Reference

Browse Our Legal Policies and Account Terms

We keep our legal documentation straightforward so you know exactly how your data, account and wallet activity are handled. Everything here applies to your use of fftoto where local law permits access, and we update these pages when regulations or our own practices change.

Data TransparencyAccount TermsCookie DisclosureWallet PrivacyRegional Access
fftoto Browse Our Legal Policies and Account Terms
HOW WE PROTECT YOU

Check How We Handle Data, Cookies and Account Security

We built our data practices around what you actually need to know: what we collect, why, how long we keep it, and what you can do about it. These six areas cover the operational reality behind our legal framework so there are no surprises when you use your fftoto account or deposit through DANA, OVO or GoPay.

Data Collection Scope

We collect your registration details, login timestamps, device fingerprint and transaction records. Nothing beyond what is necessary to run your account securely. Wallet credentials from DANA, OVO or GoPay never touch our servers — authentication stays on their side.

Cookie Practice

Session cookies keep you logged in. Analytics cookies help us understand page performance. We do not use cross-site tracking pixels or sell cookie data. Your browser controls let you block non-essential cookies without losing core account functionality.

Account Security Layers

Your password is hashed, not stored in plain text. Login attempts from unrecognised devices trigger a verification step sent to your registered contact. Session tokens expire after inactivity so a forgotten open tab does not leave your account exposed.

Retention and Deletion

We keep active account data for as long as you use fftoto. After you request deletion, we purge personal identifiers within the timeframe required by applicable regulation. Transaction records may be retained in anonymised form for audit obligations.

Who to Contact

Any data subject request — access, correction, portability or erasure — goes through the same policy channels listed in the support section above. You do not need a lawyer or special format. Plain language works fine and we respond in kind.

Third-Party Sharing

We share data only with payment processors (DANA, OVO, GoPay), fraud-prevention services and where legally compelled. No marketing list sales, no data brokerage. Partners receive the minimum information needed to complete their function.

POLICY CONTACT PATHS

Explore Ways to Reach Our Legal and Policy Team

Need a copy of your stored data, want to request deletion or have a question about how a specific policy applies to you? Our team handles these requests through dedicated channels so nothing gets lost in general support queues. Response times vary by request complexity, but we acknowledge every submission promptly.

Live Chat Open live chat from any page on fftoto. Select the data or policy category from the pre-chat menu so your message routes directly to the compliance desk rather than general support. Available around the clock for Indonesia-based enquiries.
Email Request Send a structured request to our policy inbox. Include your registered email and a brief description of what you need — data export, correction, deletion or a policy clarification. We confirm receipt and provide a reference number for tracking.
In-App Submission From your account settings on mobile, tap the policy request option. The form pre-fills your account ID so we can locate your records without back-and-forth. Useful when you want a fast, trackable submission from your phone.

Switch to Answers on Common Policy Questions

These are the questions we hear most about our legal and data policies. Each answer reflects how things actually work on fftoto, not a generic legal template. If your question is not here, reach out through the support channels above.

We collect your name, email, phone number and any identity verification documents you submit. Device data like browser type and IP address is logged for security. We do not ask for information unrelated to running your account or processing wallet transactions through DANA, OVO or GoPay.

Yes. Submit a data access request through live chat, email or the in-app form. We compile your registration info, transaction history and login records into a downloadable file. The export is delivered to your registered email within a reasonable processing window.

Contact our policy team through any support channel and state you want account deletion. We confirm your identity, close the account and begin purging personal identifiers. Some anonymised records may remain where regulations require retention for audit purposes.

Transaction references are shared with DANA, OVO or GoPay only to the extent needed to process your deposit or withdrawal. We never expose your full wallet credentials. No payment data goes to advertisers or data brokers under any circumstance.

We use session cookies for login persistence and analytics cookies for page performance. No cross-site trackers or advertising pixels run on fftoto pages. You can disable non-essential cookies in your browser without losing the ability to access your account.

Access depends on local law and is available where eligible regions permit. If you travel to or reside in a jurisdiction where access is restricted, the platform may limit functionality. We recommend checking local regulations that apply to your situation.

Active account transaction records are kept for the duration of your membership. After account closure or deletion, anonymised transaction data may be retained for the period required by applicable regulation. Personal identifiers are removed from those records.

We monitor regulatory developments in markets where we operate. If a change affects your eligibility or account status, we notify you by email with clear next steps — including how to withdraw any remaining balance before any restriction takes effect.

Your password is hashed using industry-standard algorithms before storage. We never store plain-text passwords. Failed login attempts from new devices trigger additional verification so that credential-stuffing attacks do not compromise your account even if a password leaks elsewhere.

Reach our policy team through live chat, email or the in-app submission form. Describe your concern and we will investigate. If we cannot resolve it to your satisfaction, you retain the right to escalate to any relevant data protection authority in your jurisdiction.