Reference

Legal Framework That Governs Your Account

spbutoto login operates under a defined legal framework that sets out your rights, our obligations, and the terms under which your account and personal data are managed —…

Account TermsPrivacy & Data PolicyQRIS & DANA Transaction RulesJurisdiction NoticeCookie Policy
spbutoto login Legal Framework That Governs Your Account
KONTAK LEGAL KAMI

How to Reach Us on Legal Matters

Legal queries — including data-access requests, account-closure procedures and policy clarification — are handled by a dedicated compliance desk. We aim to respond to written legal inquiries within 2 business days. You can reach our team through the three channels below, each staffed according to the hours shown.

Team online

Live Chat (Legal Desk)

Available 07:00–23:00 WIB daily. Start a chat from the account portal and select 'Legal & Policy' from the dropdown — a compliance agent picks up within 5 minutes during stated hours.

Email Support

Send your written request to our legal inbox directly from the Help section in your account. We log the timestamp and send a reference number within 1 hour of receipt on business days.

Account Portal Form

The in-app 'Policy Request' form lets you submit data-access or data-deletion requests. Submissions are tracked in your account under 'My Requests' so you can monitor status without following up separately.

KEAMANAN & DATA AKUN

How We Handle Data, Cookies and Account Security

We apply specific technical and procedural controls across every layer of your account — from the moment you open it to the point you request deletion.

Data Encryption at Rest

All account-level personal data — name, contact detail, transaction reference — is encrypted using AES-256 at rest. Decryption keys are held separately from the data stores and rotated on a quarterly schedule.

Cookie Consent Controls

When you first load spbutoto login, a consent banner lets you accept, reject or customise which cookie categories are active. You can revisit this choice any time via the Privacy Settings link in the site footer.

Account Security — Two-Step Verification

We offer two-step verification via your registered mobile number. Enabling it means any new device login, including desktop browser changes, triggers an OTP confirmation before the session opens.

Data Retention Schedule

Active account data is retained for the duration of your account. Following a confirmed closure request, non-financial records are deleted within 30 days; transaction logs required for audit compliance are retained for the legally mandated period.

Right to Access and Correction

You may request a copy of the personal data we hold on your account at any time. Correction requests for inaccurate data are processed within 5 business days of verification through the Account Portal Form.

Third-Party Data Sharing Limits

We do not sell your personal data. Data is shared only with licensed payment processors — DANA, OVO, GoPay, QRIS — and only the minimum fields required to complete your transaction are passed to each processor.

Legal Questions We Get Asked Most

The questions below reflect what Indonesian account holders actually contact our legal desk about. Each answer reflects our current operational policy — not a generic placeholder. If your question is not covered here, use the Account Portal Form to submit it and we will respond within 2 business days.

Access to spbutoto login depends on local law. We recommend you confirm that using our platform is permitted in your specific region before opening or continuing to use your account. Our terms page reflects this obligation clearly.

We collect your name, email address, mobile number and account credentials at registration. If you use DANA, OVO, GoPay or QRIS for a transaction, the processor passes back a reference ID — we store that reference, not your payment credentials.

Submit a deletion request via the 'Policy Request' form in the Account Portal. After identity verification, non-financial personal records are deleted within 30 days. Transaction logs tied to audit obligations are retained for the legally required period only.

Our terms specify that where a provision conflicts with applicable Indonesian regulation, local law takes precedence. Disputes that cannot be resolved through our compliance desk are referred to the appropriate Indonesian legal channel.

Yes. Submit an access request through the Account Portal Form or via the legal email inbox. We will compile and send a structured summary of your account-level personal data within 5 business days of completing identity verification.

We use essential cookies to keep your session active, and optional analytics cookies to improve site performance. You can reject optional cookies via the consent banner on first visit or through Privacy Settings in the footer at any time.

DANA, OVO, GoPay and QRIS transaction references linked to your account are retained for the period mandated by Indonesian financial-record rules. Personal contact details not tied to financial records are deleted within 30 days of confirmed account closure.