Terms of Service
The account rules referenced in our Terms align word-for-word with the data handling described here. No conflicting clauses between the two documents.
This is where we explain what we collect when you open an account with us, what we keep on file, and how long it stays. We've written it...
We collect only what we need to run your account: your name, contact, verification documents, and the device fingerprint that signs you in. Wallet activity through DANA, OVO, GoPay and QRIS is logged for reconciliation where local law permits. We store this on encrypted systems and limit access to staff working on your support tickets or compliance checks. We never sell your
data to third parties. If you close your account, we keep mandatory records for the retention window required by supported regions, then purge the rest. You can request a copy of what we hold or ask us to correct anything that looks wrong — the support routes below are the fastest paths.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
Our policy team revisits this document every quarter to match how we actually run the lobby. If something changes in your account flow, the wording here changes with it before the rollout.
We wrote this with Indonesia data norms in mind, not as a copy of an offshore template. Local wallet handling for DANA, OVO, GoPay and QRIS is named, not buried under generic clauses.
Identity documents and wallet logs sit on encrypted partitions with role-based access. Only agents on your active ticket can pull the record, and every read is timestamped on our audit trail.
We don't trade your email, phone number or wallet history to marketing networks. The data you give us stays inside the systems running your ungutoto login account.
You shouldn't need a lawyer to read your own privacy terms. We keep sentences short and avoid the dense clauses that hide what's really happening to your account data.
A real compliance lead signs off on every revision. If something here is wrong or out of date, escalation reaches a person, not a generic inbox that nobody monitors.
The account rules referenced in our Terms align word-for-word with the data handling described here. No conflicting clauses between the two documents.
Cookie categories listed in the Cookie Notice match the session-log description on this page. Same retention windows, same opt-out paths.
Document collection rules in our KYC page mirror the verification data scope set out here — identity, address proof, wallet ownership check.
Wallet record retention for DANA, OVO, GoPay and QRIS is described identically across the Payment Terms and this Privacy Policy.
Marketing consent referenced in our Promotions page links back to the opt-in controls described in this document. One source of truth.
Closure flow on the Account Closure page references the same retention windows for residual data that we state here.
Escalation steps in our Complaints page reuse the contact desks named in this policy. The privacy line is the privacy line everywhere.