Reference

How pg288 Handles Your Personal Information

Your account data belongs to you — we collect only what's needed to run your wallet, process your DANA, OVO, or GoPay transactions, and keep your account secure.

Account & wallet dataDANA, OVO, GoPay transaction recordsSession and device activityYour rights to access and deletionIndonesia-applicable data handling
pg288 How pg288 Handles Your Personal Information
HOW WE PROTECT IT

Security, Retention, and Your Control

We use SSL encryption on every page and require OTP verification at login, so unauthorised access is blocked at the account layer even if someone has your password. Payment data flowing through DANA, OVO, and GoPay is handled by those providers under their own security frameworks — we receive only the transaction confirmation, not your wallet PIN or full account number. Your data is stored on servers with access controls limited to authorised operations staff, and we run regular audits on who can view account records.

Encryption in Transit SSL covers every page and every API call. Data moving between your device and our servers — including deposit confirmations from GoPay and OVO — is encrypted end to end.
OTP Login Verification Every login triggers a one-time code to your registered phone number. Without that code, account access is blocked, which protects you even if your password is compromised.
Data Retention Windows Active account data is kept while your account is open. After closure, personal records are deleted within the window mandated by applicable local data regulations in Indonesia.
Your Right to Request Changes You can ask us to correct inaccurate details, export a copy of your data, or delete your account records entirely. Submit the request via live chat or the in-account help form.
PRIVACY CONTACT PATHS

Reach Our Data and Privacy Team

If you want to access, correct, or delete the data we hold on your account, our support team handles privacy requests directly. Reach us through live chat in the lobby, by email, or through the in-account help form — we aim to respond to all data requests within the timeframe required under applicable rules.

Live Chat Open the chat widget from your account dashboard. Select 'Account & Privacy' to route your request to the right team and get a written record of your inquiry.
Email Support Send your data access or deletion request to our support address. Include your registered phone number so we can verify your identity before processing any changes.
In-Account Help Form Log in, head to Settings, and submit a privacy request through the Help form. This path auto-attaches your account ID, cutting verification time down significantly.

What You've Asked About Your Data

These are the questions we hear most from accounts in Jakarta and across Indonesia about how their data is managed, who can see it, and what happens when they want it removed.

We collect your name, email, and phone number at registration, plus device and session data each time you log in. Payment references from DANA, OVO, or GoPay are logged per transaction but your wallet PIN is never stored by us.

We share only what's needed to process your payments — transaction references go to DANA, OVO, or GoPay to confirm transfers. We do not sell personal data to advertisers or unrelated third parties.

Log in, go to Settings, and submit a data access request through the Help form. Your account ID is attached automatically. We will respond within the timeframe required by applicable local data rules.

Yes. Submit a deletion request via live chat or the in-account help form after verifying your identity. We will remove personal records within the retention window set by applicable regulations in Indonesia.

We use session cookies to keep you logged in, preference cookies for language settings, and analytics cookies to improve lobby performance. You can manage cookie preferences through your browser settings at any time.

SSL encryption covers every page. OTP verification is required at each login — a one-time code is sent to your registered phone. Access to account records on our servers is restricted to authorised staff only.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.