Reference

How pekantoto Handles Your Privacy in Indonesia

We keep your account information, payment details, and session data under strict protection — whether you fund through DANA, OVO, or GoPay. Access and eligibility depend on local law and regions where our services are permitted.

Account EncryptionPayment Data ShieldedSession PrivacyLocal Wallet Security
pekantoto How pekantoto Handles Your Privacy in Indonesia
MOBILE PRIVACY

Privacy on Your Phone and Tablet

Accessing our lobby from a mobile browser or saving a shortcut to your home screen does not grant us extra device permissions. We do not request access to your contacts, photos, or microphone. The mobile session uses the same SSL encryption as desktop. If you play Aviator or browse live casino rooms from your phone while connected to public Wi-Fi, data between your device and our servers remains encrypted in transit. Notifications — if you allow them — contain no sensitive account information, only general alerts. You can revoke notification access any time through your device settings without affecting your account status or gameplay history.

No Extra Permissions
Encrypted Mobile Sessions
Safe on Public Wi-Fi
Notification Privacy
pekantoto mobile gaming

Our Privacy Approach vs Common Alternatives

Not every platform handles privacy the same way. Here is how pekantoto stacks up against practices you might encounter elsewhere.

Wallet Credential Storage
Some platforms store your full wallet login for convenience. We never hold your DANA PIN or OVO password — only a tokenised reference that confirms the transaction occurred without exposing sensitive login data.
Data Sharing with Advertisers
Many sites monetise user data by sharing it with ad networks. We keep your browsing behaviour and gameplay patterns internal, using them only to improve your experience on our platform and never packaging them for sale.
Session Timeout Policy
Other platforms may keep sessions alive for days, increasing exposure risk. Our sessions expire after inactivity, requiring fresh authentication so that a lost phone or shared tablet does not become an open door to your account.
KYC Document Handling
We encrypt identity documents at rest and restrict viewing to verification staff during the review window. Once verified, access to raw documents is locked. Some platforms leave these accessible to broader internal teams indefinitely.
Support Chat Logs
Your chat history with our team is encrypted and retained only for dispute resolution. We do not mine support conversations for marketing insights or share transcripts with outside parties, unlike platforms that treat chat as a data source.
Account Deletion Process
Requesting data removal on some platforms means waiting months or receiving no confirmation. We process deletion requests within a defined window after identity confirmation through your registered GoPay, DANA, or OVO wallet, and confirm completion.
Mobile Permissions Scope
We ask for zero device permissions beyond what your browser needs. No camera, no contacts, no storage access. Some competing apps request broad permissions that have nothing to do with gameplay but plenty to do with data harvesting.
TRANSPARENCY SIGNALS

How We Earn Your Trust on Privacy

We back privacy commitments with real operational practices rather than empty promises.

SSL Encryption

Every page and every transaction on pekantoto uses SSL encryption. This means data travelling between your browser and our servers cannot be intercepted or read by anyone in between — whether you are on mobile data or home broadband.

No Third-Party Data Sales

We do not sell, rent, or trade your personal information with advertisers or data brokers. Payment references from DANA, OVO, or GoPay are used solely for transaction processing and dispute resolution.

Access Control Layers

Internal staff cannot view raw customer data without multi-step authorisation. Support agents see only what they need — a hashed reference, account status, and transaction history — not full personal documents or wallet credentials.

Regular Security Checks

We run periodic checks on our infrastructure to identify weaknesses before they become problems. When vulnerabilities are found, patches deploy promptly. This protects your stored data and active sessions alike from emerging threats.

Provider Privacy Standards

Game studios like Pragmatic Play and Evolution that supply our live tables and slots operate under their own data-handling policies.

Retention Limits

We do not keep data indefinitely. Transaction records are retained for the period required by applicable rules, then purged. Gameplay logs follow a similar lifecycle. Once data passes its retention window, it is removed from active and backup systems.

PRIVACY HIGHLIGHTS

Six Elements Defining Our Privacy Standards

These six points summarise the operational commitments that protect your information across every interaction with our platform.

Tokenised Wallet References Deposits from DANA, OVO, or GoPay generate a token stored on our side — not your full wallet details. This means even if an internal breach occurred, your actual wallet login stays safe with your wallet provider, completely separate from…
Encrypted Data at Rest Personal data stored in our databases — names, contact details, KYC documents — sits behind encryption at rest. Without the decryption key, this data is unreadable. Keys are managed through isolated systems with strict access controls.
Minimal Data Collection We collect only what serves a clear purpose: identity verification, transaction processing, dispute resolution, and session management. We do not ask for unnecessary personal details or build shadow profiles from browsing behaviour outside our platform.
Anonymised Gameplay Logs When you spin Gates of Olympus or join a live Dragon Tiger table, the gameplay log ties to an anonymised identifier — not your real name or wallet.
Controlled Internal Access Our team operates on a need-to-know basis. A support agent helping you with a GoPay withdrawal sees your transaction status but cannot access your full identity documents. System administrators can see infrastructure but not individual account contents.
Defined Retention Periods Data does not live on our servers forever. We assign retention periods based on purpose — transaction records follow applicable compliance timelines, while session logs clear more quickly. Expired data is purged from both active systems and backups.
PRIVACY HELP

Getting Help with Privacy Concerns

If you have questions about how your data is stored or want to request account information, our support channels are ready to assist.

Live Chat Privacy Requests Open the chat widget and ask to speak with a privacy-trained agent. They can walk you through what data we hold, how long we retain it, and what deletion options exist for your account. Chat logs themselves are stored encrypted.
Email Data Inquiries Send a message to our support address with your account reference. We respond with a summary of stored data categories — no raw data leaves the system via email.
Account Deletion Pathway If you want to close your account entirely, contact support and request full deletion. After verifying your identity through your registered DANA, OVO, or GoPay wallet, we remove personal data within a reasonable processing window, retaining only what local regulation…
pekantoto What Our Privacy Practices Cover

What Our Privacy Practices Cover

Your privacy matters from the moment you open an account. We collect only what we need: your contact details for verification, your e-wallet identifiers for DANA, OVO, or GoPay transactions, and device information to keep sessions secure. We never sell personal data to third parties. When you deposit via DANA or withdraw through OVO, the transaction reference stays between you, your wallet

provider, and our payment processor. Session tokens expire after inactivity, so if you leave the lobby open on your phone and forget about it, nobody can resume your session later. Players in Yogyakarta or anywhere else accessing our platform get the same privacy protections regardless of device or connection type. We encrypt data in transit using SSL, and stored information sits behind

access controls that limit internal visibility. Our privacy approach covers account credentials, wallet verification records, gameplay logs, and support chat histories — each handled according to its sensitivity level.

Key Privacy Terms Explained Simply

Understanding these terms helps you make sense of what happens with your data when you use the platform.

What does SSL mean?

SSL stands for Secure Sockets Layer. It encrypts data travelling between your device and our servers so that no one between those two points — like someone on the same Wi-Fi — can read what is being sent.

What is tokenisation in payments?

Tokenisation replaces your real wallet details with a random reference code. Our system uses this token to confirm a DANA or OVO transaction happened, without ever storing your actual wallet credentials or PIN on our servers.

What does KYC mean?

KYC stands for Know Your Customer. It is the identity check we perform when you request a withdrawal or exceed certain activity thresholds. You submit an identity document, we verify it, and then restrict access to that document internally.

What is data retention?

Data retention refers to how long we keep your information. Each data category — transaction logs, chat history, session records — has a defined period after which it is deleted from active storage and eventually removed from backups.

What is encryption at rest?

Encryption at rest means data stored on our servers is scrambled using a cryptographic key. Even if someone gained access to the physical storage, they could not read your personal information without the separate decryption key.

What does session expiry mean?

Session expiry is the point at which your active login becomes invalid after a period of inactivity. You will need to log in again, which protects your account if you walked away from your phone or closed your browser without logging out.

What is an anonymised identifier?

An anonymised identifier is a code that links your gameplay activity to your account for audit purposes, without using your real name, email, or wallet reference. It allows fairness checks without exposing who you actually are.

What does access control mean?

Access control limits who inside our organisation can view specific data. A support agent may see your transaction status but cannot open your KYC documents. This layered approach keeps sensitive information visible only to authorised roles.

What is a hashed password?

Hashing converts your password into a fixed-length string of characters using a one-way mathematical function. We store only this hash — not the original password — so even our own systems cannot reverse it back to what you typed.

What does data minimisation mean?

Data minimisation is the practice of collecting only the information we actually need. We do not request your location history, phone contacts, or unrelated personal details — just what is necessary for account operation, payments, and security.

Privacy Questions from Our Indonesia Visitors

Real questions we receive through live chat and email about how your data is handled on pekantoto.

No. Your wallet PIN stays entirely with your wallet provider. When you deposit through DANA or OVO, our system receives only a confirmation token — a reference that the payment succeeded — never your login credentials or PIN.

Yes. Contact our support team via live chat or email with your account reference. After verifying your identity through your registered wallet, we provide a summary of data categories stored. Sensitive raw data is viewable only in your secure account portal.

Once you confirm deletion through identity verification via GoPay, DANA, or OVO, we remove personal data within a processing window. Only records required by applicable local regulation are retained, and those are purged once the retention period ends.

Absolutely not. Your game sessions — whether on Mahjong Ways, live baccarat, or Aviator — are tied to your private account. No other account holder can see what you play, how long you play, or your transaction history.

We share only a session token and a region flag so the provider can serve you the correct game version. Personal details like your name, wallet reference, or contact information are never passed to game studios.

Sessions expire after inactivity, so a thief would need to log in fresh. Contact support immediately — we can freeze your account while you secure your device. No funds move without passing your registered wallet verification step.

Yes. Chat logs are encrypted and stored solely for dispute resolution. They are not shared with external parties, used for marketing analysis, or visible to any internal team member who was not part of the conversation or its escalation.

No. Privacy protections apply equally regardless of which city or network you connect from within eligible regions. SSL encryption, session expiry, and data handling rules remain the same whether you are on mobile data or a fixed broadband connection.

Yes. In your account settings you will find a notification preferences section where you can disable promotional messages. This does not affect transactional notifications — like withdrawal confirmations — which remain active for your account security.

Transaction records are kept for the period required by applicable compliance timelines in eligible regions. Once that window closes, records are purged from active databases and subsequently from backup systems. We do not retain them indefinitely.