Reference

How montirtoto Protects Your Personal Data

At montirtoto, your personal data is handled with clear rules: we collect only what is necessary to operate your account, process payments through DANA, OVO, GoPay and QRIS…

Data encrypted at rest and in transitDANA, OVO, GoPay & QRIS transaction data protectedAccount deletion requests processed within 14 daysNo data sold to third parties
montirtoto How montirtoto Protects Your Personal Data
PRIVACY CONTACT CHANNELS

How to Reach Our Privacy Team

If you have a question about your data, want to update stored information, or need to submit a deletion request, our privacy support team is available 24 hours a day, 7 days a week. We aim to respond to all privacy-related messages within one business day and complete verified data requests within 14 calendar days. Reach us through any of the three channels below.

Team online

Live Chat

Start a conversation directly inside your account dashboard. Our privacy support agents are available around the clock and can verify your identity in real time to handle sensitive data requests securely.

Email Support

Send your data access or deletion request to our dedicated privacy inbox. Include your registered email and account ID so we can locate your record and confirm the request within one business day.

In-Account Help Centre

Navigate to Settings → Privacy in your account to submit a structured data request form. This route automatically tags your ticket as a privacy matter, reducing processing time to the shortest possible window.

DATA HANDLING STANDARDS

Six Ways We Handle Your Data Responsibly

Every data-handling practice at montirtoto is built around a straightforward principle: your information exists to serve your account, not to generate revenue for us in other ways.

End-to-End Encryption

All data moving between your device and our servers — including DANA and OVO payment tokens — is encrypted using TLS 1.3. Stored records use AES-256 encryption so that even internal access requires layered authorisation.

Cookie Transparency

We use strictly necessary cookies to keep your session active and preference cookies to remember your lobby settings. No advertising or tracking cookies are placed without your explicit consent via our cookie consent panel.

Account Security Alerts

Any login from a new device or unusual IP address triggers an automatic notification to your registered email or phone. You can review active sessions and revoke access from the Security tab in your account settings.

Data Retention Schedule

Transaction records linked to GoPay or QRIS are retained for the period required by applicable financial regulations, then deleted. Non-financial profile data is removed within 30 days of a verified account closure request.

Third-Party Data Sharing

We share data only with payment processors — DANA, OVO, GoPay and QRIS — and identity verification partners who are contractually bound to use your data solely for the purpose of completing your transaction or verification.

Your Right to Access and Correct

You may request a full export of the personal data we hold on your account at any time. Corrections to stored name, contact details or payment references can be submitted through Live Chat and are processed within 5 business days.

Your Privacy Questions, Answered Directly

The questions below reflect what account holders commonly ask about how their data is managed at montirtoto. If your specific question is not covered here, our privacy support team is reachable 24/7 via Live Chat or the in-account Help Centre.

We collect your name, email, phone number, and payment identifiers such as your DANA or OVO reference. We also record your IP address and device type to protect your account from unauthorised access. Nothing beyond what is operationally necessary is stored.

Your DANA, GoPay, OVO or QRIS payment data is shared only with the relevant payment processor to complete your transaction. Those processors are contractually prohibited from using your data for any other purpose, including marketing or analytics.

Financial transaction records are kept for the period required under applicable regulations. Non-financial profile data — name, contact details, preferences — is deleted within 30 days of a verified closure request submitted through Settings or Live Chat.

Yes. Submit a data export request through Live Chat or the in-account Help Centre under Settings → Privacy. We will prepare a structured file of your stored data and deliver it to your registered email within 14 calendar days.

We use strictly necessary session cookies and optional preference cookies. Advertising or third-party tracking cookies are not placed without your consent. You can manage or withdraw cookie consent at any time through the cookie panel in the site footer.

In the event of a confirmed breach affecting personal data, we will notify impacted account holders by email within 72 hours of detection, detail what data was involved, and outline the steps we are taking to contain and remediate the incident.

Certain data rights and the scope of data we may process depend on local law. For accounts registered from Indonesia, we apply Indonesian data protection standards as the baseline. Specific rights may vary where local law permits or restricts them.