Data Security & Payment Security Policy
This Data Security & Payment Security Policy explains the measures used by PT Awakening Journey Bali, operating under the brand aJourney, to protect customer information, account data, payment-related information, and digital transactions.
This Policy applies to ajourney.app, the aJourney customer account system, digital content services, tour booking services, and, where applicable, the aJourney mobile application.
This Policy should be read together with our Privacy Policy, Payment & Distance Sale Agreement, Terms & Conditions, and Cookie Policy.
1. Who We Are
The aJourney platform is operated by:
Legal Company Name: PT Awakening Journey Bali
Brand Name: aJourney
Website: ajourney.app
Country of Registration: Indonesia
Customer Support & Security Contact: info@ajourney.app
Business Address:
Jalan Gunung Soputan Nomor 1 A,
Desa/Kelurahan Pemecutan Kelod,
Kec. 80119 Denpasar, Bali, Indonesia
2. Our Approach to Security
aJourney uses reasonable administrative, technical, and organizational safeguards designed to protect information against:
- Unauthorized access;
- Unauthorized disclosure;
- Loss;
- Misuse;
- Alteration;
- Destruction;
- Account takeover;
- Fraudulent transactions;
- Other security threats.
Security measures may vary depending on the type of information and the system involved.
No internet-based system can guarantee absolute security. However, we aim to apply security measures appropriate to the nature of our Services and the information processed.
3. Secure Website Connections
aJourney is designed to use secure encrypted connections when customers interact with the website.
Where HTTPS encryption is enabled, information transmitted between your browser and the aJourney website is protected using standard transport encryption.
Customers should verify that they are using the official aJourney website:
ajourney.app
We recommend avoiding entry of account or payment information on suspicious websites, unofficial domains, or links claiming to represent aJourney.
4. WordPress and WooCommerce Security
aJourney uses WordPress and WooCommerce to support website, account, product, order, and e-commerce functionality.
Security measures may include:
- Access controls;
- User-role restrictions;
- Software updates;
- Plugin and theme updates;
- Security monitoring;
- Secure administrator authentication;
- Server-level security;
- Backup procedures;
- Protection against unauthorized access;
- Other appropriate technical safeguards.
Only authorized persons should have access to administrative systems according to operational need.
5. Customer Account Security
Customer accounts may contain information such as:
- Name;
- Email address;
- Purchased digital content;
- Membership information;
- Tour bookings;
- Favorites;
- Order history;
- Account preferences.
Users are responsible for helping protect their accounts.
We recommend that users:
- Use a strong and unique password;
- Avoid reusing passwords from other services;
- Keep login credentials private;
- Sign out on shared devices;
- Avoid accessing sensitive accounts over insecure public networks where possible;
- Contact us if unauthorized access is suspected.
6. Password Security
Where traditional email and password login is used, passwords should be stored using appropriate secure authentication mechanisms rather than in readable plain-text form.
aJourney personnel are not intended to have access to customer passwords in readable form.
If a password is forgotten, users should use the available password reset procedure instead of requesting the original password.
7. Social Login Security
Where available, aJourney may support login through:
- Google Sign-In
- Sign in with Apple
- Facebook Login (Meta)
When social login is used, authentication is performed through the relevant provider.
aJourney does not receive or store the user’s Google, Apple, or Facebook password.
The provider may send aJourney limited authentication information required to create or access the customer’s account.
Users should also protect the security of their Google, Apple, or Facebook account because access to those accounts may affect connected services.
8. Payment Security
aJourney may accept payments using:
- Credit cards;
- Debit cards;
- PayPal;
- Other authorized payment methods displayed during checkout.
Payments may be handled through specialized third-party payment processors.
These providers may operate secure payment infrastructure separately from the aJourney website.
9. Credit and Debit Card Information
Where card transactions are processed directly by an authorized payment provider, aJourney does not intend to store complete credit or debit card numbers on its own systems.
Depending on the payment provider, aJourney may receive limited transaction information such as:
- Payment status;
- Transaction reference;
- Payment method;
- Limited card details, such as the last digits;
- Billing information;
- Refund status.
Full payment card details may be collected and processed directly by the relevant payment processor.
10. PayPal Security
Where PayPal is available, customers may complete payments using PayPal’s secure payment systems.
aJourney does not receive the customer’s PayPal password.
PayPal may independently use security measures such as:
- Account authentication;
- Fraud monitoring;
- Transaction verification;
- Device analysis;
- Risk assessment;
- Other security procedures.
PayPal transactions are also subject to PayPal’s own terms and privacy policies.
11. Payment Authentication
Depending on the bank, payment provider, card network, or transaction, additional security verification may be required.
This may include:
- 3D Secure;
- One-time passwords;
- Banking application confirmation;
- Two-factor authentication;
- Identity verification;
- Fraud screening;
- Device verification.
aJourney cannot override authentication procedures required by a bank or payment provider.
12. Fraud Prevention
We may use automated or manual procedures to help identify suspicious activity.
A transaction may be reviewed, delayed, rejected, or cancelled where we reasonably detect signs of:
- Unauthorized card use;
- Stolen payment credentials;
- Account takeover;
- Unusual purchasing behavior;
- Duplicate or suspicious transactions;
- Chargeback abuse;
- Automated attacks;
- Other potentially fraudulent behavior.
In certain cases, additional verification may be requested before an order or booking is completed.
13. Payment Provider Responsibility
Payment providers are responsible for the security of the systems under their control.
Their services may have their own:
- Security standards;
- Privacy policies;
- Authentication procedures;
- Data retention rules;
- Fraud-prevention practices.
aJourney selects external providers based on operational requirements but does not directly control the security architecture of independent payment companies.
14. Storage of Personal Information
Personal information may be stored in systems used to operate aJourney, including:
- Website databases;
- Customer account systems;
- WooCommerce;
- Booking systems;
- Email systems;
- Hosting infrastructure;
- Backup systems;
- Other business systems.
Access should be restricted according to operational necessity.
15. Access Controls
Where appropriate, aJourney may apply access-control measures designed to limit access to personal information.
Examples may include:
- Administrator permissions;
- Staff-level access controls;
- User roles;
- Password-protected systems;
- Authentication requirements;
- Restricted database access.
Employees, contractors, or service providers should only access information reasonably necessary for their role.
16. Administrative Access
Administrative access to website, e-commerce, and customer systems may provide access to sensitive operational information.
We seek to restrict administrative access to authorized persons.
Administrative users are expected to:
- Protect their credentials;
- Avoid sharing access;
- Use secure authentication practices;
- Follow appropriate security procedures.
17. Backups
We may maintain backups of website, customer, order, or operational data to support:
- Business continuity;
- Recovery from technical failures;
- Protection against accidental loss;
- Restoration after certain security incidents.
Backup systems may be subject to separate access controls and retention procedures.
18. Software Updates
Outdated software can create security risks.
We therefore aim, where reasonably practical, to maintain and update relevant:
- WordPress core software;
- WooCommerce;
- Plugins;
- Themes;
- Server software;
- Applications;
- Security components.
Updates may occasionally cause temporary service interruptions.
19. Security Monitoring
We may use monitoring tools or security services designed to identify:
- Unauthorized login attempts;
- Malware;
- Suspicious requests;
- Abnormal traffic;
- Automated attacks;
- Website vulnerabilities;
- Other potentially harmful activity.
Security logs may contain technical information such as IP addresses, timestamps, device data, or system events.
20. Protection Against Automated Attacks
aJourney may use security mechanisms intended to protect against:
- Brute-force login attacks;
- Spam;
- Bots;
- Scraping;
- Malicious traffic;
- Credential stuffing;
- Other automated abuse.
Such systems may temporarily restrict or block access when suspicious activity is detected.
21. Data Minimization
We aim to collect and retain only information reasonably necessary for purposes such as:
- Processing purchases;
- Providing digital content;
- Managing tours;
- Maintaining customer accounts;
- Providing customer support;
- Preventing fraud;
- Meeting legal obligations.
Reducing unnecessary data collection also helps reduce security risk.
22. Data Retention and Security
Information is not intended to be stored indefinitely without reason.
Retention periods may depend on:
- Legal requirements;
- Tax requirements;
- Accounting obligations;
- Customer account status;
- Active purchases;
- Booking history;
- Fraud prevention;
- Dispute resolution.
When information is no longer reasonably required, it may be deleted, anonymized, or otherwise handled in accordance with our Privacy Policy and applicable law.
23. Third-Party Service Providers
aJourney may rely on third-party companies for services including:
- Website hosting;
- Cloud infrastructure;
- Payment processing;
- Analytics;
- Email delivery;
- Security services;
- Authentication;
- Backup systems;
- Customer support;
- Other technical services.
These service providers may process information necessary to perform their services.
Where appropriate, we seek to work with providers offering reasonable security practices.
24. International Data Processing
Because aJourney serves international customers and may use international technology providers, certain information may be processed or stored in different countries.
Security and privacy protections relating to international data processing are further described in our Privacy Policy.
25. Mobile Application Security
If aJourney is provided through a mobile application, the application may use security technologies such as:
- Authentication tokens;
- Secure communication;
- Device-level storage;
- Application security controls;
- Session management;
- Provider authentication.
Users should keep their device operating system and aJourney application updated where possible.
26. Device Security
The security of aJourney also depends partly on the security of the user’s device.
Customers are encouraged to:
- Use device passcodes or biometric protection;
- Install security updates;
- Avoid installing untrusted software;
- Avoid rooting or jailbreaking devices where this creates security risks;
- Protect devices against unauthorized access.
aJourney cannot control the security condition of individual customer devices.
27. Public and Shared Devices
Users accessing aJourney through public or shared computers or devices should exercise additional caution.
We recommend:
- Logging out after use;
- Avoiding password-saving features on public devices;
- Not leaving accounts open unattended;
- Clearing sensitive session data where appropriate.
28. Phishing and Impersonation
Customers should be alert to phishing attempts.
aJourney will not normally ask customers to send:
- Complete credit card numbers;
- Card security codes;
- Account passwords;
- Google passwords;
- Apple passwords;
- Facebook passwords;
- PayPal passwords
by ordinary email.
If you receive a suspicious message claiming to be from aJourney, please contact us through the official contact address:
29. Official Domain
The official aJourney domain is:
ajourney.app
Customers should exercise caution with websites that imitate the aJourney name, branding, or appearance.
aJourney is not responsible for fraudulent third-party websites that falsely impersonate our brand, although we may take reasonable action when such activity is identified.
30. Security Incidents
Despite reasonable safeguards, security incidents may occasionally occur.
If we become aware of a security incident affecting personal information, we may take steps including:
- Investigating the incident;
- Restricting affected systems;
- Resetting access credentials;
- Working with technical providers;
- Taking measures to reduce further risk;
- Notifying affected individuals where required;
- Notifying authorities where required by applicable law.
The exact response will depend on the nature and severity of the incident.
31. Customer Notification
Where legally required, affected customers may be notified if a security breach creates a relevant risk to their personal information.
Notifications may be sent through:
- Email;
- Website notification;
- Application notification;
- Other appropriate communication channels.
Customers are responsible for maintaining current contact information in their account where possible.
32. Reporting a Security Concern
If you believe you have identified a security problem relating to aJourney, please contact:
Please provide sufficient information to help us understand the issue.
We ask users not to exploit, publicly disclose, or unnecessarily access personal data while reporting a suspected vulnerability.
33. Unauthorized Account Access
If you believe your account has been compromised, you should:
- Change your password where applicable;
- Review your social login account security;
- Sign out of unknown sessions where available;
- Contact aJourney;
- Contact your payment provider if unauthorized payments occurred.
You can contact us at:
34. Unauthorized Payments
If you notice a payment that you did not authorize, you should promptly contact:
- Your bank or card issuer;
- PayPal, where applicable;
- aJourney.
You may contact aJourney at:
We may request reasonable information to investigate the transaction.
35. Employee and Contractor Confidentiality
Persons who have access to personal or operational information through their work with aJourney are expected to use such information only for legitimate business purposes and to maintain appropriate confidentiality.
Access may be removed when no longer required.
36. Privacy by Design
Where reasonably practical, we aim to consider privacy and security when introducing new systems or features.
This may include consideration of:
- What information is necessary;
- Who needs access;
- How data is transmitted;
- How long information should be retained;
- Whether third parties receive information;
- Whether additional user permissions are required.
37. No Absolute Security Guarantee
Although aJourney uses reasonable security measures, no website, application, server, network, or digital transaction system can be guaranteed to be completely secure.
Accordingly, we cannot promise that unauthorized third parties will never defeat security safeguards.
This statement does not reduce any obligations or responsibilities that cannot legally be excluded.
38. Customer Responsibility
Users also play an important role in protecting their personal information.
Customers should:
- Protect their login credentials;
- Use secure devices;
- Keep contact information current;
- Avoid sharing accounts;
- Report suspected unauthorized access;
- Avoid suspicious payment or login links.
39. Relationship With Our Privacy Policy
This Policy focuses specifically on data and payment security.
For broader information about:
- What personal information we collect;
- Why we process it;
- Who we share it with;
- Data retention;
- Privacy rights;
- Account deletion;
- Cookies;
- International transfers;
please review our Privacy Policy.
40. Relationship With Payment Terms
Information about payment authorization, accepted payment methods, refunds, currency conversion, payment failures, and electronic transactions is provided in our:
Payment & Distance Sale Agreement
Refund and cancellation rules are separately provided in our:
Cancellation & Refund Policy
41. Changes to This Policy
We may update this Data Security & Payment Security Policy from time to time to reflect changes in:
- Our technology;
- Hosting infrastructure;
- Payment providers;
- Security systems;
- Authentication methods;
- Mobile application;
- Business operations;
- Legal or regulatory requirements.
The latest version will be published on this page with the updated revision date.
42. Contact Us
For questions about data security, payment security, unauthorized access, or suspicious transactions, please contact:
PT Awakening Journey Bali
Brand: aJourney
Website: ajourney.app
Country: Indonesia
Security & Customer Support: info@ajourney.app
Business Address:
Jalan Gunung Soputan Nomor 1 A,
Desa/Kelurahan Pemecutan Kelod,
Kec. 80119 Denpasar, Bali, Indonesia
Last Updated: September 10, 2026


