Privacy policy

Last updated: 22 July 2026

This Privacy Policy explains how Treelogy collects, uses, shares and protects your personal data when you visit treelogy.com (the “Site”), purchase our products, subscribe to our communications, or otherwise interact with us.

1. Who is responsible for your data

The data controller is:

PT. Treelogy Regenerative Moringa
Jl. Bumbak, Kerobokan, Kec. Kuta Utara, Kabupaten Badung, Bali 80361, Indonesia
Privacy contact: privacy@treelogy.com

For card payments processed via Stripe, payment transaction data is processed by our affiliate Treelogy Premium Organic Moringa Pte. Ltd., 68 Circular Road #02-01, Singapore (049422), acting as a data processor (prosesor data pribadi) on the documented instructions of PT. Treelogy Regenerative Moringa, which remains the data controller for all personal data covered by this Policy. All rights requests, including those relating to Stripe card payments, should be directed to privacy@treelogy.com.

We process personal data in accordance with Indonesian Law No. 27 of 2022 on Personal Data Protection (UU PDP) and, where applicable to customers in the European Economic Area or United Kingdom, the General Data Protection Regulation (GDPR / UK GDPR).

2. What personal data we collect

  • Identity and contact data: name, email address, phone number, shipping and billing address.
  • Order and transaction data: products purchased, order history, subscription details (product, variant, frequency, status), payment method type, transaction amounts and currency. We do not store your full card number — payment credentials are collected, tokenized and stored by our payment processors (Xendit and Stripe).
  • Account data: login credentials, preferences, and subscription management history.
  • Device and usage data: IP address, browser and device type, pages visited, and interactions with the Site, collected via cookies and similar technologies (see Section 8).
  • Communications: messages you send us by email, WhatsApp, chat or social media, and your marketing preferences.
  • Health-related information (optional): if you voluntarily tell us about health goals or conditions (e.g., in a consultation or review), we treat this as sensitive data and process it only with your consent.

We collect this data directly from you, automatically through the Site, and from our service providers (e.g., payment confirmation from Xendit or Stripe, delivery status from couriers).

3. Why we process your data and on what legal basis

Purpose Legal basis (UU PDP / GDPR)
Processing and delivering your orders; managing your subscription (including recurring billing, renewal reminders, pause/cancel requests) Performance of a contract
Payment processing, fraud prevention and chargeback handling Performance of a contract; legitimate interests; legal obligation
Customer service and responding to your requests Performance of a contract; legitimate interests
Marketing emails, SMS/WhatsApp and personalized offers Consent (you can withdraw at any time via the unsubscribe link or by contacting us)
Analytics, Site improvement and security Legitimate interests
Tax, accounting and regulatory compliance Legal obligation

We do not use your personal data for automated decision-making that produces legal or similarly significant effects without human involvement.

4. Who we share your data with

We share personal data only with parties who need it to provide our services:

  • Shopify — our e-commerce platform, which hosts the Site and processes orders and account data;
  • Xendit — payment processing for Indonesian payment channels (e-wallets, virtual accounts, QRIS, cards), including tokenized storage of recurring payment credentials for subscriptions;
  • Stripe (via Treelogy Premium Organic Moringa Pte. Ltd.) — card payment processing, including tokenized storage of recurring payment credentials for subscriptions;
  • Shipping and courier partners — to deliver your orders;
  • Email and messaging providers (e.g., Klaviyo) — to send transactional and, with your consent, marketing communications;
  • Analytics and advertising partners (e.g., Google, Meta) — subject to your cookie choices (see Section 8);
  • Professional advisers and authorities — where required by law, legal process, or to protect our rights.

We do not sell your personal data. Where a provider processes data on our behalf, we put in place contractual protections consistent with UU PDP and, where applicable, GDPR Article 28.

5. International data transfers

Your data may be transferred to and processed in countries other than your own (including Singapore, the United States and other countries where our service providers operate). Where data is transferred out of Indonesia, we do so in accordance with UU PDP’s cross-border transfer requirements (ensuring an adequate level of protection, appropriate safeguards, or your consent where applicable). Where data of EEA/UK residents is transferred outside the EEA/UK, we rely on adequacy decisions or Standard Contractual Clauses (SCCs) and equivalent UK mechanisms.

6. How long we keep your data

  • Account data: for as long as your account is active, and up to 2 years after your last activity;
  • Order, transaction and tax records: up to 10 years, as required by Indonesian tax and accounting regulations;
  • Subscription mandate records: for the life of the subscription plus the period needed to handle disputes and chargebacks;
  • Marketing data: until you unsubscribe or withdraw consent, plus a short suppression record to honor your opt-out;
  • Customer service communications: up to 2 years after resolution.

When data is no longer needed, we delete or anonymize it.

7. How we protect your data

We use appropriate technical and organizational measures, including encryption in transit (HTTPS/TLS), access controls, and the PCI-DSS-certified infrastructure of Shopify, Xendit and Stripe for payment data. No system is perfectly secure. If a failure of personal data protection occurs, we will notify you and the competent Indonesian authority in writing within 3×24 hours of discovery, as required by UU PDP (Article 46). Where the GDPR applies, we will also notify the competent supervisory authority within 72 hours and affected individuals where the breach is likely to result in a high risk to them.

8. Cookies

We use cookies and similar technologies to operate the Site (essential cookies), remember your preferences, measure Site performance, and — with your consent where required — support advertising and social media features. You can manage cookies through the cookie banner on the Site and through your browser settings. Blocking some cookies may affect Site functionality. Where required (e.g., for EEA/UK visitors), non-essential cookies are set only after consent. The Site honors Global Privacy Control (GPC) signals where legally required.

9. Your rights

If you are in Indonesia (UU PDP), you have the right to: access your personal data and obtain a copy; rectify inaccurate data; delete or destroy your data; restrict or object to processing (including objecting to automated decision-making); data portability; withdraw consent at any time; lodge a complaint with the competent Indonesian authority; and claim compensation for violations as provided by law.

If you are in the EEA or UK (GDPR), you have the right to: access, rectification, erasure, restriction of processing, data portability, objection (including to direct marketing), withdrawal of consent, and to lodge a complaint with your local supervisory authority.

If you are a California resident (CCPA/CPRA), you have the right to know what personal information we collect, request its deletion or correction, and opt out of the “sale” or “sharing” of personal information. We do not sell personal information for money; you can opt out of advertising-related sharing via our cookie settings. We will not discriminate against you for exercising your rights.

To exercise any right, contact privacy@treelogy.com. We may need to verify your identity before responding, and will respond within the timeframe required by applicable law. You may also designate an authorized agent where the law allows.

10. Children

The Site is not directed at children. We do not knowingly collect personal data from anyone under 18 without parental or guardian consent. If you believe a child has provided us personal data, contact us and we will delete it.

11. Third-party links

The Site may contain links to third-party websites and social media platforms. Their privacy practices are governed by their own policies, which we encourage you to read.

12. Changes to this policy

We may update this Privacy Policy from time to time. The current version is always available on the Site with its “Last updated” date. For material changes, we will provide notice on the Site or by email.

13. Contact