Privacy Policy
Last updated: 9 July 2026 · Effective date: 9 July 2026
This policy explains what personal information Book Ubud collects, why we collect it, how we use it, and the rights you have under Indonesia's Undang-Undang No. 27 Tahun 2022 tentang Perlindungan Data Pribadi (UU PDP) and Undang-Undang No. 11 Tahun 2008 jo. No. 19 Tahun 2016 tentang Informasi dan Transaksi Elektronik (UU ITE).
1. Who we are
Book Ubud is a direct-booking website for a collection of private pool villas in greater Ubud, Bali. The business is operated by I Nyoman Suardika, an Indonesian individual entrepreneur licensed as a Pondok Wisata (small-scale homestay) accommodation operator in the Republic of Indonesia under:
- NIB (Nomor Induk Berusaha): 1602260015674
- KBLI 55193: Penyediaan Akomodasi Jangka Pendek Lainnya (Other Short-Term Accommodation)
- Pondok Wisata license under Peraturan Daerah Provinsi Bali, regulated by the Government of Gianyar Regency
For the purposes of UU PDP, I Nyoman Suardika (operating as Book Ubud) is the Pengendali Data Pribadi (data controller) responsible for the information processed through this website and our WhatsApp channel. If you are a resident of the European Economic Area, you also benefit from rights under the EU General Data Protection Regulation (GDPR), which we honor on a best-effort basis as a courtesy to international guests.
2. What information we collect
We only collect the information we actually need to host you:
- WhatsApp messages: the content of messages you send to our booking number (+62 859-3524-3151), including your WhatsApp display name and phone number.
- Booking details: your full name, nationality, passport number (only when required for guest reporting to local authorities), contact email and/or phone number, number of guests, check-in and check-out dates, and any special requests you share when confirming a booking.
- Payment confirmations: proof-of-transfer screenshots or bank reference numbers you send us after paying a deposit or balance. We never see or store your card details; those stay with your bank or with Wise.
- Analytics data: pages visited, approximate location (country/city), device and browser type, referrer, and time-on-page, collected through cookies and similar technologies (see Section 4).
3. How we use your information (Tujuan pemrosesan)
We use the data above only for the following purposes:
- To respond to your booking inquiries on WhatsApp.
- To process and confirm bookings, including issuing quotes, sending payment instructions, and providing arrival information.
- To send booking confirmations, pre-arrival logistics, and follow-up messages relevant to your stay.
- To improve this website, for example, by understanding which villas visitors view most and where they drop off.
- To comply with Indonesian tax and accommodation reporting obligations, including PB1 (Pajak Hotel & Restoran) 10% filings with the Gianyar Regency Government and guest reporting to the local banjar and immigration where required.
The lawful bases for processing under UU PDP Pasal 20 are: (a) performance of the accommodation contract you enter into with us when booking; (b) compliance with legal obligations under Indonesian tax and tourism law; and (c) consent for non-essential cookies and marketing-related processing. For EEA guests, the equivalent GDPR bases (Art. 6) apply.
4. Cookies and tracking
We use a small number of cookies and similar technologies, in line with the data-protection principles of UU PDP and UU ITE Pasal 26. What runs, and when, depends on where you are browsing from. We use Google Consent Mode v2 and configure it differently for the regions whose law requires prior consent. Google determines your region from the IP address your browser presents when it requests the tag.
- In the European Economic Area (the EU-27 plus Iceland, Liechtenstein and Norway), the United Kingdom, and Switzerland: every non-essential storage signal — analytics, advertising, ad personalization, functionality and personalization — starts as denied. No analytics or advertising cookie is written before you press Accept. Google's measurement tag is still present on the page, but until you accept it may only send an anonymous, cookieless signal that carries no identifier for you or your device.
- Everywhere else — for example Australia, the United States, Singapore, Japan or Indonesia — Google Analytics 4 starts as soon as the page loads and writes its first-party cookies, and the banner works as an opt-out rather than an opt-in. This is lawful in those jurisdictions and it is the only way a site of our size obtains usable visitor statistics at all.
- If you decline (the Necessary only button),
we do two things immediately: we switch every Google consent signal to
denied, and we delete the analytics and advertising cookies that were already
set on your device — including
_ga,_ga_*,_gid,_gcl_au,_clck,_clsk,_fbpand_ttp. If a session recording had already started, the page reloads so that it stops. Your refusal is remembered and re-applied on every page you open afterwards, so it does not quietly lapse on your next click. - Meta Pixel, TikTok Pixel and Microsoft Clarity never run before you press Accept — in any country, including Australia, the United States and Indonesia. Their scripts are not even requested from Meta, TikTok or Microsoft until you have consented, so those companies are not told that you visited this site. (Meta Pixel and TikTok Pixel are only present at all while we are running advertising campaigns on those platforms.)
We honor your browser's Global Privacy Control (GPC) / Do Not Track signal as an automatic refusal, in every region. When one of these signals
is present we do not show you the banner at all, we set every consent signal
to denied before any tag runs, and Meta, TikTok and Clarity stay off. This
also applies retroactively: if you accepted cookies here and later switch the signal on in your
browser, your earlier consent is treated as withdrawn the next time you load a page. The only exception is a consent you gave
while the signal was already enabled — we read that as a deliberate,
site-specific override and leave it in place until you change it.
Below is what each tool does when it is allowed to run:
- Google Analytics 4: site usage statistics (pages, sessions, geography at city level). It sets first-party cookies that recognize your browser across visits under a random identifier — not under your name. Opt out via the Google Analytics opt-out browser add-on, or simply choose Necessary only on the banner.
- Meta Pixel: measures the effectiveness of our ads on Facebook and Instagram. Consent-gated everywhere. You can also disable activity off-Meta technologies in your Meta Accounts Center.
- TikTok Pixel: measures the effectiveness of our ads on TikTok. Consent-gated everywhere.
- Microsoft Clarity: heatmaps and session replay provided by Microsoft, used to understand how visitors interact with our pages. Consent-gated everywhere.
You can change your mind at any time through the Cookie settings link in the footer of every page, which reopens the banner. We remember
your choice in your browser's local storage and, when you accept, in a
buv-consent cookie that expires after six months. You can also clear or block cookies
at any time in your browser settings; blocking everything may mean the site
forgets that you already answered the banner. For the full list of cookies
we use, see our Cookie Policy.
5. Data sharing (Pengungkapan data)
We do not sell your personal data. In accordance with UU PDP Pasal 47, we share data only with the following categories of recipients, and only as needed:
- Payment processors: Bank Negara Indonesia (BNI) and Wise (Wise Payments Limited), which receive whatever information is necessary to process your transfer.
- Indonesian authorities: Direktorat Jenderal Pajak, the Gianyar Regency Tax Office (for PB1 filings), Imigrasi (for foreign-guest reporting where required), local banjar administration, and the licensing offices of the Bali Provincial Government and Gianyar Regency, when required by law.
- Service providers: Cloudflare (hosting and CDN), Google (analytics and advertising), Microsoft (Clarity heatmaps and session replay, only with your consent), and Meta and TikTok (advertising, only with your consent), each acting as a Prosesor Data Pribadi (data processor) under their own contractual safeguards.
We never share your data with other guests, with other villas outside our group, or with marketing third parties.
6. Data retention
Retention periods reflect the storage-limitation principle of UU PDP Pasal 16(2) and Indonesian tax and bookkeeping rules:
- Booking records: kept for 5 years after your stay, to comply with Indonesian tax and accommodation reporting law (Direktorat Jenderal Pajak retention rules).
- WhatsApp message history: retained on our business device for as long as it is operationally useful, then deleted. You may ask us to delete your conversation at any time.
- Analytics data: retained in Google Analytics for 14 months, then automatically deleted.
- Payment confirmations: kept for 10 years to comply with Indonesian anti-money-laundering and corporate bookkeeping obligations.
7. Your rights (Hak Subjek Data Pribadi)
Under UU PDP Pasal 5 sampai Pasal 15 you have the following rights, which we honor regardless of where you live (EEA guests also enjoy the equivalent GDPR Art. 15–22 rights):
- Access (akses): request a copy of the personal data we hold about you.
- Correction (perbaikan / pembaruan): ask us to fix anything that is wrong or out of date.
- Deletion (penghapusan): request that we delete your data, subject to the legal retention obligations described in Section 6.
- Portability (pemindahan data): receive your data in a structured, machine-readable format and have it transmitted to another controller.
- Object or restrict processing (penolakan / pembatasan pemrosesan): including withdrawing consent for analytics or marketing at any time.
- Lodge a complaint: with the Lembaga Perlindungan Data Pribadi once formally established under UU PDP, or with your home-country data-protection authority if you are an EEA resident.
To exercise any of these rights, message us on WhatsApp (see below). We respond within 3 × 24 hours per UU PDP expectations and aim to resolve every request within 7 days.
8. International transfers (Transfer data ke luar negeri)
We are based in Indonesia, but some of our service providers (Google, Meta, Cloudflare) process data on servers in the United States and other jurisdictions. Per UU PDP Pasal 56 and PP No. 71 Tahun 2019, such transfers are only made where the receiving jurisdiction provides comparable data-protection standards, or where adequate contractual safeguards (such as standard contractual clauses) are in place. For EEA guests, equivalent GDPR Chapter V safeguards apply.
9. Security of your data
In line with UU ITE Pasal 26 and Peraturan Menteri Kominfo No. 20 Tahun 2016, we apply reasonable technical and organizational measures to protect your data, including HTTPS on the website, access controls on the business WhatsApp device, and limited employee access to booking records on a need-to-know basis. No system is 100% secure; we notify you and the competent authority of any qualifying personal data breach within 72 hours, as required by UU PDP.
10. Children
Our services are intended for adult travelers. Per UU PDP Pasal 25, personal data of children (under 18) is only processed with the consent of a parent or legal guardian, and only to the extent strictly necessary for the family booking. If you believe a child has provided us with data without parental consent, please contact us and we will delete it.
11. Contact for privacy requests
For any privacy question, complaint, or data-subject request, the fastest channel is WhatsApp:
- WhatsApp: +62 859-3524-3151
12. Governing law (Yurisdiksi)
This Privacy Policy is governed by the laws of the Republic of Indonesia (Republik Indonesia). Any dispute relating to personal data falls under the jurisdiction of the competent Indonesian authority and, if litigated, the Pengadilan Negeri Gianyar (Gianyar District Court).