Reference

Privacy Policy at petatoto link

petatoto link collects only the data needed to keep your account secure and your transactions running — deposits via DANA, OVO, GoPay and QRIS processed accurately and withdrawals…

Data encrypted at rest and in transitAccount info never sold to third partiesDANA, OVO, GoPay & QRIS payment records protectedDeletion requests handled within 14 business days
petatoto link Privacy Policy at petatoto link
PRIVACY CONTACT PATHS

How to Reach Our Privacy Team

If you want to access, correct or delete the personal data we hold on your account, our privacy team is reachable every day from 08:00 to 23:00 WIB — including weekends. Many players in Bandung and across Indonesia send their requests via live chat and receive a first response within two hours during peak hours. For formal written requests, email is the appropriate channel and we aim to confirm receipt within one business day.

Team online

Live Chat

Available daily 08:00–23:00 WIB. Start a session from your account dashboard under Settings → Help, and a privacy-trained agent will pick up your data request directly.

Email Request

Send your data access, correction or deletion request to our privacy address listed in your account portal. We confirm receipt within one business day and resolve most requests within 14 business days.

In-Account Form

Log in, navigate to Settings → Privacy, and submit a structured request form. This route auto-tags your account ID so our team can locate your records without additional back-and-forth.

DATA HANDLING PRACTICES

Six Ways We Protect Your Account Data

Every measure below is operational — not a policy statement sitting in a document. These are the actual controls running on the platform today, covering how your payment details, login credentials and…

End-to-End Encryption

All data transmitted between your device and our servers uses TLS 1.3 encryption. This covers login credentials, DANA and OVO payment tokens, and every account settings change you submit.

Cookie Controls

We use session cookies for login continuity and analytics cookies to understand page performance. You can review and withdraw consent for non-essential cookies at any time from your browser or the cookie banner on your first visit.

Account Security Layers

Two-factor authentication is available for all accounts. We send a one-time code to your registered phone number every time a login is attempted from an unrecognised device or IP address.

Data Retention Schedule

Transaction records linked to GoPay and QRIS payments are retained for five years to meet financial-record obligations. Account profile data is deleted within 30 days of a confirmed account closure request.

Third-Party Sharing Policy

We share data with payment processors — including DANA, OVO, GoPay and QRIS operators — only as needed to complete your transaction. We do not sell, rent or license your personal data to advertisers or data brokers.

Your Right to Correction

If any personal detail on your account is inaccurate, contact us via live chat or the in-account form and we will update the record within three business days after verifying your identity.

Frequently Asked Privacy Questions

Below are the questions our users ask most often about how we handle personal data, what rights you have, and how to act on those rights. Each answer reflects the actual process we follow — not a generic policy template.

We collect your name, email address, phone number and the wallet or account identifiers for whichever payment method you use — DANA, OVO, GoPay or QRIS. We also log your device type and IP address for security screening, stored for 90 days.

We store the transaction reference and wallet identifier needed to match your deposit to your account. Full wallet credentials are never stored on our servers; they are processed directly through the DANA, OVO, GoPay or QRIS payment gateway and not retained by us.

Log in and go to Settings → Privacy to submit a data-access request, or contact live chat between 08:00 and 23:00 WIB. We will compile and deliver your data summary within 14 business days of verifying your identity.

Yes. Submit a deletion request via the in-account form or by email. We will remove your profile data within 30 days of account closure confirmation. Transaction records linked to GoPay or QRIS may be retained for five years to meet financial-record obligations.

We share data only with payment processors — DANA, OVO, GoPay and QRIS operators — to complete transactions, and with fraud-detection services that operate under strict data-processing agreements. We do not sell your data to advertisers or any external parties.

We use essential session cookies to keep you logged in and optional analytics cookies to measure page performance. You can withdraw consent for analytics cookies at any time through the cookie settings panel accessible from the footer of every page.

Yes — whether certain data-handling or disclosure obligations apply to your account depends on local law. We apply the most protective standard available in your region and will notify you if a legal obligation requires us to process your data in a specific way.