Kebijakan Privasi.
Berlaku · 27 Mei 2026 · Versi 1.0
GoAmbulance ("kami", "platform") menghormati privasi setiap pengguna —
pasien, keluarga, driver, paramedis, dan operator armada. Kebijakan ini
menjelaskan data apa yang kami kumpulkan, mengapa, dengan siapa kami
berbagi, dan hak Anda di bawah UU No. 27 Tahun 2022 tentang
Pelindungan Data Pribadi (UU PDP).
1. Data yang kami kumpulkan
1.1 Data yang Anda berikan langsung
- Identitas: nama lengkap, nomor telepon, alamat email opsional.
- Kredensial: kata sandi (disimpan dalam bentuk hash bcrypt, tidak pernah dalam bentuk asli).
- Profil medis (opsional, hanya pasien): golongan darah, alergi, kondisi medis kronis, kontak darurat, nomor BPJS.
- Pembayaran: kami tidak menyimpan nomor kartu kredit atau saldo e-wallet — proses pembayaran ditangani oleh Midtrans yang berlisensi Bank Indonesia.
- Driver/Paramedis: nomor SIM, KTP, sertifikasi (ALS, ACLS, PALS), nomor KIR & STNK kendaraan.
1.2 Data yang dikumpulkan otomatis
- Lokasi: koordinat GPS pasien saat memanggil ambulans (sekali, untuk dispatch) dan koordinat GPS driver selama perjalanan aktif (live streaming setiap ~5 detik untuk peta tracking). Driver dapat mematikan mode online untuk berhenti berbagi lokasi.
- Riwayat perjalanan: waktu, lokasi penjemputan, rumah sakit tujuan, tier (BASIC/ALS/ICU), ongkos, rating.
- Catatan klinis (perjalanan aktif): tanda vital pasien (HR, BP, SpO₂, suhu, GCS) yang dicatat paramedis di aplikasi Driver.
- Telemetri teknis: jenis perangkat, versi aplikasi, alamat IP, log crash (via Sentry) untuk perbaikan bug.
2. Tujuan pemrosesan
- Dispatch ambulans: mencocokkan permintaan dengan unit terdekat berdasarkan lokasi + tier.
- Pemberitahuan IGD: mengirim ringkasan kondisi pasien ke rumah sakit tujuan sebelum tiba (sesuai PMK 47/2018).
- Penagihan & klaim BPJS: dengan persetujuan Anda, kami memformat data perjalanan untuk klaim BPJS.
- Verifikasi identitas: OTP via WhatsApp untuk memastikan nomor telepon valid.
- Komunikasi: pemberitahuan trip (driver assigned, tiba, selesai) — wajib operasional, tidak dapat dimatikan untuk perjalanan aktif. Marketing/promosi opt-in.
- Kualitas layanan: rating, laporan kejadian, audit ops dispatcher.
- Kewajiban hukum: respons terhadap permintaan resmi penegak hukum, pengadilan, atau regulator (BPJS Kesehatan, Kemenkes).
3. Dengan siapa kami berbagi
- Driver & paramedis Anda: nama, nomor telepon, lokasi penjemputan, profil medis (jika dibagikan). Akses berakhir saat perjalanan selesai.
- Rumah sakit tujuan: ringkasan kondisi pasien + ETA via API pre-notifikasi (PMK 47/2018).
- Operator armada (Fleet): hanya data agregat unit mereka (utilisasi, pendapatan) — bukan data pasien.
- Midtrans: data pembayaran (jumlah, nomor order) untuk pemrosesan transaksi. Midtrans memiliki kebijakan privasi terpisah di midtrans.com/privacy-policy.
- Sentry / Firebase: log crash dan token notifikasi (tidak termasuk data medis atau lokasi historis).
- WhatsApp (Meta): nomor telepon untuk mengirim OTP — Meta hanya menerima nomor + teks pesan OTP, tidak ada data lain.
- Penegak hukum & regulator: hanya berdasarkan surat resmi yang valid (PSC 119, kepolisian, pengadilan, BPJS Kesehatan, Kemenkes).
Kami tidak pernah menjual data pribadi Anda kepada pihak ketiga
untuk iklan, pemasaran ulang, atau profiling komersial.
4. Penyimpanan & keamanan
- Lokasi server: Indonesia — data tidak ditransfer ke luar yurisdiksi nasional.
- Enkripsi transit: seluruh lalu lintas via TLS 1.2+ (Let's Encrypt).
- Enkripsi at-rest: kata sandi di-hash bcrypt; OTP di-hash SHA-256; token refresh di-hash; database backup terenkripsi.
- Retensi:
- Data perjalanan aktif & klinis: 24 bulan (sesuai PMK 47/2018 lampiran II).
- Log lokasi historis: 90 hari setelah perjalanan selesai.
- Data pembayaran: 10 tahun (sesuai UU Pajak).
- Akun tidak aktif: dapat dihapus atas permintaan Anda kapan saja.
- Akses internal: hanya tim ops dispatcher (role
ops) dengan audit log; semua akses dicatat dengan timestamp + user ID.
5. Hak Anda (UU PDP 2022)
Anda berhak untuk:
- Akses seluruh data pribadi Anda yang kami simpan — minta ekspor JSON via privacy@goambulance.com (gratis, dalam 14 hari).
- Koreksi data yang tidak akurat (langsung dari profil aplikasi).
- Penghapusan akun & data terkait — kecuali data yang harus disimpan menurut hukum (perjalanan klinis, pajak).
- Penarikan persetujuan untuk pemrosesan opsional (marketing, profil medis).
- Portabilitas — ekspor data dalam format standar (JSON).
- Keberatan atas profiling otomatis (kami tidak melakukan profiling untuk pengambilan keputusan kritis).
- Pengaduan ke Lembaga PDP (Kominfo) jika Anda merasa hak Anda dilanggar.
6. Anak di bawah umur
Aplikasi Rider boleh digunakan oleh siapa saja di atas 13 tahun. Untuk anak
di bawah 17 tahun, kami menyarankan akun didaftarkan oleh orang tua atau
wali. Profil medis anak dapat disimpan di akun orang tua. Kami tidak
sengaja mengumpulkan data anak di bawah 13 tahun — jika Anda menemukan
akun semacam itu, mohon laporkan ke privacy@goambulance.com.
7. Perubahan kebijakan
Kami dapat memperbarui kebijakan ini untuk merefleksikan perubahan layanan
atau hukum yang berlaku. Versi terbaru selalu tersedia di halaman ini
dengan tanggal "Berlaku" yang baru. Perubahan material akan diberitahukan
melalui notifikasi aplikasi atau email setidaknya 14 hari sebelum berlaku.
8. Kontak
Petugas Pelindungan Data (DPO):
Email: privacy@goambulance.com
Pengaduan umum: hello@goambulance.com
GoAmbulance Indonesia · Jakarta, DKI · NPWP: [terdaftar]
Privacy Policy.
Effective · 27 May 2026 · Version 1.0
GoAmbulance ("we", "the platform") respects every user's privacy —
patients, families, drivers, paramedics, and fleet operators. This
policy explains what data we collect, why, with whom we share it, and
your rights under Indonesia's Personal Data Protection Law (UU
PDP 2022).
1. Data we collect
1.1 You provide directly
- Identity: full name, phone number, optional email.
- Credentials: password (stored as bcrypt hash, never in plaintext).
- Medical profile (optional, patients only): blood type, allergies, chronic conditions, emergency contact, BPJS number.
- Payment: we never store card numbers or e-wallet balances — Midtrans (a Bank Indonesia-licensed gateway) handles payment processing.
- Driver/Paramedic: driving licence, ID card, certifications (ALS, ACLS, PALS), vehicle KIR & STNK numbers.
1.2 Collected automatically
- Location: GPS coordinates of the patient at the time of an ambulance request (once, for dispatch) and GPS coordinates of the driver during an active trip (live stream every ~5 s for the tracking map). Drivers can switch off "online" to stop sharing location.
- Trip history: timestamps, pickup, destination hospital, tier (BASIC/ALS/ICU), fare, rating.
- Clinical notes (active trip): patient vitals (HR, BP, SpO₂, temperature, GCS) recorded by the paramedic in the Driver app.
- Technical telemetry: device type, app version, IP address, crash logs (via Sentry) for bug fixes.
2. Why we process it
- Ambulance dispatch: match the request to the nearest unit by location + tier.
- Hospital pre-notification: send a patient condition summary to the destination hospital before arrival (per PMK 47/2018).
- Billing & BPJS claims: with your consent, format trip data for BPJS claims.
- Identity verification: WhatsApp OTP to confirm the phone number is valid.
- Communication: trip notifications (driver assigned, arrived, completed) — operationally required, cannot be disabled mid-trip. Marketing/promo is opt-in.
- Quality assurance: ratings, incident reports, ops dispatcher audit log.
- Legal compliance: respond to lawful requests from law enforcement, courts, or regulators (BPJS Kesehatan, Kemenkes).
3. Who we share with
- Your driver & paramedic: name, phone number, pickup location, medical profile (if shared). Access ends when the trip completes.
- Destination hospital: patient condition summary + ETA via pre-notification API (PMK 47/2018).
- Fleet operators: only aggregate data on their units (utilisation, revenue) — never patient data.
- Midtrans: payment data (amount, order ID) for transaction processing. Midtrans has its own privacy policy at midtrans.com/privacy-policy.
- Sentry / Firebase: crash logs and notification tokens (no medical data or historical location).
- WhatsApp (Meta): phone number for OTP delivery — Meta only receives the number + OTP text, nothing else.
- Law enforcement & regulators: only with valid legal process (PSC 119, police, courts, BPJS Kesehatan, Kemenkes).
We never sell your personal data to third parties for
advertising, remarketing, or commercial profiling.
4. Storage & security
- Server location: Indonesia — data is not transferred outside the national jurisdiction.
- In-transit encryption: all traffic over TLS 1.2+ (Let's Encrypt).
- At-rest encryption: passwords bcrypt-hashed; OTPs SHA-256-hashed; refresh tokens hashed; database backups encrypted.
- Retention:
- Active trip & clinical data: 24 months (PMK 47/2018 Annex II).
- Historical location logs: 90 days after trip completion.
- Payment data: 10 years (Indonesian Tax Law).
- Inactive accounts: can be deleted on request at any time.
- Internal access: only ops dispatchers (role
ops) with audit logging; every access is timestamped with user ID.
5. Your rights (UU PDP 2022)
You have the right to:
- Access all personal data we hold about you — request a JSON export via privacy@goambulance.com (free, within 14 days).
- Correct inaccurate data (directly via the app profile).
- Delete your account & related data — except data we must retain by law (clinical trips, tax).
- Withdraw consent for optional processing (marketing, medical profile).
- Portability — export in a standard format (JSON).
- Object to automated profiling (we don't profile for critical decisions).
- Lodge a complaint with the Personal Data Protection Authority (Kominfo) if you believe your rights have been violated.
6. Minors
The Rider app may be used by anyone over 13 years old. For users under
17, we recommend an account registered by a parent or guardian. A
child's medical profile can be stored under the parent's account. We do
not knowingly collect data from children under 13 — if you find such an
account, please report it to privacy@goambulance.com.
7. Policy changes
We may update this policy to reflect service or legal changes. The
latest version is always at this URL with a new "Effective" date.
Material changes are communicated via in-app notification or email at
least 14 days before they take effect.
8. Contact
Data Protection Officer (DPO):
Email: privacy@goambulance.com
General inquiries: hello@goambulance.com
GoAmbulance Indonesia · Jakarta, DKI · NPWP: [registered]