Reference

obortoto Privacy Policy for Indonesian Accounts

We keep this page plain so you can open an account knowing how your data is handled.

ACCOUNT DATACOOKIE CONTROLREQUEST ACCESSLOCAL LAW
obortoto obortoto Privacy Policy for Indonesian Accounts
REQUEST CHANNELS

Contact us about privacy requests

Fast contact matters when a privacy request needs an answer. We keep a human path open from 09:00-22:00 WIB through live chat, WhatsApp, and email, so you can ask about stored data…

Live Chat Use live chat from the account area when you need a privacy correction, a copy request, or help with device access. We answer from 09:00-22:00 WIB and confirm your account before changing anything.
WhatsApp Send a WhatsApp message if chat is busy. We use the same ownership check for every privacy request, then tell you what we changed, what we kept, and why.
Email Email us when you want a written trail for your privacy case. We keep the thread tied to your account so you can follow the status without repeating details.
ACCOUNT SAFETY

Data control, cookies and retention

Privacy handling stays narrow on our side. We use account data, cookies, and device signals to verify access, keep requests tied to the right profile, and reduce stray records.

Data Intake

We collect only the details needed to run the account: your form entry, login time, device data, and the DANA, OVO, GoPay, or QRIS reference used for matching. That helps us answer later correction requests without extra back-and-forth.

Cookie Control

Cookies remember the session, the page language, and a few safety checks. On Chrome, Safari, or the browser on your phone, you can clear them through Settings > Privacy > Cookies, and the policy still governs stored logs.

Access Safety

When a new device logs in, we may ask you to confirm it by code or account detail. That check helps stop account takeovers and keeps your privacy request linked to the right profile.

Retention Window

We keep records only while they are needed for account operation, dispute handling, legal duty, and fraud checks. After that, we remove or anonymize them so the data does not sit around longer than needed.

Change Requests

To correct, export, or delete data where local law allows, send a request from your registered email or through live chat. We verify ownership first, then process only the exact change you asked for.

Contact Path

If you want a human explanation of this policy, ask for the privacy desk. Our support team routes the case to the people who handle records, cookies, and account access, so the answer stays consistent.

Common privacy questions from you

These are the privacy questions you may ask before you open an account or send a request. We answer them with the same rules we use for support: ownership check first, minimal data handling, and clear retention limits. If local law does not permit access in your area, we do not provide the service there, but the policy still explains how we manage any record already held.

We collect the details you type into the form, login timestamps, device signals, and the wallet reference used with DANA, OVO, GoPay, or QRIS. That lets us match your account and respond to later requests.

Yes. Send the corrected detail from your registered email or live chat, and we check ownership before updating the record. If we need proof, we ask only for the smallest matching item, such as the right wallet reference.

Cookies keep you signed in, remember language choice, and help us spot unusual logins. You can clear them in Chrome, Safari, or your phone browser settings, but some session settings may reset after that.

We keep records only as long as they are needed for account operation, dispute handling, legal duty, or fraud checks. After that period, we remove or anonymize the data so it is no longer tied to your profile.

Only the support staff who handle privacy cases can see it. We keep the thread attached to your ticket, do not spread it across unrelated teams, and confirm the final action back to you.

If local law does not permit access or use in your area, we do not open the service there. The policy still explains how we protect any data already collected where access was allowed.