Reference

How totomakau handles your privacy

When you open an account with us, your personal information—from your login credentials to your payment details—stays secure and private.

Account data encryptedPayment info protectedYour control over access
totomakau How totomakau handles your privacy
REACH OUT ANYTIME

Contact us about your privacy

Team online

Live chat

Open your account dashboard, select Help, and start a chat with our team. We respond during Indonesia business hours, Monday to Friday, 09:00 to 20:00 Jakarta time.

Email support

Send your privacy request or data access question to [email protected] with your account email. We confirm receipt within 24 hours and provide a detailed response within seven business days.

Account settings

Log into totomakau, go to Settings > Privacy & Data, and manage your preferences directly. You can download your data or request deletion through the same section.

SECURITY PRACTICES

How we keep your data safe

Encryption

All data sent between your device and totomakau is encrypted using TLS 1.3. Your password is hashed and never stored in plain text, so even our team cannot see it.

Payment security

Deposits and withdrawals through DANA, OVO, GoPay and QRIS use tokenisation—we never store your full payment credentials. Each transaction is verified independently by the payment processor.

Access logs

We record login times, device types, and IP addresses for every account access. You can review this history in Settings > Login Activity and flag any unrecognised session.

Data retention

Personal data is kept for as long as your account is active plus three years after closure, or longer where local law requires. Transaction records are retained according to regulatory obligations.

Third-party disclosure

We share data only with payment processors, identity verification partners, and law enforcement where local law permits. We do not sell or rent your information to marketers.

Data requests

You can request access, correction, or deletion of your data by contacting [email protected]. We respond within the timeframe set by your local privacy laws, typically five to ten business days.

Your questions about privacy at totomakau

When you close your account, your data is deactivated and moved to archived storage. We retain it for three years for regulatory and dispute purposes, then securely delete it. You can request earlier deletion by emailing [email protected], subject to legal holds.

Yes. Log into your account, go to Settings > Profile, and update your email, phone, or name. For identity documents, contact [email protected] with new documents; we'll verify and replace them in your file within two business days.

No. Your withdrawal records are shared only with the payment processor (DANA, OVO, GoPay or QRIS) needed to complete that specific transaction. We do not sell or share your payment history with third parties, where local law permits.

Go to Settings > Privacy & Data > Download My Data, select the date range, and click Export. Your account activity, deposits, withdrawals, and profile details are packaged into a file sent to your registered email within 24 hours.

We use session cookies to keep you logged in and analytics cookies to understand how you navigate the lobby. No tracking cookies follow you outside totomakau. You can disable non-essential cookies in Settings > Privacy > Cookie Preferences at any time.

Email [email protected] from your registered address. We'll ask for your account email, date of birth, and recent deposit method (e.g., DANA transaction ID). Once verified, we send a reset link to regain access within one hour.

Yes. Our privacy practices depend on local law and comply with applicable Indonesian data protection and gaming regulations. For specifics on how your jurisdiction's laws apply to your account, contact [email protected].