Reference

What Our Legal Terms Mean for Your Account

These terms set out how nestoto operates for you — your rights around account data, how we handle wallet transactions through DANA, OVO, and GoPay, and what applies based on where you access the platform.

Account eligibility by regionDANA, OVO, GoPay transaction scopeData rights and retention policyCookie and session handlingContact path for legal requests
nestoto What Our Legal Terms Mean for Your Account
HOW WE HANDLE THIS

Data, Cookies, Security and Your Rights

Nestoto applies account security and data handling practices that reflect how people actually use the platform in Indonesia — including wallet-connected sessions via DANA, OVO, and GoPay, and mobile-first access patterns. Here is how each area works in practice.

Account Security

Each login session uses OTP verification tied to your registered number. Session tokens expire after inactivity. Any wallet-linked account change — such as updating your GoPay number — triggers a separate re-verification step.

Data Retention

We retain your account data for as long as your account is active and for a period after closure as required by applicable rules. Transaction records from DANA, OVO, or GoPay deposits are kept as part of your account history.

Cookies and Sessions

We use session cookies to keep you logged in across pages and analytics cookies to understand how the platform is used. You can manage cookie preferences from your account settings at any time.

Your Rights

You can request a copy of the data we hold on your account, ask us to correct inaccurate records, or request deletion where no legal obligation requires us to keep it. Use the legal request form or email us directly.

REACH US DIRECTLY

Contact Paths for Legal and Policy Questions

If you have a specific question about how our terms apply to your account — including wallet data from DANA, OVO, or GoPay — or if you want to request a data review, these are the direct channels to use. We keep legal contact separate from general account support so your request reaches the right team without delay.

Legal Email Send your legal or policy query by email. Include your account ID and the specific term or data point you are asking about so we can respond accurately and without back-and-forth.
Account Support Chat For wallet-linked concerns — such as how your DANA or OVO transaction data was recorded — start a chat from within your account dashboard. Our team can locate your records directly.
Legal Request Form Use the in-platform legal request form to submit a data deletion, access, or correction request. You will receive a reference number to track progress on your submission.

What You Actually Want to Know About Our Policy

These are the questions we get most often about how our legal terms work in practice — covering data access, wallet records, eligibility, and how to contact us when something needs reviewing.

Access and eligibility depend on local law in your region. Where local regulation restricts access, those rules apply. We do not override local law with our platform terms.

We record the transaction amount, timestamp, and wallet type used. We do not store your full wallet credentials — only what is needed to match the deposit to your account record.

Yes. Submit a data access request through the legal request form in your account dashboard. Include your account ID so we can locate your records and respond accurately.

Use the legal request form or contact us by email. We will process deletion where no legal or regulatory obligation requires us to retain the record. You will receive a reference number.

We retain transaction records for the period required under applicable rules after account closure. After that period, data is deleted or anonymised in line with our retention policy.

We post notice of significant changes in the legal section of the platform before they take effect. Continuing to use your account after that date means you accept the updated terms.
Reference

Legal

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.