Reference

How We Protect Your Personal Data

Your privacy matters to every decision we make at sbototo login — from the moment you create an account to every deposit and withdrawal you process through DANA…

Data encrypted in transit and at restNo sale of personal data to third partiesAccount deletion available on requestQRIS & DANA payment data handled securelyRetention periods clearly defined
sbototo login How We Protect Your Personal Data
PRIVACY CONTACT PATHS

Reach Us About Your Data

Live Chat — 24 Hours Our live chat team is available around the clock. If you want to know what data we hold about your account, request a correction, or ask about data retention, our agents can log and escalate your inquiry within minutes — any time of day from Jakarta to Yogyakarta.
Email Privacy Desk Send a written data request to our dedicated privacy email address. We acknowledge all privacy-related emails within 24 hours and aim to provide a full response within 7 working days, covering data access, correction requests, and deletion inquiries.
In-Account Request Form Log into your account, navigate to Settings, then Privacy, and submit a formal data request directly from your dashboard. This channel creates an auditable record of your request and generates a reference number you can use to follow up with our team.
DATA HANDLING PRACTICES

How We Handle and Secure Your Information

We apply layered security measures across every stage of your data's lifecycle — from collection at account creation through to deletion on your request.

Cookies and Tracking

We use session cookies to keep you logged in and analytics cookies to understand which features you use most. You can manage cookie preferences from your browser settings at any time. We do not use cookies to build advertising profiles for external parties.

Account Security

Your account password is stored using a one-way hashing function — we cannot read it, only verify it. We also offer two-step verification at login. Any suspicious login attempt from an unrecognised device triggers an automatic email alert to your registered address.

Payment Data Retention

Transaction references for DANA, OVO, GoPay, and QRIS payments are retained for the period required by Indonesian financial regulations. We do not store your full e-wallet credentials — only the masked reference needed to verify and reconcile each transfer.

Data Access Rights

You can request a copy of the personal data we hold on you at any time through the in-account form or by emailing our privacy desk. We will deliver a structured data export within 7 working days of verifying your identity.

Correction and Deletion

If any data we hold about you is inaccurate, submit a correction request and we will update it within 5 working days. Account deletion requests are processed within 30 days, after which your personal data is removed from our active systems entirely.

Third-Party Processors

We share data only with processors necessary to operate the platform — payment gateways for QRIS and GoPay settlement, identity verification services, and fraud-detection providers. Each processor is bound by a data processing agreement that prohibits secondary use of your information.

Your Questions About This Policy Answered

The questions below cover what Indonesian account holders ask most often about how sbototo login handles personal data, payment records, cookies, and the rights you hold over your own information. If your question is not answered here, reach us through live chat at any hour.

We collect your name, email address, phone number, and a government-issued identity document for verification. Once you deposit, we also record the payment reference from your DANA, OVO, GoPay, or QRIS transaction. Device and session data are collected automatically to detect fraud and maintain account security.

No. We do not sell, rent, or trade your personal data to any advertiser or data broker. Data is shared only with the processors that make the platform operate — payment gateways, identity checks, and fraud prevention — all bound by strict data processing agreements.

Active account data is retained for as long as your account exists. After account closure, we retain records for the legally required period under Indonesian financial and consumer regulations. Once that period expires, your personal data is deleted from our active databases.

Yes. Submit a data access request through Settings, then Privacy, in your account dashboard, or email our privacy desk. We verify your identity first, then deliver a structured export of your personal data within 7 working days of confirming the request.

Use the correction request form in your account settings or contact our live chat team — available 24 hours a day. We review and apply corrections within 5 working days. For identity document updates, you may be asked to provide a fresh verified copy.

Payment transaction references are subject to Indonesian financial record-keeping requirements. Even after account deletion, masked transaction references are retained for the legally required period, then permanently removed. We never retain full e-wallet credentials — only the reference needed for reconciliation.

We use session cookies to authenticate your login and analytics cookies to see which parts of the platform you use. You can block or delete cookies through your browser settings at any time. Disabling analytics cookies will not affect your ability to log in or make deposits.