htoto Privacy Policy
This page describes what we collect when you use htoto and how we keep that data protected. We recognize that account holders across Jakarta, Surabaya, Bandung, Medan, and Semarang trust us with personal information—email addresses, national ID numbers, payment details, and activity logs—and we take that responsibility seriously. Our privacy practices follow industry-standard encryption, restricted-access storage, and transparent disclosure.
We at htoto do not sell your data to third parties for marketing purposes. We do share information with payment processors (DANA, e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, online payment, e-wallet) to process deposits and withdrawals, and with compliance partners to meet anti-money-laundering and fraud-prevention obligations. Beyond those necessary functions, your information remains within our control.
This policy outlines what we collect, how we use it, your rights, and how to contact us if you have privacy concerns.
What Data We Collect on htoto
Account registration and Know Your Customer information
When you open an htoto account, we collect your email address, chosen password, and phone number. We use your phone number for one-time password (OTP) verification during login and account recovery. Next, we require Know Your Customer (KYC) verification—you submit a photograph of your national ID and a selfie photograph of yourself. We store these documents securely and use them to verify your identity, prevent duplicate accounts, and comply with anti-money-laundering law in our service jurisdictions.
Payment and transaction data on htoto
When you deposit or withdraw via DANA, e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, online payment, or e-wallet, we collect transaction records—the amount, date, time, and payment method. We store these records to reconcile your account balance, generate your transaction history, and support dispute resolution. We do not store your full payment credentials (e.g., full bank account numbers or card details)—our payment processors handle those securely on their own systems. We receive only confirmation tokens and transaction references from them.
Game activity and account behavior
We log every game round you engage with on htoto—sportsbook predictions, live-dealer table plays, slot spins, esports selections. We record the date, time, stakes, outcomes, and settlement amounts. We use these logs for settlement disputes (e.g., if you believe a Liga 1 sportsbook bet was calculated incorrectly or a blackjack round did not settle properly), fraud detection, and platform analytics. Your complete activity history is visible in your account dashboard under "Transaction History" or "Game History."
- Personal data
- Email, phone, name (from ID), date of birth, and address; collected during KYC verification.
- Payment data
- Transaction records from mobile banking, local payment, online payment, e-wallet, and bank partners; stored for reconciliation and audit.
- Activity logs
- Sportsbook predictions, live-dealer plays, slot activity, esports selections, and settlement records; retained indefinitely for disputes.
- Device and IP data
- Your IP address, device model, and browser type; used for fraud detection and login verification.
Device, IP, and login information
When you log into htoto, we record your IP address, device model (e.g., phone type), operating system, and browser type. We use this data to detect suspicious login attempts from unfamiliar locations or devices, trigger additional security checks if needed, and generate your "Login History" report. You can review all recent login activity in your account settings and sign out of other sessions remotely if you detect unauthorized access.
How We Use Your Data and Protect It
Data usage and third-party sharing on htoto
We at htoto use your data primarily to operate your account, settle game outcomes, and process deposits and withdrawals. We share information with payment processors to execute transactions—they receive your payment details and confirmation data to credit or debit your account. We share aggregated, non-identifying data with our sportsbook and live-dealer partners to optimize table availability and game offerings. We share transaction records with compliance partners to screen for money-laundering risk and report suspicious activity to relevant authorities where required by law.
We do not sell your personal data to advertisers, data brokers, or marketing firms. We do not use your data to create behavioral profiles for external sale. We may use your email address to send service notifications (e.g., "Your withdrawal has been processed") and, if you opt in, promotional announcements about new game releases or seasonal events. You can manage your email preferences in your account settings.
Data protection and encryption on htoto
We transmit all data between your device and our servers using TLS 1.3 encryption. Your password is hashed using industry-standard algorithms and is never stored in plaintext. Your national ID photograph and selfie are encrypted and stored in secure, access-controlled facilities. Your payment information is tokenized—our systems store only a reference token, not the full details. We conduct regular security audits and penetration tests to identify vulnerabilities. If a breach occurs despite our efforts, we notify affected users within timeframes required by applicable privacy law.
Data retention and deletion on htoto
We retain your account information (email, phone, verified identity) as long as your account is active and for a reasonable period after closure to support dispute resolution and audit compliance. We retain transaction and game activity logs indefinitely to support settlement disputes—for example, if you contact us months later claiming a Liga 1 sportsbook bet was settled incorrectly, we need access to historical records. You can request deletion of your account by contacting our support team; we will delete your profile data within thirty days but retain transaction records as required by law.
Your rights regarding htoto data
- Right to access: request a complete export of your personal data collected by htoto
- Right to rectification: correct inaccurate information in your htoto account (e.g., name, email)
- Right to deletion: request deletion of your htoto account and associated profile data (transaction logs retained per legal requirement)
- Right to object: opt out of promotional email communications from htoto
- Right to data portability: receive your data in standard format (CSV, JSON) from htoto
Cookies and tracking on htoto
We use cookies to store your login session, remember your language preference, and track your navigation within the htoto site. These are functional cookies necessary to operate the platform—they do not contain personal data. We do not use third-party tracking cookies or analytics providers that build behavioral profiles. You can disable cookies in your browser settings, though this may prevent htoto from functioning correctly.
Data location and jurisdiction
Our servers may sit outside your jurisdiction. When you use htoto from Jakarta, Semarang, or anywhere else, your data may be transmitted to and processed on infrastructure located in other countries. We maintain encryption and access controls regardless of location. By using htoto, you consent to this cross-border data transfer. If you have concerns about international data transfer, contact our support team to discuss alternatives.
Contact us about htoto privacy
If you have a question about this privacy policy or wish to exercise your rights (access, deletion, correction, objection), contact our htoto support team via email or in-app chat. Include a clear description of your request and your account email address. We aim to respond within ten business days. For urgent privacy concerns or complaints about our data handling, you may escalate to our designated privacy officer through the contact form in your account settings.
This privacy policy may be updated periodically to reflect changes in our practices or applicable law. We will notify you of material changes via email or in-app announcement. Your continued use of htoto following a policy update constitutes acceptance of the revised terms. Our services are available only where local law permits. Users are responsible for verifying that access and use comply with their own jurisdiction's privacy and data protection law.
↑