Who this covers
This notice applies when readers use IndoPac pages, create or use a reader account, set editorial preferences, upload a profile image, or subscribe to an IndoPac email product. It also covers technical requests made to systems controlled by IndoPac.
IndoPac operates as an editorial publication under the IndoPac and IndoPac Desk names. Reading public coverage does not require registration, and an account is not a condition of access.
Data we process
Web delivery can create infrastructure logs with an IP address, user agent, requested URL, referrer, timestamp, response status, and similar diagnostic fields. Hosting, CDN, and security systems generate these records; IndoPac does not build reader profiles from them.
If you register, Amazon Cognito processes your email address, verification status, account identifier, sign-in credentials, authentication events, and security information. Cognito manages passwords and sign-in; IndoPac's profile database does not receive or store your password.
The account service copies the verified email and account identifier from the authenticated sign-in and stores them with the profile and preference information you choose in DynamoDB. This may include a display name, short biography, profile-image reference, allowlisted HTTPS social or website links, region and topic interests, email products and cadence, format, time zone, quiet hours, pause settings, display theme, content density, reduced-motion choice, and profile-visibility preference. Optional fields may be left blank.
Email records can include the submitted address, signup source, consent and confirmation times, chosen products and coverage, delivery state, unsubscribe or suppression state, and limited delivery-event information. Those choices are used to assemble the editions you requested; they are not advertising segments.
Saved-story identifiers and account authentication tokens are stored in the browser as described on the cookies page. IndoPac does not collect payment details because it does not offer paid reader accounts.
Profile photos, biographies, and links
A profile photo, biography, display name, and social links are optional. The public-profile preference is off by default. In this release it does not expose a public profile: there is no public account directory or public profile-reading endpoint. IndoPac will explain the audience and fields before activating any future public display.
Profile images are stored in a private Amazon S3 bucket, not a public media folder. An authenticated reader receives a constrained upload request that expires after five minutes and, after the file is accepted, a viewing link that expires after 15 minutes. A signed request acts like a temporary access key and should not be shared.
Uploads are limited to JPEG, PNG, or WebP images no larger than 5 MB. Before moving an upload from temporary storage, the service checks account ownership, recorded size and type, and the file signature. It rejects a mismatch, generates its own storage key, deletes a replaced image, and automatically expires an unfinished temporary upload. IndoPac may remove content that is unsafe or inconsistent with a profile image.
Account and file security
Account API requests require an unexpired Cognito token that is verified before profile data is returned or changed. Passwords stay with the managed authentication service. The account table is encrypted at rest and protected with point-in-time recovery, and version checks prevent one stale edit from silently overwriting a newer one.
Profile-image storage blocks public access. Signed upload and viewing access is limited in purpose and time, and the final image is kept under an account-specific service-generated key. These safeguards reduce risk but no internet service can promise absolute security; readers should use a unique sign-in method, protect their browser session, and avoid putting sensitive data in a profile.
Why we process data
- To deliver requested pages and files through the hosting and CDN stack
- To maintain uptime, troubleshoot failures, and respond to abuse or security events
- To register and authenticate optional reader accounts and keep them secure
- To save profile and editorial preferences and provide account controls
- To confirm requested email subscriptions, select relevant coverage, schedule delivery, prevent duplicate sends, and process pauses or unsubscribes
- To understand aggregate readership and improve coverage and signup paths
- To protect the service, its infrastructure, and the publishers and sources it references
- To comply with legal obligations when preservation or disclosure is required
Legal bases in the EU and EEA
Where EU or EEA privacy law applies, IndoPac relies on legitimate interests to deliver and secure a public news publication and to prevent fraud or abuse. It processes account data to provide the optional service a reader requests. Separate editorial email products rely on the reader's affirmative choice and confirmation where required. Legal obligations may require limited preservation or disclosure.
Consent for one email product does not enroll a reader in every product. A reader can change regions, cadence, or products in preferences and can withdraw from editorial email through the account or the link in an edition. Service messages needed to verify, secure, or close an account are separate from editorial subscriptions.
IndoPac uses GA4 for audience measurement and does not use that measurement for targeted advertising or reader profiling. Analytics can be disabled from the footer, and a browser Global Privacy Control signal disables it. The site does not run advertising technology or cross-site behavioral segments.
Service providers and external links
IndoPac uses service providers for hosting, CDN, DNS, authentication, databases, private object storage, email, scheduling, audience measurement, and security. They may process technical, account, profile, image, or subscription data on IndoPac's behalf to provide those functions.
IndoPac links to outside publishers, and a signed-in reader may save allowlisted external profile links. The current account API does not expose those profile links publicly. When someone opens an external site, that site's privacy practices, cookies, and terms apply.
Weekly interactive maps
Where runtime configuration enables it, a weekly update includes an interactive map provided by Google Maps. The map begins loading when the weekly page loads; the article, map headlines, and ordinary story links remain readable if the third-party map is blocked or unavailable.
Loading the map causes the browser to request Google Maps resources directly. Those requests can disclose the reader's IP address, device and browser information, and the referring page or site origin to Google, which handles that information under the Google Maps Platform Terms of Service and Google Privacy Policy.
Google-supplied logos, copyright notices, and map or data-provider attribution must remain visible and must not be removed, altered, hidden, or obscured.
Advertising, sharing, and children
IndoPac does not currently sell personal information, share it for cross-context behavioral advertising, or run targeted advertising segments. It is also not directed to children under 13 and is not designed to knowingly collect personal information from children.
Email addresses and preferences are used for confirmation, account administration, security, segmentation, and delivery of the products a reader selects. They are not sold, rented, added to advertising profiles, or shared for cross-context behavioral advertising.
Retention and international hosting
IndoPac runs on cloud infrastructure, so technical logs, account records, profile images, subscription records, and backups may be processed outside a reader's home country. We retain an active account and its settings while the service is provided. Authentication, security, and delivery logs are kept only as long as reasonably needed for operation, abuse prevention, troubleshooting, and legal obligations.
An active account record has no automatic expiration and remains until the reader deletes the account. Deletion requires a recent sign-in, explicit confirmation, and the current record version; it deletes the current profile, preferences, private profile photo, and Cognito identity. An unfinished temporary image upload expires automatically after about one day. Unconfirmed email signups expire after the confirmation window.
After an unsubscribe or account deletion, IndoPac may retain a minimal suppression record so the address is not contacted again, plus limited consent, security, or delivery evidence where required. Deletion from rotating backups may take longer, and legal preservation duties can override the ordinary schedule.
We will revise this notice if the site's data practices change in a meaningful way. The snapshot below reflects the current service.
- • IndoPac remains readable without an account, paywall, payment profile, or public comment history.
- • An optional reader account can hold an email address, profile details, email choices, and reading preferences.
- • Amazon Cognito manages sign-in credentials. Account profiles and preferences are stored separately in DynamoDB.
- • Profile photos are optional, kept in private object storage, and made available only through time-limited signed access.
- • Email consent is granular: readers can choose products, cadence, and coverage, pause delivery, or unsubscribe.
- • Google Analytics 4 measures site use. Advertising storage, Google signals, personalization, and behavioral profiling stay off.
- • Readers can turn analytics off in the footer. Global Privacy Control is also honored.
- • The public-profile preference is off by default, and this release exposes no public profile endpoint.
- • IndoPac does not sell personal information or use it for targeted advertising.
Your controls and privacy rights
A signed-in reader can correct profile details, change email and coverage preferences, keep profile visibility off, remove a profile image, download an authenticated JSON export, or delete the account. Each editorial edition also includes an unsubscribe control. Withdrawing from email does not require deleting an account, and deleting an account does not remove a minimal do-not-contact record where one is needed to honor the withdrawal.
Privacy rights differ by jurisdiction. The privacy-rights page explains access, correction, deletion, objection, restriction, portability, and available self-service controls.