Last updated

Who we are

GOTAG.me is run by PT. Penanda Citra Global, Menara Cakrawala, Lt. 12, Unit 05A, Jln. M.H. Thamrin No.9, Jakarta 10340, Indonesia ("GOTAG.me", "we"). We are responsible for the personal data described here. This policy covers the photo site and its sign-in and account pages. Questions about it go to [email protected].

The short version

  • Searching for your photos and downloading free ones needs no account and sets no tracking cookie.
  • We never use face recognition. Photos are matched by the number on your bib, and nothing else.
  • If you buy photos we keep what the order needs. Card and e-wallet details are entered on the payment provider’s own page — we never see or store your full card number.
  • Analytics is off until you allow it.
  • You can ask us to remove a photo of you, or to delete your account, at any time.

When you search without an account

When you download a free photo we record the event, the photo, the time, a coarse network prefix (never your full address) and your browser's user-agent string, so we can see how the service is used and detect abuse. We do not set a tracking cookie, we do not fingerprint your device, and we do not create any durable identifier for you. Like any website, our servers also keep short-lived technical logs of requests, including IP addresses, to keep the service secure and working; these are deleted after about 30 days.

Photographs of you

Photos are taken at events by the photographers the organiser engaged, and are published here for the people who took part. We read the numbers visible on bibs automatically — this is text recognition, not face recognition, and we hold no biometric data. Anyone who knows the event and a bib number can find the photos that number appears in. If you appear in a photo and want it removed, email [email protected] with a link to the photo and we will take it down.

If you create an account

An account is only needed for buying photos. For one, we keep:

  • your email address, which is also how you sign in;
  • your password, stored only as a one-way hash that cannot be turned back into the password;
  • your name, if you choose to give it;
  • your consent choices, and when you made or changed them;
  • sign-in security records: the devices and IP addresses of your active sessions, failed sign-in attempts, and whether two-factor authentication is on.

If your account dates from our earlier race-registration service, it may also hold details you gave then, such as a date of birth, a blood type or an identity document number. We no longer ask for these or use them, and you can ask us to delete them.

If you buy photos

  • the order: which photos, their price, and each change to its status;
  • a name for the receipt, only if you add one;
  • what the payment provider tells us about the payment — its status and reference, and details such as the payment method or the last digits of a card. Full card numbers and e-wallet or bank log-ins are entered on the provider’s own page, and we never see them;
  • for a bank transfer, the receipt you upload, which may show your bank account details: it is stored privately and seen only by the staff who confirm payments;
  • when you download a photo you bought, so the download stays available to you.

Why we use your data

  • to provide what you asked for — search, your account, your orders and your downloads;
  • to keep accounts and payments secure and to prevent fraud and abuse;
  • to meet our legal obligations, such as keeping financial records;
  • with your consent, and only then: marketing email and analytics.

Email we send

We send the email an account needs: a welcome, address confirmation, password resets, payment receipts, download notices, refund notices and account-deletion confirmations. Marketing email is separate, opt-in, and never set on your behalf; you can turn it off at any time from your profile.

Cookies and browser storage

We use a small number of cookies, and none of them track you across other websites:

  • a sign-in cookie, which keeps you signed in across the GOTAG.me sites while you are signed in;
  • a security cookie on the sign-in pages, which protects their forms against being submitted from somewhere else;
  • a basket cookie, set only when you add a photo to a basket without being signed in;
  • your choice of light or dark theme, and your analytics choice, kept in your own browser’s storage rather than sent to us;
  • Google Analytics cookies — only after you allow analytics.

Analytics

If you agree to it, we use Google Analytics to count page visits, BIB searches, shares and photo downloads. That tells an event organiser how their race is doing. We send the event, the page you are on with any identifying part removed, whether a search found anything, and how many photos were downloaded. We never send your BIB number, which photo you opened, your name or your email. Analytics is off until you choose to allow it, nothing loads before you do, and your choice is stored on your own device — clearing this site’s data makes us ask again.

Who we share data with

We do not sell personal data. We share it only with the services that run the platform for us:

  • payment providers such as Midtrans and Xendit, to take a payment you start;
  • Cloudflare, which delivers the website and checks sign-in and registration forms for bots;
  • our cloud hosting and storage providers — our servers and photo storage are in Singapore;
  • an email delivery provider, to send the email described above;
  • an error-monitoring service, which receives technical details when something breaks;
  • Google Analytics, only if you allow it.

Event organisers see how their event is doing — counts of searches and downloads — and never your account or order details. We also disclose data where the law requires us to.

How long we keep it

  • your account, until you ask us to delete it;
  • orders and payment records, for as long as tax and accounting law requires — this can outlast the account;
  • technical server logs, for about 30 days;
  • security records of account activity — sign-ins, changes to your account, purchases and downloads, with the IP address and browser used — for as long as they are needed to protect accounts and to answer questions about an order;
  • event photos, for the period agreed with the event organiser.

Your rights

Under Indonesia's Personal Data Protection Law (Law No. 27 of 2022) you can ask to see the personal data we hold about you, have it corrected, have it deleted, withdraw a consent you gave, and object to how it is used. Your name and your consent choices can be changed on your profile at any time, and you can request account deletion from your account page. For anything else, write to [email protected]; we will reply as quickly as we can and within the time the law allows.

Security

Every page is served over an encrypted connection. Passwords are stored only as hashes, two-factor authentication is available on every account, staff access to personal data is limited to those who need it and the changes they make are recorded, and full card numbers never pass through our systems.

Children

People of every age take part in events. Accounts, and purchases, are for adults: if you are under 18, ask a parent or guardian to buy for you. A parent or guardian can ask us to remove a photo of a child at [email protected].

Changes to this policy

When this policy changes we update the date at the top of this page. If a change affects how we use data you have already given us, we will also tell account holders by email.

Contact

PT. Penanda Citra Global, Menara Cakrawala, Lt. 12, Unit 05A, Jln. M.H. Thamrin No.9, Jakarta 10340, Indonesia. Privacy questions: [email protected]. Everything else: [email protected].