Privacy & Cookies
This Privacy Policy explains what personal information gle ready to wear collects, why we collect it, how we use it, and the rights you have over it. It applies whenever you visit glereadytowear.com, place an order, sign up for our communications, or visit one of our Bali rooms. By interacting with us you consent to the handling of your personal information as described below.
1. Who We Are
In this policy, "gle", "we", "us" and "our" mean gle ready to wear, the operator of glereadytowear.com and the atelier and stores in Canggu, Seminyak and Ubud, Bali.
We handle personal information in line with the Indonesian Personal Data Protection Law (UU No. 27 of 2022, the UU PDP), and, for customers in scope, the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.
2. Information We Collect
We only collect what we need to take your order, deliver it, support you afterwards, and run the business. Specifically:
• Identity & contact: name, email address, phone number, billing and shipping address.
• Order details: pieces purchased, sizes, colour, price, order history, gift notes.
• Payment details: handled by our payment processor. We do not store full card numbers on our servers; we may retain a card token and the last four digits to recognise repeat payments and resolve disputes.
• Account details: username, password (stored only as a salted hash), saved preferences and addresses.
• Communications: the content of emails, messages and reviews you send us.
• Technical & usage data: IP address, device and browser type, referring page, pages visited, and similar diagnostics.
• In-store interactions: contact details and fitting notes you share with us in Canggu, Seminyak or Ubud.
We do not knowingly collect sensitive personal data (such as health, religion or political views) and ask you not to send it to us.
3. How We Collect Your Information
We collect personal information directly from you in most cases: when you place an order, create an account, subscribe to our communications, message us, or visit one of our stores.
We also collect a limited amount of technical information automatically when you use the site, through server logs, cookies and similar technologies (see clause 4).
Occasionally we receive information from third parties. For example, a courier returning a delivery confirmation, or a payment provider confirming a transaction.
4. Cookies & Similar Technologies
Cookies are small text files placed on your device by your browser. We use a small number of cookies to make the site work and to understand how it is used:
• Strictly necessary cookies: required for the cart, checkout, login session and your selected language. The site will not function correctly without these.
• Preference cookies: to remember choices such as currency or language.
• Analytics cookies: to count visits, see which pages are popular and improve the site. Where required by law, these are only set after you consent.
You can block or delete cookies in your browser settings. Disabling strictly necessary cookies will break parts of the site such as checkout.
5. How We Use Your Information
We use your personal information to:
• take, confirm, fulfil and deliver your order, including arranging shipping and customs paperwork;
• process payments and protect against fraud and chargeback;
• provide customer service: answer questions, handle returns and faults, and resolve complaints;
• manage your account, save your preferences, and recognise you on return visits;
• send transactional messages (order confirmations, shipping updates);
• with your consent or where otherwise permitted by law, send you marketing communications about new arrivals, restocks and events, and personalise what you see on the site;
• understand how the site is used and improve it;
• comply with our legal, tax and accounting obligations.
We do not sell your personal information.
6. Who We Share Your Information With
We share personal information only with the parties below, and only what they need to do their job:
• Couriers and customs agents (for example DHL Express): to deliver your order and clear it through customs.
• Payment processors: to take payment and refund returns.
• Cloud and infrastructure providers (Cloudflare and similar): to host the site, store our database, and protect against abuse.
• Email, messaging and analytics providers: to send our communications and understand site usage.
• Professional advisers (accountants, lawyers and auditors), bound by their own duties of confidentiality.
• Regulators, courts and law enforcement: where we are required by law to disclose, or where it is necessary to protect our rights or the safety of others.
• A successor business: if we sell or restructure the business, personal information may pass to the buyer as part of that transaction, subject to this policy.
We do not authorise these third parties to use your information for their own marketing.
7. Direct Marketing
If you have purchased from us or subscribed to our updates, we may send you marketing emails about new collections, restocks and events. Where required by law, we only do so with your consent.
Every marketing email includes a one-click unsubscribe link. You can also opt out at any time by writing to glereadytowear@gmail.com.
Even if you opt out of marketing, we will still send transactional messages about your orders.
8. International Transfers
We are based in Indonesia and ship worldwide. Personal information you provide will be transferred to and processed in Indonesia and, in some cases, in other countries where our service providers operate (including cloud regions in Asia-Pacific, the European Union and the United States).
Where we transfer personal information out of the EU/UK or out of Indonesia, we rely on appropriate safeguards: typically the European Commission's Standard Contractual Clauses, equivalent UK or Indonesian transfer mechanisms, or your explicit consent.
9. How Long We Keep It
We keep personal information only as long as we need it for the purposes set out in this policy, and to meet our legal, tax and accounting obligations.
Order and tax records: typically kept for ten (10) years from the end of the tax year, to comply with Indonesian record-keeping rules.
Account information: kept while your account is active and for a reasonable period afterwards in case you return.
Marketing data: kept until you unsubscribe or ask us to stop processing it.
After these periods we delete or anonymise the information.
10. How We Protect It
We take reasonable physical, electronic and procedural steps to protect personal information against loss, misuse, unauthorised access, alteration and disclosure. These include HTTPS-encrypted connections to the site, access controls on our systems, and ongoing review of our security practices.
No system is perfectly secure, however. If we become aware of a breach that materially affects you, we will notify you and the relevant authorities as required by law.
11. Your Rights
Subject to the applicable law, you have the right to:
• ask us what personal information we hold about you, and request a copy;
• ask us to correct information that is inaccurate or out of date;
• ask us to delete your personal information where we no longer have a lawful reason to hold it;
• ask us to restrict or object to certain processing;
• ask us to provide your information in a portable format, or transfer it to another service provider;
• withdraw any consent you have given us at any time, without affecting processing already carried out;
• complain to a privacy regulator (see clause 14).
To exercise any of these rights, please email glereadytowear@gmail.com. We may need to verify your identity before acting on the request.
12. Children
Our site and services are not directed to children. We do not knowingly collect personal information from anyone under the age of 16 without the consent of a parent or guardian. If you believe we have collected information from a child, please contact us and we will delete it.
13. Visitors from the EU / UK (GDPR)
If you are based in the European Economic Area, the United Kingdom or Switzerland, GDPR/UK-GDPR applies to our handling of your personal information. The lawful bases on which we rely are:
• Contract performance: to take and deliver your order and run your account.
• Legal obligation: to meet our tax, accounting and consumer-law duties.
• Legitimate interests: to run the business, prevent fraud, improve the site and (where allowed) send relevant marketing. You can object to legitimate-interests processing at any time.
• Consent: for cookies and marketing where consent is required. You can withdraw consent at any time.
For these visitors, gle ready to wear is the data controller. You may complain to your local data protection authority: for the EU, your national supervisory authority; for the UK, the Information Commissioner's Office (ico.org.uk).
14. Changes to this Policy
We may update this policy from time to time to reflect changes in our practices or in the law. When we make material changes we will update the "last updated" date at the top and, where appropriate, notify you by email or a notice on the site.
Please check this page from time to time. Continued use of the site after a change means you accept the updated policy.
15. Contact Us
Questions, requests or complaints about your privacy can be sent to glereadytowear@gmail.com. We aim to respond within thirty (30) days.
If you are not satisfied with our response, you may escalate your complaint to the Indonesian Ministry of Communication and Digital Affairs (Komdigi), the data protection authority in your country of residence, or the relevant supervisory authority under GDPR/UK-GDPR.