Reference

How We Protect Your Personal Data

At istana168, your personal data is handled with a clear, documented process — every piece of information you share when opening an account, making a deposit via DANA…

Data collected only for account operationDANA, OVO, GoPay & QRIS transaction records securedYour data is never sold to third partiesRight to request data access or deletionIndonesia-specific privacy handling
istana168 How We Protect Your Personal Data
PRIVACY CONTACT CHANNELS

How to Reach Our Privacy Team

If you have a question about how your data is stored, want to request a copy of the information we hold, or wish to ask us to delete your account data, our dedicated privacy support team is reachable seven days a week. We respond to all privacy-related requests within 48 hours of receipt, and our team based in Indonesia handles queries in both English and Bahasa Indonesia. You can reach us through the channels below — we aim to confirm receipt of every request within one business day.

Team online

Live Chat

Available 24 hours a day, seven days a week directly inside your account dashboard. Submit a privacy request or data deletion query and receive a reference number within minutes of opening the chat window.

Email Privacy Request

Send detailed data access or correction requests to our privacy inbox. We acknowledge every email within one business day and complete standard requests within 14 calendar days of receiving full verification from you.

Account Settings Panel

Log in, navigate to Account Settings, then select Privacy Controls. From there you can download a copy of your stored data, update your communication preferences, or submit a formal erasure request without contacting support.

DATA HANDLING PRACTICES

Six Ways We Keep Your Data Safe

Our data security posture covers encryption, access controls, retention schedules, and cookie management — each layer is designed so that your account information stays under your control.

End-to-End Encryption

All data transmitted between your device and our servers uses TLS 1.3 encryption. This covers your login credentials, payment method details such as linked DANA or GoPay accounts, and every message you send to our support team.

Cookie Management

We use session cookies to keep you logged in and analytics cookies to measure page performance. You can accept, reject, or customise cookie categories via the Cookie Preferences panel in the site footer — changes take effect immediately without requiring a page reload.

Account Security Verification

Before processing a withdrawal to OVO or QRIS, we verify the registered account name matches the payment wallet holder. This step protects your funds and ensures no third party can redirect a payout away from your verified wallet.

Data Retention Schedule

Transaction records are retained for a minimum of five years to satisfy internal audit standards. Non-transactional data — such as device logs and session metadata — is automatically purged after 12 months of account inactivity unless a legal hold applies.

Third-Party Sharing Policy

We share data with payment processors such as DANA and GoPay only to the extent required to complete your transaction. We do not sell, rent, or trade your personal information to marketing companies or data brokers under any circumstances.

Right to Erasure

You may request full deletion of your account and associated personal data at any time through Account Settings or by contacting our privacy team via live chat. We complete verified erasure requests within 30 calendar days and confirm completion by email.

Privacy Policy Questions We Hear Most

The questions below come directly from account holders asking about their data rights at istana168. Each answer reflects our actual internal process — from how we handle a DANA transaction record to what happens to your data when you close your account. If your question is not covered here, our live chat team is available around the clock to help.

We collect your name, email, phone number, date of birth, and the payment method you register — such as DANA, OVO or GoPay. We also log your IP address and device type to protect your account from unauthorised login attempts.

We share data only with payment processors needed to complete your transaction — for example, passing your wallet reference to GoPay or QRIS when you withdraw. We do not sell or share your data with advertisers, data brokers, or unrelated third parties.

Transaction records tied to DANA, OVO, GoPay and QRIS deposits and withdrawals are retained for a minimum of five years. Non-financial session data is deleted after 12 months of account inactivity. Legal holds may extend these periods where applicable.

Log in and go to Account Settings, then select Privacy Controls and choose 'Download My Data'. You can also send a written request via our privacy email. We deliver the data package within 14 calendar days of confirming your identity.

Yes. Submit an erasure request through Account Settings or contact our live chat team. We process verified requests within 30 calendar days and send a confirmation email once your data has been removed from our active and backup systems.

We use session cookies for login continuity and analytics cookies to measure site performance. Open the Cookie Preferences panel in the site footer to review, accept or reject each category. Your preferences are saved immediately and respected on every subsequent visit.

All payment data is encrypted using TLS 1.3 during transmission. Before any withdrawal is processed to OVO or QRIS, we verify the wallet name matches your registered account, ensuring your funds cannot be redirected to an unverified destination.