Reference

How We Handle Your Privacy at koitoro

We wrote this policy so you know exactly what happens with your information when you use your account, make a deposit through DANA, OVO or GoPay, or reach out to our support channels.

Account Data ProtectionE-Wallet Transaction PrivacyYour Rights ExplainedLive casino and slots
koitoro How We Handle Your Privacy at koitoro
DATA HANDLING DETAIL

How We Protect and Manage Your Information

Privacy is not a single checkbox — it touches every part of how your account works. Below is a clear view of what we do across the main areas where your data is involved, from cookies through to how long we keep records and what happens if you want out.

Account Security

Your login is protected by OTP verification sent to your registered mobile number. Session tokens expire after inactivity, and if we detect access from an unfamiliar device we trigger re-verification before anything in your account can be changed or funds…

Cookie Usage

We use cookies to remember your session, language preference and last-used payment method. No advertising cookies from third-party networks run on our pages.

Transaction Records

Every deposit and withdrawal through DANA, OVO or GoPay generates a transaction record tied to your account. These records include amount, timestamp and payment channel. We retain them as long as required by applicable regulation in your region.

Data Retention

Non-essential data like session logs and device fingerprints are purged on a rolling schedule. Core account data remains active while your account is open.

Third-Party Sharing

We share data only where necessary to process your payment — meaning your chosen e-wallet provider receives the transaction details they need. We do not sell, rent or trade your personal information to advertisers, data brokers or unrelated platforms.

Requesting Changes

You have the right to ask for a copy of the data we hold on you, request corrections to inaccurate information, or ask us to delete non-essential records.

PRIVACY CONTACT PATHS

How to Reach Us About Your Data

Have a question about what we store or want something changed? Here is how you get to the right person. Our support team handles privacy-related requests with priority, so you are not waiting in a general queue when your concern is about personal data.

Live Chat Open the chat widget from any page on mobile or desktop. Tell the agent your request is privacy-related and they will route you to the data team.
Email Request Send your privacy request to our support email with the subject line containing your account ID and the word 'privacy'.
Account Settings Inside your account dashboard you can review and update personal details directly — name, contact number, linked e-wallet. For changes that affect verification status, the system will prompt you through a short re-confirmation step via OTP to your registered number.

Common Questions About Your Data and Privacy

We get asked these regularly — straightforward answers about what we keep, who sees it, and what you can do about it. If your specific question is not here, reach out through live chat and the team will clarify.

We collect your name, mobile number, email address and the e-wallet details you link for deposits and withdrawals. Device type and IP address are logged at registration for security. We do not ask for information beyond what is needed to verify your identity and process payments.

Only the transaction details required to process your deposit or withdrawal are sent to the e-wallet provider you select. They receive the amount, reference ID and your linked wallet identifier. No browsing history, game activity or communication logs are shared with payment providers.

Transaction records are retained for the duration required by applicable regulation in your region. While your account is active, you can view your full history in the account dashboard. After account closure, we keep only what regulation requires and remove the rest.

Yes. Contact support via live chat or email with your account ID and request deletion. We will remove all non-essential data and confirm what has been deleted. Certain records required by local regulation may be retained even after deletion, but we will tell you exactly which ones.

We use session cookies to keep you logged in and preference cookies to remember your language and last payment method. No third-party advertising cookies are placed. You can block or clear cookies in your browser settings — you will just need to log in again on your next visit.

Deposits processed through DANA, OVO or GoPay use those providers' encrypted channels. On our side, we do not store full wallet credentials — only a tokenised reference that links your account to the payment. This means even if session data were compromised, your wallet details remain with the provider.

If we identify unauthorized access to personal data that could affect you, we will notify you through your registered email and via an in-account alert. The notification will include what was accessed, what steps we are taking, and what you should do on your end such as changing your password.

We may use aggregated, non-identifying activity patterns to improve platform features, but we do not build individual advertising profiles or sell behavioural data. If we send promotional communications, you can opt out at any time from the notification settings inside your account.

Log into your account, go to settings, and update your mobile number, email or linked DANA, OVO or GoPay wallet. Changes to verified details will trigger an OTP confirmation to your current registered number before the update goes through, so no one else can alter your information.

Service availability and specific data handling obligations depend on local law in eligible regions. Where local regulation imposes stricter requirements on retention or disclosure, we follow those. The core principles — minimal collection, no selling data, your right to access and delete — apply everywhere we operate.