Guides

Custom or off-the-shelf: a verdict for Indonesian nonprofits

Updated 2026-08-13 · Kaiser Khan

Short answer Reviewed 2026-08-13

Should an Indonesian nonprofit build custom software?

Usually not. Start with off-the-shelf tools you already have, and build custom only if staff copy data into three places or sensitive data sits in personal accounts. Kode Nirlaba will refuse to rebuild a spreadsheet, form or inbox that already fits. Skip this guide if you already want a paid consumer app.

What is the short verdict for this year?

Use off-the-shelf for mail, files and one-off forms. Consider custom for aid queues, donors with local rules, or beneficiary identity data. If the gap is only brand appearance, do not build. If field staff lose the thread every time a phone is replaced, then talk about custom.

The verdict is conservative on purpose. Unmaintained custom software becomes a new burden: a password only one person remembers, expired hosting, and features staff are afraid to touch. Small Indonesian nonprofits fail more often from brittle systems than from a lack of “innovation.”

Kode Nirlaba applies the same test to itself. If Google Workspace, a form and a tidy spreadsheet solve your problem in two weeks, we will say so and decline the project. Declining is the service.

What is the difference between custom, off-the-shelf and no-code?

Off-the-shelf is a product someone else maintains. No-code is off-the-shelf that you assemble. Custom is software built for your flow and it must have an owner after launch. All three are legitimate. The danger is custom with no owner, or no-code that stores beneficiary data in a staff member’s personal account with no backup.

Off-the-shelf examples: organisation Gmail, Drive, WhatsApp as an intake channel. No-code examples: a form that writes to a locked spreadsheet. Custom examples: an aid queue that rejects duplicate identities, routes board approval, and exports CSV for the accountant.

Three tool models
ModelWho maintains itWhen it winsMain risk
Off-the-shelfThe product vendorGeneric needsYour flow is forced to follow the product
No-codeYour staff plus the vendorSimple flows that change fastPersonal accounts, messy permissions
CustomA technical partner plus staffUnique flows, sensitive dataNo owner after launch

When should a spreadsheet be retired?

When two or more people copy the same rows, when identity files sit in a column without permissions, or when “final_final2” becomes the source of truth. Spreadsheets still win for a small list with one editor. Retire them for risk and duplication, not because they look old.

Many yayasan chairs feel embarrassed about spreadsheets. Do not. A spreadsheet with one owner, a Drive backup and agreed columns beats an app staff never open.

Signals we use in scoping: more than one “source of truth,” ID-card or bank details in a cell anyone in the group can download, or board reports that are always wrong because of copy-paste. Two of those three usually justify talking about a system, not a new colour theme.

How does the PDP law change the tool choice?

Law No. 27 of 2022 on Personal Data Protection governs personal data, including data nonprofits collect from beneficiaries. This is not legal advice. The practical meaning: do not put ID-card copies in a chat group, do not use a staff member’s personal Gmail as the archive, and do not build custom if you cannot delete data when a lawful request arrives.

The statute is published on BPK’s regulation network. We cite that text, checked 13 August 2026, not social-media rumour. For a compliance decision, use counsel authorised in Indonesia.

Off-the-shelf tools with organisation-level permission controls are often safer than custom written in a hurry. “Custom” is not a synonym for “more compliant.”

Sources and dates: UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (2026-08-13)

Which tools usually win without us?

Organisation email and documents, file storage with permissions, event registration forms, and a calendar. WhatsApp remains a reasonable human channel in Indonesia — do not try to kill it — but do not make chat the database. If that is all you need, you do not need Kode Nirlaba.

We take no commission from Google, Microsoft, Meta or any forms vendor. If we name a product, it is because nonprofit staff already use it, not because of an affiliate deal. There are no paid links in this guide.

When a product changes price or terms, we do not promise weekly monitoring. Check the vendor’s terms before you move data. This guide was reviewed on 13 August 2026.

  • Email on the organisation domain, not the chair’s personal address
  • Drive or equivalent with folders whose permissions are written down
  • One intake form, one locked spreadsheet, one backup person
  • WhatsApp for conversation; a system for the record

When will Kode Nirlaba build custom?

When the partnership filter passes and off-the-shelf tools force staff to harm the mission every week. Examples: duplicate aid queues, donations that do not match the bank, volunteers the board cannot approve. We still write down who maintains it after launch. Without an owner, we do not start.

Read the services page and the custom-or-ready tool as well. The tool uses the same test as this section, so the verdict is not trapped in prose.

How do you decide in a single board meeting?

Write the workflow on a board: who enters data, who approves, who reports. Mark each step “off-the-shelf,” “no-code” or “custom.” If more than half the steps are still off-the-shelf, do not start a custom project. If sensitive data has no written permission, stop adding tools until that permission exists.

One meeting is enough to decline. Accepting custom needs a longer scoping because the hidden cost is maintenance, not the demo.

Print the table above. If the board cannot point to a data owner in five minutes, you are not ready to build anything — custom or not.

Which questions remain after the verdict?

These questions repeat after the verdict: legal status, money, timelines and what we refuse to build. Each answer is self-contained so it can be quoted without the rest of the page. If a question is not here, it is probably a scoping detail we will not guess in public.

Does Kode Nirlaba always recommend custom software?

No. We often recommend off-the-shelf tools and refuse to build. We count that as a successful verdict.

Are spreadsheets always wrong?

No. A spreadsheet with one editor and a backup is often the right system. What is wrong is a spreadsheet as an open identity database in a group.

Is this legal advice on the PDP law?

No. It is a practical summary of a dated public text. Use legal counsel for a compliance decision.

What should you read next?

Continue with another decision guide, then the matching interactive tool, then apply only if the filter still passes. Do not send beneficiary data with the form. If a free tool already fits, stop here — that is a successful reading of this guide.