Reference

Your Data, Handled With Care at mikototo

At mikototo, every piece of personal data you share — from your account registration details to your DANA or OVO transaction records — is collected for one purpose…

Data collected only for account purposesDANA, OVO, GoPay, QRIS transactions protectedYou control your personal dataClear retention and deletion policyIndonesia-region data handling
mikototo Your Data, Handled With Care at mikototo
PRIVACY CONTACT CHANNELS

How to Reach Us About Your Privacy

If you have a question about how your data is stored, want to request a copy of your records, or need to correct information on your account, our privacy support team is…

Live Chat Support Open your account dashboard and tap the chat icon to reach our privacy team instantly — available daily from 08:00 to 23:00 WIB for data-related questions and account correction requests.
Email: [email protected] Send a written request to [email protected] for formal data access, correction, or deletion queries. We aim to respond within two business days with a clear written answer.
WhatsApp Support Line Message our WhatsApp support line with your registered account number and your privacy concern. Our team verifies your identity before discussing any account data, keeping your records safe.
DATA PROTECTION STANDARDS

How mikototo Protects Your Personal Data

Data protection at mikototo is an operational process, not just a policy statement. From the moment you deposit via GoPay in Bandung to the moment a withdrawal clears back to your QRIS…

Encryption in Transit and at Rest

All data exchanged between your device and our servers — including DANA and OVO payment details — is encrypted using TLS 1.2 or higher. Stored records are encrypted at rest with AES-256 so your payment data stays protected even if server access is attempted.

Cookie and Session Management

We use session cookies to keep you logged in and analytics cookies to understand which pages you visit. You can review and adjust cookie preferences in your account settings at any time; disabling analytics cookies does not affect your ability to deposit or withdraw.

Account Security and Login Monitoring

Every login attempt is logged with device type, IP address, and timestamp. If we detect a login from an unfamiliar device or location, we send an email alert to your registered address immediately so you can confirm or block that session.

Data Retention and Deletion Schedule

We retain account records for as long as your account is active, plus a period required by applicable financial record-keeping rules. Once you close your account and that period expires, your personal data is permanently deleted from our systems within 30 days.

Third-Party Data Sharing Policy

We share your data only with payment processors — such as the DANA and GoPay gateways — strictly for the purpose of completing your transactions. We do not share your data with advertisers, data brokers, or any unrelated third party.

Your Right to Access and Correct Data

You have the right to request a full copy of the personal data we hold about you, correct inaccuracies, or ask for deletion where local law permits. Submit your request through live chat or email and we process it within five business days.

Your Privacy Policy Questions

Below are the questions we hear most often from people reviewing our privacy practices. If your question is not covered here, our support team at [email protected] can address it directly within two business days.

We collect your full name, email address, phone number, date of birth, and the payment method you register — DANA, OVO, GoPay, or QRIS. We also log your device identifiers and IP address for security monitoring purposes.

Yes. Every deposit and withdrawal record processed through DANA, OVO, GoPay, or QRIS is encrypted at rest using AES-256 and stored on access-controlled servers. Only authorised payment-processing staff can query these records for dispute resolution.

We keep your records for the period required by applicable financial regulations after account closure. Once that period ends, your data is permanently deleted from our systems within 30 days, and we send you a confirmation email.

Yes. Email [email protected] with your registered account number and the subject line 'Data Access Request'. We verify your identity and send a full data export within five business days, where local law permits.

We share data only with the payment gateways — DANA, OVO, GoPay, and QRIS — that process your transactions. We do not share your information with advertisers, data brokers, or any party unrelated to operating your account.

Contact us via live chat in your dashboard (08:00–23:00 WIB) or email [email protected]. State your account ID and the specific data you want corrected or removed. We respond with a resolution plan within two business days.

We use essential session cookies to keep you logged in, and optional analytics cookies to improve page performance. You can review and switch off analytics cookies in your account settings — this does not affect deposits, withdrawals, or game access.