How We Handle Your Account Data
This is the topslot888 privacy policy — the page that tells you what we collect when you open an account, why we keep it, and how long it...
Policy Posture & Jurisdiction Notes
We collect what we need to run your account: the email or phone you register with, the device you sign in from, the wallet handle you use to top up, and the games you open in our lobby. We process this where local law permits and only inside supported regions. Marketing messages are off by default — you switch them on yourself
from the account panel. We do not sell your data to third parties; we share it only with payment partners that route DANA, OVO, GoPay and QRIS transfers, and only for the transaction in front of them. Retention follows Indonesian record-keeping windows; once the window closes, we purge or anonymise your record.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
Privacy Contact Paths
If something in this policy isn't clear, or you want to see the data tied to your account, reach us through any of the channels below. Our privacy desk answers separately from...
How This Policy Is Reviewed
This policy isn't a static page. We review it on a fixed cadence and whenever Indonesian data rules shift, so the wording matches what actually happens on our servers.
Quarterly Review
Our legal and product leads sit down every quarter to walk through the policy line by line, checking that each clause still describes how the topslot888 lobby and sportsbook actually move your data.
Indonesian Counsel
We retain local counsel familiar with Indonesia's personal data protection framework. They sign off wording before any clause about retention, consent or cross-border transfer goes live on this page.
Named Data Owner
A single data protection lead owns this document. Their initials sit on the change log, and escalations from the privacy inbox land on their desk inside one working day.
Change Log Public
Every edit to the policy gets a dated entry at the bottom of this page. You can see what changed, when it changed, and which section was touched without asking us.
Vendor Audits
Payment partners handling DANA, OVO, GoPay and QRIS references are audited yearly. We confirm they only hold the transaction data we send and purge on the agreed window.
Staff Access Logs
Internal access to your account record is logged and reviewed. Support agents see only the fields they need; full data exports require sign-off from the named privacy lead.
Consistency Across Our Policy Pages
We keep this policy aligned with our other legal pages so you don't get conflicting answers depending on where you read.
| Terms of Service | Account rules referenced here use the same definitions as our Terms page — the word 'account', 'session' and 'wallet handle' mean exactly the same thing in both documents. |
|---|---|
| Cookie Notice | Tracker categories listed in our cookie notice mirror the lobby-activity section here. If a cookie isn't named there, it isn't dropping data into your account record either. |
| KYC Statement | Identity-check fields described in the KYC page match the verification clause in this policy, including which documents we keep and which we view-and-discard at the counter. |
| Payments Page | Wallet-handle storage explained on the payments page lines up with the partner-sharing clause here, covering DANA, OVO, GoPay and QRIS routing references the same way. |
| Account Closure | The deletion timeline written in account-closure help matches the retention window in this policy — same days, same fields purged, same anonymised residue kept for audit. |
| Marketing Preferences | Opt-in defaults shown on the preferences screen match the consent clause here. Nothing in this policy lets us message you on a channel you haven't switched on yourself. |
| Complaint Path | Escalation steps written in our complaints page apply to privacy issues too, with the privacy desk slotting in as the first specialist tier before any external route. |
What Shapes This Policy Page
A few editorial choices define how this document reads — short clauses, named owners, and a layout that lets you jump straight to the part you...
Plain-English Clauses
Every clause is written in the same Southeast-Asian English we use across the lobby. No dense legalese, no Latin, no clauses-within-clauses — if a sentence needs a second read, we rewrite it before publishing.
Section Anchors
Each topic on this page has its own anchor link, so you can share a direct line to the retention clause or the consent paragraph without making someone scroll the whole document first.
Dated Edits
The footer of this page carries a 'last reviewed' stamp and a short note describing the latest change. You always know whether you're reading the current version or a cached copy.
Indonesia Scope
Wording is scoped to Indonesia and supported regions. We don't pad the page with clauses for markets we don't serve, which keeps the document short and the obligations clear.
Named Owner
A real person owns this policy, not a generic legal@ alias. Their role and contact route sit at the top of the support section so escalations don't bounce around the inbox.
Mobile Layout
The page renders cleanly on a phone — collapsible sections, readable type and tappable anchors — because most of you open it from the same device you signed in with.