Reference

How warkoptoto1 Protects Your Personal Data

Your account data, payment details, and browsing behaviour on warkoptoto1.xyz are handled under a clear, documented privacy framework — one we apply consistently whether you deposit via DANA…

Data encrypted at rest and in transitDANA, OVO, GoPay & QRIS payment data protectedAccount data deletion on requestNo data sold to third partiesIndonesia-region data handling
warkoptoto1 How warkoptoto1 Protects Your Personal Data
PRIVACY CONTACT

Reach Us About Your Data Rights

If you want to access, correct, or delete the personal data we hold on your warkoptoto1 account, our privacy team is reachable through the channels below.

Live Chat Start a live-chat session directly from your account dashboard. Available 08.00–23.00 WIB every day; our team will log your data request and send a written confirmation within the same session.
Email Privacy Desk Send a detailed request to our privacy email address found in your account settings. We acknowledge all email submissions within 24 hours and resolve data queries within five business days.
In-Account Form Log into warkoptoto1.xyz, go to Account Settings › Privacy, and submit the data-request form. The form pre-fills your account ID so our team can verify your identity and begin the process immediately.
DATA HANDLING STANDARDS

Six Ways We Keep Your Account Data Safe

Every part of our data-handling practice is designed to give you meaningful control over what we store and how long we keep it.

End-to-End Encryption

All data transmitted between your browser or app and our servers uses TLS 1.3 encryption. Payment identifiers for DANA, OVO, GoPay and QRIS are tokenised before storage — we never hold raw wallet credentials on our databases.

Cookie Transparency

We use session cookies to keep you logged in and analytics cookies to understand how you navigate our lobby. You can review and withdraw consent for non-essential cookies at any time through the cookie preference panel in your account settings.

Account Security Alerts

If a new device or IP address attempts to access your account, we send an immediate email alert and temporarily flag the session for review. You can approve or block the new access directly from the alert link.

Data Retention Schedule

Active account data is retained for the duration of your membership. If you close your account, non-financial records are deleted within 30 days. Transaction logs are kept for the period required by applicable financial regulations, then permanently erased.

No Third-Party Data Sales

We do not sell, rent, or trade your personal data to any external party for marketing purposes. Service providers we work with — such as payment processors for DANA and GoPay — access only the minimum data needed to complete their specific task.

Your Right to Request Changes

You may request a full export of your stored data, ask us to correct inaccurate details, or submit a deletion request at any time via live chat, email, or the in-account privacy form. We confirm all requests in writing.

Privacy Policy: Questions We Hear Most

The answers below address the specific data and privacy questions we receive from account holders. If your question is not covered here, use the live-chat channel (08.00–23.00 WIB) or submit an in-account privacy request and our team will respond within five business days.

We collect your name, email address, and the payment identifiers you link (DANA, OVO, GoPay, or QRIS). We also log device type, IP address, and session timestamps to verify your identity and secure your account from unauthorised access.

Payment identifiers are tokenised immediately on receipt — we store a secure reference, not your raw wallet number. Tokens are held on encrypted servers and are only used to match incoming deposits or outgoing withdrawals to your account record.

Yes. Log into your account, navigate to Account Settings › Privacy, and submit a data-export request. We will prepare a downloadable file of your stored data and send it to your registered email address within five business days.

Submit a deletion request through the in-account privacy form or via our live-chat desk. Non-financial records are removed within 30 days of account closure. Transaction logs required by financial regulations are retained only for the mandatory period, then permanently erased.

We do not sell or share your data for advertising. We share only the minimum necessary information with payment processors — such as QRIS and GoPay infrastructure providers — strictly to complete your deposit or withdrawal transaction.

We use essential session cookies to keep you logged in and optional analytics cookies to improve lobby navigation. You can manage non-essential cookie consent at any time through the cookie preference panel inside your account settings page.

Personal profile data and behavioural records are deleted within 30 days of closure. Financial transaction logs are retained only for the period required by applicable regulation and then permanently purged. You may request written confirmation once deletion is complete.