Ubalist
  • Features
  • Pricing
  • News
  • About
  • Contact
  • Sign in
  • Get started

Privacy Policy

Effective date: August 13, 2026

PT Satria Jaya Darmadi and its associated companies ("us", "we", or "our") operate the https://ubalist.com website, the partner-facing portal at https://partners.ubalist.com, the short-link redirect host at https://l.ubalist.com, the public API at https://api.ubalist.com, and the developer documentation at https://docs.ubalist.com (together, the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use the Service and the choices you have associated with that data. We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined here, terms used in this Privacy Policy have the same meanings as in our Terms of Service.

Definitions

  1. Service. The websites, portals, hosts, APIs, and documentation listed above, operated by PT Satria Jaya Darmadi.
  2. Personal Data. Data about a living individual who can be identified from those data, or from those data together with other information in our possession or likely to come into our possession.
  3. Usage Data. Data collected automatically, either generated by use of the Service or from the Service infrastructure itself.
  4. Cookies. Small pieces of data stored on your device.
  5. Workspace. A product-owner tenancy within the Service. Every workspace has one or more members with defined roles (Owner, Admin, Manager, Analyst, Finance, Viewer).
  6. Partner. An affiliate, influencer, or content creator invited by a workspace to promote its offers. Partners have their own separate accounts on the partner portal.
  7. Data Controller. The natural or legal person who determines the purposes and manner of processing. Product owners are Data Controllers of their partner rosters, campaigns, and conversion data. PT Satria Jaya Darmadi is a Data Controller of account-level identifiers and platform telemetry.
  8. Data Processor. Any natural or legal person who processes the data on behalf of the Data Controller. When a product owner uploads a partner roster, we act as a Data Processor for that partner-level personal data.
  9. Data Subject. Any living individual using the Service who is the subject of Personal Data.

Information Collection and Use

We collect several types of information for the purposes of providing and improving the Service.

Personal Data (product owners)

When you sign up as a product owner or accept an invitation to a workspace, we may ask you to provide:

  1. Email address
  2. First name and last name
  3. Password (stored as an argon2id hash; never in plaintext)
  4. Phone number (optional, for two-factor authentication via SMS)
  5. Company or workspace name
  6. Payment card details (collected by our payment processor, not stored on our servers)
  7. Cookies and Usage Data

Personal Data (partners)

When you register on the partner portal or accept an invitation from a workspace, we may collect:

  1. Email address
  2. Display name and legal name
  3. Country and preferred currency
  4. Platform handles (e.g. Instagram, TikTok, YouTube — provided by you)
  5. Audience metadata (self-reported size, demographics)
  6. Payout details processed by PayPal or Stripe Connect (their account identifier and encrypted metadata; the underlying account is held with the provider, not us)
  7. Tax identification number, if required by your jurisdiction (stored encrypted at rest)
  8. Cookies and Usage Data

Usage Data

We collect information that your browser or device sends when you access the Service. This may include your Internet Protocol (IP) address, browser type and version, the pages of the Service you visit, the time and date of the visit, the time spent on those pages, unique device identifiers, mobile operating system, mobile browser type, and other diagnostic data.

Raw IP addresses are never stored on our servers. Every IP we ingest is immediately hashed with SHA-256 combined with a per-workspace salt that rotates quarterly. Only the hash is retained. This means we cannot reverse an IP back to a device, and neither can a workspace administrator who queries our audit logs.

Attribution and short-link click data

When a user clicks a Ubalist short link at https://l.ubalist.com/:shortcode, the redirect host records the click as a click event containing: the tracking-link identifier, the hashed IP as described above, the User-Agent string, an inferred country/region/city from the IP geolocation, an inferred device category (desktop, mobile, tablet, or bot), the HTTP referrer if present, and a first-party attribution cookie called ub_click that is set on the destination domain. The attribution cookie is HTTP-only, SameSite=Lax, and expires 30 days after the click.

When a conversion is subsequently reported by the destination merchant, we match it to the last click within the attribution window locked to the partner's commission-rule version. The conversion event stores the order identifier, the amount and currency, the matched partner and click, a customer external reference for the purpose of matching future renewals to the original conversion, and any UTM parameters passed through.

Location Data

We infer approximate country, region, and city from your IP address for fraud detection, currency preselection, and analytics segmentation. We do not collect precise GPS location. You cannot opt out of this inference for click-attribution or fraud-rule purposes, because it is fundamental to the honest operation of the Service.

Tracking and Cookies Data

We use cookies and similar tracking technologies to operate the Service and to hold certain information. Examples:

  1. Session Cookies. We use Session Cookies to keep you signed in.
  2. Preference Cookies. We use Preference Cookies to remember your workspace, timezone, and interface settings.
  3. Security Cookies. We use Security Cookies to prevent cross-site request forgery and to bind sessions to a specific device.
  4. Attribution Cookies. The ubclick cookie described above is set at the destination domain to associate a subsequent conversion with the originating click and partner.

You can instruct your browser to refuse cookies or to warn before accepting them. If you refuse the session cookie you will not be able to sign in. If you refuse the attribution cookie, click attribution may fall back to the shorter server-side window.

Use of Data

PT Satria Jaya Darmadi uses the collected data for various purposes:

  1. To provide and maintain the Service, including the workspace app, the partner portal, the short-link redirect host, and the public API.
  2. To notify you about changes to the Service, including critical security notices, billing changes, and payout status.
  3. To provide customer support and to answer questions submitted to customer.success@ubalist.com or through the WhatsApp channel.
  4. To gather analytics that let us improve the Service (aggregated usage, feature adoption, latency, error rates).
  5. To monitor the usage of the Service, detect abuse, and enforce the Terms of Service.
  6. To operate the fraud-detection engine that screens clicks and conversions for bots, fake audiences, and suspicious patterns before they cost workspaces money.
  7. To detect, prevent, and address technical issues.
  8. To send you occasional news, product updates, and educational content, only if you have not opted out of marketing communications. You can opt out at any time via the link at the bottom of any marketing email.
  9. To personalize your experience (for example, by remembering your last-used workspace or by defaulting a country in a form).
  10. To comply with our legal and tax obligations, including retention of transaction records related to partner payouts.

Legal Basis for Processing Under GDPR

If you are from the European Economic Area (EEA), our legal basis for collecting and using the personal information described in this Privacy Policy depends on the Personal Data in question and the context of collection. We may process your Personal Data because:

  1. We need to perform a contract with you (for example, to run your workspace or to send a partner their earned payout).
  2. You have given us permission to do so (for example, by ticking a consent box for marketing communications or AI training).
  3. The processing is in our legitimate interests and is not overridden by your rights (for example, product analytics, fraud prevention, security monitoring).
  4. For payment processing purposes.
  5. To comply with the law.

The training-data opt-in for AI features defaults to OFF at both the workspace level and the individual user level. We do not use your data to train or fine-tune AI models unless you have expressly opted in.

Transfer of Data

Your information, including Personal Data, may be transferred to and maintained on computers located outside your state, province, country, or governmental jurisdiction where data-protection laws may differ. Our primary data hosting is provided by Supabase and Vercel, whose data centers may be located in the United States or the European Union. If you are located outside Indonesia and choose to provide information to us, please note that we may transfer that data, including Personal Data, to Indonesia, the United States, or the European Union, and process it there.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer. PT Satria Jaya Darmadi will take all steps reasonably necessary to ensure your data is treated securely and in accordance with this Privacy Policy, and no transfer of your Personal Data will take place to an organization or country unless there are adequate controls in place, including the security of your data and other personal information.

Disclosure of Data

Business Transaction

If PT Satria Jaya Darmadi is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.

Disclosure for Law Enforcement

Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (for example, a court or a government agency).

Legal Requirements

We may disclose your Personal Data in the good-faith belief that such action is necessary to:

  1. Comply with a legal obligation.
  2. Protect and defend the rights or property of PT Satria Jaya Darmadi.
  3. Prevent or investigate possible wrongdoing in connection with the Service (this includes referring suspected fraud, click-farming, or affiliate-abuse patterns to the affected workspace).
  4. Protect the personal safety of users of the Service or the public.
  5. Protect against legal liability.

Security of Data

We implement a variety of security measures to safeguard your personal information:

  1. All connections to the Service use TLS 1.2 or above.
  2. Sensitive fields are encrypted at rest, including partner tax identifiers, workspace-level KMS keys, outbound-webhook signing secrets, and Slack webhook URLs.
  3. API keys are hashed with argon2id before storage and shown to you exactly once at creation time.
  4. Payment card details are handled by our payment processors (PayPal, Stripe) and never touch our servers.
  5. Every state-changing operation writes an append-only row to an audit log that cannot be updated or deleted, even by us.
  6. IP addresses are hashed with a per-workspace salt as described above.
  7. Access to the production database uses role-scoped connections; the workspace-scoped connection cannot read another workspace's data at the row level.
  8. Two-factor authentication (TOTP) is required for Owner and Admin roles within seven days of account creation.

The security of your data is important to us, but no method of transmission over the Internet, and no method of electronic storage, is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

Data Retention

We retain Personal Data for as long as your account is active, and for a further period necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention windows include:

  1. Account records: retained while your account is active, and for one year after account closure to allow reactivation.
  2. Financial transaction records (ledger entries, payout records, invoices): retained for seven years after the transaction to comply with tax and accounting obligations.
  3. Audit log entries: retained for two years, then archived.
  4. Click events and conversion events: retained for two years for attribution analytics and dispute resolution.
  5. Fraud signals: retained for two years for pattern analysis.
  6. Soft-deleted records: purged permanently thirty days after the delete, unless the workspace's retention policy overrides this window.

When you or your workspace administrator delete a record, it moves to a "trash" state with a scheduled purge date. The record continues to be visible in the Deletion Log for the workspace after the purge, but the underlying snapshot is redacted.

"Do Not Track" Signals

We do not currently respond to Do Not Track browser signals. We do respect the GPC (Global Privacy Control) signal for opting out of marketing communications where it is legally required.

Your Data Protection Rights

Regardless of your jurisdiction, you have the following rights with respect to your Personal Data:

  1. The right to access, update, or delete the information we hold about you. Whenever possible you can perform these actions directly from your account settings. Where you cannot, contact us and we will assist.
  2. The right of rectification. You have the right to have your information corrected if it is inaccurate or incomplete.
  3. The right to object. You have the right to object to our processing of your Personal Data.
  4. The right of restriction. You have the right to request that we restrict the processing of your Personal Data.
  5. The right to data portability. You have the right to be provided with a copy of your data in a structured, machine-readable, and commonly used format.
  6. The right to withdraw consent. Where we relied on your consent to process your data, you have the right to withdraw that consent at any time.

To exercise any of these rights, submit a Data Subject Access Request (DSAR) at https://ubalist.com/dsar or email us at customer.success@ubalist.com. We respond to DSARs within thirty days of receipt. If your request is complex or you have submitted multiple requests, we may extend that window by up to sixty additional days and will notify you of the extension.

You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, contact your local data protection authority in the EEA.

Service Providers

We employ third-party companies and individuals to facilitate the Service, provide the Service on our behalf, perform Service-related services, or assist us in analyzing how the Service is used. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. The list below is not exhaustive and may change from time to time.

Hosting and infrastructure

  1. Supabase. Managed PostgreSQL database, authentication service, storage, and realtime infrastructure. Data is stored in the region selected by us at project creation. Their privacy policy is at https://supabase.com/privacy.
  2. Vercel. Application hosting, edge network, and CDN. Their privacy policy is at https://vercel.com/legal/privacy-policy.
  3. Upstash. Rate-limiting infrastructure for the public API and outreach engines. Their privacy policy is at https://upstash.com/trust/privacy.pdf.
  4. Inngest. Background job execution for scheduled work (payout batches, analytics refresh, retention enforcement). Their privacy policy is at https://www.inngest.com/privacy.

Payments

We use third-party services for payment processing. We do not store your payment card details on our servers. Those details are provided directly to our third-party payment processors, whose use of your personal information is governed by their own privacy policy. All processors we use comply with PCI-DSS.

  1. Freemius. Merchant of Record for our SaaS billing of product-owner accounts. Freemius handles subscription checkout, invoicing, and VAT/tax remittance where applicable. Their privacy policy is at https://freemius.com/privacy.
  2. PayPal. Handles partner payouts on the PayPal rail. Their privacy policy is at https://www.paypal.com/webapps/mpp/ua/privacy-full.
  3. Stripe. Handles partner payouts on the Stripe Connect Standard rail. Their privacy policy is at https://stripe.com/privacy.

AI providers

Where you use our AI features (Voice RAG assistant, analytics chat, content moderation), the following providers process your prompts and any data included in your prompts:

  1. Anthropic (Claude API). Used for the primary reasoning engine of the Voice RAG assistant and analytics chat. Their privacy policy is at https://www.anthropic.com/privacy.
  2. OpenAI. Used for the Realtime speech-to-text pipeline of the Voice assistant and for text embeddings that power our knowledge-base search. Their privacy policy is at https://openai.com/policies/privacy-policy.
  3. ElevenLabs. Used for text-to-speech synthesis in the Voice assistant. Their privacy policy is at https://elevenlabs.io/privacy.

We do not permit these providers to use your prompts or outputs to train their public models. Your training-data opt-in defaults to OFF; where you opt in, we may use your anonymized data to improve our own retrieval and prompt-engineering.

Communications

  1. Resend. Transactional email delivery (workspace invites, payout receipts, DSAR fulfillment, security notices). Their privacy policy is at https://resend.com/legal/privacy-policy.
  2. Twilio. Outbound SMS delivery for partner outreach sequences and two-factor authentication codes. Their privacy policy is at https://www.twilio.com/en-us/legal/privacy.

Analytics

We may use third-party services to monitor and analyze use of the Service.

  1. Vercel Analytics. First-party page-view and interaction analytics, cookie-free by default. Their privacy policy is at https://vercel.com/legal/privacy-policy.
  2. Google Analytics (if enabled per workspace). Web analytics service offered by Google that tracks and reports website traffic. Their privacy policy is at https://policies.google.com/privacy.

Links to Other Sites

The Service may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Short-link destinations set by our workspaces are third-party sites in this sense. The workspace, not Ubalist, is responsible for the content and privacy practices at the destination URL.

Children's Privacy

We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you believe your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the effective date at the top. For material changes we will additionally notify you by email or a prominent notice within the Service before the change becomes effective. You are advised to review this Privacy Policy periodically for any changes. Changes are effective when posted.

Terms of Service

Please also review our Terms of Service, which govern your use of the Service, at https://ubalist.com/terms-of-service.

Contact Information

Phone: +62 811 8999 7163

Email: customer.success@ubalist.com

Address: Blok A2 No. 31, Mutiara Taman Palem, Cengkareng, Jakarta Barat 11730, Indonesia

Company: PT Satria Jaya Darmadi

Copyright: © 2026 PT Satria Jaya Darmadi

Ubalist

Run your affiliate program without building the plumbing.

WhatsApp

Solutions

  • Ubalist
  • Features
  • Pricing

Company

  • News
  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy
+62 811 8999 7163customer.success@ubalist.com
Blok A2 No. 31, Mutiara Taman Palem, Cengkareng, Jakarta Barat 11730, Indonesia

© 2026 PT Satria Jaya Darmadi. All rights reserved.