Privacy Policy

Effective date: 23 September 2026  |  Last updated: 23 September 2026

This Privacy Policy explains how PT Kotta Hospitality Management (“Kotta Hotels”, “we”, “us”) collects, uses, shares and protects your personal data across all of our digital properties, including:

together the “Services”. This Policy applies whether or not you create an account, book a stay, or install the App — simply browsing our websites or subscribing to our newsletter is enough to bring you under it.

By creating an account, making a booking, or subscribing to our newsletter through the Services, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Services.

1. Who is responsible for your data

The data controller is:

We process personal data in accordance with Indonesia’s Law No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Pribadi) and, where applicable to guests in those regions, the EU/UK General Data Protection Regulation.

2. Information we collect

2.1 Information you give us

2.2 Information from sign-in providers

The App does not have its own password. You sign in with a third-party provider, which shares a limited set of profile data with us:

Your sign-in with these providers is also governed by Google’s Privacy Policy and Apple’s Privacy Policy.

2.3 Booking, stay and loyalty data

2.4 Payment information

We do not collect or store your card, bank or e-wallet details. Payments are processed by Duitku (PT Adimulia Karya Teknologi), our payment gateway. When you proceed to payment, the App opens Duitku’s secure hosted payment page inside an in-app browser. You enter your payment details directly with Duitku. We receive only a booking reference and the resulting payment status (e.g. paid, pending, failed). Duitku’s handling of your data is governed by its own privacy policy.

2.5 Information collected automatically

2.6 Cookies (websites only)

The App does not use cookies. Our websites (kottahotels.com and book.kottahotels.com) use cookies and similar technologies for: keeping you logged in and remembering your preferences; the analytics described above; and, if you interact with the newsletter sign-up, Mailchimp’s own cookies. You can control or delete cookies through your browser settings; blocking them may affect how well our websites work.

2.7 What we do not do

The App contains no advertising, no third-party analytics or tracking SDKs, and no crash-reporting SDK. We do not track you across other apps or websites. We do not build advertising profiles. We do not sell your personal data.

3. How we use your information

PurposeLegal basis (UU PDP / GDPR)
Create and manage your account; keep you signed inPerformance of a contract with you
Process and confirm your reservations; pass the necessary guest details to the hotel so it can host your stayPerformance of a contract
Process payments (via Duitku) and detect payment fraudPerformance of a contract; legitimate interest
Operate the membership and loyalty programme (points, tiers, stay history)Performance of a contract; your consent
Send you transactional messages (booking confirmations, changes, receipts)Performance of a contract
Provide customer support and respond to your enquiriesLegitimate interest
Maintain security, prevent abuse, and keep records required by law (e.g. tax and accounting)Legal obligation; legitimate interest
Improve the Services and fix problemsLegitimate interest

We do not send marketing email without your separate opt-in (e.g. subscribing to our newsletter). Where we rely on your consent, you may withdraw it at any time (see section 7).

4. How we share your information

We share personal data only as described here:

We do not share your personal data with advertisers or data brokers.

5. Data retention

6. Account and data deletion

You can ask us to delete your Kotta Hotels account and associated personal data at any time by sending a request from your registered email address to privacy@kottahotels.com with the subject “Delete my account”. You do not need the App installed to make this request.

We will verify your identity and complete the deletion within 30 days. This removes your profile, saved contact details, loyalty record and stay history from active systems. We will confirm by email when it is done.

What we may retain: reservation and payment records that we are legally required to keep for tax, accounting and fraud-prevention purposes are retained for the period stated in section 5, in restricted-access storage, and are then deleted. Data already shared with a hotel for a completed or upcoming stay, or with Duitku for a completed payment, is retained by them under their own obligations.

Signing out or uninstalling the App does not delete your account on our servers — use one of the methods above.

7. Your rights

Subject to applicable law, you have the right to:

To exercise any of these rights, contact privacy@kottahotels.com. We respond within the timeframe required by law (30 days under UU PDP, extendable where permitted).

8. Data security

We protect your data with measures including: encryption in transit (HTTPS/TLS) for all communication between the App and our servers and payment provider; token-based authentication; encrypted storage of session data on your device; and access controls limiting staff access to personal data. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the authorities of a breach where required by law.

9. International data transfers

Our servers are located in Indonesia. Some of the third parties described in section 4 — our sign-in providers (Google, Apple), Mailchimp (our newsletter provider), Google Analytics, and, for guests in some regions, our payment provider — may process data on servers outside Indonesia, including in the United States. Where data is transferred internationally, we rely on appropriate safeguards as required by applicable law.

10. Children’s privacy

The Services are intended for individuals aged 17 and over. We do not knowingly collect personal data from children. A booking may include a child as a named guest, but the account and booking must be made by an adult. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Links to third-party services

Our App and websites may link to external services such as WhatsApp (to contact a hotel), Google Maps (to view a location), or social media pages. Those services are operated by third parties under their own privacy policies; this Policy does not cover them.

12. Changes to this Policy

We may update this Policy from time to time. We will post the revised version here with a new “Last updated” date and, for material changes, provide a notice in the App or by email before the change takes effect. Continued use of the Services after the effective date means you accept the updated Policy.

13. Contact us