exoto Platform Privacy Notice

This page describes what we collect when you use exoto and how we keep that data protected. We operate exoto as an online gaming and sportsbook platform available where local law permits. When you create an account, deposit funds, or play games on exoto, we collect personal information necessary to verify your identity, process payments, and comply with Indonesian banking regulations.

We take data privacy seriously. We encrypt all transactions, tokenize payment credentials so we never store your actual card or e-wallet details, and retain personal information only as long as required by law. We do not sell or lease your data to third parties. This notice explains our practices in plain language so you understand what happens to your information on exoto.

If you have questions about how we handle your data, or if you want to request access to or deletion of your personal information, contact our support team using the channels listed at the end of this page.

What Data We Collect on exoto

We collect information in three categories: account registration, payment processing, and gameplay activity. During account opening, we ask for your full name, email address, phone number, and date of birth. We use this information to verify your identity and send you account notifications. We do not collect your full ID number during signup; we request it only when you make your first deposit or withdrawal, as part of our know-your-customer (KYC) verification process.

When you deposit funds into your exoto account, we collect payment method details — such as your DANA, e-wallet, mobile banking, local payment, online payment, or e-wallet account identifier, or your mobile banking, local payment, online payment, or e-wallet virtual-account number. We never store your actual e-wallet PIN or bank login credentials. Instead, we save a tokenized reference that only our secure payment gateway can decode. This token allows us to process future deposits and withdrawals without ever seeing your real credentials.

When you play games on exoto, we log your gameplay activity — which games you enter, your bet amounts, outcomes, and balance changes. We use this data to calculate your account balance, detect fraud, and comply with gaming regulations. We also track your IP address and device information to identify suspicious login attempts or account takeovers.

How We Use Your Data on exoto

We use your personal information for five main purposes. First, we verify your identity to comply with Indonesian anti-money-laundering (AML) and know-your-customer (KYC) standards. Second, we process your deposits and withdrawals through our payment partners. Third, we detect and prevent fraud — we monitor for unusual login patterns, rapid withdrawals, or account access from multiple countries. Fourth, we provide customer support — when you contact us with a question or issue, we use your account information to help resolve it. Fifth, we comply with legal obligations — if a court or regulator requests information about your account, we may disclose it as required by law.

We do not use your data for marketing purposes unless you explicitly consent. We do not sell your information to third parties. We do not use your gameplay data to profile you or make automated decisions about your account (such as blocking you from playing based on algorithmic assessment).

Your data is encrypted on exoto

All communication between your device and our servers uses SSL (Secure Sockets Layer) encryption. This means your login credentials, payment details, and account balance are protected from interception.

Third-Party Processors and Data Sharing

We share your data with third parties only when necessary to provide exoto services. Our payment partners (mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, local payment) receive your payment method information to process deposits and withdrawals. These partners are bound by their own privacy policies and data-protection agreements with us. We do not control how they use your data beyond processing your transaction.

We also share data with our fraud-detection service provider, who analyzes login patterns and transaction anomalies to protect your account. Our hosting provider stores our servers and databases; we use data-centre operators in multiple regions, which means your data may be stored outside Indonesia. We ensure all processors sign data-processing agreements that require them to protect your information and use it only for the purposes we specify.

We may disclose your information if required by law — for example, if a court orders us to provide account details, or if a regulator investigates suspected money laundering. We will notify you of such requests unless legally prohibited from doing so.

Cookies and Tracking on exoto

We use cookies to keep you logged into your exoto account and to remember your preferences (such as language and game-lobby view). These are session cookies that expire when you close your browser, or persistent cookies that remain for up to one year. We do not use cookies to track your behaviour across other websites.

We also use analytics tools to understand how players use exoto — which games are popular, where users encounter errors, how long sessions last. This data is anonymized; we do not link it to your personal identity. We use these insights to improve exoto's performance and user experience.

Session cookies
Expire when you close your browser; keep you logged into exoto during your visit.
Persistent cookies
Remain on your device for up to one year; remember your login and preferences.
Analytics cookies
Track anonymized usage patterns to help us improve exoto's performance.
Tokenization
Your payment credentials are replaced with secure tokens; we never store your actual card or e-wallet details.

Data Retention and Your Rights on exoto

We retain your personal information only as long as necessary. Account data (name, email, phone) is kept for as long as your exoto account is active, plus seven years after closure to comply with Indonesian financial regulations. Payment transaction records are retained for seven years. Gameplay logs are retained for one year unless needed for fraud investigation or legal proceedings.

You have the right to request access to your personal data on exoto. You can download your account information, transaction history, and gameplay logs by contacting our support team. You also have the right to request correction of inaccurate data — for example, if your name is misspelled in our system. You may request deletion of your account and associated data, subject to legal retention requirements. We will honour deletion requests within 30 days unless we are required by law to retain the information.

If you believe we have mishandled your data, you can lodge a complaint with Indonesia's Personal Data Protection Authority (Otoritas Jasa Keuangan, OJK) or other relevant regulator. We will cooperate with any official investigation.

Our Privacy Commitments and Contact

We commit to protecting your privacy on exoto. We use industry-standard encryption, tokenize payment credentials, and limit data access to employees who need it to provide exoto services. We conduct regular security audits and update our systems to address emerging threats. We do not sell your data, and we do not use it for purposes beyond what we describe in this notice.

Our servers may sit outside Indonesia; however, we comply with Indonesian data-protection standards and banking regulations. If you access exoto from Jakarta, Surabaya, Bandung, Medan, Semarang, or Yogyakarta, your data is protected under the same policies regardless of where our servers are located.

This privacy notice may be updated from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by email or by posting a notice on exoto. Your continued use of exoto after such changes constitutes your acceptance of the updated notice.

How to Contact exoto About Privacy

If you have questions about this privacy notice, want to exercise your data rights, or suspect a data breach affecting your exoto account, reach out to our support team. You can contact us through in-app chat (available during standard business hours) or by email. We respond to privacy requests within 14 days. For urgent security concerns — such as unauthorized account access — contact us immediately so we can investigate and secure your account.

We also welcome feedback on how we can improve our privacy practices. Your input helps us refine exoto's data handling and security measures. Thank you for trusting us with your information.