LEGAL REFERENCE

Your Privacy Comes First at cbtoto

We built cbtoto around your account security and data protection. Every transaction through DANA, OVO, GoPay and QRIS is encrypted. This policy shows exactly how we handle your...

Data EncryptedQRIS ProtectedAccount SecurePayment SafeIndonesia Compliant
cbtoto Your Privacy Comes First at cbtoto

How We Protect Your Information

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

PLAYER SUPPORT

Privacy Questions? Reach Out

Email Support Send privacy concerns to our data protection team...
Live Chat Chat with our support team directly from your...
Account Settings Manage your privacy preferences, communication opt-outs and data...
WHY VISITORS TRUST US

Why Your Data Is Safe With Us

SSL Encryption

Every login, deposit and withdrawal uses 256-bit SSL encryption. Your DANA, OVO, GoPay and QRIS transactions are protected end-to-end.

PCI Compliance

We meet Payment Card Industry standards for handling payment data. Regular audits ensure our security protocols stay current and effective.

Data Minimization

We collect only the information needed to run your account and process payments. No unnecessary data collection or tracking beyond lobby operations.

Fraud Detection

Our systems monitor for suspicious activity on your account. Unusual login patterns or payment attempts trigger immediate verification steps.

Regular Audits

Third-party security firms audit our infrastructure quarterly. We fix vulnerabilities immediately and publish transparency reports annually.

Indonesia Jurisdiction

cbtoto operates under Indonesian law where applicable. Your privacy rights are protected by local regulations and our commitment to transparency.

Our Privacy Standards vs Industry Baseline

Data RetentionWe keep account records for 7 years post-closure for dispute resolution. Most platforms retain indefinitely or delete after 3 years.
Payment TransparencyYour DANA, OVO, GoPay and QRIS transaction history is visible in your account. Many platforms hide payment details or charge for access.
Third-Party SharingWe never sell your data to advertisers or data brokers. Industry standard allows selling anonymized data; we don't participate.
Encryption StandardAll data in transit and at rest uses 256-bit encryption. Competitors often use 128-bit or weaker protocols for cost savings.
Breach NotificationWe notify affected users within 24 hours of any security incident. Industry average is 30-60 days or longer.
User ControlYou can download your data, request deletion or opt out of communications anytime. Most platforms require support tickets or deny requests.
Policy UpdatesWe notify you 30 days before any privacy policy change. You can review changes and close your account if you disagree.
SERVICE CONTEXT

What Defines Our Privacy Approach

01
Account Ownership Your account is yours alone. We never access your funds, share your login or use your account for testing or internal purposes.
02
Payment Method Privacy DANA, OVO, GoPay and QRIS details are tokenized. We never store full payment credentials on our servers or in backups.
03
Gameplay Privacy Your betting history, game preferences and session data stay private. We don't sell gameplay patterns to game providers or advertisers.
04
Communication Control You choose how often we contact you. Opt out of promotions, newsletters or notifications anytime from your account settings.
05
Dispute Resolution We keep transaction records to resolve payment disputes fairly. Your data is used only for your account and never for marketing.
06
Deletion Rights Request account deletion and we remove your personal data within 30 days. Some records stay for legal compliance; we explain what and why.

Privacy Policy Questions Answered

We retain account records for 7 years post-closure to resolve disputes and comply with Indonesian financial regulations. Personal data like your name and email are deleted after 30 days unless legal holds apply. You can request earlier deletion; we'll explain any records we must keep.

No. Payment credentials are tokenized immediately upon entry. We store only a secure token linked to your account. Your actual payment details never touch our database. All transactions are encrypted end-to-end and processed through PCI-compliant payment gateways.

We share data only when required by law or to process your payments through DANA, OVO, GoPay and QRIS partners. We never sell your information to advertisers, data brokers or marketing firms. Your consent is required for any new sharing arrangement.

We notify affected users within 24 hours with details of what was accessed and steps to protect your account. We also notify relevant Indonesian authorities as required by law. We maintain cyber insurance and conduct quarterly security audits to prevent breaches.

Log into your account, go to Settings > Privacy, and select Download Data or Request Deletion. You'll receive your data within 7 days or confirmation of deletion within 30 days. Support can help if you've forgotten your login credentials.

We use essential cookies for account security and session management. Optional analytics cookies help us improve your lobby experience. You can disable non-essential cookies anytime in your browser settings without losing account access.

Click Unsubscribe in any promotional email or text message. You can also manage preferences in your account settings under Communications. Opt-outs take effect within 24 hours. You'll still receive account security alerts and transaction confirmations.