Reference

How zonacodot Handles Your Personal Data

At zonacodot, your personal data is collected only for the purposes of running your account, processing deposits through DANA, OVO, GoPay and QRIS, and delivering support when you…

Data encrypted in transitDANA, OVO, GoPay & QRIS transaction privacyAccount data access on requestRetention limits clearly statedContact us at any time
zonacodot How zonacodot Handles Your Personal Data
PRIVACY CONTACT PATHS

Reach Us About Your Privacy Rights

If you have a question about how your personal data is stored, want to request a copy of your records, or need to correct information on your account, our privacy support team…

Live Chat Start a live chat session directly from your account dashboard. Our privacy team responds within three minutes during operating hours, 08:00–23:00 WIB, every day of the week.
Email Support Send your data access or deletion request to our privacy inbox. We acknowledge every email within two hours and resolve most requests within 72 hours of receiving full verification from you.
In-Account Request Form Log in, navigate to Account Settings, then select Privacy Requests. Submit your query directly from there — your identity is already verified, so we can action your request faster than any other channel.
DATA HANDLING PRACTICES

Six Ways We Protect and Manage Your Information

Our data practices are built around a simple principle: we collect only what we genuinely need to operate your account and keep it secure.

End-to-End Encryption

Every data packet — including your DANA, OVO, GoPay and QRIS payment identifiers — travels over TLS 1.3 encrypted connections. We do not store raw payment credentials on our servers at any point during or after a transaction.

Cookie Transparency

We use session cookies to keep you logged in and analytics cookies to understand which pages you visit most. You can review and withdraw cookie consent at any time from the Privacy Settings tab inside your account.

Account Security Alerts

Any login from an unrecognised device triggers an immediate email alert to the address on your account. You can then revoke that session from Account Security without needing to contact our team first.

Data Retention Schedule

Active account data is retained while your account remains open. If you close your account, we retain transaction logs for a maximum of five years for audit compliance, then delete all remaining personal identifiers from our systems.

Third-Party Processors

We share only the minimum data necessary with payment processors handling your DANA, OVO, GoPay or QRIS transfers. Each processor operates under a data processing agreement that mirrors our own retention and security standards.

Data Access Requests

You can request a full export of the personal data we hold on you at any time. Submit through Account Settings or email our privacy inbox, and we will deliver your data export within seven business days of verifying your identity.

Your Questions About Our Privacy Policy

These are the questions we receive most often about how zonacodot handles personal data. If your question is not answered here, open a live chat or use the in-account Privacy Request form — our team will respond within the hours stated above.

We collect your name, email address, and device information at registration. If you deposit via DANA, OVO, GoPay or QRIS, we also log the payment identifier and transaction amount — nothing beyond what is operationally required to run your account.

No. We do not sell or rent your personal data to third-party advertisers. Data is shared only with payment processors like DANA, OVO, GoPay and QRIS, and only to the extent needed to complete your transaction securely.

Log in to your account, go to Account Settings, and select Privacy Requests. Alternatively, email our privacy inbox. We verify your identity first, then deliver a full data export within seven business days of confirming your request.

Yes. Submit a deletion request through Account Settings or via email. We will remove your personal identifiers after the mandatory five-year audit retention period for transaction logs. We will confirm the deletion timeline in writing when we acknowledge your request.

Transaction records are kept for five years to meet audit requirements. After that period, all remaining personal identifiers — name, email, device data — are permanently deleted from our systems with no backup retention.

We do not store raw payment credentials. Your DANA, OVO, GoPay and QRIS identifiers are passed to the respective payment processor over an encrypted connection and are not written to our own database at any stage of the transaction.

Reach our privacy team via live chat (08:00–23:00 WIB daily) or by email. We treat all data-handling complaints as priority tickets and aim to provide a substantive response within 48 hours of receiving the details from you.