Reference

How indosttoto Handles Your Personal Data

This privacy policy explains exactly what data we collect when you use your account, how we store it, and who can access it — covering everything from your DANA or OVO wallet details to your login activity.

Account data protectedDANA, OVO, GoPay wallet privacyNo third-party data sellingYou control your dataIndonesia-region policy
indosttoto How indosttoto Handles Your Personal Data
PRIVACY CONTACT PATHS

How to Reach Us About Your Privacy

If you want to request access to your stored data, ask us to correct something, or raise a concern about how your information is handled, our support team is the right place to start. Reach out through any of the channels below and include your registered account details so we can verify your identity before acting on any request.

Team online

Live Chat

Start a live chat session from your account dashboard. Identify yourself with your registered email and we will handle your privacy request directly through the chat thread.

Email Support

Send your data access or correction request to our support email. Include your account username and the specific data point you want reviewed, corrected, or removed.

Account Help Centre

Visit the Help Centre section inside your account. The privacy request form there lets you submit a structured request that goes straight to the data team for review.

DATA HANDLING PRACTICES

Security, Cookies, Retention and Your Rights

We apply several layers of protection to the data tied to your account. SSL encryption covers all data in transit between your device and our servers. Account access requires your registered credentials plus OTP verification — so even if someone has your password, they cannot reach your account without your phone. Here is how we handle the four areas you are most likely to ask about.

Cookie Use

We use session cookies to keep you logged in and analytics cookies to understand how the lobby is used. You can adjust cookie settings in your browser at any time without losing account access.

Account Security

Every login triggers an OTP to your registered number. Failed login attempts are flagged automatically, and repeated failures lock the account pending identity verification through our support team.

Data Retention

We keep your account data for as long as your account is open. Once you request closure, personal data is deleted or anonymised within the period required by applicable law in eligible regions.

Your Rights

You can request a copy of the data we hold on you, ask us to correct inaccurate records, or ask us to delete your data where no legal retention obligation applies. Contact our support team to start that process.

Common Questions About Your Privacy on indosttoto

These are the questions we hear most often about how we manage account and payment data. If your question is not covered here, live chat or the Help Centre form will get you a direct answer from the data team.

We store only the transaction reference numbers needed to verify and reconcile your deposits and withdrawals. We do not store your full wallet login credentials or PIN for any of those payment methods.

Access is restricted to authorised team members who need it to provide support, verify transactions, or investigate security issues. No external advertiser or marketing partner has access to your personal data.

Yes. Submit a data access request through the Help Centre form or via email. We will verify your identity first, then provide a summary of the personal data tied to your account within a reasonable timeframe.

Contact us through live chat or email with your account details and a deletion request. We will process it after identity verification, subject to any retention obligations under applicable law.

We may update this policy when our practices change or when applicable law requires it. If changes are material, we will notify you through your registered contact details or a notice on the account dashboard.

Session activity logs are kept while your account is open for security and support purposes. After account closure, logs are anonymised or deleted within the period set by applicable law for eligible regions.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.