Reference

How koihoki Handles Your Personal Data

At koihoki, your personal data belongs to you — we collect only what we need to run your account, process deposits via DANA, OVO, GoPay and QRIS, and…

Data collected only as neededDANA, OVO, GoPay & QRIS transaction data encryptedYou may request full data deletionPolicy updated when regulations changeContact us any time via live chat
koihoki How koihoki Handles Your Personal Data
PRIVACY CONTACT PATHS

How to Reach Our Privacy Team

If you have a question about your data, want to correct stored information, or would like to exercise your right to deletion, our privacy support team is reachable seven days a week.

Live Chat Open the chat widget on any koihoki page — available 07:00–23:00 WIB daily. Type 'privacy request' and an agent routes you to our data team within minutes, no queuing required.
Email Privacy Team Send your request to our dedicated privacy address shown in the footer. Include your registered email so we can verify your identity before making any changes to stored account data.
Account Settings Panel Log in, go to Settings → Privacy, and submit a data-access or deletion request directly. The panel shows the categories of data we hold and lets you flag items for review without contacting support.
HOW WE PROTECT YOU

Six Ways We Keep Your Account Data Safe

Security at koihoki is layered — encryption, access controls, audit logs and a clear retention policy work together so your personal details never sit exposed.

End-to-End Encryption

Every data packet — including your DANA or OVO transaction reference — travels over TLS 1.3. Data at rest on our servers uses AES-256 encryption, so intercepted files are unreadable without our private keys.

Cookie Transparency

We use session cookies to keep you logged in and analytics cookies to spot broken pages. You can review and withdraw consent for non-essential cookies via the cookie banner that appears on your first visit to koihoki.

Account Access Logs

Every login attempt — successful or not — is time-stamped and stored for 90 days. You can request your own access log from Settings → Privacy to spot any sessions you do not recognise, then change your password immediately.

Minimal Data Retention

We keep your payment data — including GoPay and QRIS references — only for the period required by applicable financial regulations. After that window closes, records are anonymised so they can no longer be linked back to your identity.

Third-Party Data Sharing Policy

We share data with payment processors such as DANA and OVO solely to complete your transactions. No behavioural profile, browsing history or account balance detail is passed to any advertiser or data broker, under any arrangement.

Right to Erasure Requests

Submit a deletion request through Settings → Privacy or via email. We verify your identity within 24 hours and confirm deletion of non-legally-required data within seven business days, sending written confirmation to your registered email address.

Your Privacy Questions, Clearly Answered

The questions below reflect what our account holders in Indonesia ask most often about data privacy. If your question is not listed here, reach out via live chat between 07:00 and 23:00 WIB and our privacy team will respond with a direct, specific answer — not a scripted redirect.

We collect your name, email, mobile number and the payment identifier for your chosen method — DANA, OVO, GoPay or QRIS. We also log your device type and IP address for security purposes only, not for marketing profiling.

Your payment identifiers are shared only with the relevant payment processor — DANA or OVO — to complete your transaction. No external advertiser, data broker or unrelated third party receives your payment reference under any arrangement we have in place.

Retention periods depend on local law and applicable financial regulations. Once the legally required window closes, your personal records are anonymised or deleted on a rolling schedule. You can ask our privacy team for the specific period that applies to your account.

Yes. Log in and go to Settings → Privacy to request a data summary. Alternatively, email our privacy team with your registered address and we will send a structured report within 48 business hours detailing every category of data linked to your account.

Submit a deletion request in Settings → Privacy or email our privacy address shown in the footer. We verify your identity within 24 hours and complete deletion of non-legally-required data within seven business days, confirming the outcome by email.

We use essential session cookies to keep you logged in and optional analytics cookies to improve page performance. You can accept or withdraw consent for non-essential cookies at any time through the cookie preference panel on the koihoki site.

We notify you by email and display an in-app banner whenever this policy changes in a way that affects your rights. The updated policy takes effect 14 days after notification, giving you time to review it and contact our team with any concerns.