Reference

Open istoto Privacy Policy Clearly

istoto Privacy Policy explains how we collect, use, store and protect the details connected with your account, device and wallet activity.

Account detailsWallet recordsCookie choicesPrivacy requests
istoto Open istoto Privacy Policy Clearly
REQUEST HELP SAFELY

Contact Us About Privacy Policy

A clear contact path helps when you want to ask about Privacy Policy rather than an unsettled wallet transaction.

Data access request Ask us which account details, device records and payment references we hold about you.
Correction request If your phone number, email address or account detail is outdated, tell us what…
Security concern If a login alert or wallet reference looks unfamiliar, contact support from the account…
DATA HANDLING

Explore How We Protect Privacy Policy

Privacy Policy works alongside the account controls you use every time you log in. We separate identity details from ordinary lobby activity where our systems allow, limit internal access to operational needs…

Account security

We use your phone verification and account sign-in records to help confirm access. If a new device behaves differently from your usual path, we may ask for an additional account check before discussing personal details.

Cookie controls

Essential cookies help maintain your signed-in session, while optional cookies may support page measurement or remembered preferences. Your browser controls can limit optional storage, though changing them may affect the account path.

Wallet matching

A DANA, OVO, GoPay, QRIS, bank transfer or virtual account reference can help us match a receipt to your account. We use the reference for payment checks and do not need your private wallet password.

Device records

When you open the lobby on a phone or desktop, we may record device and browser signals linked to login security. These records help us examine unusual access without treating your device as a permanent identity.

Storage period

We retain account, support and transaction records for operational, security, dispute and legal reasons. When a record is no longer needed for those purposes, we assess whether it can be removed or kept in a restricted form.

Policy changes

If Privacy Policy changes in a material way, we will place the updated wording where you can read it before continuing with relevant account activity. The page date and current text show which version applies to your request.

Browse Privacy Policy Answers

These Privacy Policy answers focus on the account questions you are most likely to ask before opening access. We explain what may be collected, why wallet references appear in records, how to request a copy or correction, and what happens when you use a phone or desktop browser. For a case involving your own account, use the support path shown after login and avoid sending passwords or wallet security codes.

It covers account details, phone verification, device and browser signals, cookies, support messages, security events and transaction references. It explains why we use each category, how we protect it, how long we may retain it and how you can ask about access, correction or deletion.

A DANA or QRIS reference can appear when we match a payment receipt with your account. The same may apply to OVO, GoPay, bank transfer or virtual account records. We use transaction references for reconciliation and do not request your private wallet PIN.

Use the support route in your account area and ask for a data access request. Include the email or phone detail connected to your account. We may complete an account verification step first, then explain which records can be provided under applicable local requirements.

Yes. Send a correction request through the account support path and identify the detail that is wrong, such as an email address or phone number. We compare the request with your account record before changing it, so another person cannot alter your profile.

On a phone browser, essential cookies can keep your session and account path working. Optional cookies may remember preferences or measure page use. You can adjust browser settings, but limiting essential storage may require you to sign in again or affect account functions.

We keep different records for different periods because account administration, security checks, payment matching, disputes and legal duties do not end at the same time. We review retention needs and remove or restrict records when there is no continuing operational or legal reason.

Yes. Access and eligibility depend on local law. We may use account, device and location-related signals where needed to apply access rules. If you need clarification about a personal request, contact us through the account support route rather than sending sensitive credentials.