Linza legal

Privacy Policy

Pre-production privacy framework for Linza accounts, Discovery, storefronts and pseudonymous usage analytics.

PLACEHOLDER LEGAL COPY — the Linza owner and qualified Indonesian legal counsel must review, replace and approve this text before production launch.
Draft effective date
31 July 2026
Document version
Draft 0.2
Language
EnglishBahasa Indonesia

This page includes a print-optimized version.

Contents

  1. 1. Data Linza may process
  2. 2. Search queries and product analytics
  3. 3. Controller and processor roles
  4. 4. Why data is used
  5. 5. Retention
  6. 6. Sharing and subprocessors
  7. 7. Rights, security and contact
Contents
  1. 1. Data Linza may process
  2. 2. Search queries and product analytics
  3. 3. Controller and processor roles
  4. 4. Why data is used
  5. 5. Retention
  6. 6. Sharing and subprocessors
  7. 7. Rights, security and contact

1. Data Linza may process

Account and organization data may include names, business email addresses, role membership, profile settings, audit events and merchant-provided storefront content.

Discovery and storefront analytics may include a random browser-session identifier, language, entry source, page and entity interactions, coarse area, search-result counts and route or message actions. Linza does not put precise device location, email, phone or arbitrary metadata into Discovery analytics events.

A signed-in Discovery account may store saved places or products, personal lists, followed places, notification preferences and demand or report history. Optional contact email on a demand request or report is stored only when the visitor explicitly enables and supplies that field.

2. Search queries and product analytics

Discovery may retain both submitted search text and a normalized search intent (the search_query analytics dimension). Search text can accidentally contain personal information, so the raw text has a shorter retention period.

These product analytics events cover aggregate impressions and opens. Merchants receive only branch/place-scoped totals and trends; merchant analytics do not expose consumer user IDs, browser-session IDs, email addresses, contact details or individual search histories.

3. Controller and processor roles

For merchant account, catalog and storefront administration, the merchant generally acts as data controller and Linza generally acts as processor.

For account security, platform operations, abuse prevention and service diagnostics, Linza may act as an independent controller. Final role allocation requires Indonesian legal review.

4. Why data is used

Data is used to operate accounts, secure tenant boundaries, publish storefronts, improve kiosk usability, produce merchant analytics and diagnose failures.

5. Retention

Raw Discovery analytics events are scheduled for deletion after 365 days. Raw search-query text is scheduled to be erased after 90 days. Normalized intent and daily aggregate rollups may be retained while commercially useful. Final deletion-rights wording still requires legal approval.

6. Sharing and subprocessors

Production copy must identify hosting, email, database, monitoring and other subprocessors. Linza does not sell kiosk visitor profiles in this placeholder policy.

7. Rights, security and contact

The final policy must explain applicable rights, contacts and complaint channels. Linza uses role controls, tenant scoping, audit records and restricted public writes.

There is no self-service account deletion control in the current runtime. A production support/contact and verified deletion process must be approved and published before launch. Scout field evidence and source media remain private operational data; public place pages use a separate approved projection.

This document is a product implementation placeholder and is not legal advice.

Terms of ServicePrivacy PolicyCookie & Analytics NoticeBack to Linza