Reference

How hitamtoto Handles Your Personal Data

Your privacy matters to how we run every part of this platform — from the moment you open an account to every deposit you make via DANA, OVO…

Data encrypted at rest and in transitNo third-party sale of your informationDANA, OVO, GoPay & QRIS transaction data protectedAccount data deletion available on requestApplies where local law permits
hitamtoto How hitamtoto Handles Your Personal Data
HUBUNGI TIM PRIVASI

Reach Our Privacy Team Directly

If you have a question about how we handle your data, want to correct information on your account, or wish to submit a deletion request, our privacy team is available around the clock. You can reach us through any of the three channels below — we aim to acknowledge every privacy request within 24 hours and resolve it within seven working days. Players in Semarang and across Indonesia can submit requests in English or use the contact form on this page.

Team online

Live Chat

Open the chat widget from any page on hitamtoto. Our team is available 24 hours a day, seven days a week, specifically for account and privacy queries — no waiting in a queue for general support.

Email Privacy Request

Send your data access, correction, or deletion request to our dedicated privacy address. We log every inbound email with a ticket number so you can track your request from submission to resolution.

In-Account Support Form

Log into your account, navigate to Settings, then select Privacy Request. Fill in the form — it pre-populates your account details — and submit. Confirmation arrives in your registered inbox within minutes.

PRAKTIK PERLINDUNGAN DATA

How We Protect and Manage Your Information

We have built our data practices around six core commitments — each one tied to a specific operational control rather than a general statement.

End-to-End Encryption

All data moving between your device and our servers — including DANA, OVO, GoPay, and QRIS transaction details — is encrypted using TLS 1.3. Data stored on our servers is encrypted at rest using AES-256, so raw records are never readable if storage media is accessed outside our systems.

Cookie Control

We use session cookies to keep you logged in and analytics cookies to understand which features you use most. You can adjust cookie preferences in your browser settings at any time. Strictly necessary cookies cannot be turned off, but we do not use cookies to serve third-party advertising on this platform.

Account Security Layers

Your account is protected by password hashing and optional two-step verification via your registered phone number. Failed login attempts trigger an automatic lock after five consecutive errors, and we notify your registered email immediately so you can confirm whether the attempt was yours.

Data Retention Schedule

Account profile data is kept for the duration of your active account plus the minimum period required under applicable financial regulations. Once you request deletion and the retention window closes, records are permanently removed from our live and backup systems within 30 days.

Third-Party Data Sharing

We share data with payment processors — including the infrastructure behind DANA, OVO, GoPay, and QRIS — solely to complete your transactions. We do not sell, rent, or trade your personal information to marketers or data brokers under any circumstances.

Your Rights Over Your Data

You have the right to access a copy of the data we hold on you, request corrections, object to certain processing, and ask for deletion where local law permits. Submit any of these requests through Live Chat, email, or the in-account privacy form, and we will respond within seven working days.

Frequently Asked Privacy Questions

The questions below cover the situations we hear about most often — from data access requests to how your QRIS payment history is stored. If your question is not answered here, our privacy team is reachable 24 hours a day via the channels listed above.

We store your name, email address, phone number, country, and the payment method you registered — for example DANA or OVO. We also retain login timestamps and device identifiers for security purposes. No payment credentials such as e-wallet PINs are stored on our servers.

Log into your account, go to Settings, and select Privacy Request, then choose 'Access My Data'. Alternatively, contact our privacy team via Live Chat or email. We will send a structured data export to your registered email address within seven working days of your request.

Yes. Submit a deletion request through the in-account Privacy Request form or by emailing our privacy team directly. We will action the deletion once the mandatory financial data retention period has elapsed, and confirm completion in writing within 30 days of the retention window closing.

Transaction data is shared only with the payment processor needed to complete or verify that specific transaction — for example, the GoPay or DANA infrastructure. We do not share your payment history with advertisers, analytics companies, or any unrelated third parties. Sharing depends on local law requirements.

We use session cookies to keep you signed in and analytics cookies to see which sections of the platform are used most. You can disable non-essential cookies in your browser settings at any time. Turning off analytics cookies does not affect your ability to deposit, play, or withdraw.

Inactive accounts are flagged after 12 months of no login activity. We retain your data for the minimum period required under applicable financial regulations, then schedule it for deletion. You will receive an email notification before any deletion process begins, giving you a chance to reactivate.

Reach our privacy team immediately via Live Chat, available 24 hours a day, or send a detailed email to our privacy address. We log every complaint with a reference number, investigate within five working days, and respond with our findings and any remediation steps we have taken.