How We Handle Your Account Data
This is the totobet slot privacy policy — the page that tells you, in plain words, what we collect when you open an account, why we keep it...
Our Data Posture and Your Rights
We collect the minimum needed to run your account: your sign-in identifiers, the e-wallet handle you link, session logs, and the device fingerprint we use to flag unusual logins. Where local law permits, we keep transaction records for the retention windows Indonesia financial rules ask for, then we purge. You can request a copy of what we hold, ask us to correct
it, or close the account and trigger deletion of anything we're not legally required to keep. We never sell your contact details to third parties, and marketing consent is opt-in — toggle it off in your account settings whenever you like, and the change applies on the next session.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
How This Policy Stays Honest
We treat this page as a living document, reviewed on a fixed cadence and updated whenever the underlying flow changes. Here's what sits behind each line you read.
Quarterly Review
Our policy is read line-by-line every quarter against the actual data flows in the product. If the engineering side changes, the wording on this page changes the same week — no drift.
Named Owner
A single data protection lead signs off every revision. That name is on file with our regulator contact and is the person who answers escalations, not a rotating support pool.
Change Log
Material edits are logged with a date and a one-line summary at the foot of this page. You can scan the log to see what moved between visits without re-reading the entire policy.
Plain Wording
We avoid lawyer-only phrasing where a normal sentence works. If a clause has to stay technical for legal reasons, we add a short reader note underneath so the meaning is clear.
Indonesia Context
References to retention, consent and disclosure are written against Indonesia rules, not copied from a foreign template. That's why DANA, OVO, GoPay and QRIS are named directly here.
Independent Audit
Our data handling is reviewed by an external assessor on an annual schedule. The assessor's scope covers account data, payment metadata and session logs — the three areas this policy governs.
Consistency Across Our Policy Pages
This privacy policy sits alongside our terms, cookie notice and account-closure pages. The table below shows how each topic is treated here versus the sibling pages so you...
| Data Collected | Listed in full on this page; summarised one-line on the cookie notice and not repeated on terms. |
|---|---|
| Retention Windows | Defined here per data category; terms reference these windows by name rather than restating them. |
| Marketing Consent | Opt-in toggle described on this page; the account settings page links back here for the legal basis. |
| Third Parties | Named categories appear here; the cookie notice lists the specific tag vendors used on the site. |
| Your Rights | Access, correction and deletion explained here; the closure page describes the deletion mechanic itself. |
| Contact Routes | Privacy contacts on this page; general support contacts on the help centre, with no overlap in queues. |
| Update Cadence | Quarterly here; terms update on a separate cycle and carry their own dated revision header for clarity. |
What Shapes This Policy Page
A privacy policy is only useful if you can actually find what you're looking for. We've built this page around six visible elements so the clause you need is one scroll away, not buried...