Privacy Policy for Your suster123 indonesia Account
This is the privacy policy that governs how we handle the data tied to your suster123 indonesia account — the email you sign up with, the device you...
How We Handle Your Personal Data
Our privacy posture is shaped by Indonesian data-protection rules and the access conditions of the regions we serve. We collect the minimum needed to run your account: identity details at sign-up, transaction references when you top up via DANA, OVO, GoPay or QRIS, and session logs that keep your lobby secure. Where local law permits, we retain transaction records for the period
required by financial regulators, then purge them. We don't sell your contact details to third parties, and marketing messages only go out if you opt in. You can request a copy of your data, ask us to correct it, or close the account at any time — the request paths are listed in the support section below. Cookies used on the site
are limited to session, preference and fraud-prevention categories.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
How This Policy Is Reviewed
This policy isn't a one-and-done page. We revisit it on a fixed cycle and whenever Indonesian rules shift.
Legal Review
Our in-house counsel reviews this policy every six months against current Indonesian data-protection guidance, flagging any clause that needs rewording before we push the update live to your account dashboard.
Security Sign-Off
The security lead signs off on the data-handling sections, confirming that storage, encryption and access controls described here actually match what runs on our servers and the wallet integration layer.
Plain-Language Pass
Every revision goes through a plain-language pass so you don't need a lawyer to read it. We strip jargon, shorten sentences and keep the structure consistent across all our policy pages.
Change Log
Material changes are logged at the foot of this page with the date applied. If a change affects how we use your data, we email the address on your account before it takes effect.
Independent Audit
An external auditor checks our data flows annually, focusing on payment-reference handling for DANA, OVO, GoPay and QRIS top-ups. Findings feed straight into the next policy revision cycle.
User Feedback
Privacy questions you raise through chat or email are reviewed monthly. Recurring themes get addressed directly in the policy text, so the document keeps pace with what account holders actually ask.
Consistency Across Our Policy Pages
This privacy policy sits alongside our terms, cookie notice and account rules. We keep the wording aligned so nothing contradicts.
What Defines This Policy Page
A few editorial choices shape how this policy reads and where to find things on the page.
Plain Sections
We split the policy into short, named sections instead of one wall of text. Skim the headings, jump to what you need, and the cross-references inside each block point you to the related clause.
Indonesia Framing
The policy is written for an Indonesian account base, so jurisdictional language refers to local data-protection guidance rather than a generic global template that wouldn't match how we actually operate.
Wallet References
Where transaction data is discussed, we name the rails involved so you know exactly which top-up flow leaves a record on your account profile.
Version Stamp
The footer of the page shows the date this version went live and a short note on what changed. Old versions stay archived if you need to compare wording.
Inline Contacts
Contact paths sit inside the policy itself, not buried on a separate page, so the moment a question forms you can act on it without hunting through the site.
Rights Summary
A compact rights summary near the top tells you what you can ask us to do with your data — access, correct, export, delete — before the longer clauses spell out the procedure.