Reference

How maimum88 Handles Your Privacy in Indonesia

Your account belongs to you — and so does the information attached to it. This page walks through exactly how we collect, store and protect your personal data, wallet credentials and transaction history when you access maimum88 from Indonesia, where availability depends on local…

Account DataWallet PrivacyDANA & OVO SecurityData Access Rights
maimum88 How maimum88 Handles Your Privacy in Indonesia
PRIVACY HELP PATHS

Get Help With Your Privacy Questions

If something about your account data does not look right, or you want to know exactly what we hold on your account, reach our support team through any of the channels below. We handle data-access requests separately from general account queries so your request reaches the right team without delay.

Live Chat Support Reach us through the live chat icon on your account page. Privacy and data-access questions are flagged to a dedicated handler so you get a direct, informed response rather than a general reply.
Account Email Channel Send a written data-access or deletion request to our account support email. Include your registered wallet number — DANA, OVO or GoPay — so we can locate and review your record accurately.
In-App Account Settings Open account settings on mobile or desktop, navigate to Privacy, and view which data categories are stored. You can request a data summary directly from that screen without contacting support.
maimum88 What We Collect and Why It Matters

What We Collect and Why It Matters

When you open an account, we collect the minimum needed to verify your identity and connect your preferred payment method — whether that is DANA, OVO or GoPay. Your wallet number is stored in encrypted form and is never shared with third-party advertisers. Transaction records are held to support withdrawal verification and account-balance reconciliation. Session data — device type, browser, IP region

— helps us detect unusual login attempts. Players in Jakarta and Surabaya access the same encrypted account environment. We do not sell personal data. If we ever update our data practices, we notify you through your registered account contact before changes take effect.

HOW WE STAY ACCOUNTABLE

Privacy Practices You Can Verify

We run our data handling against a clear set of internal standards. These are not abstract policies — they map directly to what happens when you top up via GoPay, when you submit KYC documents, and when you request a withdrawal. Each item below reflects a real operational commitment, not marketing language.

Encrypted Wallet Storage

Your DANA, OVO and GoPay details are stored using encryption at rest. The raw wallet number is never written to a log file or exposed in plain text at any stage of the transaction flow.

KYC Data Isolation

Identity documents submitted during KYC verification are stored in an isolated environment, separate from your gameplay and transaction data, and are not used for marketing profiling.

Access Logs Available

You can request a summary of login events tied to your account — including device type and region — directly from the Privacy section of account settings, giving you visibility over who accessed your account.

No Third-Party Data Sales

We do not sell, rent or trade your personal information to advertisers or data brokers. Any third-party service we work with — such as payment processors — receives only the minimum data needed to complete the transaction.

Key Privacy Terms Every Account Holder Should Know

These definitions cover the terms you will see in our privacy policy and account settings. Each one is explained in plain language so you know exactly what it means for your maimum88 account.

What is KYC in the context of my account?

KYC stands for Know Your Customer. It is the identity verification step where you submit a government-issued ID so we can confirm your account belongs to you before processing withdrawals.

What does 'data controller' mean?

The data controller is the entity — in this case maimum88 — that decides how and why your personal data is collected and used. You can direct data-access requests to the controller.

What is encryption at rest?

Encryption at rest means your stored data — wallet numbers, personal details — is scrambled using a cipher key while saved on our servers, so it cannot be read even if storage is physically accessed.

What is a data access request?

A data access request is a formal ask for a copy of the personal information we hold about you. You can submit one via account settings or through our support email at any time.

What does 'session data' include?

Session data covers technical details logged during a visit — your device type, browser version, IP region and session duration. It is used for security monitoring and detecting unusual login attempts.

What is a data retention period?

The data retention period is how long we keep your information after account closure. Transaction and identity records are held for the period required by applicable law before deletion.

Your Privacy Questions, Answered Directly

These are the questions we hear most from account holders in Indonesia about how their data works, what we store and how to control it. Each answer reflects how our systems actually operate — not generic policy language.

Your wallet number is shared only with the payment processor needed to complete your transaction. It is never passed to advertisers, analytics providers or any other third party. The number is encrypted before storage.

Open account settings, go to the Privacy section, and select 'Request Data Summary'. You can also send a written request through our support email, including your registered wallet number so we can identify your record.

Yes. Send a deletion request through the support email channel or live chat. We will remove personal and wallet data within the timeframe permitted by applicable law, which may require us to retain certain transaction records.

After account closure, we retain transaction and KYC records for the period required under applicable law. Your wallet number and personal details are removed once the legal retention window closes. We do not use closed-account data for marketing.

We use OTP verification on login, encrypted session tokens, and device-level login tracking. If a login attempt comes from an unfamiliar device or region, we trigger an additional verification step before granting access.

Yes. Any material change to how we handle your data will be communicated through your registered account contact — email or in-app notification — before the updated terms take effect. We do not change terms silently.
Reference

Privacy Guide Indonesia

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.