Reference

How poltar toto Handles Your Personal Data

This Privacy Policy explains exactly what personal data poltar toto collects when you open an account, how we store it, who can access it, and how you can…

Data encrypted at rest and in transitDANA, OVO, GoPay, QRIS payment data protectedAccount deletion available on requestNo data sold to third partiesRetention periods clearly stated
poltar toto How poltar toto Handles Your Personal Data
PRIVACY CONTACT PATHS

Reach Us About Your Privacy Rights

If you want to access, correct or delete your personal data, our privacy support team is reachable seven days a week, from 08:00 to 23:00 WIB.

Live Chat (Account Dashboard) Available 08:00–23:00 WIB, seven days a week. Use the chat icon inside your logged-in account to submit a privacy question or data access request instantly.
Email Privacy Request Send a formal data access, correction or deletion request to our privacy team by email. We acknowledge within 24 hours and resolve within 14 business days.
Account Settings Self-Service Navigate to Account Settings, then Privacy Controls to download your stored data, update your contact details or flag a data inaccuracy without contacting support.
HOW WE PROTECT YOU

Data Handling, Cookies and Account Security

Every layer of your account data — from your QRIS payment history to your session logs — is protected by AES-256 encryption both in storage and during transmission.

Encryption Standard

All account data, including DANA and OVO transaction references, is encrypted with AES-256. This applies to data at rest in our database and in transit between your device and our servers.

Cookie Policy

We use only session cookies (deleted when you close the browser) and first-party analytics cookies. No third-party ad-network cookies are placed on your device from our pages.

Account Security Controls

Two-factor authentication is available and we recommend enabling it under Account Settings. Any login from an unrecognised device triggers an email alert to your registered address within seconds.

Data Retention Schedule

Active account data is retained while your account is open. After you close your account, we hold records for five years for legal compliance, then permanently delete them on schedule.

Third-Party Sharing Limits

We share data only with payment processors like GoPay or QRIS networks strictly to complete your transaction, and with fraud-prevention partners under strict data processing agreements.

Your Right to Erasure

Submit a deletion request via live chat or email. We will remove your personal data within 30 days, except where retention is required by applicable law or ongoing transaction records.

Frequently Asked Questions About Your Privacy

These are the privacy questions we hear most often from Indonesian account holders — covering what data we hold, how long we keep it, how to access or delete it, and what happens to your payment details when you use DANA, OVO, GoPay or QRIS on our platform.

We collect your name, email address, phone number and your chosen payment method identifier — for example, your registered DANA or OVO mobile number. We also log your device ID and IP address to protect against unauthorised access.

No. We store only the transaction reference or order ID generated by the payment network. Your wallet PIN, bank password or full QRIS token is never transmitted to or stored on our servers.

We retain your account records for five years after closure to meet legal compliance requirements. After that period, all personal data is permanently deleted from our systems on a scheduled basis.

Yes. Navigate to Account Settings, then Privacy Controls to download your stored data directly, or contact our privacy team by email. We acknowledge requests within 24 hours and deliver the data within 14 business days.

Access is limited to authorised staff in account operations, fraud prevention and compliance roles. All staff with data access operate under confidentiality agreements, and access logs are reviewed quarterly by our internal audit team.

We do not sell or share your personal data with advertising networks. Data is shared only with payment processors to complete your DANA, GoPay or QRIS transactions, and with fraud-prevention partners under formal data processing agreements.

Submit a deletion request through live chat (08:00–23:00 WIB) or by email to our privacy team. We process deletions within 30 days, except where records must be retained under applicable law — which depends on local law in your jurisdiction.