Reference

Your data, session, and privacy

We keep one clear policy for the data tied to your account, your device, and your support chats, so you can see what we store before you move…

Account dataCookie choicesSupport requestsRetention rules
cartetoto Your data, session, and privacy
REQUEST PATHS

Where to send privacy requests

When you want to ask about privacy, we keep the path simple: send a message from the account form, use live chat, or email our support team from the footer link.

Live Chat Use the chat panel inside your account for privacy questions, correction requests, or a copy request. The queue is monitored 08:00-22:00 WIB, seven days a week, so you do not have to wait for office hours.
Email Send a written request to the support address in the footer if you need a record of the conversation. We use email for data corrections, access questions, and requests that need a longer explanation.
Contact Form The form in the account area is the cleanest path when you want to change a detail or object to a cookie setting. We log the request time and reply with the next step after we verify the account.
HANDLING CHECKS

How we protect your details

Our privacy handling is built around minimum collection, short retention windows, and account-only changes.

Data we collect

We keep the details needed to run your account: login name, contact channel, device type, session time, and the transaction reference tied to DANA, OVO, GoPay, or QRIS when you use those rails.

Cookies and session

Cookies remember language choice, login state, and basic safety checks. If you clear them, the page may ask you to sign in again, but the core policy and your saved request history stay in our records.

Account security

On Android or iPhone, the Account > Security path is where you can change the login email, phone number, or device check settings after a fresh verification step.

Retention

We keep support threads and transaction records only as long as we need them for checks, dispute handling, or legal duties. After that period, we limit access or remove the record under the same internal rules.

Your requests

You can ask to see, correct, or close the data file linked to your account. After we confirm it is really you, we reply with the next step and tell you whether a local-law limit applies.

How to reach us

Use live chat, the account form, or email to send privacy questions. If you need a change to a stored detail, include the login email and the reason so we can locate the right record quickly.

Privacy questions people ask most

These are the questions we hear most when you want to know what happens to your data after sign-in, payment checks, or a support message. We answer in plain English, and where local law allows a request, we handle it after identity confirmation inside the account area. If you need a record, the same channel can send it by email.

We keep the login details, contact channel, device signals, and any request history tied to the account. If you use DANA, OVO, GoPay, or QRIS, we keep the reference needed to reconcile the action, not full wallet credentials.

Yes. Send the request through live chat, email, or the account form, and we will ask you to confirm the login email before we share anything. If local law limits the request, we explain the limit clearly.

No. Cookies remember session status, language choice, and basic safety checks. Passwords stay in the login system, and you can clear cookies in your browser or phone settings without losing the underlying account record.

We keep records only as long as needed for support, dispute handling, security checks, and legal duties. After that, we reduce access or remove what we no longer need under our internal retention rules.

Yes, after sign-in you can ask us to correct the login email, phone number, or other stored contact detail. We may ask for a fresh verification step so the change goes to the right account.

Use the account form for written requests, live chat for faster replies, or email if you want a record in your inbox. We route the request to the team that handles data access, corrections, and removal.