LEGAL REFERENCE

How po4d Handles Your Account Data

This is the po4d privacy policy page. We've written it for you in plain language so you can see exactly what we collect when you open an account...

Plain-language policyAccount data scopeCookie postureWallet detailsIndonesia-aligned
po4d How po4d Handles Your Account Data

Policy Posture and Jurisdiction Notes

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

SUPPORT

Privacy Contact Paths

Privacy Inbox Write to our privacy desk for data access...
Live Chat Escalation Open the chat widget from any logged-in page...
Account Settings Most consent toggles, marketing preferences and session-cookie controls...
EDITORIAL CLARITY

How We Keep This Policy Honest

Named Data Officer

A named officer signs off every revision of this policy. That person is reachable through the privacy inbox and is accountable for how your account information moves through our systems.

Quarterly Policy Review

We re-read this page every quarter against current Indonesia data rules and partner contracts. Any change to wording, retention period or vendor list gets a dated entry on the revision log.

Vendor Vetting

Every processor that touches your data — hosting, KYC, wallet rails — signs a data agreement with us first. We list the categories they handle and the safeguards we require from them.

Encryption In Transit

Account credentials, wallet references and session tokens move across encrypted channels. Internal access is logged, scoped to role, and audited so unusual reads get flagged the same day.

Minimal Collection

We ask for the fields we actually need to run your lobby and keep payments compliant. Optional fields are clearly marked, and skipping them never blocks you from playing.

Clear Revision Log

Each update to this policy carries a date and a short note on what changed. You can scroll the log and see exactly when retention windows or cookie categories were adjusted.

Consistency Across Our Policy Pages

Scope of Data
This page mirrors the data categories listed in our terms and KYC notice. The same field names appear everywhere so you don't have to reconcile different vocabularies.
Retention Windows
Retention periods quoted here match the figures in our compliance schedule. If one page changes, the others update in the same release cycle so timelines stay aligned.
Cookie Categories
Cookie buckets — strictly necessary, functional, analytics, marketing — use identical labels on the cookie banner, the settings panel and this policy page so toggles map cleanly.
Third Parties
The vendor list referenced here is the same set named in our security note. Adding or removing a partner triggers updates on both pages within the same week.
User Rights
Access, correction, portability and deletion rights appear with the same wording on the help centre. Whichever route you arrive through, you read the same entitlements.
Marketing Consent
Marketing toggles described in this policy match the controls in your account settings. Switching off promotional contact in one place switches it off everywhere we reach you.
Jurisdiction Lines
Phrases like 'where local law permits' appear identically across legal pages so the regional posture reads the same whether you arrive at terms, KYC or this policy.
PLATFORM SNAPSHOT

What This Policy Page Shows You

Section Anchors A sticky list of section anchors sits on the side...
Plain-Language Summary Each block opens with a one-sentence summary in everyday English...
Revision Date The current revision date sits at the top so you...
Cookie Toggle Link A direct link drops you into the cookie preferences panel...
Data Request Form A short form lets you file an access, correction or...
Mobile-First Layout The whole policy reads cleanly on a phone. Headings collapse...

Privacy Policy Questions

We collect your name, contact details, date of birth, a wallet reference and the device signals needed to keep the session secure. Optional marketing fields are flagged as optional and never block account creation.

We retain core account records for the period our compliance rules in supported regions require, typically several years. After that window expires we either delete the data or anonymise it so it can't be linked to you.

Yes. Send a request through the privacy inbox or the data request form in your account. We verify your identity, then return a structured copy of the personal data tied to your profile.

Wallet identifiers are stored as tokenised references, not as raw account numbers. The actual movement of funds happens at the payment partner, and we receive only the confirmation signals needed to credit your lobby balance.

We share only with vetted processors — hosting, KYC checks, payment rails, anti-fraud — and only the fields each one needs. Every partner signs a data agreement before they touch a single record from our systems.

Open your account settings and flip the marketing toggle off. The change applies across email, SMS and on-site prompts within the same session, and we log the consent change against your profile.

Yes, we revise it as rules and vendors evolve. Each update carries a date and a short note on what shifted. Material changes also trigger an in-app notice so you see them before your next login.