Reference

How apolo77 Handles Your Personal Data

Your personal data — the details you share when you open an account, make a deposit via DANA, OVO, GoPay or QRIS, or contact our support team —…

Data collected only as neededDANA, OVO, GoPay & QRIS transactions securedRetention periods clearly statedYour right to request data accessContact us to update or delete records
apolo77 How apolo77 Handles Your Personal Data
PRIVACY CONTACT PATHS

Reach Us About Any Data Question

Our privacy support team is available seven days a week, from 08.00 to 23.00 WIB, to answer questions about how your data is stored, to process access requests, or to handle deletion requests. You can also reach us from Makassar or anywhere else in Indonesia through any of the three channels below — we aim to respond within 24 hours of your first message.

Team online

Live Chat

Open the chat widget inside your account dashboard at any time between 08.00 and 23.00 WIB. A member of our privacy team picks up data-related queries within the same session.

Email Support

Send your data access, correction or deletion request to our dedicated privacy address. We acknowledge every email within 24 hours and complete most requests within seven working days.

In-Account Form

Log in, navigate to Account Settings, and select Privacy Request. Fill in the form detailing what you need — access, correction or removal — and our team reviews it in the next working day.

DATA HANDLING STANDARDS

Six Ways We Protect Your Account Data

From the moment you submit your first deposit through GoPay or QRIS to the moment a withdrawal clears, your data passes through layered controls.

Encrypted Storage

All personal data — including your registered payment methods such as DANA and OVO — is stored using AES-256 encryption at rest. This means raw account details are never readable in our database without the correct decryption key.

Cookie Transparency

We use session cookies to keep you logged in and analytics cookies to understand which lobby sections you visit most. You can adjust cookie preferences in your browser settings at any time without losing account access.

Account Access Logs

Every login event is timestamped and tied to a device fingerprint. If we detect a login from an unfamiliar device or region, we trigger a verification step before the session opens — protecting you against unauthorised access.

Retention Schedule

Transaction data is held for five years from the date of the last activity, in line with standard financial record-keeping requirements. Profile data that is no longer needed for active account operation is purged on a rolling 12-month review cycle.

Third-Party Sharing Rules

We share data with payment processors — DANA, OVO, GoPay, QRIS — only to complete the specific transaction you initiate. We do not share your data with advertisers, data brokers, or any entity outside our operational chain.

Your Correction Rights

You have the right to request a copy of the data we hold, ask us to correct inaccurate records, or ask us to erase data where no legal retention obligation applies. Submit requests via our in-account Privacy Request form or by email.

Common Questions About Your Data Rights

The questions below cover what Indonesia account holders ask us most about how their personal data is collected, stored and managed. If your question is not listed here, reach our privacy team through live chat between 08.00 and 23.00 WIB, or submit an in-account Privacy Request form and we will respond within 24 hours.

We collect your name, email address, date of birth, and the payment method you register — such as DANA, OVO, GoPay or QRIS. Device identifiers and session timestamps are also recorded automatically to secure your login.

Transaction records, including deposit and withdrawal history linked to QRIS or bank transfer, are retained for five years from your last account activity. After that period, records are deleted unless a legal obligation requires further retention.

Yes. Log in and navigate to Account Settings, then select Privacy Request and choose the data access option. We compile your data summary and send it to your registered email address within seven working days of receiving the request.

We share data only with payment processors — DANA, OVO, GoPay, QRIS — to complete transactions you initiate. No data is sold to advertisers or data brokers. Disclosure to authorities only occurs when required by a lawful order.

Submit a deletion request through the in-account Privacy Request form or email our privacy team directly. We action deletion within seven working days where no financial retention obligation prevents removal of the data in question.

We use session cookies for login continuity and analytics cookies to understand lobby usage patterns. You can disable non-essential cookies in your browser settings at any time; your account access and payment functionality will remain unaffected.

Your data is processed under the same privacy rules regardless of whether you access your account from Jakarta, Semarang or anywhere else in Indonesia. Availability of certain features depends on local law, but data handling standards are uniform across all regions we serve.