LEGAL REFERENCE

Your Data Stays Yours

We built xyz388 around your privacy. Every account detail, every transaction through DANA, OVO, GoPay or QRIS, and every lobby session is encrypted and protected by industry-standard security...

EncryptedQRIS ProtectedDANA SecureOVO VerifiedGoPay Safe
xyz388 Your Data Stays Yours

How We Collect and Use Your Information

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

24/7 SUPPORT

Privacy Questions? We're Here

Email Support Send privacy concerns to our data protection team at [email protected]. We respond within 24 hours and can explain any policy detail or help you request your data.
Live Chat Open the chat widget in your account dashboard to ask about how we handle your information. Our team can walk you through data access, deletion or correction requests in real time.
Account Settings Visit your privacy centre in account settings to download your data, update contact details or adjust communication preferences. Changes take effect immediately across all xyz388 services.
WHY VISITORS TRUST US

Privacy Standards We Meet

SSL Encryption

All data in transit between your device and our servers uses 256-bit SSL encryption. Your DANA, OVO, GoPay and QRIS...

Annual Audits

We commission independent security audits every year to verify our encryption, access controls and data handling practices. Audit reports are...

Data Minimisation

We collect only the information needed to verify your identity, process payments and deliver your lobby. We don't ask for...

Retention Policy

Account data is kept for seven years after closure to meet regulatory requirements. Payment records are retained for tax compliance...

Staff Training

Every xyz388 team member completes privacy and data protection training annually. Access to personal information is restricted to staff who...

Incident Response

If a security incident affects your data, we notify you within 48 hours with details of what happened, what we're...

SIDE BY SIDE

How Our Policy Compares

01

Data Sharing

We share your information only with payment processors (DANA, OVO, GoPay, QRIS), fraud prevention partners and regulators where required by law. No third-party marketing or data brokers.

02

Cookie Use

We use cookies to remember your login, track your lobby preferences and prevent fraud. You can disable non-essential cookies in your browser; essential ones keep your account secure.

03

Third-Party Links

Our site may link to payment provider pages or support resources. Those sites have their own privacy policies. We're not responsible for their data practices once you leave xyz388.

04

Children's Data

xyz388 is for adults only. We don't knowingly collect data from anyone under 18. If we discover a minor's account, we close it immediately and delete their information.

05

International Transfers

Your data may be processed on servers in supported regions outside Indonesia. We apply the same encryption and access controls regardless of server location to keep your information safe.

06

Your Rights

You can request access to your data, correct inaccuracies, download your information or ask us to delete it. Contact [email protected] with your request and we'll respond within 30 days.

07

Policy Updates

We update this policy when our practices change. We'll email you 30 days before any material change takes effect. Continued use of xyz388 after the update means you accept the new terms.

QUICK SIGNAL

What Protects Your Account

01
Two-Factor Authentication Enable 2FA in your account settings to add a second verification step when you log in. We send a code to your phone; only you can enter it. This stops unauthorised access even if your password leaks.
02
Payment Verification Every DANA, OVO, GoPay and QRIS transaction is verified through the payment provider's own security layer. We never store your full payment details; we store only a secure token tied to your account.
03
Withdrawal Confirmation When you request a withdrawal, we send a confirmation email and SMS to your registered phone. You must approve it within 15 minutes or the request expires. This prevents accidental or fraudulent withdrawals.
04
Login Alerts We email you every time your account is accessed from a new device or location. If you don't recognise the login, you can immediately change your password and contact our support team.
05
Fraud Detection Our system monitors your account for unusual activity like rapid deposits, multiple failed logins or withdrawals to new bank accounts. We flag suspicious patterns and may ask you to verify your identity.
06
Account Recovery If you lose access to your account, we verify your identity through email, phone and security questions before we reset your password. This protects your account from takeover attempts.

Privacy Questions Answered

We retain your account data for seven years to comply with tax and anti-money-laundering regulations. After seven years, we delete all personal information except what we're legally required to archive. You can request deletion of non-essential data anytime by emailing [email protected].

Yes. Go to your account settings, select Privacy Centre and click Download My Data. We'll compile your profile, transaction history, login records and communication preferences into a file and email it to you within 7 days. You can also request this via [email protected].

No. We never sell your personal information to third parties. We share data only with payment processors (DANA, OVO, GoPay, QRIS), fraud prevention partners and regulators where required by law. Your data stays within xyz388 unless you explicitly consent to share it.

We don't store your full payment details. When you link a payment method, we receive a secure token from the provider. All transactions are encrypted end-to-end. Your bank details remain with DANA, OVO, GoPay or QRIS; we only see confirmation that the payment succeeded.

We notify you within 48 hours if a security incident affects your data. We'll explain what happened, what information was exposed and what steps you should take. We also notify regulators and work with cybersecurity experts to patch the vulnerability and prevent future breaches.

Yes. Every marketing email includes an unsubscribe link at the bottom. Click it and you'll be removed from our mailing list immediately. You can also manage email preferences in your account settings under Communication Preferences.

Contact our support team at [email protected] and request account deletion. We'll close your account, delete your personal information and confirm completion within 30 days. Some data may be retained for legal or regulatory reasons, which we'll explain in our response.