Reference

What Our Legal Terms Mean for Your Account

tot21 operates under terms shaped for Indonesia, where account access, wallet use and data handling depend on local law and eligible regions.

Jurisdiction-aware termsDANA, OVO, GoPay account contextData rights on requestAccount security commitmentsIndonesia-eligible access only
tot21 What Our Legal Terms Mean for Your Account
ACCOUNT PROTECTION DETAIL

How We Handle Data, Cookies and Account Security

We take the handling of your account data seriously. Every session runs over encrypted connections, and we do not store raw wallet credentials for DANA, OVO or GoPay — only the transaction reference that the payment provider returns. Cookie use on tot21 is limited to session management, preference storage and basic analytics; you can adjust cookie preferences through your browser settings at any time.

Data Retention

Account and transaction data is retained for as long as your account is active and for a defined period after closure, in line with applicable record-keeping requirements for eligible regions.

Cookie Policy

We use session cookies to keep you logged in, preference cookies to remember your settings and analytics cookies to understand page performance. No cookies are sold to advertisers.

Account Security

Login uses an OTP verification step tied to your registered mobile number. Changing your linked wallet — DANA, OVO or GoPay — requires identity re-verification through the account settings flow.

Rights and Requests

You can request a copy of your account data, ask us to correct inaccurate records, or ask us to delete your account and data by contacting support in writing through email or live chat.

LEGAL CONTACT PATHS

Reach Us on Policy or Account Questions

If you have a question about how these terms apply to your account, how your DANA or OVO wallet data is stored, or how to request a data change, our support team is the right starting point. You can reach us through live chat, email or the in-app message channel — choose whichever fits your situation.

Live Chat Open the chat widget from your account dashboard to ask about terms, data requests or account policy. Available for eligible Indonesia accounts where local access is permitted.
Email Support Send detailed policy queries, data access requests or account-closure requests by email. We respond in the order received and will confirm receipt of any formal data request.
In-App Message Use the message tab inside your account to flag a policy concern linked directly to your session or wallet transaction. Keeps all context in one thread for faster resolution.

Common Questions About Our Legal Terms

These are the questions we get asked most often about how our terms work, what rights you have and how to take action on your account data. If your question is not here, live chat or email support can help directly.

Access and eligibility depend on local law and your specific region. Where local law in Indonesia permits access, these terms govern your account fully — including wallet use, data handling and transactions.

Contact support by email or live chat with a written data access request. Include your registered account email and we will confirm receipt and process the request within our standard review period.

Yes. Submit a written deletion request through email support. We will close the account and remove personal data subject to any retention obligations required by applicable law for eligible regions.

Wallet credentials are not stored on our side — only the transaction references returned by the payment provider. Those references are retained for the required period, then removed as part of account closure.

We update the version date at the bottom of this page when terms change. For material changes, we notify you through your registered contact before the new terms take effect.

Start with our support team via live chat or email. We handle disputes through an internal review process first. If that does not resolve the issue, we can discuss next steps from there.
Reference

Legal

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.