Home
Introduces our lobby, payment rails and game count. Privacy policy link is in the footer.
We built toto22 around your privacy. Every account detail, payment transaction and gaming session stays encrypted and protected. This policy explains exactly how we handle your information across...
When you open your toto22 account, we collect your name, email, phone number and identity details to verify your age and location. Payment information — your DANA, OVO, GoPay or QRIS identifier — is tokenized and never stored in plain text on our servers. We log your gaming activity (bets placed, tables visited, session timestamps) to detect fraud and honour your account
balance. Where local law permits, we may share anonymized gameplay data with our game providers (Pragmatic, Evolution, PG Soft) to improve lobby performance. You can request a full data export or deletion by contacting our support team.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
Every login, payment and bet is encrypted end-to-end. Your session token expires after 30 minutes of inactivity to prevent unauthorized access.
Our data handling practices are reviewed annually by independent security firms. Audit reports are available on request to account holders.
We never sell your personal information to advertisers or brokers. Payment details stay between you, toto22 and your bank or e-wallet provider.
Although toto22 operates in Indonesia, we follow GDPR principles for data minimization, retention limits and user rights across all regions.
We monitor account activity for suspicious logins, unusual bet patterns and payment anomalies. You'll be notified immediately if we flag a concern.
Account data is kept for 7 years after closure to comply with Indonesian financial regulations. Gaming logs are archived after 2 years.
Introduces our lobby, payment rails and game count. Privacy policy link is in the footer.
Covers account rules, betting limits and dispute resolution. References this privacy policy for data handling specifics.
Outlines account controls like session limits and self-pause features. Does not duplicate privacy details.
Details DANA, OVO, GoPay and QRIS integration. Directs users here for encryption and tokenization info.
Answers common account and lobby questions. Links to this policy for data access and deletion queries.
Lists support channels and response times. Privacy team email is listed separately for urgent data requests.
Explains session cookies, analytics tracking and ad pixels. Complements this policy with technical cookie details.
We log every login, bet and withdrawal so you can audit your account history. No hidden activity. No surprise charges.
Your DANA, OVO, GoPay and QRIS details are converted to secure tokens. We never see your full account number or PIN.
Enable 2FA in Settings to add a second verification step at login. SMS or authenticator app — your choice.
Request your full account data in JSON or CSV format. Download it, share it with advisors or migrate it elsewhere.
Close your account and request permanent data deletion. We remove your profile within 30 days, except where law requires retention.
If we detect unauthorized access to your account, we notify you within 24 hours with steps to secure your profile.