Reference

How totocash Handles Your Personal Data

Your privacy matters to every decision we make at totocash — from the moment you open an account to each deposit you process via DANA, OVO, GoPay or…

Data collected only for account & transaction purposesDANA, OVO, GoPay, QRIS payment data encrypted in transitYou may request data access or deletion at any timeCookies used for session security, not advertising profilesNo sale of personal data to third parties
totocash How totocash Handles Your Personal Data
PRIVACY CONTACT CHANNELS

Reach Us About Your Privacy Rights

If you want to review, correct or remove the personal data we hold, our privacy support team is available every day from 08:00 to 23:00 Western Indonesia Time. Whether you are in Yogyakarta or anywhere across the country, you can reach us through the three channels below and expect a written response within 3 business days.

Team online

Live Chat

Start a live chat session directly from your account dashboard. Our privacy team reads every message during operating hours — 08:00 to 23:00 WIB — and responds within two hours on average.

Email Support

Send your data request to our dedicated privacy address. Include your registered account ID so we can locate your records quickly. Written replies are issued within 3 business days, confirming the action taken.

In-Account Form

Log into your account, go to Settings, then Privacy, and submit a data access or deletion request directly. The form timestamps your request automatically and creates a trackable reference number.

DATA HANDLING STANDARDS

Six Ways We Protect Your Account Data

From the encryption layer covering your QRIS transactions to the 90-day deletion window after an account is closed, every step in our data lifecycle is designed to keep your information under control.

Encryption in Transit

Every piece of data moving between your device and our servers — including DANA and OVO payment confirmations — travels over TLS 1.3 encryption, making interception by third parties effectively impossible during the transfer.

Cookie Policy

We use session cookies to keep you logged in securely and functional cookies to remember your language preference. We do not place third-party advertising cookies on your browser, and you can clear session cookies at any time from your browser settings.

Account Security Controls

Two-factor authentication is available on every account. We send an SMS or email verification code each time a new device attempts to log in, so your account remains protected even if your password is exposed elsewhere.

Data Retention Schedule

Active account data is held while your account remains open. If you close your account, personal identifiers are deleted within 90 days. Transaction records required for financial compliance are retained for the statutory period, then securely destroyed.

No Third-Party Data Sales

We do not sell, rent or trade your personal data — including GoPay wallet IDs or QRIS transaction history — to advertisers, data brokers or any commercial third party. Data is shared only with payment processors and fraud-prevention services essential to running your account.

Your Right to Request Changes

You may request a full copy of the data we hold about you, ask us to correct inaccuracies or submit a deletion request — all through the in-account Privacy form or by emailing our support team. We confirm every action in writing.

Your Privacy Questions, Clearly Answered

The questions below are the ones we hear most often from people reviewing this policy before they open an account or make their first deposit. If your question is not covered here, our live chat team can address it directly during operating hours.

We collect your name, email address, date of birth and the payment method you register — such as DANA, OVO, GoPay or QRIS. We do not collect financial credentials like PINs or banking passwords at any point during registration.

Payment identifiers — such as your linked DANA phone number or OVO wallet ID — are encrypted at rest using AES-256 and stored on servers accessible only to authorised payment-processing systems. They are never written to logs in plain text.

Yes. Log in, go to Settings, then Privacy, and submit a data access request. We will compile and deliver a copy of your account records to your registered email address within 3 business days of receiving the request.

We share data only with payment processors like QRIS and GoPay gateways needed to complete transactions, and with fraud-prevention services. We do not share your data with advertisers or unrelated commercial partners under any circumstances.

Submit a deletion request through the in-account Privacy form or email our support team with your account ID. Personal identifiers are removed within 90 days. Statutory transaction records are held only for the legally required period, then destroyed.

We use session cookies for login security and functional cookies for language preferences. No advertising or tracking cookies are placed by us. You can disable or clear cookies in your browser settings, though this may affect login functionality.

Reach our privacy team via live chat (08:00–23:00 WIB), email support or the in-account Privacy form. We issue a written acknowledgement within 24 hours and a full resolution response within 3 business days of your submission.