Reference

How bonanja Handles Your Privacy in Indonesia

Your account data is yours — we collect only what we need to verify your identity, process wallet transactions via DANA, OVO, or GoPay, and keep your session secure.

Account DataWallet SecurityData RightsCookie PolicyKYC Process
bonanja How bonanja Handles Your Privacy in Indonesia
HOW WE PROTECT YOU

Security Practices Behind Your Account

We apply industry-standard security practices across every part of the account flow — from how you log in to how wallet data is stored. These are not marketing claims; they are operational steps we follow every time a transaction or session is initiated.

SSL Encryption All data sent between your device and our servers travels over SSL-encrypted connections. This covers your login credentials, KYC documents, and wallet transaction details equally.
KYC Verification Identity verification is completed once during account setup. We check your submitted ID against your registered name and wallet details before any withdrawal is processed.
Session Monitoring We track active session tokens so that if a login appears from an unrecognised device, your account can be flagged and reviewed before further actions are taken.
Data Retention Policy We keep your account data only as long as your account is active or as required by applicable law. Closed accounts are subject to a structured data deletion process on request.
bonanja Data We Collect and Why It Matters

Data We Collect and Why It Matters

When you open an account, we collect your name, email, and the e-wallet details you use — whether that is DANA, OVO, or GoPay. Transaction records are stored to process deposits and withdrawals accurately. Device data, including your browser type and IP address, helps us detect unusual login patterns and protect your session. We do not sell your data to third parties.

For identity verification, the KYC process asks you to submit a government-issued ID once; after that, your details stay on file only as long as your account remains active. Players in Palembang access the same data protections as anywhere else on the platform.

PRIVACY HELP PATHS

Get Help With Your Privacy Settings

If you have a question about how your data is stored or want to update your account details, our support team is ready through the channels below. Wallet-linked queries — like unlinking an OVO or GoPay account — can usually be resolved directly from your account settings page.

Live Chat Support Reach our support team through the live chat window in your account dashboard. Raise a data query, request a record download, or flag an unusual login from there.
Email Privacy Request Send a formal data request to our support email address listed in the account help section. We aim to respond to data access requests within the timeframe required by applicable rules.
Account Settings Panel Update your linked e-wallet, change your password, or review active sessions directly inside your account panel — no support ticket needed for most routine changes.

Key Privacy Terms for Indonesia Accounts

These are the terms that appear most often when you read through account privacy settings or data request forms. Knowing what each one means makes it easier to manage your account with confidence.

01
What is KYC?

KYC stands for Know Your Customer. It is the identity verification step where you submit a government-issued ID so we can confirm your name matches your registered account and wallet.

02
What does data processing mean?

Data processing covers any action taken with your information — collecting it, storing it, using it to verify transactions, or deleting it. It applies to everything from your login details to your GoPay transaction records.

03
What is a privacy policy?

A privacy policy is a published document that explains what personal data a platform collects, why it collects it, how it is stored, and what rights you have over that data.

04
What are cookies in this context?

Cookies are small data files stored on your device when you visit a site. They help keep you logged in, remember your wallet preference, and track session behaviour for security purposes.

05
What is a data access request?

A data access request is a formal ask to see what personal information we hold about you. You can submit one via our support email; we respond within the timeframe required by applicable rules.

06
What does consent mean for data?

Consent means you have actively agreed to your data being collected and used for specific purposes — such as processing your DANA deposit or verifying your account identity during KYC.

Privacy Questions Indonesia Account Holders Ask

These are the questions we hear most from account holders in Indonesia around data handling, wallet privacy, and account security. Each answer reflects how we actually operate — not a generic policy summary.

No. Your e-wallet details — whether DANA, OVO, or GoPay — are used only to process your transactions. We do not sell or share wallet data with advertisers or unrelated third parties.

Send a data access request through our support email address, which is listed in the account help section. We will compile your records and respond within the timeframe required by applicable rules.

Yes. If you close your account and submit a deletion request, we begin a structured removal process. Some data may be retained as required by applicable law, but active personal details are cleared.

Your password is hashed — we never store it in plain text. Sessions use token-based authentication, and an OTP may be required when logging in from a new device for the first time.

We do use cookies for session management and security monitoring. You can adjust non-essential cookie preferences from your browser settings, though disabling session cookies may affect your login experience.

Yes. Data handling practices apply where local law permits. Availability of certain account features and data rights depends on your eligible region and the applicable local legal framework.
Reference

Privacy Guide Indonesia

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.