Reference

bbmtoto Privacy Policy: What We Collect and Why

This Privacy Policy tells you exactly what personal data bbmtoto collects when you open an account, make a deposit via DANA, OVO, GoPay or QRIS, and access our…

Account data protectedDANA, OVO, GoPay & QRIS transaction recordsNo third-party data salesIndonesia-aware data handlingClear deletion request path
bbmtoto bbmtoto Privacy Policy: What We Collect and Why
PRIVACY CONTACT PATHS

How to Reach Us About Your Privacy

If you have a question about how we handle your data, want to request a copy of what we hold, or need to ask us to…

Live Chat Open the chat widget inside your account dashboard any time between 08:00 and 23:00…
Email Support Send your data request or policy question to our support email.
Account Help Centre Log into your bbmtoto account, navigate to Settings, then select 'Privacy & Data'.
DATA HANDLING STANDARDS

Six Ways We Manage Your Information Responsibly

Data protection at bbmtoto is not a background function — it is wired into account creation, payment processing and lobby access.

Cookie Transparency

We use session cookies to keep you logged in and analytics cookies to see which lobby sections you visit most. You can review and adjust cookie preferences inside your account settings at any time.

Account Security

Phone-number verification is required before any account access. We do not store your full payment credentials; DANA, OVO, GoPay and QRIS transactions are tokenised so raw wallet details never sit in our database.

Data Retention Period

We keep your account and transaction records for as long as your account remains active, plus a short period afterwards for dispute resolution. Once that window closes, records are deleted from our live systems.

Third-Party Sharing Rules

We share data only with the payment processors needed to complete a QRIS scan or a BCA virtual account transfer. No marketing or advertising partners receive your personal information.

Your Right to Access

You can request a summary of the personal data we hold about you at any point. Use the Settings > Privacy & Data path in your account, or contact live chat between 08:00 and 23:00 WIB.

Correction and Deletion

If any detail in your account record is wrong, you can update it under Profile Settings or ask our support team to correct it. Full account deletion requests are processed within five business days.

Privacy Policy Questions We Hear Most Often

These are the Privacy Policy questions that come up most frequently from people opening an account or making their first DANA or QRIS deposit on bbmtoto. If your question is not here, our live chat team is available from 08:00 to 23:00 WIB.

We collect your mobile number, name and device information during phone verification. When you deposit via DANA, OVO, GoPay or QRIS, we log transaction references — not your full wallet credentials. No extra data is collected beyond what account access requires.

We share data only with payment processors required to complete your deposit or withdrawal — for example, the gateway handling your QRIS scan or BRI virtual account. We do not sell or share your information with advertisers or unrelated third parties.

Records are kept while your account is active and for a short period after closure to handle any dispute. After that window, your data is removed from our live systems. The exact retention period depends on local law.

Log into your account, go to Settings, then Privacy & Data, and submit a data request. Alternatively, contact live chat between 08:00 and 23:00 WIB and type 'privacy request' to reach the right team. We aim to respond within two business days.

Yes. Submit a deletion request through Settings > Privacy & Data in your account, or email our support team with your registered phone number. Full deletion is processed within five business days where local law permits.

Your OVO, GoPay, DANA and QRIS transactions are tokenised. That means the raw wallet credentials you enter with your payment provider are never stored directly in our database — only the transaction reference and timestamp are recorded on our side.

Our data practices apply across Indonesia, but some features and data-handling specifics depend on local law. If access to a particular account feature is restricted in your area, that reflects legal requirements rather than a platform decision.