws, regulatory obligations, audit, accounting, dispute resolution, security or legitimate business purposes.

Where personal data is no longer required for business or legal purposes, or where an account has remained inactive for an extended period, such data will be securely deleted or anonymised in accordance with our data retention policy.

12 – How We Protect Your Personal Data

We have implemented appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction.

We restrict access to personal data to authorised personnel on a need-to-know basis. Where we engage third-party service providers to process personal data on our behalf, we take reasonable steps to ensure that they have implemented adequate security and data protection measures.

Such measures may include access controls, authentication controls, system monitoring, encryption or other safeguards where appropriate, staff confidentiality obligations and vendor due diligence.

13 – Accuracy of Personal Data

We take reasonable steps to ensure that personal data we hold is accurate, complete and up to date. If you believe that the personal data we hold about you is inaccurate or incomplete, you may contact us to request a correction.

14 – Access and Correction

You may write to us to request access to, or correction of, personal data that we hold about you. We will respond to your request within 30 days of receipt, or notify you if additional time is required. We may charge a reasonable fee for processing access requests.

Before we provide access to personal data, we may need to verify your identity. We may decline an access or correction request where permitted or required under applicable law.

15 – Data Breach Notification

In the event of an actual or suspected data breach involving personal data under our possession or control, we will take reasonable steps to assess, contain and remediate the incident. Where the incident is assessed to be a notifiable data breach under the PDPA or other applicable data protection laws, we will notify the relevant regulator and/or affected individuals in accordance with the applicable notification requirements and timelines.

16 – Contacting Us

If you have any questions, feedback or complaints about this Privacy Policy or how we handle your personal data, please contact our Data Protection Officer (DPO) at:

Email: [email protected]

Your query or complaint should include your full name, contact information and a brief description of the matter. We will treat all queries and complaints seriously, in confidence and within a reasonable timeframe.

17 – Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements or business practices. We will notify you of material changes by posting the updated Policy on our website. Please check this page periodically for updates.

Last updated: [26 Jun, 2026]

Chat with us
on WhatsApp