Last updated: 2026-05-23
This Privacy Policy explains how Zapi (operated by Zeative Labs) collects, uses, stores, and protects your personal data as a Platform user. This policy is prepared in accordance with Law No. 27 of 2022 on Personal Data Protection (the PDP Law) of the Republic of Indonesia.
The personal data controller for the data you provide is Zeative Labs, domiciled in the Republic of Indonesia. For all matters relating to personal data protection, you can contact [email protected].
When you sign up and use the Platform, we collect: • Identity: name, email, avatar, provider ID from OAuth (Google/GitHub). • Credentials: API key (hashed, not stored in plaintext). • Account metadata: registration timestamp, last seen, subscription tier. • Billing data (for paid tiers): invoice recipient name, tax ID/NPWP (optional), payment history via a third-party payment gateway. • Activity logs: IP address, user agent, endpoint accessed, timestamp, status code, latency.
• Passwords — we use OAuth, so we never receive your password. • Credit card numbers — processed directly by the payment gateway, never touching Zapi servers. • API request/response body content — we store only metadata (endpoint, status, latency), not the payload. • Cross-site tracking outside the Platform.
In accordance with Article 20 of the PDP Law, we process your personal data based on: • Explicit consent when you agree to the Privacy Policy and Terms of Service. • Performance of the contract between you and Zapi (providing the API service). • Legal obligations (e.g. tax recordkeeping, audits). • The Controller's legitimate interest in preventing fraud and abuse and maintaining Platform security.
Personal data is processed for the following purposes: • Authentication and authorization of Platform access. • Billing, invoicing, and financial administration. • Tracking quota and rate limits per account. • Detecting and preventing abuse, fraud, and AUP violations. • Transactional communications (billing notifications, service changes, security alerts). • Internal research and improving the Platform's quality (in aggregate, non-identifying form).
We retain personal data only for as long as necessary: • Account data: for as long as the account is active + 90 days after deletion for auditing and disputes. • Activity logs: 30 days in raw form, then rolled up into aggregates without identifiers. • Billing data & invoices: 10 years in accordance with Indonesian tax obligations. • Once the retention period ends, data is permanently deleted or anonymized.
We do NOT sell personal data. Data is only shared with: • Infrastructure providers (cloud hosting, CDN, database) bound by equivalent confidentiality agreements. • The payment gateway (MustikaPayment) to process paid-tier payments. • Analytics providers (Google Analytics, Microsoft Clarity) for website usage metrics, with IP anonymization enabled. • Competent legal authorities pursuant to a court order or valid regulatory obligation.
Some of our infrastructure may be located outside the territory of the Republic of Indonesia (e.g. the Singapore/Tokyo regions). Transfers are carried out with assurances of a level of protection equivalent to the PDP Law, through standard contractual clauses or recognized security certifications (ISO 27001, SOC 2, etc.).
We use cookies for: • Session authentication (JWT token). • User preferences (theme, locale). • Basic analytics (Google Analytics, Microsoft Clarity) to understand website usage. We do NOT use advertising cookies or retargeting. You can reject analytics cookies through your browser settings; session cookies are required for the Platform's functionality.
In accordance with Articles 5–13 of the PDP Law, you have the right to: • Obtain information about the personal data being processed. • Access and obtain a copy of your personal data (data export). • Correct inaccurate personal data. • Erase personal data (right to erasure) — your account, along with API keys & logs, will be deleted within 7 business days. • Withdraw your consent to processing. • Object to certain processing. Requests can be submitted via the dashboard or by email to [email protected] with the subject "PDP REQUEST".
We apply reasonable technical and organizational measures: • TLS 1.2+ encryption for all communications. • At-rest encryption for the production database. • Hashing of API keys with a cryptographically strong algorithm (bcrypt/argon2). • Role-based access control (RBAC) for internal team access. • Logging & audit trails for changes to sensitive data. • Periodic rotation of credentials and secrets. However, no system is 100% secure — users must also safeguard their own credentials.
In accordance with Article 46 of the PDP Law, in the event of a personal data protection failure that poses a risk to data subjects' rights, we will: • Notify affected data subjects within 3x24 hours of becoming aware. • Report to the PDP Authority within the timeframe prescribed by regulation. • Explain the type of data affected, mitigation steps, and recommended actions.
The Platform is not intended for children under the age of 18. We do not knowingly collect data from minors. If you become aware of any minor's data that has entered the Platform without valid guardian consent, please report it to [email protected] so it can be deleted promptly.
This Privacy Policy may be updated from time to time to reflect changes in practices, law, or Platform features. Material changes will be notified via email at least 30 days before they take effect. The last update date is shown at the top of this document.
Questions, data access requests, or privacy-related complaints can be submitted to [email protected] with the subject "PDP REQUEST" for requests related to the PDP Law. If you believe your PDP rights have not been fulfilled, you also have the right to file a complaint with the Personal Data Protection Authority of the Republic of Indonesia.