ForEach › Privacy Policy

Privacy Policy

1. Who We Are

This Privacy Policy is issued by PT Fondasi Inovasi Digital ("ForEach," "we," "us," "our"), an Indonesian limited liability company domiciled in Bandung, Indonesia, operator of the ForEach platform (Pilates studio-management software and Kos-kosan boarding-house-management software) at foreach.id and its subdomains.

Contact for all privacy matters: [email protected].

2. Scope

This Policy covers:

  • The ForEach marketing site (foreach.id) and its visitors.
  • ForEach's product applications (Pilates, Kos-kosan) and the people who use them: Studio/Property Owners (our direct paying customers), their staff, and their Members/Tenants (end-customers of the studio or property, not of ForEach directly).
  • The ForEach Internal Console, used by ForEach staff to manage prospective and active studio/property accounts.

3. Two Roles ForEach Plays: Controller and Processor

This distinction matters, so we're stating it plainly rather than burying it in legal boilerplate:

  • When we hold data about a Studio/Property Owner's own account (business name, owner contact details, billing records with ForEach) — ForEach is the data controller. We decide why and how that data is processed, and this Policy applies to it directly.
  • When we hold data a Studio/Property Owner has entered about their own Members or Tenants (customer names, phone numbers, booking history, rental records, etc.) — the Studio/Property Owner is the data controller, and ForEach acts as their data processor, processing that data only as needed to run the software they've subscribed to. If you are a gym/studio member or a boarding-house tenant with a question about your data, your studio or property manager is your first point of contact — they control that relationship; we secure the systems it runs on. We will still respond to any inbound query sent to us directly and route it to the relevant studio/property where needed.

4. What We Collect

4.1 Studio/Property Owner accounts (ForEach is controller)

Business name, owner/staff name, email, phone, subscription/billing records (via the ForEach Internal Console), and platform usage/support history.

4.2 Members and Tenants (Studio/Property is controller, ForEach processes on their behalf)

FieldPilates (Customer/Member)Kos-kosan (Tenant)
NameYesYes
PhoneYes (unique identifier)Yes (unique identifier)
EmailOptionalOptional
GenderYes (required, default recorded)Optional
Date of birthOptionalOptional
AddressOptionalOptional
Height / weightOptional (studio-entered)
Medical history (free text)Optional, studio-entered
Booking / attendance / payment historyYesYes (rental/payment history)
Payment proof imagesYesYes

Members who use the self-service Member Portal (Pilates) set their own login (email + password only — we do not offer or use Google/social sign-in). Studios may also enter this data on a member's behalf at front-desk registration.

We flag this honestly: date of birth, gender, and (for Pilates) medical history fall into categories Indonesia's Personal Data Protection Law (UU PDP 27/2022) treats with heightened care ("specific personal data" for health-related fields). These fields are currently optional and studio-entered, gated behind staff permissions, but ForEach has not yet built a dedicated consent-capture flow for them at the point of collection. Closing this is a near-term priority, not deferred indefinitely.

4.3 Site visitors (foreach.id)

We use Plausible Analytics, self-hosted, cookieless — no Google Analytics, no advertising pixels, ever. It records aggregate page-view/referrer data, not individual visitor profiles, and sets no tracking cookie. A first-party, functional cookie may be set to remember your language preference (EN/ID) on the product apps; this is not used for tracking.

5. Why We Process Data (Legal Basis)

  • Contract necessity — to provide the software service a Studio/Property Owner has subscribed to (running bookings, payments, member communication).
  • Consent — for optional fields (email, date of birth, medical notes) and for marketing communications a person has opted into.
  • Legitimate interest — service security (bot defense, fraud prevention, abuse monitoring), product improvement, and responding to support requests.
  • Legal obligation — bookkeeping/tax records where Indonesian law requires retention.

6. Who We Share Data With

We do not sell personal data. We share it only as needed to run the service, with the following processors:

ProcessorPurposeWhat's shared
Midtrans / XenditPayment processing (studio-opted-in only, off by default)Transaction amount + order ID. The studio's own merchant credentials are used — ForEach never holds customer funds. No member name/phone/email is sent to the gateway.
Meta (WhatsApp Cloud API)Booking reminders (studio-opted-in only, off by default)Member phone number + templated message content (studio name, session time).
ResendTransactional email (approvals, invites, password resets, receipts)Recipient email address + message content.
CloudflareR2 file storage (payment/registration proof images), Turnstile bot defense, Pages hosting, Tunnel routingUploaded files; request metadata for bot-defense scoring. Cloudflare's infrastructure is global — this is a cross-border data transfer (see §7).
Plausible Analytics (self-hosted)Aggregate site-traffic analyticsPage views, referrers — no individual-level data.

We do not use any other third-party analytics, advertising, or data-broker service.

7. International Data Transfer

Our primary application servers and databases run on infrastructure we operate ourselves, physically located in Indonesia. However, uploaded files (payment proofs, registration documents) are stored on Cloudflare R2, whose network operates globally — meaning some data may be processed or transiently routed outside Indonesia. Under UU PDP 27/2022, cross-border transfer requires either an adequacy finding for the destination country, appropriate safeguards (such as standard contractual clauses with the processor), or the data subject's consent. This disclosure is that consent basis, pending a full contractual review with Cloudflare.

8. How Long We Keep Data

We're stating this plainly, including where we fall short today:

  • Abandoned registration requests (never approved) and their proof images are automatically purged after 90 days.
  • Active member/tenant/customer records, payment history, and staff accounts do not yet have a defined automatic retention or deletion schedule. Deletion today happens on request (see §9) or via manual removal by studio staff, not on a timer. Financial/payment records (proof-of-payment images, transaction logs) are deliberately not auto-purged, since they double as audit records a studio may need for bookkeeping.
  • Backups: daily, retained 7 days, stored on the same infrastructure as production (no offsite backup copy at this time).

We will set an explicit retention schedule for each data category as our studio base grows beyond pilot scale, rather than leave this open-ended.

9. Your Rights

Under UU PDP 27/2022, if we (or a studio using our platform, via us) hold your personal data, you have the right to:

  • Access the personal data held about you.
  • Request correction of inaccurate data.
  • Request deletion or restriction of processing, subject to legitimate retention needs (e.g., financial records).
  • Withdraw consent for anything processed on a consent basis.
  • Request a copy of your data in a portable format.
  • Object to processing based on legitimate interest.
  • Lodge a complaint with Indonesia's personal-data-protection supervisory authority.

To exercise any of these rights, contact [email protected] (for Studio/Property Owner account data) or your studio/property directly (for member/tenant data, since they are the controller — we'll assist and route as needed either way).

10. Children

Our services are intended for adults (18+) acting in a business or personal-service context (studio owners, staff, gym/studio members, boarding-house tenants). We do not knowingly collect data from children. We do not currently enforce an age gate in the product — this is a known gap we're tracking.

11. Security

We use industry-standard measures including encrypted credential storage (bcrypt for passwords, AES-256-GCM for stored payment-gateway credentials), role-based access control (studio staff see only what their role permits), bot defense (Cloudflare Turnstile) on public-facing forms, and account lockout after repeated failed logins. No system is perfectly secure; we will notify affected parties and the relevant authority as required by law in the event of a data breach.

12. Cookies

See §4.3. We use no advertising or cross-site tracking cookies. A functional locale-preference cookie may be set on product apps only (not the marketing site).

13. Changes to This Policy

We'll post the effective date of any material change here and, where required, notify Studio/Property Owners directly.

14. Contact

PT Fondasi Inovasi Digital
Bandung, Indonesia
Email: [email protected]


Read our Terms of Service →