Reference

How tto12 Handles Your Personal Information

This Privacy Policy explains exactly what data we collect when you open an account, make a deposit via DANA, OVO or GoPay, and use our platform — and how we keep that data secure.

Account data protectionDANA, OVO, GoPay wallet privacyYour right to access your dataClear data retention termsSecure account communication
tto12 How tto12 Handles Your Personal Information
REACH OUR PRIVACY TEAM

How to Contact Us About Your Data

If you have a question about this policy, want to request a copy of the data we hold, or need to update information on your account, our support team handles privacy requests directly. Reach us through live chat on the platform, email us at the address shown in your account settings, or use the in-app help form. We aim to respond to all data-related requests within a reasonable period as required under applicable law.

Team online

Live Chat

Start a chat directly from your account dashboard. Our team can handle data access requests, account queries and wallet-related privacy questions.

Email Support

Send a written data request or privacy concern to the address listed in your account settings. Keep your registered email address in the subject line for faster routing.

In-App Help Form

Use the help form inside the tto12 platform to submit a formal data correction or deletion request. Our compliance team reviews these separately from general support tickets.

DATA HANDLING IN PRACTICE

How We Protect and Manage Your Data

Knowing your data is handled carefully matters. Here is a plain account of the four areas we focus on — cookies, account security, data retention, and your right to make changes — so you know what to expect at each step.

Cookies and Session Data

We use cookies to maintain your login session and remember display preferences. You can clear cookies through your browser settings at any time, though this will log you out of your current session.

Account Security Measures

Account access uses OTP verification sent to your registered mobile number. Login attempts from unrecognised devices trigger an additional verification step before access is granted.

Retention and Deletion

We keep account and transaction data for as long as your account is active and for the period required by applicable law. Once that period ends, data is deleted or anonymised from our records.

Requesting Changes to Your Data

You can request a correction or deletion of your personal data by contacting us through live chat or email. Wallet-linked data such as GoPay or OVO references follows the same request process.

Common Questions About This Privacy Policy

These are the questions we hear most often from account holders about how their data is handled on tto12. If your question is not covered here, reach out via live chat.

We collect your name, email, mobile number and any wallet details you add — such as DANA, OVO or GoPay. Device and IP data is also recorded for security purposes during each login session.

We share data only with payment processors like DANA, OVO and GoPay to complete transactions, and with authorities where local law requires it. We do not sell your data to marketers or unrelated third parties.

Your data is kept while your account is active and for the legally required period after closure. Once that period passes, data is deleted or anonymised in line with our retention schedule.

Yes. Submit a data access request via live chat or email using your registered address. Our compliance team will respond within the timeframe required under applicable law in your region.

Log into your account and use the profile settings to change contact details. For more sensitive changes, such as linked wallet corrections, contact support through live chat or the in-app help form.

We store transaction references and wallet identifiers in encrypted format. We never store your e-wallet PIN or password. Payment data is accessible only to authorised staff handling account verification.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.