Reference

What Our Legal Terms Cover for Your Account

These legal terms set out how onitoto operates your account, handles your data, and applies platform rules — availability depends on local law and eligible regions in Indonesia.

Account Terms & ConditionsPrivacy & Data PolicyDANA, OVO, GoPay Payment RulesUser Rights & RequestsJurisdiction-Dependent Access
onitoto What Our Legal Terms Cover for Your Account
LEGAL CONTACT PATHS

How to Reach Us on Legal or Policy Matters

Team online

Live Chat Support

Open the live chat window from any page in your account dashboard. Legal and policy questions are routed to the compliance team. For payment disputes involving DANA, OVO, or GoPay, have your transaction reference ready so we can pull the record without delay.

Email — Policy Requests

Send data access requests, deletion requests, or written complaints to our registered support email. Include your account username and the specific policy area you are querying. We acknowledge all written requests and aim to respond with a clear position on your case.

Account Help Centre

The Help Centre inside your account lists every active policy document, including the current version of our privacy notice and payment terms. Use it to check when each document was last updated and to download a copy for your records. Access it from the account menu.

ACCOUNT SECURITY STANDARDS

How onitoto Handles Data, Security and Your Rights

Your account security and data rights are built into how we operate the platform — not added as an afterthought. Here is what we keep consistent across every account, regardless of which payment method you use or which part of the lobby you access.

Data We Collect

We collect only the information needed to operate your account — your registration details, session activity, and payment transaction references from DANA, OVO, or GoPay. We do not collect payment card numbers or store full wallet credentials.

Cookie Use

We use session cookies to keep your account logged in and functional cookies to remember your lobby preferences. Analytics cookies help us understand how the platform is used — these are non-identifying.

Account Security Practices

Every login is protected by OTP verification sent to your registered contact. SSL encryption covers all data exchanged between your device and our servers.

Data Retention Policy

Account data is retained for as long as your account is active. If you close your account, we retain transaction records for the period required by our internal audit policy and then delete personal data from active systems.

Your Right to Access and Change Data

You can request a copy of the data we hold on your account at any time through our support email. Correction requests — for example, if your registered name or contact details are wrong — are handled by the account…

Who to Contact and How

For all legal, privacy, or data rights enquiries, reach us via live chat or support email — both accessible from your account dashboard.

Common Questions About Our Legal Terms and Your Rights

These are the questions we hear most often when it comes to account policy, data handling, and what our legal terms actually mean for you as an account holder in Indonesia.

Our terms apply to your account from the point you register. However, access to platform services — including the lobby, payments, and live tables — depends on whether it is permitted under local law where you are located. If access is not lawful in your region, the terms do not create a right to use the service.

We collect registration details, session activity, and transaction references from your chosen payment method — DANA, OVO, or GoPay. We do not retain full wallet credentials or payment card numbers. A full list of collected data categories is in the privacy notice, which you can access from your account settings page.

Yes. Send a data access request to our support email with your account username and the specific data you want to see. We acknowledge the request and provide a response with the data we hold. There is no charge for a first access request within any 12-month period.

Contact the account team via live chat or support email and specify which details are incorrect — for example, a misspelled registered name or outdated contact number. We verify your identity first, then update the record and confirm the change in writing. Some fields require supporting documentation before they can be amended.

Transaction records are kept for the period required by our internal audit policy after you close your account. Personal profile data is removed from active systems after that retention period ends. You can ask for a summary of what we hold and when it is scheduled for deletion before you close the account.

Each payment generates a transaction reference that we log for audit and dispute-resolution purposes. We do not store your wallet login details or PIN. If you raise a payment dispute, we use the transaction reference to trace the record. Disputes must be raised within 30 days of the transaction date.

Send a written complaint to our support email. State your account username, the specific policy or decision you are challenging, and the outcome you are requesting. We log every complaint, assign a reference number, and respond with our position. If the matter involves a payment, attach the relevant transaction reference.

We use session cookies for login continuity, functional cookies for lobby preferences, and non-identifying analytics cookies to understand platform usage. You can manage or block cookies through your browser settings. Blocking analytics cookies does not affect your account access or payment functions, but session cookies are needed to stay logged in.

We notify you through your registered contact — either email or the in-account notification — before material changes to the terms take effect. The updated document is also published in the Help Centre inside your account. Continuing to use the platform after the effective date of any update means you accept the revised terms.

OTP verification is required at every login. SSL encryption covers all data moving between your device and our servers. If we detect login activity from an unrecognised device, we pause access and contact you before restoring it. These practices apply to every account regardless of whether you deposit via DANA, OVO, or GoPay.