Reference

Open castoto Privacy Policy Clearly

castoto Privacy Policy explains what we collect, why we use it and how you can ask about your account data before opening an account.

Account choicesPayment clarityPrivacy requests
castoto Open castoto Privacy Policy Clearly
REQUEST A CHECK

Contact Us About Your Privacy Policy

A clear contact path helps you resolve a privacy question without guessing which team to reach.

Account questions Ask through the account support route when you want to know which personal details…
Payment records For a DANA, OVO, GoPay or QRIS reference, share the date, amount and visible…
Access concerns If a privacy request arrives while your account access is stalled, tell us which…
DATA HANDLING DETAILS

Browse Your Privacy Controls

We keep the policy practical by linking each privacy choice to an account action you recognise.

Data collected

We may handle your account name, contact details, phone verification result, support messages and transaction references. On a mobile browser, we can also process device and connection signals needed to keep a signed-in session stable and investigate an access error.

Cookie choices

Cookies can preserve a session between the login page and the lobby and can help us identify repeated technical faults. You can adjust cookie controls in your browser, although blocking some cookies may affect account access or remove remembered preferences.

Account security

We use phone verification and account checks before discussing private details or changing sensitive account information. Keep your password and verification codes private; support will not need those secrets to answer a Privacy Policy request.

Payment separation

A DANA, OVO, GoPay or QRIS reference can help us match an account event, but the wallet provider controls its own data handling. Bank transfer and virtual account records may also involve BCA, BRI, Mandiri or BNI processing systems.

Retention requests

You can ask why a particular record remains stored and how long an operational, security or legal need applies. We assess the request against account history and applicable requirements instead of removing a record that must still be kept.

Correction route

If your contact detail or account data is inaccurate, tell us what needs changing and provide the account check we request. We record the correction request, verify the account holder and confirm the result through the available support contact.

Find Privacy Policy Answers

These Privacy Policy answers address the questions we expect before you open an account or send a data request. They cover account access, mobile devices, cookies, local wallets and the practical checks needed to protect your information. If your situation is different, contact us with the account details you can safely provide.

It covers account details, phone verification, support messages, device and connection signals, cookies and payment references linked to your activity. It also explains why we use those details, how retention works and how you can request access, correction or deletion where applicable.

Phone verification helps us connect a privacy request to the correct account and reduce the chance of disclosing details to another person. We may ask for an additional account check, but you should not send your password or one-time verification code.

It covers the transaction references we receive when you use DANA, OVO, GoPay or QRIS with your account. Each wallet also has its own privacy rules. We use the reference to check account status, while the wallet provider handles its separate processing.

When you access an account from a mobile or desktop browser, we may process browser type, device settings, connection signals and session details. We use them to keep login steps working, detect access faults and protect account information from unusual activity.

Contact account support and state that you are making a Privacy Policy data access request. Include the account identifier you can safely share and describe the records you want. We verify account ownership before explaining which data can be provided.

Yes, you can request a correction or deletion through the support contact. We first verify the account and then assess the request against operational, security and legal needs. Some transaction or account records may need to remain stored for those reasons.

Yes. Access and eligibility depends on local law, and our Privacy Policy is applied alongside the rules relevant to your location. If you are in Indonesia, use the account and payment paths only where local law permits and contact us with policy questions.