Data we store
We store data necessary to provide the service: account identity, email, profile, roles/access, checkout, payments, vouchers, referrals, transaction snapshots, invoice/payment status, audit logs, preferences, accepted legal-document version, and support correspondence. If you use Trading Journal, journal data, models, statistics, screenshot uploads, and profile privacy settings are also stored according to your choices.
Usage evidence for refunds
For curriculum access and refunds, FlowJob may store usage evidence such as opened materials, module progress, completion status, available-material counts, access time, and verification records. If video features are active, video position or watch duration is used only when needed for progress or support. The fj_ref cookie is used for 30 days for referral attribution.
Analytics and cookies
Cookies, local storage, PostHog, and Vercel Analytics/Insights may be used as configured for login, security, referral attribution, performance measurement, product funnels, and service improvement. Analytics may be pseudonymous, cohort-based, or linked to an account where needed for support, security, or product usage understanding. Checkout is not an automatic marketing opt-in.
Service providers
Processors used may include Supabase/Supabase Auth, Vercel, Midtrans, Discord, Resend, Upstash, PostHog, Vercel Analytics/Insights, media providers, and other operational providers required by the application. Provider-side processing follows their policies, security, processing locations, and information they can verify.
Rate limits, security, and retention
IP, user agent, device, cookies, and technical signals may be used for rate limits, abuse detection, fraud prevention, admin audits, account security, and incident investigation; salted hashes may be persisted. Transaction data and required logs are retained as needed for operations, audit, claim defense, tax/accounting obligations, dispute resolution, and legal compliance. Data no longer needed will be deleted, anonymized, or restricted according to system capability and legal obligations.
Processing bases
Data is processed to perform the service contract, comply with legal obligations, protect legitimate interests such as security and fraud prevention, handle claims, and based on consent where the law requires it. You may withdraw consent for consent-based processing, but certain features may become unavailable after withdrawal.
Your requests and rights
Requests for access, correction, portability, restriction, objection, deletion, consent withdrawal, or other applicable rights may be sent to support@flowjob.id. We may request identity and account verification before processing. Deletion may be limited where data remains necessary for transactions, security, audit, dispute resolution, or legal obligations.