Brunei PDPO 2025 notice
Privacy Notice
This notice explains how Sturee collects, uses, discloses, transfers, protects, and retains personal data for storefronts, ordering, merchant accounts, reviews, and loyalty features.
- Last updated
- 2026-07-23
- Policy version
- v1.0-2026-07-23
Who is responsible
Sturee is currently operated as Carl's personal project, with no Brunei company formed yet. For PDPO purposes Carl is the organisation/controller and sole operator responsible for Sturee's compliance.
Privacy Officer / designated individual under PDPO S.7(c): Carl. Business contact: privacy@sturee.com.
What personal data we collect
- Account data: name, email, password hash, role, settings.
- Merchant data: shop name, phone, address, payment account details, storefront media.
- Order data: customer name, phone, notes, delivery address, receipt URL, order items and status.
- Loyalty/review data: phone, phone hash, name, card code, display name, rating, comment.
Why we collect it
We collect only data reasonably needed to provide storefront, ordering, merchant tooling, loyalty, review, security, support, and legal/audit functions. Point-of-collection forms explain the specific purpose before you submit personal data.
| Account creation | Create and secure your merchant/customer login. |
|---|---|
| Order fulfilment | Let merchants prepare, contact you about, deliver, and audit orders. |
| Loyalty storage | Operate loyalty cards, prevent duplicates, and recover cards. |
| Review publication | Moderate and publish reviews using your chosen display name. |
Consent and withdrawal
Where consent is used, Sturee records the subject, policy version, timestamp, IP hash, and user agent. You may withdraw consent from the consents dashboard or by emailing the Privacy Officer. Withdrawal may stop optional uses, but Sturee may retain data where needed for legal, audit, security, or order fulfilment purposes.
Cross-border transfers
Sturee uses processors outside Brunei: Neon for Postgres hosting, Cloudinary for image/payment receipt storage, Resend for transactional email, and Railway for app runtime. Sturee maintains a Transfer Impact Assessment and vendor DPA checklist to support comparable protection under PDPO S.24. Transfers are limited to the data needed for each service, protected by access controls, HTTPS, account security, processor safeguards, and retention limits.
Retention
Account deletion requests are reviewed and processed within 30 days where no legal or business purpose requires continued retention. Personal fields on retained order and loyalty records are anonymised while transaction events remain available for audit. Orders and loyalty events are retained for 7 years. Inactive loyalty members are anonymised after 24 months without events. Analytics events are kept 24 months, audit logs/correction requests 3 years, and consent/breach records 7 years.
Your rights
You can request access to your data, correction of inaccurate data, and withdrawal of consent. Logged-in users can use Data settings and Manage consents. You can also email privacy@sturee.com.
Cookies and local storage
Sturee uses essential NextAuth session cookies for protected dashboards. Storefronts use local storage for carts, fulfilment choices, loyalty card tokens, and acknowledgement of the cookie notice. Sturee records first-party storefront analytics events without third-party advertising cookies.
Complaints and contact
Send privacy questions or complaints to privacy@sturee.com. Sturee will acknowledge privacy complaints within 3 business days and target a substantive response within 30 days. If unresolved, you may escalate to AITI through the channel it designates.