Reference

How casatoto Handles Your Personal Data

Your personal information — from your account details to payment records via DANA, OVO, GoPay and QRIS — is held under a clear set of rules that put…

Data collected with your consentDANA, OVO, GoPay & QRIS transaction records protectedAccount data encrypted at restRight to request data removalIndonesia-based support for privacy queries
casatoto How casatoto Handles Your Personal Data
PRIVACY CONTACT PATHS

Open a Privacy Request With Our Team

If you want to access, correct or delete data we hold about you, our privacy team is reachable seven days a week. You can send a formal data request via live chat between 08:00 and 23:00 WIB, raise a ticket by email at any hour, or contact us through our dedicated privacy form inside your account dashboard under Settings — My Data.

Team online

Live Chat

Available 08:00–23:00 WIB daily. Start a chat from the account dashboard and a privacy agent will respond within three minutes to handle data access or deletion requests.

Email Support

Send your request to our privacy inbox any time. We acknowledge every email within 24 hours and resolve data queries within five working days, in line with our retention policy.

In-Account Form

Log in, go to Settings, then My Data, and submit a structured privacy request. This path lets you specify whether you want data access, correction or full account-data deletion.

HOW WE PROTECT YOU

Browse Our Data Handling and Security Practices

From the moment you open an account, every layer of data handling follows a defined internal protocol — from AES-256 encryption at rest to TLS 1.3 in transit.

Data Encryption

All account data, including payment references for DANA, OVO, GoPay and QRIS, is encrypted with AES-256 at rest.

Cookie Policy

We use session cookies to keep you logged in and analytics cookies to measure page performance.

Account Security

Two-factor authentication is available under Security Settings.

Data Retention Rules

Transaction logs are kept for 12 months for fraud review, then purged.

Third-Party Sharing

We do not sell your personal data. Payment processors (such as those handling DANA or QRIS) receive only the reference…

Your Rights and How to Use Them

You have the right to access a copy of your data, request corrections, or ask for full deletion.

Questions About Your Data on casatoto

These are the privacy questions we hear most often. If your situation is not covered here, our privacy team is available via live chat 08:00–23:00 WIB or by email around the clock.

We collect your name, email address, phone number and the payment identifiers you link — such as your DANA or OVO account reference. We do not store full wallet passwords or card PINs at any point during registration or transactions.

Payment processor references are stored in an encrypted database separate from your profile. Only the transaction token is retained for up to 12 months for fraud monitoring; after that it is automatically purged from our systems.

Yes. Log in, navigate to Settings, then My Data, and submit a data-access request. We will compile and send you a full export of your account data within five working days, formatted as a readable file.

Submit a deletion request through the My Data form in Settings or email our privacy team directly. We complete the deletion within 30 calendar days and send a written confirmation once your data has been fully removed from our servers.

We do not sell or share your personal profile with advertisers. Payment processors receive only the transaction tokens needed to clear your DANA, GoPay or QRIS payment — nothing more. No browsing or session data is passed to external ad networks.

Open Privacy Settings inside your account and toggle each cookie category on or off. Withdrawing analytics or marketing cookies does not affect your ability to log in, deposit or access any part of the lobby — session cookies remain active for functionality.

Yes. Data collection, retention and sharing practices depend on local law. Where local law permits, we apply Indonesia's personal data protection framework, and access to certain data-processing features may be adjusted accordingly for Indonesia-based accounts.