Reference

How istana138 Handles Your Personal Data

When you open an account with istana138, you share personal information with us — your name, contact details, and the e-wallet connections you use for DANA, OVO, or GoPay transactions.

Account data kept secureDANA, OVO, GoPay wallet data protectedNo third-party data sellingAccess and deletion requests acceptedIndonesia-region data handling
istana138 How istana138 Handles Your Personal Data
PRIVACY CONTACT PATHS

Reach Us About Your Data

If you have a question about how your personal data is handled, want to request a copy of what we hold, or need to correct information on your account, our support team is the right place to start. You can reach us through live chat directly inside the lobby, by email at the address listed in your account settings, or through the in-app help menu on mobile. For data deletion requests, our team will verify your identity before processing — this step protects your account from unauthorised removal requests.

Live Chat Open the live chat panel inside your account dashboard. Available during active lobby hours. For privacy questions, select the 'Account & Data' topic so your message reaches the right team member without delay.
Email Support Send your data request or privacy concern to the support email listed in your account settings page. Include your registered phone number or username so we can verify your identity before responding to any data-related action.
In-App Help Menu On mobile, tap the help icon in the top menu to access the support form. You can submit data access or correction requests directly from here. This path works on both Android and iOS without needing to open a separate browser.
HOW WE PROTECT YOUR DATA

Data Handling, Cookies, and Account Security

We apply a layered approach to protecting your account information — from the moment you register to every transaction you complete. SSL encryption covers all data transmitted between your device and our servers, so your DANA, OVO, and GoPay transaction details are not readable in transit. Within our systems, access to personal records is role-limited, meaning only the teams handling payment verification, account support, and fraud review can retrieve your data. We retain your account information for as long as your account remains active; if you close your account, we hold records only as long as required to complete any pending transactions or satisfy applicable legal requirements in eligible regions.

SSL Data Encryption Every connection between your browser or mobile app and our servers uses SSL encryption. This means data you enter — including login credentials and the wallet details you use when transacting via DANA, OVO, or GoPay — is protected from interception during transmission.
Role-Limited Data Access Your personal records are not visible to every staff member. Access is restricted to specific teams — payment verification, account support, and fraud review — each of which needs your data only to carry out their assigned function. No one outside those roles can retrieve your stored information.
Cookie Controls We use functional and session cookies to keep you logged in and remember your lobby preferences. We do not set advertising or cross-site tracking cookies. You can review and clear these at any time through your browser settings or the privacy panel inside your account.
Account Security Alerts If a login attempt comes from an unrecognised device or location, our system flags it and can trigger an OTP verification step. This is separate from your regular password — it is an automatic layer that activates when something about the login looks unusual.
Data Retention Policy We keep your account data only as long as your account is open. After account closure, records are held only for the minimum period needed to finalise pending payments or meet applicable requirements for eligible regions. You can request details about retention periods via support.
Data Access and Correction Rights You can request a copy of the personal data we hold on your account, ask us to correct any inaccurate details, or request deletion where no pending obligation prevents it. Submit these requests through live chat or the support email in your account settings — identity verification is required before we act.

Common Questions About Your Data and Privacy

These are the questions we hear most often from account holders in Indonesia about how their personal data is handled, what rights they have, and how to take action when something needs to change. If your question is not covered here, the support team can address it directly through live chat or email.

We collect your name, email address, phone number, and the username and password you create. If you link a payment method, we record the transaction reference from your DANA, OVO, or GoPay transfer — not the wallet credentials themselves, which stay inside your e-wallet app.

We do not sell or rent your personal data to marketing companies. We share data only with payment processors (such as the networks that handle DANA, OVO, and GoPay transfers) and fraud-prevention systems, and only the information those services need to complete their specific function.

We record the transaction reference number, the amount, and the timestamp of each deposit or withdrawal. This log is used to verify your account balance and resolve any payment queries. We do not store your e-wallet PIN or login credentials — those remain entirely within your DANA, OVO, or GoPay app.

Yes. Send a data access request through live chat or the support email listed in your account settings. We will verify your identity first, then provide a summary of the personal information we hold. We aim to respond within a reasonable timeframe after identity is confirmed.

Some details — like your phone number or email address — can be updated directly in your account settings. For information you cannot edit yourself, submit a correction request through support with the correct details. We will review and update the record after verifying your identity.

After your account is closed, we hold your records only for the minimum period required to settle any pending transactions and meet applicable legal requirements for eligible regions. Once that period passes and no obligation remains, your data is removed from active systems.

We use session cookies to keep you logged in and functional cookies to remember your lobby preferences. We do not use cookies to build advertising profiles or track you across unrelated sites. You can clear or block cookies at any time through your browser settings or the privacy panel in your account.

We use SSL encryption on all connections, restrict internal data access to relevant teams only, and apply automatic OTP verification when a login attempt comes from an unrecognised device. On mobile, the session also expires after a period of inactivity to reduce exposure if you leave the app open.

You can submit a deletion request through live chat or support email. We will process it after identity verification and once any pending transactions are finalised. If a legal retention requirement applies in your eligible region, we will explain what data we must keep and for how long.

Reach us through live chat inside your account dashboard — select 'Account & Data' when prompted — or email the address in your account settings. For sensitive requests like deletion or data access, email is recommended so you have a written record of the request and our response.