Reference

How catoto Handles Your Account Data

Your account data — including the wallet details you use with DANA, OVO, and GoPay — stays inside our system for one purpose: making your account work.

No data sold to third partiesDANA, OVO, GoPay wallet info protectedAccount data kept only as long as neededYou can request data access anytimeAvailable where local law permits
catoto How catoto Handles Your Account Data
PRIVACY CONTACT

How to Reach Us About Your Data

If you want to access, correct, or delete the data we hold on your account, our support team handles these requests directly. You can reach us through live chat inside your account dashboard, by email, or via our help centre. We aim to respond to all data-related requests within a reasonable timeframe, and we will confirm receipt of your request before processing it.

Live Chat Open your account dashboard and start a live chat session. Our Indonesia support team is available around the clock for account and data queries.
Email Support Send your data request or privacy question to our support email. Include your registered account name so we can locate your records quickly.
Help Centre Our help centre has a dedicated section for privacy and account data requests, covering how to ask for a copy of your data or submit a deletion request.
HOW WE PROTECT DATA

Security, Retention and Your Rights

Account security and data handling are not afterthoughts here. Every piece of data we collect is stored with access controls that limit who inside our team can view it. Your wallet credentials for DANA, OVO, and GoPay are never stored in plain text — transaction references are encrypted and held only for as long as they are needed to support your account history. If you close your account, we retain only what applicable law requires and remove the rest within a reasonable period.

Data Encryption

Wallet references and account credentials are encrypted at rest. DANA, OVO, and GoPay transaction data is never stored in a readable plain-text format inside our system.

Access Controls

Only authorised team members handling account support or payment queries can access your personal data. Access is logged and reviewed on a regular basis.

Data Retention

We keep your account data for as long as your account is active or as required by applicable law. After account closure, non-required data is removed within a defined period.

Your Rights

You have the right to request a copy of your data, correct inaccurate records, or ask us to delete data we no longer need. Reach our team via live chat or email to start the process.

Common Questions About This Privacy Policy

These are the questions we get most often about how catoto collects, stores, and protects your account data. If your question is not answered here, our support team can help directly through live chat or email.

We collect your name, email address, and the wallet identifier linked to your DANA, OVO, or GoPay account. We also log device and session data to keep your account secure from unauthorised access.

We do not sell your data. We share it only with payment processors — such as DANA, OVO, and GoPay — strictly to complete your transactions, and with service providers bound by confidentiality agreements.

Your data is held for as long as your account remains active. After you close your account, we retain only what applicable law requires and remove the rest within a reasonable defined period.

Contact our support team via live chat inside your account dashboard or by email. Include your registered account name and we will process your data access request and confirm receipt before responding.

Yes. Wallet transaction references are encrypted and never stored in plain text. Your wallet credentials are not visible to our general support team — only authorised staff handling payment queries can access transaction records.

This policy applies where access to catoto is permitted under local law. Use of the platform in your region depends on applicable local regulations, and data handling follows those requirements accordingly.