LEGAL REFERENCE

Your Data Stays Yours

We built castle toto around one principle: your account information, payment details and gaming activity belong to you. This policy shows exactly how we handle, protect and respect...

EncryptedIndonesia-CompliantQRIS SecureAccount-First
castle toto Your Data Stays Yours

What We Collect and Why

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

PLAYER SUPPORT

Privacy Questions? Reach Us

Email Support Send privacy concerns to our data team at [email protected]. We respond within 48 hours and can walk you through your data, deletion requests or account export.
Live Chat Open the chat widget in your account dashboard. Our team can answer policy questions, explain data use and help you manage your privacy settings in real time.
Account Settings Visit your profile to review what we hold, update your contact details, download your data or request permanent deletion. Changes take effect immediately.
REVIEW SIGNALS

How We Earn Your Trust

Third-Party Audit

Our encryption and data handling are audited annually by independent security firms. Reports confirm our systems meet international standards for...

Transparent Logging

Every access to your account is logged and visible to you. You can see login times, IP addresses and payment...

No Data Brokers

We do not share your gaming history, payment method or personal details with advertisers, data brokers or affiliate networks. Your...

Deletion on Request

Request full account deletion and we remove your data within 30 days, except where law requires us to retain records...

Encrypted Payments

DANA, OVO, GoPay and QRIS transactions are encrypted at every step. We never see your wallet PIN or full payment...

Regular Updates

We review this policy quarterly and notify you of material changes via email. You can always access the current version...

Consistency Across Our Brand

Same Policy Everywhere
Whether you access castle toto on mobile, desktop or tablet, your data protection rights remain identical. We do not change privacy rules by device or region.
Unified Account
Your single castle toto login works across all lobbies, live tables and sportsbook markets. One account means one privacy profile; we do not fragment your data.
Consistent Encryption
Every deposit via DANA, OVO, GoPay or QRIS uses the same encryption standard. We do not downgrade security for any payment method or account tier.
Shared Audit Trail
All your activity — logins, deposits, withdrawals, game sessions — appears in one audit log. You see the same record we keep; no hidden tracking.
One Support Standard
Privacy requests, data exports and deletion demands receive the same 48-hour response time regardless of your account age, deposit history or region.
Aligned Retention
We keep your data for the same duration across all lobbies and games. No silo stores different versions; your information lives in one secure vault.
Transparent Cookies
Our cookie policy is the same on every page. We use session cookies for lobby navigation and analytics cookies to improve your experience; you control both.
AT A GLANCE

What Defines Our Privacy Approach

01
Account Verification First We verify your identity before your first deposit to prevent fraud and comply with Indonesian financial regulations. This protects both your account and our platform.
02
Session-Based Tracking We track your lobby activity to show you personalized game recommendations and detect unusual account behaviour. You can disable analytics cookies in settings.
03
Payment Processor Handoff When you deposit via DANA, OVO, GoPay or QRIS, your payment details go directly to the processor. We receive only a confirmation; we never touch your wallet credentials.
04
Withdrawal Verification Before we send winnings back to your DANA, OVO, GoPay or QRIS account, we verify the withdrawal request matches your registered payment method for security.
05
Responsible Account Tools You can set Deposit references, session timers and Account closure periods directly in your account. These preferences are encrypted and enforced server-side.
06
Dispute Resolution Log If you dispute a transaction or raise a privacy concern, we log every step of the resolution. You can review the full history in your account dashboard.

Privacy Policy Questions

We retain your account data for seven years to comply with Indonesian financial regulations and fraud prevention. After that period, we delete everything except anonymized transaction summaries required by law. You can request earlier deletion; we'll remove personal identifiers within 30 days.

Yes. Go to Account Settings, select Privacy, and click Export Data. We'll email you a complete JSON file with your profile, transaction history, game activity and preferences within 24 hours. You can import this data to another platform if you choose.

Game providers receive only your session ID and game outcome data to deliver live tables and slots. They do not see your name, email, payment method or account balance. We sign strict data-processing agreements with every provider.

Your payment credentials never touch our servers. When you deposit, you're redirected to the payment processor's secure page. We receive only a transaction confirmation. All data in transit is encrypted with TLS 1.3.

If we merge with another company, your data privacy rights transfer with the deal. We'll notify you by email and give you 30 days to request deletion before any data moves. You always have the right to opt out.

Yes. In Account Settings under Privacy, toggle off Analytics Cookies and Personalization. We'll stop tracking your lobby behaviour and game preferences. You'll still see the full lobby; recommendations will just be random.

Email [email protected] immediately with details. We investigate within 24 hours and notify you of findings. If your account was compromised, we'll reset your password and review your transaction history for fraud.