Privacy Policy
What we collect, why we need it, who sees it and how we look after it, whether you are planning an event, running a hotel on Venora or just chatting with us.
Last updated: 9 October 2026
On this page
The short version
- We only collect what we need to connect event organisers with hotels: your account, your company, your requests and the paperwork for a booking.
- A hotel sees the request you send it. It never sees which other hotels you asked.
- We never touch the money for a venue. You pay the hotel directly, into its own bank account.
- We don't sell your data, we don't use it for ads, and there are no ad or analytics trackers on Venora.
- Bank account numbers, tax numbers (NPWP) and phone numbers are encrypted in our database.
- You can see, fix, download or delete your data. Just ask and we'll help.
About this policy
Venora (venora.asia) is a marketplace for MICE venues: meetings, incentives, conferences and exhibitions. Organisers use it to find meeting rooms and ballrooms, hold sessions, send requests for proposal to hotels and see a booking through to payment. Hotels use it to manage their rooms and answer those requests.
This policy covers everyone who uses Venora: visitors, organisers (personal and company accounts), hotel partners, people who apply to list a hotel, and anyone who chats with us. It applies to the website, the emails we send, the documents we create (proposals, Pro Forma Invoices and receipts) and our Ask Venora chat. Under Indonesia's Personal Data Protection Law (Law No. 27 of 2022, the "UU PDP"), Venora is the controller of this data.
When you send a request to a hotel, the hotel gets what it needs to reply to you. From then on, how the hotel uses that information in its own business is its responsibility, under its own privacy practices.
What we collect
We keep it to what the service actually needs. Most of it comes from you; a little is recorded automatically as you use the site.
- Your accountyour name, email, phone number, job title, profile photo (if you add one), and the language and theme you pick. Your password is stored only as a scrambled one-way hash, so nobody can read it, not even us. If you turn on two-step sign-in, its secret key and recovery codes are encrypted.
- Your companyfor company accounts: company name, industry, office address and city, tax number (NPWP) and website.
- Your requests and bookingswhat you tell a hotel about your event (name, type, date and sessions, number of guests, notes and a contact phone) and everything that follows: quotes, counter-offers, holds, confirmations, and the reasons given when a request is cancelled or declined.
- Venue paymentswe don't receive the money, but we keep track of it: the Pro Forma Invoice the hotel sends, the proof of transfer you upload (photo or PDF, with the amount, date, bank and sender name), whether the hotel accepted it, and the receipt. We also keep the hotel's bank details so they can go on its invoices.
- Premiumthe plan and period you choose, how you'd like to pay, the amount and where your order stands. Card numbers typed into the checkout are never sent to us.
- Hotelsthe hotel's profile, photos, packages and prices, its sales contact (name and WhatsApp) and bank account, plus the accounts of the people who manage it. If you apply to list a hotel, we keep your name, job title, email, phone, the hotel's name and city, and your message.
- Ask Venora chatthe messages you send and receive. If you're not signed in and ask to talk to our team, also the name and email you give us so we can reply.
- Recorded automaticallyyour IP address and browser details when you sign in or do something security-related (these go into our activity log), a note of the browsers you've signed in from, and the cookies listed below. No analytics, no ad trackers.
What we use it for
- Running Venora for yousetting up your account, showing you venues, placing and keeping holds, getting your requests to the hotels you choose, letting them quote and negotiate with you, and creating proposals, invoices and receipts.
- Keeping track of paymentsshowing both sides what's owed, passing your proof of transfer to the hotel, and marking a booking as paid. The money itself moves between you and the hotel.
- Premiumtaking your order, sorting out payment with you and switching Premium on for your account.
- Keeping in touchemails about your account and requests (codes, confirmations, quotes, invoices, security alerts), and replies in the chat or by email. We don't send marketing emails.
- Keeping accounts safechecking sign-ins, letting you know when your account is used from a new browser, turning down passwords that have already leaked, slowing down repeated attempts, and keeping an activity log so misuse can be spotted and looked into.
- Understanding how Venora is doingtotals for hotels and for our team (requests, conversion, revenue, commission), all counted inside our own system.
- Following the lawkeeping the records tax and commercial law require, and responding to lawful requests from the authorities.
We don't sell or rent out personal data, and we don't build ad profiles. We also don't make decisions about you purely by computer that have a legal or similarly serious effect on you.
Why we're allowed to
The UU PDP (Article 20) lists the legal grounds for using personal data. We rely on these:
- Our agreement with yourunning your account, requests, holds, bookings and membership.
- Your consentwhich you give when you sign up or send us information. You can withdraw it any time, going forward, by contacting us.
- Legal obligationskeeping the records the law requires and answering lawful requests.
- Legitimate interestskeeping Venora secure, preventing fraud and misuse, and improving the service, always balanced against your rights.
Who we share it with
- Hotels you send a request toget your brief, your name and job title, your company profile and the contact phone for the event, so they can reply. If you send the same request to several hotels, none of them learns who else you asked. You get the hotel's sales contact once it sends your Pro Forma Invoice, or right away if you're Premium.
- Organiserssee a hotel's public profile, rooms and prices, its sales contact (as above), and, on an invoice, the bank account the hotel wants to be paid into.
- Companies that help us run Venoraand only on our instructions: our server and email host; the cloud storage that holds our backups; Google, whose map appears on room pages (your browser loads it straight from Google); Have I Been Pwned, which only ever sees the first five characters of a scrambled version of a new password, never the password itself, to tell us if it has leaked before; and our uptime monitor, which just checks the site is online and gets no personal data.
- Authoritieswhen the law says we must, or to protect the rights, property or safety of Venora, its users or the public.
- A new ownerif Venora is ever reorganised, merged or sold. This policy, or one that protects you at least as well, would still apply.
Data outside Indonesia
Some of the services we use, Google for example, may handle data on servers outside Indonesia. When that happens we follow Article 56 of the UU PDP: the data only goes where it is protected at least as well as here, with the right safeguards in place, or with your consent.
Cookies and browser storage
We only use the cookies Venora needs to work. No ad cookies, no analytics, no social-media trackers.
| Name | What it does | How long |
|---|---|---|
venora-session |
Keeps you signed in and remembers your visit. Encrypted. | Two hours after the last page you open |
XSRF-TOKEN |
Stops other sites from sending forms in your name. | Same as the session |
remember_web_… |
Keeps you signed in when you tick "Remember me on this device". | Until you sign out, at most 400 days |
theme, locale |
Remembers your theme and language. | One year |
venora_chat |
Lets you pick up your Ask Venora chat again if you're not signed in. | 90 days |
venora_device |
Recognises browsers you've signed in from, so we can email you when a new one is used. | Five years, or until you clear it |
Venora also keeps a few small notes in your browser's session storage, like a notice you've closed or a form you haven't sent yet. They never leave your browser and disappear when the browser session ends.
The Google map on room pages comes straight from Google, which may set its own cookies under Google's privacy policy. You can block or delete cookies in your browser, but if you block Venora's own, you won't be able to sign in.
How long we keep it
- Account and company detailsfor as long as your account is open. When an account is deleted, its details are removed or anonymised, apart from the records below that we have to keep.
- Requests, bookings, invoices, proofs of transfer and receiptsfor as long as the booking and any dispute about it need, and then for as long as tax and commercial law say records must be kept.
- Activity log365 days, then deleted automatically.
- Finished chats180 days after they close, then deleted automatically, messages and all.
- Browsers you've signed in fromforgotten after 365 days of not being used.
- Backupsnightly backups stay 14 days on our server and up to 60 days in separate cloud storage, then they're deleted. So when you delete something, it's gone from the backups once they expire too.
How we keep it safe
- Every page is sent over HTTPS, and browsers are told to always use it.
- Passwords are stored as one-way hashes. Bank account numbers, tax numbers (NPWP), phone numbers and two-step sign-in keys are encrypted in the database.
- Anyone can turn on two-step sign-in. We email you when your account is used from a new browser, and we turn down passwords that are known to have leaked.
- Everyone only sees what they need: a hotel sees its own hotel and requests, an organiser sees their own requests, and our team works in a separate admin area. Team sessions sign out on their own after a while without activity.
- Repeated sign-in attempts are slowed down, security-related actions go into the activity log, and the site limits which scripts are allowed to run on its pages.
- Proofs of transfer, unpublished photos and profile photos are stored privately and only shown to the people involved.
No system is ever completely secure. If personal data is ever exposed, we'll tell the people affected and the authority in writing within 3 × 24 hours, as Article 46 of the UU PDP requires: what was exposed, when and how it happened, and what we're doing about it.
Your rights
The UU PDP (Articles 5 to 13) gives you the right to:
- know who is using your data, why, and on what basis;
- see your data and get a copy of it;
- have wrong or incomplete data fixed;
- have us stop using your data and delete or destroy it;
- withdraw your consent;
- object to decisions made about you purely by computer;
- have us pause or limit how we use your data;
- get your data in a common format and have it moved to another provider;
- complain if your rights are breached, and claim compensation.
You can change most of your details yourself under Profile and Settings. For anything else, get in touch using the details below. We'll check it's really you first, reply within the time the UU PDP allows, and let you know if the law requires us to keep any of it. Some rights can be limited where the law allows, for example for law enforcement.
Children
Venora is built for businesses and adults planning events. It isn't meant for anyone under 18, and we don't knowingly collect their data. If you think a child has given us personal data, let us know and we'll delete it.
Other websites
Venora links to sites we don't run, like hotels' own websites, WhatsApp, social networks and maps. When you use them, their own privacy policies apply.
Changes to this policy
We'll update this policy when Venora or the law changes, and the date at the top always shows the latest version. If a change makes a real difference to how we use your data, we'll tell you by email or with a notice on the site before it takes effect.
This policy is available in English and Indonesian. If the two ever differ, the Indonesian version is the one that counts.
Get in touch
Questions about this policy, or want to use any of your rights? Contact us:
Or just open Ask Venora, the chat in the bottom corner of every page.