1. Pengumpulan dan Penggunaan Informasi Pribadi
Kami mengumpulkan informasi pribadi seperti nama pelanggan, alamat, dan rincian pembayaran untuk memproses pesanan dan mengirimkan produk. Kami juga dapat menggunakan informasi ini untuk menghubungi pelanggan mengenai pesanan mereka atau untuk memberikan informasi tentang produk dan layanan kami. Kami tidak akan membagikan informasi ini dengan pihak ketiga kecuali jika diwajibkan oleh hukum atau diperlukan untuk memenuhi pesanan.
2. Perlindungan Informasi Pribadi
Kami mengambil keamanan informasi pribadi pelanggan kami dengan serius dan telah menerapkan tindakan keamanan standar industri untuk melindunginya dari akses, pengungkapan, perubahan, atau penghancuran yang tidak sah. Kami juga mengharuskan karyawan dan mitra kami untuk mengikuti kebijakan dan prosedur kerahasiaan yang ketat saat menangani informasi pribadi.
3. Layanan Pihak Ketiga
Kami dapat menggunakan layanan pihak ketiga seperti kurir pengiriman, pemroses pembayaran, atau platform pemasaran untuk memenuhi pesanan dan mempromosikan produk kami. Layanan ini dapat mengumpulkan dan memproses informasi pribadi atas nama kami, tetapi kami hanya bekerja dengan mitra terpercaya yang mengikuti kebijakan privasi yang ketat dan mematuhi peraturan perlindungan data.
4. Kepatuhan dengan Peraturan Perlindungan Data
Kami mematuhi semua peraturan perlindungan data yang berlaku, termasuk Peraturan Umum Perlindungan Data (GDPR) dan Undang-Undang Perlindungan Konsumen California (CCPA). Pengguna memiliki hak untuk mengakses, memodifikasi, atau menghapus informasi pribadi mereka kapan saja dengan menghubungi layanan pelanggan kami.
5. Perubahan pada Kebijakan Privasi ini
Kami dapat memperbarui kebijakan privasi ini dari waktu ke waktu untuk mencerminkan perubahan dalam praktik bisnis atau kewajiban hukum kami. Kami akan memberi tahu pengguna tentang perubahan signifikan dan memberikan mereka kesempatan untuk meninjau dan menerima kebijakan yang diperbarui sebelum melanjutkan menggunakan layanan kami.
6. Storage, Handling, and Disposal
You will take each of the below measures and agree to securely store, handle, and dispose of all Shopee Content, Personal Data, Protected Data, and Restricted Content that is subject to this DPP.
10.1 You will physically or logically separate and segregate Shopee Content from your other clients’ data.
10.2 You will utilise industry standard encryption algorithms and key strengths to encrypt:
(a) all Protected Data that is in electronic form while in transit over all public wired networks (e.g., the internet) and all wireless networks;
(b) passwords with irreversible industry standard algorithms, with randomly generated "salt" added to the input string prior to encoding to ensure that the same password text chosen by different users will yield different encodings; and
(c) any mobile devices used outside of a Data Centre (e.g., laptop, desktop tablet) to perform any services pursuant to the Terms of Service or any of your Applications.
10.3 To the extent you are operating a Data Centre or utilising a third party Data Centre, you will comply with physical security controls outlined in one or more of the following industry standards: ISO 27001, SSAE 16 or ISAE 3402, or PCI-DSS.
10.4 Except where prohibited by applicable laws, upon the earliest of (i) the termination of the Terms of Service; (ii) the cessation of the need of any Protected Data for the purposes of the Terms of Service; or (iii) at any time upon written request from Shopee, you will:
(a) promptly remove the Protected Data from your environment and destroy it within a reasonable timeframe, but in no case longer than thirty (30) days thereafter,
(b) sanitise or destroy, as required in Section 10.5, all media used to store Protected Data, and
(c) provide Shopee a written certification regarding such removal, destruction, and/or cleaning upon request.
10.5 You will utilize TLS 1.2 or above and will provide a secure, encrypted communication channel between yourself and your clients for any communications containing or in respect of any Protected Data. If for any reason, Shopee becomes aware that you are not using TLS-enabled communications, Shopee will provide written notice requesting rectification, following receipt of which you agree to rectify the communication channel within 30 days. Failure to take sufficient remedial action in response to any issues that are detected is a violation of this DPP and, without limitation to any other remedy available, will result in immediate termination of your use of the Services.
10.6 You shall not retain or store any Personal Data and Restricted Data (including but not limited to the Customer Name, Phone Number, Email Address, and Address) that is subject to this DPP for any period of time longer than is necessary to serve the purposes of this Agreement (which, in any event, shall be no longer than ninety (90) days, subject to applicable law). Thereafter, all data should be disposed of in accordance with Clause 10.7 below.
10.7 You will dispose of the relevant Protected Data when it is deemed no longer necessary to continue being preserved, or has exceeded industry best practices for the time/duration/age of the Protected Data. Protected Data should be disposed of in a method that prevents any recovery of the data in accordance with industry best practices for shredding of physical documents and wiping of electronic media. You will destroy any equipment containing Protected Data that is damaged or non-functional. All Protected Data must be rendered unreadable and unrecoverable regardless of the form (physical or electronic).