Reference

How hana189 Handles Your Privacy

We built this policy around practical transparency — what we collect, why we collect it, and how you stay in control. Every data point tied to your DANA, OVO or GoPay transactions is governed by the commitments on this page.

Data TransparencyPayment PrivacyAccount ControlContact Options
hana189 How hana189 Handles Your Privacy
DATA HANDLING SPECIFICS

Six Ways We Keep Your Information Safe

Privacy is not a single checkbox — it runs through every layer of how we operate your account, from the moment you tap 'open account' on your phone in Jakarta to the day you decide to close it. Here is what that looks like in practice across six areas.

Encrypted Storage

All personal data sits behind SSL encryption both in transit and at rest. Your DANA or OVO payment references are tokenised — we never store your full e-wallet credentials on our servers, only the reference needed to match a deposit…

Cookie Policy

We use session cookies to keep you logged in across page loads and preference cookies to remember your chosen language and last-visited lobby section. No advertising cookies from third-party networks are placed without your explicit consent in the cookie banner.

Account Security Layers

Your account is protected by a password you set plus an OTP sent to the phone number on file whenever you request a withdrawal or change sensitive details.

Data Retention Period

We keep active account data for as long as you use the platform. After you close your account, we retain records only for the minimum period that applicable local regulation requires, then we permanently purge them from our systems and…

Third-Party Sharing

We share data only with payment processors (DANA, OVO, GoPay) to complete your transactions, and with fraud-prevention services to protect your wallet. We never sell, rent or trade your information to marketing companies or data brokers under any circumstance.

Your Right to Access and Delete

You can request a full export of the data we hold about you at any time through live chat or email.

PRIVACY CONTACT PATHS

How to Reach Us About Your Data

Have a question about what we store, or want something changed? These are the direct channels for any privacy-related request. We aim to acknowledge your message promptly and resolve data queries as quickly as verification allows.

Live Chat Open the chat widget from any page on mobile or desktop. Tell the agent your request is privacy-related and they will route it to the data team.
Email Send your data request to the email address listed in your account settings under the privacy section. Include your registered username so we can locate your records without asking for extra verification steps over multiple messages.
Account Settings Panel Inside your account dashboard you can view stored payment methods, toggle marketing communications on or off, and submit a formal data-deletion request directly. The panel works the same on phone browsers and desktop — no app download needed.

Common Questions About Your Data and Privacy

Below are the questions our support team receives most often about data handling. If yours is not here, reach out through live chat or email and we will answer directly.

We collect your name, email address, phone number and a password you create. If you deposit via DANA, OVO or GoPay we also receive a transaction reference from the e-wallet provider — we do not store your e-wallet PIN or full credentials.

Only with the payment processors needed to complete your deposits and withdrawals, and with fraud-detection services that protect your wallet. We never sell or rent your personal data to advertisers, marketing firms or any unrelated third party.

Open your account settings panel on mobile or desktop and look for the privacy section. From there you can request a full data export. Alternatively, message our live chat or send an email with the subject line 'data access request' and include your username.

Yes. Submit a deletion request through your account settings or via live chat. Once we verify your identity through an OTP to your registered phone, we begin the removal process. Any data we must keep for legal compliance is purged after that minimum period ends.

We use session cookies to maintain your login and preference cookies for language and lobby layout. A cookie banner lets you accept or reject non-essential cookies. Blocking session cookies may log you out between pages, but we respect your choice.

GoPay handles your PIN entry and authentication entirely on their side. We receive only a confirmation token and the deposit amount. That token is stored encrypted so it cannot be reverse-engineered into your GoPay account credentials by anyone.

Our services are available where local law permits. If regulation in your region requires specific data-handling procedures — longer retention, mandatory deletion timelines, or additional disclosures — we follow those local requirements for your account specifically.

If your account goes inactive we retain your records in encrypted storage. Once you formally close the account, we keep data only for the minimum period required by applicable regulation, then permanently delete it from all systems including backups.

Yes. If we detect unauthorised access to systems holding your personal data, we will notify you via the email and phone number on your account. The notification will explain what happened, what data was involved and what steps we are taking to contain it.

Go to your account settings on mobile or desktop, find the communications toggle, and switch marketing messages off. You will still receive essential account notifications — like withdrawal confirmations and security alerts — but nothing promotional.