Reference

How We Handle Your Account Data

Your account data — including the wallet details you use with DANA, OVO, and GoPay — is managed under a clear set of rules.

Data collected only as neededDANA, OVO, GoPay wallet handlingAccount-level access controlsRight to request deletionContact path always open
bibirtoto How We Handle Your Account Data
DATA HANDLING PRACTICES

How We Protect and Manage Your Information

Data protection at bibirtoto is built around the principle of collecting only what the account actually needs. We apply access controls at the account level, meaning your wallet data and transaction history are visible only to you and to the internal systems that process your requests. Below are the six areas we take most seriously when it comes to your privacy.

Wallet Data Handling

When you link DANA, OVO, or GoPay to your account, we store only the reference needed to process your transaction — never your full wallet credentials or PIN. Payment verification happens server-side and the raw input is not logged. Your wallet link can be updated or removed from your account settings at any time.

Cookie Usage

We use session cookies to keep you logged in as you move between the lobby, your account page, and the withdrawal screen. Analytics cookies help us understand which pages load slowly on mobile. You can block non-essential cookies through your browser, but session cookies are required for the platform to function while you are logged in.

Account Security

Login attempts are monitored for unusual patterns — multiple failed PINs, new device logins, or access from an IP address not associated with your account history. When something looks off, we may send a verification prompt to your registered contact. You can also enable two-step verification inside account settings for an extra layer.

Data Retention

Transaction records are retained for as long as required by applicable financial regulations. Account profile data is kept while your account is active. If you request account closure, non-regulatory data is removed within a reasonable period after verification. Regulatory audit logs follow the retention schedule set by applicable local law.

Third-Party Access

We work with payment processors to handle DANA, OVO, and GoPay transactions. These processors receive only the data they need to complete and verify the payment. We do not share your account data with advertisers. Any third-party integration is governed by a data processing agreement that limits how that data can be used.

Your Rights and Requests

You can request a copy of the data we hold on your account, ask us to correct something that is wrong, or request deletion of data that is not subject to a legal retention requirement. Submit requests via live chat or email with your account ID. We aim to respond within a reasonable timeframe as defined by applicable local regulation.

PRIVACY CONTACT PATHS

How to Reach Us About Your Data

If you want to request access to the data we hold on your account, ask for a correction, or raise a concern about how your information has been handled, our support team is the right starting point. Use any of the three channels below — live chat gets you a response fastest; email works well for written requests that need a paper trail. All privacy-related requests are handled separately from general account support to make sure nothing falls through.

Live Chat Open the chat widget from any page while logged in. State that your request is privacy-related and our team will route it to the right person. This is the fastest path for urgent data access or correction requests.
Email Support Send your privacy request to our support address with your registered account ID in the subject line. We respond to privacy emails during standard support hours. Written requests via email create a clear record for both sides.
Account Settings Some data preferences — such as cookie consent and session storage — can be adjusted directly inside your account settings without contacting support. Log in, go to Settings, and look under Privacy & Data to see what you can manage yourself.

Your Privacy Questions, Clearly Answered

These are the questions we hear most often from people checking how their data is handled on bibirtoto. If your question is not covered here, the support paths in the section above are always open.

We collect your login credentials, registered contact detail, and the e-wallet reference you choose — DANA, OVO, or GoPay. We also collect device and session data to keep your account stable across mobile and browser. We do not collect data beyond what is needed to run your account.

Only a transaction reference linked to your wallet is stored, not your full wallet credentials or PIN. When you send a payment via DANA or OVO, the wallet app handles authentication on its own side. We receive confirmation of the transaction, not your login details for those apps.

Yes. Send a data access request through live chat or email with your registered account ID. We will compile the account data we hold and share it with you. Some transaction data tied to regulatory requirements may be shared in summary form rather than full transaction logs.

Contact support via live chat or email and request account closure with data deletion. We will remove non-regulatory profile and session data within a reasonable period after we verify your identity. Data subject to financial regulatory retention requirements follows the schedule set by applicable local law and cannot be removed ahead of that.

We share data only with the payment processors needed to complete DANA, OVO, and GoPay transactions, and only the minimum data required. We do not sell account data or share it with advertisers. Third-party processors are bound by data processing agreements that restrict further use.

Session cookies keep you logged in and are required for the platform to work. Analytics cookies help us see how pages perform on mobile devices. You can block analytics cookies in your browser settings. Blocking session cookies will prevent you from staying logged in, so we recommend leaving those enabled while you are active on the platform.

Login activity is monitored for unusual patterns — new devices, repeated failed attempts, or unfamiliar access locations. You may be prompted to verify your identity if something looks different from your normal pattern. Two-step verification is available in account settings and adds a second check to any new login attempt.

Transaction records are retained for as long as required by the financial regulations applicable to your region. Account profile data is kept while your account remains active. After a confirmed account closure request, non-regulatory data is removed within a reasonable period following identity verification.

Yes. If something on your account profile is inaccurate — a wrong contact detail or an outdated wallet reference — contact us via live chat or email. Some fields can also be updated directly from your account settings page without going through support. We aim to process correction requests promptly.

The policy applies to all accounts accessed from Indonesia. Availability of specific features and data-related rights may depend on local law and the region in which you are located. Where access or eligibility is subject to local regulation, we note that and apply the policy accordingly. If you have a region-specific question, reach out through the support channel.