Privacy Policy
Last updated: July 12, 2026
Niagora is committed to maintaining the confidentiality and privacy of your corporate data. This policy explains the types of data we collect in our B2B ecosystem, the purposes of collection, and with whom we share that data.
1. Business Compliance Data Collection (KYB)
Unlike B2C platforms, Niagora collects certain corporate legal data (role-based data) to ensure entity validity. We collect:
- Business Entity Data: NIB (Business Identification Number), Corporate NPWP, Deed of Establishment, and operational correspondence address.
- Responsible Person Data: Director's ID / authorized company representative, corporate email, and mobile number.
- Financial Data: Corporate bank accounts for withdrawal purposes for Sellers.
2. Audit Log Data Collection
Every activity on the platform, especially those involving the procurement workflow, is recorded in an audit trail:
- History of approvals/rejections by each sub-account (Purchasing, Accounting, Finance, Director).
- History of creation, price changes, and signing of B2B Contract documents (Price Lock).
- This data is permanently recorded and stored in our system and cannot be altered or deleted by any party to meet your company's audit standards.
3. Data Sharing with Third Parties
Niagora never sells your corporate data. We only share encrypted data with infrastructure partners on a strictly-need-to-know basis to process transactions:
- Payment Gateways (Xendit & Midtrans): Transaction IDs and amounts to issue Virtual Accounts (VA), as well as Seller banking data for releasing funds from Escrow (Disbursement).
- Logistics Aggregator (Biteship): Warehouse address (Seller), shipping address (Buyer), product dimensions and weight to calculate shipping rates and generate logistics receipts.
- Compliance Verification (OSS, DJP, AHU): We cross-reference profile data with government databases to validate your entity registration numbers.
4. Data Infrastructure Security
All data, documents, and communications are secured with Transport Layer Security (TLS) encryption in transit, and encrypted at-rest in high-security certified cloud facilities (AWS/GCP). Specifically for sub-account passwords, we implement one-way hashing so that not even Niagora staff can view your password.
5. Data Retention Policy
We use a soft delete scheme. When you decide to delete an entity or close an account on Niagora, the system will only hide your account from the public interface. Given the nature of B2B transactions which require data availability for inter-entity tax reporting (VAT), we are obligated to store historical transaction data and invoices for a minimum of 10 (ten) years in accordance with Indonesian legislation.
6. Data Privacy Contact
For requests to export corporate audit history, data security clarifications, or KYB review requests, please contact our team at privacy@niagora.app.