Reference

How xrtoto Protects Your Personal Data

At xrtoto, your personal data is handled with clear rules: we collect only what is needed to run your account, process deposits via DANA, OVO, GoPay and QRIS…

Encrypted account dataDANA, OVO, GoPay & QRIS transaction privacyRight to access your dataData deletion on requestIndonesia-region compliance
xrtoto How xrtoto Protects Your Personal Data
PRIVACY CONTACT PATHS

How to Reach Us About Your Data

Team online

Live Chat Support

Our live chat team is available 24 hours a day, 7 days a week. If you want to request a copy of your personal data or ask about how your DANA or OVO records are stored, open the chat window and select 'Privacy Request' from the menu.

Email Privacy Desk

Send a written data request to our dedicated privacy email address. We aim to acknowledge your message within one business day and provide a full response within 14 calendar days — covering account data, transaction logs and cookie records.

Account Settings Panel

Log into your xrtoto account, navigate to Settings, then select 'My Data'. From there you can download a summary of your stored profile details and manage your communication preferences without contacting support directly.

DATA HANDLING STANDARDS

Six Ways We Keep Your Data Secure

From the moment you create an account to the day you request data deletion, xrtoto applies consistent data-handling practices across every layer of your profile — from login security to payment record…

SSL Encryption on All Transfers

Every piece of data moving between your device and our servers — including DANA and GoPay payment details — travels through SSL encryption. This applies at login, during deposits and when you update your account profile or contact preferences.

Cookie Controls You Manage

We use session cookies to keep you logged in and analytics cookies to understand how pages are used. You can adjust or withdraw cookie consent at any time through the cookie banner or via your browser settings without losing access to your account.

Payment Data Minimisation

When you deposit via OVO or QRIS, we pass only the minimum required identifiers to the payment processor. We do not store full card numbers or full e-wallet credentials on our own servers — those are handled by the processor under their own security standards.

Retention Periods Are Fixed

Account data is kept for the duration your account is active plus a fixed period afterward, as required by applicable financial record rules. Once that window closes, data is deleted or anonymised unless you have an open dispute or request pending.

Access Request Handling

You can request a full export of the personal data we hold about you at any time. Requests submitted via live chat or email are processed within 14 calendar days. We verify your identity before releasing any data to protect your account from third-party requests.

Data Breach Notification

If a security incident occurs that affects your personal data, we will notify you via the email address on your account within 72 hours of becoming aware of it. The notification will describe what was affected and the steps we have taken to contain it.

Your Privacy Questions, Answered

These are the data and privacy questions we hear most often. If your question is not here, our live chat team is available around the clock to walk through your specific situation — from QRIS transaction records to account deletion timelines.

We collect your name, email address, chosen payment method (DANA, OVO, GoPay or QRIS), device identifiers, and session activity logs. We collect only what is needed to operate your account securely and process your transactions accurately.

When you deposit, we pass the minimum required transaction details to the payment processor and do not store full e-wallet credentials on our own servers. Your DANA or GoPay identifiers are encrypted in transit and handled under the processor's security protocols.

Yes. Submit a data access request via live chat or our privacy email. We verify your identity first, then deliver a full export of your stored profile, transaction logs and session data within 14 calendar days of your confirmed request.

Contact our privacy desk via live chat (24/7) or email and select 'Delete My Data'. We will process your request within the statutory window. Some records may be retained where local law requires it for financial accountability before full deletion.

We do not sell or share your personal data with advertisers. Data is shared only with payment processors — DANA, OVO, GoPay, QRIS rails — strictly to complete your transactions. No personal profile information reaches external marketing networks.

Your data is retained while your account is active and for a fixed post-closure period required by applicable financial record rules. Once that window ends, data is deleted or anonymised, unless an open dispute or formal request delays that process.

We will notify you by email within 72 hours of confirming any breach that affects your personal data. The notice will identify what was compromised and detail the containment steps taken. Access depends on local law regarding mandatory breach reporting timelines.