Reference

How toto328 Handles Your Personal Data

Your account data — including the wallet details you connect through DANA, OVO, or GoPay — is handled with care at every step, from the moment you register through every transaction you make.

DANA, OVO, GoPay wallet data protectedAccount access secured with OTP verificationNo data sold to third partiesRight to request data deletionIndonesia-region data handling
toto328 How toto328 Handles Your Personal Data
DATA HANDLING STANDARDS

How We Protect and Manage Your Information

Every layer of your account — from login to withdrawal — carries its own data protection measure. Here is how each area works in practice.

Wallet Data Handling

When you link DANA, OVO, or GoPay to your account, we store only the reference identifiers needed to route transactions — never full account credentials. Payment processors handle the actual transfer under their own security protocols, and we receive only a confirmation token once the transaction clears.

Account Security Layer

Every login triggers an OTP check sent to your registered mobile number. If the correct code is not entered within the session window, access is blocked. This means that even if someone has your password, they cannot reach your account without physical access to your registered device.

Cookie and Session Data

We use session cookies to keep your lobby state intact — so when you switch from your GoPay app back to the lobby on mobile, your position in the game is preserved. You can clear cookies from your browser or device settings at any time. Doing so will log you out of your current session.

Data Retention Policy

We retain account records for as long as your account remains active and for a period after closure as required by applicable regulations in Indonesia. Transaction records tied to DANA, OVO, or GoPay payments are kept for audit purposes. You can request details about the specific retention period that applies to your account.

Third-Party Data Sharing

We do not share your personal data with advertisers or data brokers. The only third parties who receive any portion of your data are the payment processors — DANA, OVO, GoPay — and service providers directly involved in running the platform. Each provider is bound by data handling agreements that limit how they use your information.

Your Rights and Requests

You can request access to your stored data, ask us to correct any inaccuracy, or request deletion of your account record. Deletion requests are reviewed against legal retention requirements before processing. Players in Depok and across Indonesia submit requests through the data form in account settings — our team reviews each one individually.

PRIVACY CONTACT PATHS

How to Reach Us About Your Data

Live Chat Support For questions about what data we hold on your account, open the live chat panel directly from the lobby.
Account Help Desk If you want to update your registered details — such as the email address tied to your DANA or OVO wallet — submit a request through the account help section.
Data Request Form To request a full copy of your personal data, ask for a correction, or submit a deletion request, use the dedicated data request form in your account settings. We aim to respond within a reasonable timeframe.

Common Questions About Your Privacy on toto328

Here are the questions we receive most often about data handling, account privacy, and your rights as a registered account holder.

When you register, we collect your name, contact details, and the payment method you choose — DANA, OVO, or GoPay. We also record your device identifiers and IP address for security purposes. This data is used only to manage your account and process your transactions.

No. We store only the reference token returned by the payment processor after a transaction is completed. Your actual DANA, OVO, or GoPay login credentials remain with those services and are never passed through or stored on our platform.

Yes. Submit a data access request through the form in your account settings. We will verify your identity via OTP and then provide a summary of the personal data we hold on your account, including transaction references and session history, within a reasonable timeframe.

Contact our support team through live chat or use the account help desk to submit a correction request. You will need to verify your identity first. Once verified, we update the relevant record — such as your registered email or linked payment method — and confirm the change to you.

You can submit a deletion request through the data request form in your account settings. We review each request against legal retention obligations in Indonesia before processing. Some transaction records tied to DANA, OVO, or GoPay payments may need to be kept for a defined period under applicable regulations.

We do not share your data with advertisers or data brokers. Data is shared only with payment processors — DANA, OVO, GoPay — and platform service providers who are contractually required to handle it with the same care we apply internally. No marketing use of your data by external parties.

Cookies keep your session active between page loads and preserve your lobby state when you switch apps on mobile. We also use them to remember your language and currency preferences. You can clear or block cookies through your browser or device settings, though doing so will end your current login session.

Every login requires an OTP sent to your registered mobile number. Without the correct code, access is blocked regardless of whether the password is correct. We also monitor session activity and flag logins from unrecognized devices, which may trigger an additional verification step before granting account access.

Account data is kept for as long as your account is active and for a further period after closure as required by regulations applicable in Indonesia. Transaction records linked to DANA, OVO, or GoPay are retained for audit and compliance purposes. You can request the specific retention period that applies to your account through our support team.

Yes. The same policy covers all access methods — mobile browser, desktop, or any app-based access. Mobile sessions generate the same session data and are subject to the same OTP verification and security monitoring. Access and feature availability depend on local law and eligible regions in Indonesia.