Reference

How riyaltoto Handles Your Personal Information

This privacy policy sets out exactly what data riyaltoto collects when you open an account, make a deposit via DANA, OVO or GoPay, and use our lobby — and how we keep it safe.

Account data protectionDANA, OVO, GoPay transaction privacyNo data sold to third partiesCookie and device controlsDirect contact for data requests
riyaltoto How riyaltoto Handles Your Personal Information
DATA REQUEST CONTACT

Reach Us About Your Privacy

If you need to review, correct or remove data tied to your account — including transaction records from DANA, OVO or GoPay payments — our support team handles privacy requests directly. Send your request through any of the channels below and include your registered account email so we can locate your record quickly.

Team online

Live Chat

Start a live chat session from the account page. Our team picks up privacy and data requests the same way as any account query — no separate queue.

Email Support

Send your data request to our support email address. Include your registered email and the specific data you want reviewed, corrected or deleted.

Account Help Page

Log in and head to the Help section under your account settings. From there you can raise a formal data request and track its status directly.

DATA HANDLING PRACTICE

How We Protect and Manage Your Information

We apply layered security across every part of the account and payment flow. SSL encryption covers all data in transit, and stored account records — including e-wallet references — are held in access-controlled environments. Cookies on the riyaltoto site are limited to session management, security tokens and performance monitoring; no third-party advertising cookies are set without your consent.

SSL Encryption

All data moving between your device and our servers — login credentials, DANA transfer details, session tokens — is encrypted end-to-end using SSL.

Cookie Controls

You can adjust cookie preferences from the consent banner or your browser settings. Session and security cookies are necessary; analytics cookies can be declined without affecting your account access.

Data Retention Limits

Account data is kept only as long as your account is active or as required by applicable law. Once retention periods pass, records are securely deleted or anonymised.

Third-Party Access Limits

Payment processors — the entities that handle your OVO or GoPay transfer — receive only the data fields needed to complete the transaction. No broader profile is shared.

Common Questions About Your Privacy Rights

Here are the questions we hear most often about how riyaltoto handles account data. If your question is not covered here, our support team can respond to specific data requests directly through live chat or email.

We collect your name, email, phone number and the wallet ID linked to your chosen payment method — DANA, OVO or GoPay. This is used for identity verification and transaction processing only.

Transaction references are retained for verification and dispute resolution. Once the retention period required under applicable rules passes, payment records are archived under restricted access or securely deleted.

Yes. Submit a request through live chat or our support email with your registered account address. We will identify the records tied to your account and share a summary with you.

Contact support through live chat or email and specify that you want your account data removed. We will process the request in line with applicable data-protection requirements and confirm once complete.

No. We do not sell or share identifiable account data for marketing. Anonymised, aggregate analytics may go to service providers under strict data-processing agreements — never your personal details.

Session and security cookies run by default to keep your account active across devices. Analytics cookies are optional — you can decline them via the consent banner without affecting your login or lobby access.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.