Skip to main content

Privacy policy

Last updated 21 August 2026

nest is not open to customers yet. No booking has been taken and we hold no customer data. This policy is published early so you can read it before you ever hand us anything, and it describes how your information will be handled from the day the first locker opens.

nest is operated by PT. Anuva Projects Bali. We are the data controller for the information described below. This page explains what we collect, why, who else sees it, and what you can ask us to do about it. Questions go to support@nest-locker.com.

1. What we collect

  • Your account. Name, email address, and a phone or WhatsApp number.
  • Social sign-in. If you sign in with Google, Apple or Facebook, we receive the name and email address attached to that account. We never receive your password.
  • Your bookings. Which locker, where, for how long, and what you paid.
  • Payment. Handled by our payment provider. We receive a reference and a status. We never see or store your card number.
  • Location. Only if you ask us to find the nearest locker, and only to answer that. Your browser asks you first and you can say no.
  • What you write to us. Support messages by email, WhatsApp, or in the dashboard.
  • Technical records. Server and error logs needed to keep the service running and to investigate a fault.

2. Why we use it

  • To hold and manage your reservation.
  • To identify you and keep your account secure.
  • To take payment and issue refunds.
  • To send you receipts, access instructions, and reminders about your booking.
  • To answer your support requests.
  • To detect and prevent abuse of the lockers.
  • To meet our legal, accounting, and tax obligations.

We do not sell your personal information, and we do not use it to build advertising profiles.

3. Cookies and other trackers

There are two kinds on this site, and only two.

Strictly necessary. Keeping you signed in, remembering the booking you are part way through, and remembering the answer you gave about the map. These do not ask for your consent, because without them the site cannot do the thing you asked it to do.

Google Maps. The booking map is served by Google. It sets its own cookies and receives your IP address. We do not load it until you accept, and booking works without it. You can change your mind at any time from the map itself.

We use no advertising and no analytics trackers.

4. Who else sees it

  • Our payment provider (Xendit), to take payment and process refunds.
  • Our hosting and database providers (Supabase, Vercel), which store and serve the data on our instructions.
  • Our error monitoring provider (Sentry), configured so that it does not receive your IP address or your personal details.
  • Google, for the map, and only after you have accepted it.
  • The place that hosts your locker. A café, shop or hotel sees only what it needs to let you in and help you. It never sees your payment details.
  • Authorities, where the law requires it or where someone’s safety is at stake.

5. Where your data goes

We operate from Indonesia. Some of the providers above run outside Indonesia, including in the United States and in the European Union, so your data travels there too. Where a transfer safeguard is required, we rely on the provider’s own certification or on the contractual clauses in our agreement with them.

6. How long we keep it

  • Account and profile: for as long as your account exists.
  • Reservations and payments: for as long as accounting and tax law requires, which outlives the account itself.
  • Support messages: two years.
  • Error logs: 90 days.

7. Your rights

You can ask us to:

  • give you a copy of the data we hold about you
  • correct anything that is wrong
  • delete your data
  • send your data to you, or to another provider, in a machine-readable file
  • stop using it for a particular purpose, or withdraw a consent you gave

Two of those you do yourself, from your account. On your data you can download everything we hold about you as one file, and you can ask us to delete your account. Nothing is deleted straight away: we wait 30 days, we show you the exact date, and you can cancel at any point before it. If a rental is in progress we say so and ask you to end it first, because you need the account to open the locker.

For anything else, write to support@nest-locker.com. We answer within 30 days and it costs you nothing. We may ask you to confirm who you are first, so that nobody else can make the request in your name.

One limit, stated plainly. We cannot erase a reservation that tax law obliges us to keep. In that case we remove your name and contact details from it and keep only the accounting record, which no longer identifies you. That is what deleting your account actually does to your past bookings: the money and the dates stay, you leave them.

If you are in the European Economic Area or the United Kingdom, you can also complain to your national data protection authority. In Indonesia, to the authority designated under Law 27/2022 on Personal Data Protection.

8. How we protect it

Access is restricted in the database itself, so one account cannot read another’s data even if something above it goes wrong. Traffic is encrypted in transit. Staff actions that open a locker require a second authentication factor and are recorded.

9. Children

nest is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a child has given us information, write to support@nest-locker.com and we will remove it.

10. Changes to this policy

If we change this policy, the new version appears here and the date at the top changes with it. If the change matters to you, we will tell you in the app as well.

11. Contact us