sohototo Casino & Sportsbook Data Care
This page describes what we collect when you use sohototo and how we keep that data protected. We at sohototo take your privacy seriously—your personal information, payment details, and betting activity are handled according to the data protection laws that apply where our services operate. When you open a sohototo account, verify your identity, deposit via DANA or e-wallet, or place a football bet on Liga 1, we collect only the data we need to serve you safely and meet our legal obligations.
Our sohototo privacy approach is built on three commitments: we collect only what is necessary, we use it only for the purposes we describe, and we protect it with encryption and access controls. This document covers what we collect, who has access to it, how long we keep it, and what rights you have over your data. If you have questions about our privacy practices, our support team can help—we respond to privacy enquiries via email and in-app messaging during business hours.
We serve users in supported jurisdictions where local law permits our service. Our servers may sit outside your jurisdiction, but we comply with data protection requirements that apply to sohototo's operation. By using sohototo, you agree to the data handling practices set out below.
What We Collect on sohototo
We collect your personal data in three categories: identity, account, and activity. When you open a sohototo account, we collect your email address, phone number, full name, date of birth, and government-issued ID number. Our know-your-customer (KYC) process requires a clear photo of your ID document and a recent selfie so we can verify your identity—this is a legal requirement and a security step to protect your account. We store these documents securely and use them only for verification purposes.
For deposits and withdrawals, we collect payment method details: your e-wallet account identifier if you use DANA, e-wallet, mobile banking, local payment, or online payment, or your bank account and virtual account number if you transfer via e-wallet, mobile banking, local payment, or online payment. We also collect transaction timestamps, amounts, and payment status. We never store your full card number or wallet password—payment processors handle sensitive credentials separately. We collect and store your account recovery information: security questions, backup email addresses, and linked phone numbers.
We track your activity on sohototo: which markets you view (football betting on Piala Indonesia, live-dealer tables, slot games), your wagers, your login times, and your browser type and IP address. We collect this data to personalise your experience, detect fraudulent accounts, prevent money laundering, and respond to your customer service requests. We do not sell this activity data to advertisers; we use it only internally and with law enforcement when legally required.
- Personal data
- Name, email, phone, date of birth, ID number, address, selfie photo.
- Payment data
- E-wallet handle, bank account, transaction history, deposit and withdrawal records.
- Activity data
- Login times, markets viewed, wagers placed, IP address, device type, browser data.
How We Use Your Data on sohototo
We use your sohototo data primarily to operate your account safely and comply with Indonesian gaming and financial regulations. Your identity data and payment details let us authenticate your login, process your deposits and withdrawals, and verify that you are of legal age. We use your activity data to monitor for fraud—multiple simultaneous logins from different countries, rapid account creation and closure cycles, or unusual betting patterns trigger our fraud team's review. We retain the right to request additional documentation or temporarily suspend activity if we detect risk.
We also use your data to respond to your support requests, improve sohototo's performance and user experience, and conduct required reporting to authorities. During holidays like Idul Fitri or Idul Adha, our team may have limited availability, but we process all account and payment inquiries as soon as possible. We use your email and phone number to send account notifications, service updates, and occasional promotional messages—you can opt out of promotional emails at any time. We do not use your data for automated decision-making that significantly affects you, except in cases of clear fraud.
We do not share your data with third-party marketers
sohototo never sells your activity data, betting history, or payment information to advertisers, data brokers, or marketing firms. We share data only with payment processors, fraud detection services, and law enforcement where legally required.
Third-Party Access and Data Processors
sohototo uses trusted third-party services to operate our platform. Payment processors for e-wallet, mobile banking, local payment, online payment, e-wallet, and mobile banking scan-and-pay receive only the minimum data needed to complete your transaction—your account identifier and transaction amount. These processors handle your payment credentials separately from sohototo's servers. Bank partners processing local payment, online payment, e-wallet, and mobile banking virtual account transfers also receive transaction data only. We sign data processing agreements with all processors requiring them to protect your data and use it only for the stated purpose.
We also work with fraud detection providers, who analyse patterns across our platform to identify suspicious activity. These services receive anonymised activity data and do not access your personal identity details unless we escalate a suspected breach. Our customer support platform stores your enquiry history—this is visible only to our sohototo support team, who are required to keep it confidential.
We do not transfer your data outside Indonesia unless legally required or unless you use sohototo from outside Indonesia. Our primary servers operate in Indonesia; backup systems may sit in other jurisdictions for resilience. In all cases, your data travels encrypted and remains subject to protection equivalent to Indonesian data protection law.
Your Rights and Our Responsibilities
You have the right to access, correct, and request deletion of your personal data held by sohototo. To exercise these rights, contact our privacy team via email with your request. We respond within 30 days. You can ask to download a copy of all data we hold on you—we will provide it in a machine-readable format. You can request correction if any personal details are inaccurate (for example, your registered address). You can ask us to delete your sohototo account and associated data, except where we are legally required to retain it for compliance or fraud prevention.
We retain your identity and payment data for seven years after your account closes, as required by Indonesian anti-money-laundering law. We retain your betting activity data for five years to respond to disputes and investigations. We delete promotional preference data when you unsubscribe from marketing emails. If you request account deletion, we anonymise rather than immediately erase your betting records, as raw deletion could compromise fraud detection and compliance audits.
We protect your sohototo data with industry-standard encryption (TLS 1.2 or higher), access controls, and regular security testing. Only authorised sohototo staff and contractors can access your personal data. We conduct annual data security assessments and respond to any suspected breaches within 48 hours. If we discover an incident affecting your data, we notify you promptly and provide guidance on protective steps.
This privacy policy applies globally to all sohototo users, regardless of location, but where local data protection law offers stronger protections than what we describe, that local law applies to you. If you are located in Jakarta, Surabaya, Bandung, Medan, Semarang, or Yogyakarta, or anywhere else in Indonesia, Indonesian data protection law and our policy are your baseline. For privacy concerns or complaints, you can contact the Indonesian data protection authority or reach out to our privacy team at our listed support email address. We undertake to investigate and respond within 30 days.