sumtoto Platform Privacy Notice

This page describes what we collect when you use sumtoto and how we keep that data protected. Data protection is central to how we operate: when you deposit via DANA, e-wallet, mobile banking, local payment, online payment, or e-wallet, or when you transfer funds through mobile banking, local payment, online payment, or e-wallet, we treat your information as sensitive and store it securely. We collect only what we need to run the platform, verify your identity, prevent fraud, and comply with Indonesian financial regulations. We do not sell your data, and we do not share it with marketers or data brokers.

If you have questions about how sumtoto handles your personal information, or if you want to exercise your rights—such as requesting a copy of your data or asking us to delete it—you can reach our support team anytime. We respond to all data requests within 14 days.

What We Collect on sumtoto and Why

When you open a sumtoto account, we ask for your email address, full name, date of birth, and national ID number. These are mandatory to verify your identity and comply with anti-money-laundering rules. During your first withdrawal, we may ask for a photo of your ID and a selfie to confirm you match your profile. We also collect your phone number so we can contact you about account security, disputes, or regulatory matters.

We track your device information—the type of phone or tablet you use, your operating system, and your IP address—to understand how sumtoto is accessed and to detect fraudulent login attempts. We log which games you view, which markets you explore (Liga 1, Piala AFF, Champions League, or live-dealer tables), and how long you spend on the platform. We do not use this data to build a psychological profile or to manipulate your behaviour; we use it to improve performance and to flag suspicious activity.

Payment data stays encrypted

When you provide payment details to sumtoto, they are encrypted end-to-end. We do not store your full card numbers or e-wallet passwords. Payment processing is handled by our partners, not by sumtoto directly.

How We Use Your Data

We use your information for five core purposes: first, to operate your sumtoto account and process your deposits and withdrawals. Second, to verify your identity as required by Indonesian law and to prevent fraud and money laundering. Third, to investigate disputes—if you report a transaction error or a market settlement concern, we need your account history and transaction records to respond. Fourth, to communicate with you about account security, regulatory changes, or service updates. Fifth, to maintain the platform itself, including fixing bugs and improving load times.

We do not use your data for marketing unless you explicitly opt in. We do not sell email lists or browsing history to third parties. We do not build predictive models to encourage higher spending. Your data exists to serve you and to keep sumtoto compliant.

Third-Party Processors and International Transfer

Our servers and databases may be located outside Indonesia. Your data may be processed and stored in data centres in other countries, depending on where we host our infrastructure. By using sumtoto, you consent to this transfer and processing. We ensure that all processors we work with—payment gateways, cloud providers, and fraud-prevention services—maintain security standards equivalent to Indonesian law.

Payment processors
We partner with services that handle DANA, e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, online payment, and e-wallet transactions. These partners have their own privacy policies and security practices.
Cloud hosting
We use third-party cloud providers to store sumtoto's databases and serve our website. These providers are contractually bound to protect your data.
Fraud detection
We use automated systems to flag suspicious logins and transactions. These systems may process your IP address and device fingerprint but do not make final decisions alone.

Your Rights and Our Policy on Cookies

You have the right to ask sumtoto what data we hold about you. You can request a copy of your account history, your identity verification documents, and a record of all your transactions at any time. You can also ask us to correct inaccurate information, to delete your data (subject to legal holds and dispute resolution periods), or to restrict how we use it. Submit these requests through our support channel and we will respond within 14 days.

sumtoto uses cookies and similar tracking technologies to remember your login session, to store your language preference, and to analyse how the platform is used. We use first-party cookies (set by sumtoto) and third-party analytics cookies (set by services like Google Analytics) to understand traffic patterns. You can disable cookies in your browser settings, though this may affect sumtoto's functionality. Essential cookies—those required for login and payment processing—cannot be disabled without breaking the platform.

Data Retention and Deletion

We keep your account data as long as your sumtoto account is active. After you close your account, we retain data for seven years to satisfy regulatory and dispute-resolution obligations. During Idul Fitri, Idul Adha, Imlek, and other holidays, our retention schedule does not change—data is stored continuously. After seven years, we securely delete or anonymise your information. If you have an open dispute or pending withdrawal, we extend retention until the issue is resolved.

Contact Us About Privacy

If you have questions about sumtoto's privacy policy, want to request your data, or believe we have mishandled your information, contact us at our support address. We maintain offices in Jakarta, Surabaya, Bandung, and Medan; you can reach us through any of these locations or via our online support form. We commit to responding to all privacy inquiries within 14 business days. If you are not satisfied with our response, you can escalate your concern to Indonesia's data protection authority.