Reference

dprtoto Privacy Policy: What We Collect and Why

Our Privacy Policy covers every piece of information you share when you open an account or complete a transaction — from your phone number at verification to your…

Account data securedWallet activity privateDANA & QRIS contextRetention periods statedContact path open
dprtoto dprtoto Privacy Policy: What We Collect and Why
PRIVACY CONTACT PATHS

How to Reach Us About Your Privacy Rights

If you have a question about your stored data, want to correct an account detail, or need to request deletion, our support team is available around the clock. You can reach us through live chat from inside your account dashboard, by email at the address listed in your registration confirmation, or via WhatsApp during business hours. Players in Makassar and elsewhere across Indonesia receive the same response priority regardless of channel.

Team online

Live Chat

Access live chat directly from your account dashboard, available 24 hours a day. Our agents can pull your data record and begin a correction or deletion request on the spot.

Email Support

Send your privacy request to the email address shown in your registration confirmation. We aim to respond within 48 hours and confirm receipt automatically.

WhatsApp

Reach our privacy team via WhatsApp during standard business hours. Provide your registered phone number so we can verify your identity before acting on any request.

DATA HANDLING STANDARDS

Six Ways We Protect Your Account Information

From the moment you submit your phone number at registration to the point we process a withdrawal to your OVO wallet, every step involves a data-handling rule.

Phone Verification Gate

We verify your phone number before granting account access. This step prevents a third party from opening an account in your name and limits who can trigger wallet or payment actions.

Encrypted Wallet Fields

Your DANA, OVO and GoPay wallet identifiers are stored in encrypted fields. Our cashier system reads them for transaction routing but they are never exposed in plain text in any log.

Session Timestamp Logs

Every login generates a timestamped session record. If we detect a login from an unexpected device or location, we flag the session and may require re-verification before the account cashier page loads.

Data Retention Schedule

Transaction records are kept for the period required by applicable rules, after which they are deleted from active storage. Account profile data is removed within 30 days of a verified deletion request.

Third-Party Access Controls

We share data with payment processors — including QRIS network operators and virtual account providers — strictly to complete your transaction. No broader profile data accompanies those calls.

Cookie and Tracker Disclosure

We use session cookies to keep you logged in and analytics cookies to measure page performance. You can review and clear cookies from your browser settings at any time without losing your account data.

Privacy Policy Questions We Hear Most

The questions below cover the data rights and account-privacy topics that come up most often. If your question is not listed here, open a live chat from your account dashboard and our team will point you to the right part of our Privacy Policy.

We collect your name, phone number and email address at registration. Once you add a payment method — DANA, OVO, GoPay, QRIS or bank transfer — we also store the wallet or account identifier needed to route your transactions.

Wallet identifiers are used solely to process deposits and withdrawals. They are stored in encrypted fields, passed to the payment processor for transaction routing, and never shared with advertisers or unrelated third parties.

Yes. Contact our support team via live chat or email with your registered phone number. We will compile a summary of your stored account data and send it to your verified email address within 48 hours.

Submit a deletion request through live chat or email. After we verify your identity via your registered phone number, we begin the removal process. Active transaction records are retained for the legally required period before deletion.

We share data only with payment processors — such as QRIS network operators, virtual account providers and Indonesian bank rails like BRI and Mandiri — and only to complete your transaction. No profile data is sold to advertisers.

Our Privacy Policy applies to all account holders, but certain data-handling obligations and your specific access rights depend on local law. If you have region-specific questions, our support team can clarify what applies in your area.

We use session cookies to keep your account logged in and analytics cookies to understand how pages perform. You can review or clear these from your browser settings at any time; doing so will not affect your stored account or wallet data.