Reference

How lotreonline Handles Your Personal Data

Your personal data — from your account registration details to every deposit made via DANA, OVO, GoPay or QRIS — is collected, stored, and protected under the terms…

Data collected at account openingDANA, OVO, GoPay & QRIS transaction recordsCookie and device data explainedYour right to access and deleteContact us to update your profile
lotreonline How lotreonline Handles Your Personal Data
PRIVACY CONTACT PATHS

3 Ways to Reach Our Data Team

If you want to access, correct, or request deletion of your personal data held by lotreonline, our privacy support team is available through the channels below. We aim to respond to all data-related requests within 72 hours on business days. You can also reach us from Yogyakarta or anywhere else in Indonesia without needing to visit a physical office — all requests are handled digitally.

Team online

Live Chat

Start a live chat from your account dashboard any day between 08:00 and 23:00 WIB. Type 'data request' in the opening message so the privacy team picks it up immediately.

Email Support

Send your data access or deletion request to our dedicated privacy email address. Include your registered phone number and the payment method — DANA, OVO, GoPay or QRIS — linked to your account.

Account Settings Panel

Log in, go to Account Settings, then select 'My Data'. From there you can download a copy of your stored profile data or submit a deletion request directly without contacting support.

DATA HANDLING STANDARDS

How We Protect and Manage Your Information

Every measure described here reflects how our systems actually operate — from the moment you create an account to the day you request data removal.

Encryption at Rest and in Transit

All personal data stored in our databases is encrypted using AES-256. Data moving between your device and our servers is protected by TLS 1.3, covering login sessions, payment flows and account updates.

Cookie Policy and Controls

We use session cookies to keep you logged in and analytics cookies to understand page performance. You can disable non-essential cookies at any time through the cookie preference panel in your account footer.

Payment Data Handling

Payment identifiers from DANA, OVO, GoPay and QRIS are tokenised — we store a reference token, not your full wallet credentials. Raw payment credentials never touch our application servers.

Data Retention Schedule

Account profile data is retained while your account is active and for 90 days after a closure request. Financial transaction logs are held for five years as required; after that period they are securely deleted.

Third-Party Access Limits

We share data only with payment processors (DANA, OVO, GoPay, QRIS networks) and identity verification providers necessary to run your account. No data is passed to advertisers or data brokers.

Your Right to Request Changes

You can request a copy of your data, ask us to correct inaccuracies, or submit a full deletion request at any time via Account Settings or by emailing our privacy team — response within 72 business hours.

Your Privacy Questions Answered

The questions below cover the data rights and account-security topics we hear most often from people in Indonesia. If your question is not listed here, our privacy support team is reachable via live chat between 08:00 and 23:00 WIB, or by email with a response within 72 hours on business days.

We collect your name, email, phone number and the payment identifier linked to your chosen method — DANA, OVO, GoPay or QRIS. We also record your device type and IP address to protect your account from unauthorised access.

Your profile data is kept for 90 days after a closure request, giving you a window to reactivate. Financial transaction records, including DANA and OVO deposit logs, are retained for five years in line with financial record obligations, then securely deleted.

Yes. Log in, open Account Settings and select 'My Data' to generate a downloadable copy of your stored profile and transaction history. The file is ready within 24 hours and available for seven days before it expires.

We share data only with the payment networks you use — DANA, OVO, GoPay and QRIS — and with identity verification providers required to operate your account. We do not sell or pass your data to advertisers or data brokers under any circumstances.

Submit a deletion request through Account Settings under 'My Data', or email our privacy team with your registered phone number. We aim to process requests within 72 business hours. Note that financial records subject to retention rules cannot be deleted early.

We use session cookies for login continuity and analytics cookies for performance monitoring. Non-essential cookies can be turned off via the cookie preference panel in the account footer at any time — this will not affect your ability to deposit or withdraw.

The core policy applies to all accounts opened in Indonesia. Certain data-handling provisions depend on local law, and where local law permits, we apply jurisdiction-specific adjustments. If you have questions about your specific region, contact our privacy team directly.