LEGAL REFERENCE

Your Privacy Matters at toto77

We handle your personal data, payment details and account activity with strict encryption and local compliance. Everything you share — from your QRIS identity to your deposit history...

Data EncryptedQRIS SecureAccount ProtectedIndonesia-CompliantPayment Safe
toto77 Your Privacy Matters at toto77

Privacy Policy Framework

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

SUPPORT

Privacy Support Channels

Email Support Contact our privacy team at [email protected] with questions about your data, deletion requests or account privacy concerns.
Account Settings Log in and visit Account → Privacy to review collected data, update payment methods, or request export of your information.
Live Chat Our agents can walk you through privacy controls, data retention timelines and how we protect your DANA, OVO, GoPay or QRIS details.
WHY THIS PLATFORM

Privacy Governance & Audit

Data Encryption

All personal and payment information travels over SSL/TLS encryption. Your QRIS identity, bank reference and transaction history remain encrypted at rest.

Third-Party Audit

Our privacy controls undergo annual review by independent security firms to ensure compliance with regional data protection standards.

Vendor Compliance

Payment processors handling DANA, OVO, GoPay and QRIS transactions are contractually bound to the same encryption and retention rules we follow.

Breach Notification

In the unlikely event of unauthorized access, we notify affected account holders and relevant authorities within 72 hours of discovery.

Consent Management

Your consent for marketing emails, SMS and in-app notifications is stored separately and can be withdrawn anytime from Account Settings.

Regional Compliance

We align data handling practices with Indonesian privacy principles and supported regional regulations governing online gaming platforms.

Privacy Policy Consistency

Transparent Data UseWe state exactly what data we collect, why we need it and how long we keep it. No hidden clauses or silent data sharing.
Player Deletion RightsYou can request account closure and data deletion. We retain only records required by law for anti-money-laundering and dispute resolution.
Payment Method PrivacyYour QRIS, DANA, OVO and GoPay credentials are never stored in plain text. Payment processors handle tokenization and encryption.
Cookie & Tracking PolicyWe use cookies for session management and fraud prevention, not for third-party ad targeting. You control cookie preferences on first visit.
Cross-Border Data FlowsPersonal data stays within supported regions unless you opt into international analytics. Processing servers are Indonesia-based where operationally feasible.
Children & Age VerificationWe verify all account holders are 21+ during registration. If underage access is detected, we suspend the account immediately and delete related data.
Policy UpdatesChanges to this policy are announced 30 days in advance. Continued account use after the update date constitutes acceptance of revised terms.

How We Protect Your Account

Login Security

Two-factor authentication via SMS or email is available in Account → Security. Your password is hashed and never visible to our staff.

Session Timeout

Idle sessions expire after 15 minutes for extra protection. Use Remember This Device if you're on a personal phone or computer.

IP Whitelisting

Unusual login locations trigger a verification email. You can manage trusted devices and remove old sessions from Account → Active Logins.

Payment Tokenization

QRIS, DANA, OVO and GoPay transactions use secure tokens. Your actual credentials never pass through our servers or logs.

Withdrawal Verification

Large withdrawals over Rp 10 million require email or SMS confirmation. This prevents unauthorized funds transfers to external accounts.

Fraud Detection

Our system flags unusual activity patterns and initiates real-time reviews. You'll be contacted immediately if suspicious behaviour is detected.

Privacy Questions Answered

No. We never sell, rent or share your name, email, phone or payment details with marketers, brokers or unaffiliated businesses. Data is used only for account operations, fraud prevention and regulatory compliance in supported regions.

We retain account records for 7 years to comply with anti-money-laundering rules and resolve disputes. Personal identifiers are pseudonymized after 2 years. You can request earlier deletion where local law permits.

Yes. Payment credentials are tokenized immediately upon entry and never stored in plain text on our servers. Tokens are encrypted with AES-256 and processed only by PCI-DSS certified payment gateways.

Absolutely. Visit Account → Preferences and toggle Marketing Communications off. Promotional emails and SMS will stop within 24 hours. You'll still receive transactional messages about withdrawals and account changes.

We notify all affected account holders via email and SMS within 72 hours of discovery. Credit monitoring is offered if financial data is exposed. Full details are posted on our security page and reported to local authorities.

Open Account → Privacy & Data and select Export Data or Request Deletion. Exports arrive within 7 business days as a CSV file. Deletion requests process within 30 days, retaining only legally required dispute and tax records.

No. We don't use cookies or pixels on third-party websites. Our analytics cover only in-app behaviour like lobbies browsed and games opened. You can disable all non-essential cookies via your browser settings or our Manage Cookies tool.