Reference

How gaco 88 Protects Your Personal Data

At gaco 88, your personal data — from your account registration details to every deposit you make via DANA, OVO, GoPay or QRIS — is handled under a…

Data collected only for account & transaction purposesDANA, OVO, GoPay, QRIS transaction data securedYou may request data access or deletion anytimeNo data sold to third-party advertisersApplies where local law permits
gaco 88 How gaco 88 Protects Your Personal Data
PRIVACY CONTACT PATHS

Reach Our Privacy Team Directly

If you have a question about your personal data, want to request a copy of everything we hold about your account, or need to correct an inaccuracy, our dedicated privacy support line is the fastest route. We aim to respond to all data-related requests within 72 hours. You can reach us through the channels below — our privacy team is available 07:00–23:00 WIB, seven days a week.

Team online

Live Chat — Privacy Queue

Open the chat widget in your account dashboard and select 'Privacy & Data' from the topic menu. A privacy team agent picks up the thread within 10 minutes during 07:00–23:00 WIB operating hours.

Email Privacy Request

Send your data access, correction or deletion request to our privacy inbox. Include your registered account email and the specific data category you are asking about. We confirm receipt within 24 hours.

In-Account Data Request Form

Log in, go to Settings → Privacy, and submit a formal data request directly from your account. The form routes your request to the privacy team instantly and creates a trackable ticket number for your records.

DATA HANDLING STANDARDS

Explore How We Secure and Manage Your Information

Every layer of our data infrastructure — from the moment you confirm a QRIS scan to the moment a withdrawal clears to your OVO wallet — is covered by documented security controls.

Encryption at Every Stage

All personal data fields, including payment identifiers for DANA, OVO, GoPay and QRIS, are encrypted in transit using TLS 1.3 and encrypted at rest using AES-256. Raw payment credentials never touch our application layer directly.

Cookie Usage and Control

We use session cookies to keep your account logged in and analytics cookies to measure page performance. You can review and withdraw cookie consent at any time from Settings → Privacy in your account dashboard without affecting your ability to log in.

Account Security Alerts

If we detect a login attempt from an unrecognised device or location, we send an immediate email alert to your registered address and temporarily hold the session pending your verification — reducing the risk of unauthorised access to your account.

Data Retention Schedule

Transaction records linked to DANA, OVO, GoPay and QRIS are retained for five years per financial regulations. Profile and session data not tied to financial activity is deleted after 90 days of account inactivity or upon a verified deletion request.

Third-Party Data Sharing Policy

We share data only with payment processors (DANA, OVO, GoPay, QRIS) and fraud-detection partners who operate under contractual data-handling obligations. We do not sell, rent or trade your personal data to advertisers or unrelated third parties.

How to Request Data Changes

Submit a request via Settings → Privacy or through our live chat privacy queue. Once identity is verified through your registered email, we process corrections within 5 business days and deletions within 14 business days, where local law permits.

Your Questions About Our Privacy Policy Answered

Below are the questions we receive most often about how gaco 88 handles your personal data, from what gets collected when you deposit via GoPay to how long we keep your account history on file. If your question is not covered here, use the live chat privacy queue during 07:00–23:00 WIB.

We collect your name, email address, date of birth and the payment identifiers linked to DANA, OVO, GoPay or QRIS transactions. We also log device type and session timestamps for security purposes. No more than what is necessary to run your account.

No. DANA and OVO handle authentication entirely on their own infrastructure. We only receive a transaction reference number and confirmation status — your wallet login details and PIN are never transmitted to or stored on our servers.

Yes. Log in, go to Settings → Privacy, and submit a data access request. After we verify your identity via your registered email, we compile and send a structured data export within 5 business days, where local law permits.

Submit a deletion request through Settings → Privacy or via our email privacy inbox. We process verified deletion requests within 14 business days. Note that transaction records required by financial regulations are retained for up to five years regardless of deletion requests.

We use session cookies to maintain your login and analytics cookies to improve page performance. You can review your cookie preferences and withdraw non-essential consent at any time from your account's Privacy settings without disrupting your session.

Only with payment processors — DANA, OVO, GoPay and QRIS — and contracted fraud-detection partners, all bound by strict data-handling agreements. We do not share your data with advertisers, marketing networks or any unrelated third parties.

Financial transaction records, including GoPay and QRIS payment references, are kept for five years per applicable regulations. Session and activity logs unrelated to transactions are purged after 90 days of inactivity or upon a verified deletion request, where local law permits.