Reference

How gettoto Handles Your Personal Information

This page explains exactly what data gettoto collects when you open an account, make a deposit via DANA, OVO or GoPay, or contact our support team.

Account data protectedDANA, OVO, GoPay transaction privacyNo third-party data sellingYou can request data deletionAvailable where local law permits
gettoto How gettoto Handles Your Personal Information
HOW WE PROTECT IT

Data Handling, Cookies and Account Security

We apply encryption to data in transit and at rest. Your account password is stored as a hashed value — we never see it in plain text. Sessions on mobile and desktop use token-based authentication, so logging out on one device does not leave an active session elsewhere. For players in Bandung or anywhere else accessing via mobile, this session model means your account state is tied to your verified login, not just your device.

Cookie Use We use session cookies to keep you logged in and analytics cookies to understand which account features are used most. You can manage cookie preferences in your browser settings at any time.
Data Retention Transaction records linked to DANA, OVO and GoPay deposits are kept for the period required to resolve disputes and meet applicable legal obligations. We delete inactive account data on request.
Account Security Every login triggers an OTP to your registered number. If we detect a login from an unfamiliar device or location, the session is paused until you verify via OTP — no exceptions.
Your Rights You can request access to your stored data, ask for corrections, or ask us to delete your account record entirely. Submit requests through live chat or email and we'll confirm receipt within one business day.
PRIVACY CONTACT PATHS

Reach Us About Your Data

If you want to request a copy of your data, ask us to correct something, or submit a deletion request, our support team handles all of these directly. You can reach us through live chat inside your account dashboard, by email at our listed address, or through the in-app help widget on mobile. Responses to data-related requests are prioritised over general account queries.

Live Chat Open your account dashboard and tap the chat icon. Data requests made through live chat are logged with a reference number so you can track the outcome.
Email Support Send your request to our support email address listed in the account help section. Include your registered phone number so we can verify your identity quickly.
In-App Help Widget On mobile, the help widget in the account menu connects you directly to our Indonesia support team. Use this path for wallet-related privacy queries about DANA, OVO or GoPay.

Answers to Your Privacy Policy Questions

These are the questions we hear most often about data, account privacy and how your wallet information is handled. If something isn't covered here, reach out through live chat.

We collect your name, phone number, email and registered e-wallet type — DANA, OVO or GoPay. Device and session data is also logged for account security purposes.

No. We only record the wallet type and transaction reference tied to a deposit or withdrawal. Your PIN and full wallet credentials stay inside your e-wallet app and never pass through our servers.

Yes. Send a data access request via live chat or support email with your registered phone number. We verify your identity first, then provide a summary of stored data within a reasonable timeframe.

Contact us through live chat or email and request account closure with full data deletion. We'll confirm receipt, process any pending transaction records, then remove your personal data from active systems.

We do not sell or rent your data to advertisers. Payment processors receive only the transaction data needed to complete your DANA, OVO or GoPay transfer — nothing more.

Transaction records are kept for as long as required to resolve disputes and meet legal obligations that apply in eligible regions. Inactive account data can be deleted on request at any time.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.