Reference

How We Protect Your Personal Data

At login olxtoto, your personal data is handled with clear, documented practices — from the moment you open an account to every deposit you make via DANA, OVO…

Data collected only for account & payment purposesDANA, OVO, GoPay, QRIS transaction records securedYour data is never sold to third partiesRetention period disclosed per data categoryContact us anytime to request data access or deletion
login olxtoto How We Protect Your Personal Data
PRIVACY CONTACT PATHS

How to Reach Our Privacy Team

If you have a question about how your data is used, want to correct an error in your account profile, or would like to request a full export of your personal data, our privacy support team is available seven days a week. You can reach us via live chat between 08:00 and 23:00 WIB, through email at any hour, or by submitting a form directly inside your account dashboard under 'Privacy Requests'.

Team online

Live Chat

Connect with our privacy team via live chat from 08:00 to 23:00 WIB, seven days a week. We aim to respond to data queries within two hours during operating hours.

Email Support

Send your privacy request to our dedicated data email address at any time. We aim to reply within 48 hours and confirm receipt of your request within 24 hours.

In-Account Form

Log in to your account, head to Settings, and select 'Privacy Requests'. Submit a deletion, correction, or data-access request directly — no need to leave the platform.

HOW WE HANDLE DATA

Six Ways We Keep Your Data Safe

Data handling at login olxtoto is structured around six operational commitments — from how payment data is encrypted to how long session cookies persist.

End-to-End Encryption

All data you submit — including DANA and OVO payment references — is encrypted in transit using TLS 1.3 and stored using AES-256 encryption at rest. No payment credential is ever stored in plain text on our servers.

Cookie Management

We use session cookies to keep you logged in and preference cookies to remember your lobby settings. Analytics cookies are optional and can be declined at any time via the cookie banner shown on your first visit.

Account Security Alerts

Any login from an unrecognised device triggers an automatic email alert to your registered address. You can review all recent sessions under Settings > Security Log and revoke any session you did not initiate.

Data Retention Schedule

Account profile data is retained while your account is active and for 24 months after closure. Payment transaction records linked to GoPay and QRIS are retained for 36 months to meet financial compliance requirements where local law applies.

Third-Party Disclosure Policy

We share your data only with payment processors — including the DANA, OVO, GoPay, and QRIS networks — and with technical service providers bound by strict data-processing agreements. Your data is never sold or rented to advertisers.

Your Right to Request Changes

You may request access to, correction of, or deletion of your personal data at any time. Submit a request via live chat, email, or the in-account Privacy Requests form, and we will confirm action within five business days.

Your Privacy Questions Answered

Below are the questions we receive most often from account holders about how their personal data is collected, stored, and managed. If your question is not covered here, reach our privacy team via live chat between 08:00 and 23:00 WIB or email us at any time for a response within 48 hours.

We collect your name, email address, phone number, and chosen payment method — such as DANA, OVO, GoPay, or QRIS. We also log your device ID and IP address for security purposes. We collect only what is necessary to operate your account.

We share data only with payment processors like DANA, OVO, GoPay, and QRIS networks, and with technical providers under binding agreements. We do not sell, rent, or trade your personal information to any advertiser or unrelated third party.

Profile data is kept for 24 months after account closure. Payment transaction records — including those tied to GoPay and QRIS — are retained for 36 months where local law requires it. After that, data is deleted or fully anonymised.

Log in to your account, go to Settings, and select 'Privacy Requests', or contact our team via live chat from 08:00 to 23:00 WIB. We will compile and deliver your data export within five business days of receiving your request.

Yes. You may submit a deletion request via the in-account Privacy Requests form, live chat, or email. We will confirm deletion within five business days, subject to any retention requirements that depend on local law for financial records.

We use session cookies for login continuity and preference cookies for lobby settings. Optional analytics cookies appear on first visit and can be declined. You may also clear all cookies via your browser settings at any time without losing your account.

Go to Settings > Security Log to view all active sessions and revoke any you did not initiate. You will also receive an automatic email alert whenever your account is accessed from an unrecognised device, so you can act quickly.