Privacy Policy
Last updated: August 30, 2026
aiLink ("we," "our," or "us") operates the aiLink mobile application (the "App"). This Privacy Policy explains how we collect, use, and protect your information when you use our App.
1. Information We Collect
Information you provide
- Account information: your phone number, which you verify with a one-time code when you sign in. Some accounts created before phone sign-in also hold an email address and a password.
- Profile information: display name and avatar you choose to add.
- Content: posts, comments, reviews, and photos you submit to the community.
- Shared WiFi: if you choose to share a network, we store its name (SSID), hardware address (BSSID), password, and the location of your device at the moment you shared it, so other users can find that network. Sharing is optional and never automatic.
If you use aiLink as a merchant
Merchants who claim a store and accept payments through aiLink provide additional information, some of which is required by our payment partners and by Indonesian financial regulation:
- Business details: store name, address, category, and contact details.
- Owner identity: owner name, national identity number (NIK/KTP) and a photograph of the identity document, together with photographs of the premises.
- Settlement details: bank account name and number used to receive your payouts.
This information is submitted to the payment provider that onboards your store, and is used to open and operate your merchant account. We do not use it for advertising or profiling.
Transactions
- Orders and payments: the items you order, amounts, payment method, and payment status, together with the store and time of the transaction.
- Deals and vouchers: deals you buy, the voucher issued to you, and when and where it was redeemed or refunded.
Payments are processed by our payment partners; we do not receive or store your full card number or bank credentials.
Information collected automatically
- Location: with your permission, your device location is used to show restaurants and content near you. Location used for search is processed to answer that request and is not kept as a location history. Precise coordinates are stored only in the one case described above, where you deliberately share a WiFi network.
- WiFi connections: when you connect to a participating store's shared network, we record that a connection happened, the network name, the store, your platform, and the time. This tells the merchant how many people the network brought in.
- Usage data: screens viewed, features used, and performance metrics, collected via PostHog analytics. This data is pseudonymous and linked to a randomly generated device identifier.
- Device information: device type, operating system version, and app version, used for crash reporting and compatibility.
- Push notification token: an identifier issued by Apple or Google so we can deliver notifications to your device.
2. How We Use Your Information
- Provide, operate, and improve the App and its features.
- Show you relevant local restaurants, community posts, and recommendations.
- Verify your phone number when you sign in, and send service-related notifications (for example order updates, a message when your order is ready to collect, and replies to your posts).
- Process payments, issue and redeem vouchers, handle refunds, and settle funds to merchants.
- Open and maintain merchant accounts with our payment partners, and meet the identity-verification obligations that come with accepting payments.
- Understand how users interact with the App to improve performance and user experience.
- Detect and prevent fraud, abuse, or violations of our Terms of Service.
3. Information Sharing
We do not sell your personal information. We share data only in the following limited circumstances:
- Payment partners: MonetaPay and Duwit, which process payments and, for merchants, perform account opening and identity verification. Merchant identity documents are shared with the partner that onboards that store.
- Message delivery: Twilio, which delivers your one-time sign-in codes and order-ready messages over WhatsApp or SMS, and therefore receives your phone number.
- Push notifications: Apple (APNs) and Google (Firebase Cloud Messaging), which deliver notifications to your device.
- Infrastructure: Huawei Cloud (application hosting) and Tencent Cloud (object storage for images and media).
- Analytics: PostHog.
- AI features: merchant-facing tools such as the in-app assistant, menu recognition from photos, and dish-image generation send the relevant business content (for example a menu photo, or aggregated sales figures) to Alibaba Cloud DashScope, MiniMax, or Volcengine. Customer identities are not included; where analytics are involved, diners appear only as irreversible pseudonyms.
- Legal requirements: when required by applicable law, court order, or government authority.
- Business transfers: in connection with a merger, acquisition, or sale of assets, with appropriate confidentiality protections.
4. Data Retention
We retain your account and content data for as long as your account is active. Analytics data is retained for up to 12 months. Transaction records — orders, payments, vouchers, and refunds — are retained for up to 5 years where financial and tax law requires it, even after an account is deleted; retained records are kept for that purpose only. You may request deletion of your account and associated data at any time; see our Account Deletion page.
5. Your Rights
Depending on your location, you may have the right to:
- Access and download a copy of your personal data.
- Correct inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Object to or restrict certain processing of your data.
To exercise these rights, contact us at support@ailink.id.
6. Children's Privacy
The App is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly.
7. Security
We use industry-standard measures including HTTPS encryption in transit, one-time codes instead of passwords for sign-in, bcrypt hashing for the passwords that older accounts still hold, and access controls to protect your information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Third-Party Links
The App may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties, and we encourage you to review their privacy policies.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page. Continued use of the App after changes constitutes your acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy, please contact us at:
aiLink
Email: support@ailink.id
Website: https://ailink.id