Reference

How zorototo link Handles Your Personal Data

At zorototo link, your personal data is handled with a clear purpose: we collect only what we need to operate your account, process deposits via DANA, OVO, GoPay…

Data collected with your consentDANA, OVO, GoPay & QRIS transaction records protectedAccount data retained only as long as neededYou can request data deletion at any timeIndonesia-specific data handling
zorototo link How zorototo link Handles Your Personal Data
PRIVACY CONTACT PATHS

Reach Us With Any Data or Privacy Request

If you want to review, correct or delete the personal data we hold on your account, our privacy team is available 24 hours a day, seven days a week. You can reach us through live chat inside your account dashboard, by emailing our dedicated privacy address, or via our Telegram support channel for faster responses during peak hours. We aim to acknowledge every request within one business day and resolve it within seven.

Team online

Live Chat

Access live chat directly from your account dashboard — available around the clock, every day. A privacy agent will pick up your data request and confirm receipt within one business day, no queuing required.

Email Privacy Team

Send your data access, correction or deletion request to our dedicated privacy email. We log every submission with a reference number so you can track progress. Responses are delivered within seven business days of acknowledgement.

Telegram Support

For quicker back-and-forth on privacy questions, our Telegram channel connects you to the same team. Share your account reference number so agents can pull your record immediately and begin processing your request.

HOW WE PROTECT YOU

Our Six Core Data-Handling Practices

Every practice below is enforced at the system level — not just described in a document.

Encrypted Data Storage

All personal and payment data — including your DANA, OVO, GoPay and QRIS transaction history — is stored using AES-256 encryption at rest. Decryption keys are held separately and rotated on a scheduled basis, limiting exposure even in the unlikely event of a server incident.

Cookie & Tracking Policy

We use session cookies to keep you logged in and analytics cookies to understand how our pages perform. Tracking cookies are only activated after you accept our cookie notice. You can withdraw cookie consent at any time via your browser settings without losing account access.

Account Security Controls

Two-factor authentication is available on every account and strongly encouraged. Login attempts from unrecognised devices trigger an email alert to your registered address. If you notice any suspicious activity, our live chat team is available 24/7 to freeze access immediately.

Data Retention Schedule

We retain account data for as long as your account is active plus the period required by applicable Indonesian financial regulations. Once that window closes and you have made a deletion request, your identifiable records are purged from our primary and backup databases within 30 days.

Third-Party Data Sharing

Personal data is shared only with payment processors — specifically those handling DANA, OVO, GoPay and QRIS transactions — and only to the extent necessary to complete your transaction. Each processor is vetted and bound by a data-processing agreement aligned with this policy.

Your Right to Request Changes

You can request a copy of the data we hold, ask us to correct inaccuracies, or submit a deletion request at any time through live chat, email or Telegram. We will confirm the action taken and provide a reference number for your records within the timeframes stated in this policy.

What You Most Often Ask About This Policy

These are the real questions our account holders send to the support team about how their data is handled. Each answer reflects current practice — if anything changes, we update this page and notify you by email before the change takes effect.

We collect your name, email address, mobile number and the payment identifiers linked to DANA, OVO, GoPay or QRIS. Device data — IP address, browser type, session time — is also logged automatically for security purposes.

No. We do not sell, rent or trade your personal data to any third party for marketing purposes. Data sharing is limited to payment processors who need it solely to complete your transactions.

Send a data access request via live chat, email or Telegram with your account reference number. We will compile your data summary and deliver it to your registered email address within seven business days of confirming your identity.

Contact the privacy team through any support channel — live chat is available 24/7. After we verify your identity, deletion from our primary and backup systems is completed within 30 days, subject to any retention period required by Indonesian financial regulations.

Yes. Transaction records are encrypted at rest and in transit. Only the payment processor handling your specific method and our internal compliance team can access them — and only for fraud-prevention or regulatory purposes, where local law permits.

Yes. You can withdraw analytics cookie consent through your browser settings at any time. Session cookies that keep you logged in are treated separately and are required for the account to function; opting out of analytics does not affect them.

We send an email notification to your registered address before any material change takes effect. The updated policy is also published on this page with a revision date at the top so you can review exactly what changed before it applies to your account.