Reference

Explore How We Protect Your Privacy

At nawatoto, your personal data is handled with clear rules: we collect only what is necessary to run your account, process deposits via DANA, OVO, GoPay and QRIS…

Data collected only as neededDANA, OVO, GoPay & QRIS contextYour right to access & deleteIndonesia jurisdiction appliedContact us any time
nawatoto Explore How We Protect Your Privacy
PRIVACY CONTACT PATHS

Open a Privacy Request With Our Team

If you want to access, correct, or request deletion of your personal data, our privacy team is reachable through three direct channels.

Live Chat Reach our privacy team via live chat in your nawatoto account dashboard, available 07:00–23:00 WIB daily. State your request clearly and we will log it immediately with a reference number.
Email Support Send your data-access or deletion request to our dedicated privacy email. Include your registered account email and the type of request; we respond within one business day during operating hours.
In-Account Form Log in, navigate to Account Settings, then select Privacy Request. Fill in the form with your request type — access, correction, or deletion — and submit. We track every submission through our internal ticketing system.
DATA HANDLING PRACTICES

See How nawatoto Handles Your Information

Every data-handling decision we make is built around keeping your account secure and your information private.

Cookie Usage

We use session cookies to keep you logged in and analytics cookies to understand which pages you visit. You can disable non-essential cookies in your browser settings at any time without losing account access.

Payment Data Security

When you deposit via DANA, OVO, GoPay or QRIS, we store only the payment reference token — not your full wallet credentials. This token is encrypted and accessible only to our fraud-prevention team.

Account Security

Your nawatoto account password is stored as a salted hash; we never see the plain text. We also log the device fingerprint and IP address of each login so that unusual access triggers an immediate email alert to you.

Data Retention Schedule

Active account data is retained for as long as your account remains open. Once you close your account, non-transactional personal data is deleted within 30 days; transaction records are held for the period required under applicable Indonesian law.

Third-Party Sharing

We share data with payment processors (such as DANA and OVO networks) and identity-verification partners only when necessary to complete your transaction or verify your account. We do not sell or license your data to advertisers.

Your Right to Request Changes

You may request a copy of your data, ask us to correct inaccurate details, or request full deletion at any time via the in-account form or our privacy email. We confirm each completed action in writing within 14 working days.

Browse Answers to Your Privacy Questions

Below are the privacy questions we receive most often from account holders in Indonesia. If your question is not covered here, use the live chat channel or in-account form described above and we will respond within one business day.

We collect your name, email address, phone number, date of birth for verification, and device identifiers. Payment method references from DANA, OVO, GoPay or QRIS are also stored as encrypted tokens to process your transactions.

Non-transactional data such as your profile and device logs is deleted within 30 days of account closure. Transaction records tied to DANA, OVO, GoPay or QRIS deposits are retained for the period required under applicable Indonesian regulation.

Yes. Submit a data-access request through Account Settings under Privacy Request or by emailing our privacy team. We compile and deliver your data export within 14 working days of receiving your confirmed request.

No. We share data only with payment processors such as DANA and OVO networks and identity-verification partners strictly required to run your account. We do not sell, license, or share your data with advertising networks.

Log in and navigate to Account Settings, then select Privacy Request and choose deletion. Alternatively, email our privacy team with your registered email address. We confirm deletion in writing within 14 working days.

We use session cookies for login continuity and analytics cookies to improve page performance. You can disable non-essential cookies in your browser settings at any time; your account access and deposit functionality via QRIS or GoPay will not be affected.

When you update a payment method, the old encrypted token is replaced immediately with the new one. The previous token is purged from our active systems within 24 hours and from backup logs within the standard 90-day cycle.