kopitoto Privacy Policy
This page describes what we collect when you use kopitoto and how we keep that data protected. We at kopitoto are committed to transparency about your personal information, how third parties may access it, and the rights you hold over your own data.
Our services are available only where local law permits. When you create an account on kopitoto, you provide us with personal details—your name, email address, phone number, and identity documents for verification. We explain below why we collect each type of data, who may see it, and how long we keep it.
If you have questions about our privacy practices, you can reach our support team through your kopitoto account settings or by contacting us via the contact details at the end of this page.
What we collect and why
We collect your email address and phone number during account registration. Your email is used to verify your account, send withdrawal confirmations, and notify you of important updates to our platform. Your phone number allows us to send push notifications about live football events, such as Liga 1 matches or Piala AFF tournaments, and to contact you during the KYC verification process.
We collect government-issued identification documents—national ID, driver's license, or passport—to verify your identity and age. This is a regulatory requirement in all jurisdictions where we operate. We also collect your banking information when you deposit or withdraw funds via DANA, e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, online payment, or e-wallet. This data is used only to process your transactions and is never shared with third parties outside our payment processors.
We record your login history, account activity, and game session data to monitor for fraud and to comply with anti-money-laundering regulations. Your IP address, device type, and browser information are logged each time you access kopitoto. This helps us identify unusual activity and protect your account from unauthorized access.
Data we hold
- Account credentials: email, password hash, phone number
- Identity documents: scans of ID, issued and expiry dates, verification status
- Banking details: e-wallet IDs, bank account numbers (encrypted)
- Session logs: IP address, login times, device fingerprint, game history
- Communication records: support messages, withdrawal requests, verification emails
We use cookies to remember your login session and to track which games you view most often. Our cookies do not store your password or payment information. You can disable cookies in your browser settings, though this may affect your experience on kopitoto.
How we protect your data
We store your personal data on secure servers protected by industry-standard encryption (TLS 1.2 and above). Your password is hashed using bcrypt, which means we cannot read it ourselves. Your banking details and identity documents are encrypted at rest and in transit.
Our servers may sit outside your jurisdiction. Some of our infrastructure partners operate data centres in Singapore, Malaysia, and Australia. All data transfers between kopitoto and these partners comply with data protection standards equivalent to or stronger than those in Indonesia.
We perform regular security audits and penetration testing. Our staff who access customer data—such as support agents reviewing your withdrawal request—sign confidentiality agreements. If you suspect unauthorized access to your kopitoto account, you can reset your password immediately in your account settings or contact support.
Third-party processors
We share your banking details only with our payment processor partners. When you deposit via mobile banking, local payment, online payment, e-wallet, mobile banking, or local payment, your transaction data flows through the e-wallet provider's system. Similarly, if you use a online payment, e-wallet, mobile banking, or local payment virtual account, your bank receives deposit notifications. We do not control how these partners handle your data after the transaction is confirmed.
We may share your account information with regulators or law-enforcement agencies if required by court order or local law. We will not disclose your data to marketing partners, advertisers, or data brokers.
Our customer-support team may view your email, phone number, and withdrawal history to resolve disputes or investigate account issues. Support agents operate under strict access controls and cannot view your password or stored banking details.
Your rights and data deletion
You have the right to request a copy of all personal data we hold about you. You can submit a data-access request via your kopitoto account or by emailing our support team. We will provide a downloadable file within 30 days.
You have the right to correct inaccurate information. If your registered name or phone number is wrong, you can update it in your account settings. If you need to correct your identity document details, contact our support team to begin a re-verification process.
You may request account deletion. When you delete your kopitoto account, we retain transaction records for seven years to comply with anti-money-laundering requirements. Your identity documents, banking details, and email address are deleted within 90 days, except where local law requires us to retain them longer.
You have the right to opt out of push notifications at any time. Notification preferences are managed in your kopitoto account settings. You can also unsubscribe from support emails by clicking the "unsubscribe" link in any email we send.
Contact kopitoto
If you have questions about our privacy practices, want to request your data, or believe we have mishandled your information, you can contact our support team through your kopitoto account. Our team is available to respond to privacy requests during business hours, Monday through Friday.
This privacy policy was last updated on 30 May 2026. We may revise it to reflect changes in our practices or updates to local law. Any material change will be announced via email to all active kopitoto users. Your continued use of kopitoto following a policy change constitutes acceptance of the updated terms.