Legal

Privacy Policy

Written against what the software actually does, not against a template. Every retention period below is one the system enforces on its own.

1. Who is responsible

Manufactur Digital Hub, a sole proprietorship established in Indonesia and owned by Muhamad Dedeh H, is responsible for the personal data described here. Write to manufacturdigitalhub@gmail.com about anything on this page.

2. What we collect

When you hold an account

  • Identity and sign-in: your name, email address, a one-way hash of your password (we never store the password itself), your preferred language, and which organisations you belong to.
  • A normalised form of your email address, used only to recognise when one address has been rewritten into several to claim a signup bonus more than once.
  • Billing records: plan, period, amounts, payment method used, and the transaction references your payment provider returns. We never receive or store your card number.
  • What you create: pages, HTML, styles, images and other media, products, orders, articles and settings.
  • AI usage: a ledger of each request — when, by whom, which step, how many tokens, and the prompt text, kept for billing accuracy and abuse investigation. Prompts are stored truncated to the first 4,000 characters.
  • Support messages you send us, and our replies.

Technical data

We record IP addresses in three specific places, not as a general log of your browsing: rate limiting (to stop brute-force sign-in attempts), the evidence trail behind a content-moderation decision, and a record of which address a signup bonus was granted to. For that last one, IPv6 addresses are truncated to their /64 prefix, and private or loopback addresses are not recorded at all.

On this marketing site

This site carries no third-party analytics, advertising or session-recording trackers. There is no Google Analytics, no Tag Manager, no advertising pixel. You can verify that in your browser's developer tools. Two cookies are set: a Laravel session cookie needed for the site to work, and pagehub_currency, which remembers the currency you picked for a year. Your language choice and interface preferences are kept in your browser's local storage and are not sent anywhere as identifiers.

3. Why we use it

  • To provide the service you signed up for — necessary to perform our contract with you.
  • To bill accurately and to keep the records tax law requires us to keep.
  • To keep the platform safe — preventing fraud, abuse of signup bonuses, and the publication of phishing and malware. This is our legitimate interest, and yours: a platform known for hosting fraud is worth less to everyone on it.
  • To tell you things you need to know — verification codes, password resets, billing notices, grace-period warnings, and material changes to the service.

We do not sell your personal data, and we do not share it for anyone else's advertising.

4. Who else processes it

We use a small number of providers to run the service. Each receives only what its function requires:

  • AI providers — depending on which model the platform is configured to use, this is Anthropic, OpenAI or DeepSeek. They receive the prompt you write and the page content relevant to it, in order to return a draft. We do not use your content to train any model of our own. Each provider processes it under its own API terms; treat a prompt as something that leaves our systems, and do not paste passwords, card numbers or other secrets into one.
  • Payment providers for your subscription — Xendit and, where enabled, Lemon Squeezy. They receive what is needed to take a payment and to identify it afterwards. Card details go to them, never to us.
  • Shipping carriers — where a store uses shipping rates or tracking, the origin and destination of a parcel, its weight and dimensions, and a tracking number are sent to the carrier's service (Biteship) to get a rate or a status.
  • Email delivery — an SMTP provider transmits account and transactional email. If you are on a white-label plan and have configured your own verified mail server, your account email is sent through yours instead of ours.
  • Hosting — the servers and managed database the application runs on.

Several of these operate outside Indonesia, so your data is transferred internationally. We use providers that commit to appropriate safeguards for that transfer.

5. Data belonging to visitors of the sites you publish

When someone fills in a form, places an order or browses a site you built, that information is yours, not ours. You decide what to collect and why; we store and process it on your instruction as part of running the software. That includes form submissions and leads, orders and invoices, abandoned carts, appointment bookings and daily page-view counts. Page views are counted in aggregate and are not tied to a visitor identity.

Because that data is yours, publishing a privacy notice for your own visitors — and having a lawful basis to collect what you collect — is your responsibility.

6. How long we keep it

These periods are enforced by the software itself, not left to memory:

  • Content-moderation evidence: 90 days, then deleted by a scheduled job.
  • Page revision history: the 20 most recent versions of each page.
  • AI chat history: the 40 most recent messages per page.
  • Account and content data: for as long as the account exists. After closure we delete it within 90 days, except where the next item applies.
  • Billing and tax records: kept for the period tax and accounting law requires, even after an account closes.

7. How it is protected

  • Passwords are stored as bcrypt hashes, never in a readable form.
  • Credentials you entrust to us for third-party services — payment gateway keys, mail server passwords — are encrypted at rest with AES-256-GCM, and are write-only in the interface: once saved, they can be replaced but never read back out.
  • Traffic is served over TLS.
  • Sign-in, one-time codes and other sensitive endpoints are rate limited, and repeated failed codes lock an account temporarily.
  • Access to content is checked per request against the organisation it belongs to, not against a token that may be out of date.

No system is perfectly secure. If a breach affects your personal data, we will tell you and the relevant authority as the law requires.

8. Your rights

Under Indonesia's Personal Data Protection Law (Law No. 27 of 2022) and comparable law that may apply to you, you can ask for a copy of your personal data, ask us to correct it, ask us to delete it, object to a particular use, or withdraw a consent you gave.

Your pages can be exported as HTML from within the application at any time. For everything else — a full copy of your data, or deletion of your account and its content — write to manufacturdigitalhub@gmail.com from the address on the account. We will respond within 30 days. We may need to keep billing records after a deletion, as section 6 says.

9. Children

PageHub is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, write to us and we will remove it.

10. Changes to this policy

We may update this policy. For changes that materially affect how we handle your personal data we will give notice by email, or in the application, before they take effect. The effective date of the current version is shown below.

Effective: 15 September 2026

This document is published in English and Indonesian. If the two versions differ, the English version governs.

Questions about this document: manufacturdigitalhub@gmail.com