xtoto Casino & Sportsbook Data Care

This page describes what we collect when you use xtoto and how we keep that data protected. We gather personal information—your email, phone number, identity documents—only to set up your account, process deposits and withdrawals, verify your identity for compliance, and support you if something goes wrong. We do not sell your data to advertisers or data brokers, and we do not share it with third parties unless the law requires us to.

Our servers may sit outside your jurisdiction (e.g., in Southeast Asia or Europe), but we encrypt your data in transit and at rest using industry-standard protocols. Your password is hashed so thoroughly that even xtoto staff cannot view it. If you request access to your data, or ask us to delete it, we honour those requests within the timeframe set by local law.

Our services are available only where local law permits. Users are responsible for verifying that access and use comply with their own jurisdiction's law.

What Data We Collect on xtoto

We collect information in two ways: what you give us directly, and what we gather automatically as you use xtoto. When you register, we collect your email address, username, password (encrypted), date of birth, and phone number (optional). For deposits via DANA, e-wallet, mobile banking, local payment, online payment, or e-wallet, we record the payment method, amount, and timestamp—but we do not store your payment app credentials or bank account details on our servers (those are handled by payment processors).

For your first withdrawal, we require identity verification. You upload a photo ID and proof of address; we store encrypted copies on secure servers and delete them after a retention period set by anti-money-laundering law. Automatically, we log your login times, IP address, device type (Android, iOS, browser), and game activity (which games you play, how long you play, your wins and losses). This data helps us detect fraud, improve app performance, and comply with regulatory reporting.

How We Use Your Data on xtoto

We at xtoto use your data for six main purposes. First, account management—setting up your login, processing password resets, and helping you recover a compromised account. Second, transaction processing—handling your deposits to mobile banking, local payment, online payment, or e-wallet and your withdrawals. Third, compliance—verifying your identity under anti-money-laundering rules, reporting suspicious activity to authorities if required, and keeping records for regulatory audits.

Fourth, customer support—answering your questions via live chat or email and investigating disputes (e.g., a bet you believe was settled incorrectly). Fifth, security—monitoring for fraud, detecting account abuse, and protecting xtoto's platform from attack. Sixth, analytics—counting how many users are active, which games are popular, and when our servers face heavy load, so we can improve the platform. We do not use your data to build profiles for targeted advertising, and we do not sell it to third parties.

Promotional emails: We may send you emails about promotions, new games, or Liga 1 tournament updates, but only if you have opted in. You can unsubscribe from promotional emails anytime via a link in the email itself or through your account settings on xtoto.

Third-Party Processors and Data Sharing

We share your data with trusted third parties who help operate xtoto. Payment processors (for mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, and bank transfers) receive your name, amount, and transaction reference—they need this to complete your deposit or withdrawal. Our hosting provider (where our servers sit) has access to encrypted data but is contractually bound not to view or share it. Our email service provider sends you account confirmations and support responses, but cannot see your password or payment details.

Live-dealer game studios (where we stream roulette, blackjack, baccarat, and Dragon Tiger tables) may see your username and bet amounts during gameplay, but we do not share your identity documents or financial data with them. In rare cases, we may disclose data to law enforcement or government agencies if legally required (e.g., a money-laundering investigation), and we will notify you unless the law forbids us to.

Cookies and Tracking on xtoto

Our xtoto website and app use cookies (small files stored on your device) to keep you logged in, remember your preferences, and measure how users interact with our platform. Essential cookies are necessary for xtoto to work—without them, you could not log in or place a bet. Analytical cookies help us understand which pages are popular and where users struggle, so we can improve the experience. We do not use tracking cookies to follow you across other websites.

You can disable non-essential cookies in your browser settings, but this may break some xtoto features (e.g., you might be logged out after each page). Our app automatically clears cookies when you log out, so your data is not left behind on a shared phone. If you use xtoto from Jakarta, Surabaya, Bandung, or Medan via a shared device, always log out before handing the phone to someone else.

Essential cookies
Session tokens that keep you logged in to xtoto; these expire when you log out or close your browser.
Preference cookies
Remember your chosen language, theme (light/dark), and notification settings on xtoto.
Analytical cookies
Track page views and user journeys so we can measure xtoto's performance and fix slow features.
Security cookies
Flag suspicious login attempts or unusual account activity on xtoto to protect against fraud.

Your Rights Regarding Data on xtoto

Under privacy law (e.g., GDPR if you are in the EU, or similar local laws), you have rights over your data. You can request access to all data we hold about you—we will provide it in a portable format within 30 days. You can request correction if your name or address is wrong. You can request deletion of your data (right to be forgotten), though we may need to keep some records for legal compliance or fraud investigation.

To exercise these rights on xtoto, contact our support team via live chat or email (accessible in the app). Provide your username and the specific request (access, correction, or deletion). We will verify your identity and respond within 30 days. If we cannot fully comply (e.g., because law requires us to keep data for anti-money-laundering purposes), we will explain why and offer alternatives where possible.

Data Retention and Deletion on xtoto

We at xtoto keep your account data as long as your account is active. Once you request account closure, we anonymise or delete most personal data within 90 days, except where law requires us to keep records. For example, we must retain transaction logs and identity verification documents for five to seven years to comply with anti-money-laundering regulations. We also keep activity logs (login history, game records) for at least two years to investigate disputes.

If your account is inactive (no login for two years), we may delete your account and associated data, except for transaction records required by law. We will notify you by email before deletion if your registered email is still valid. If you want to delete your account earlier, contact xtoto support and we will process your closure request, subject to any outstanding bets or pending withdrawals.

International Data Transfers

Our xtoto servers and backups are located in Southeast Asia and possibly Europe. If you are outside these regions, your data crosses international borders when you use xtoto. We protect data in transit using encryption (TLS 1.2+), and we use standard contractual clauses or other legal mechanisms to ensure the receiving country offers adequate protection. Your data may also be processed by our payment partners, who may hold servers in different countries—each partner is contractually bound to apply the same security standards we use.

Contact xtoto About Your Data

If you have questions about how xtoto handles your data, want to exercise your privacy rights, or believe we misused your information, contact our privacy team via the support section of the xtoto app or website. Live chat is available Monday to Friday, 9 AM to 10 PM Jakarta time. For detailed requests (access, deletion), send an email to the support email address visible in the app—include your xtoto username, the date you created your account, and a clear description of your request.

We will acknowledge your request within 5 business days and provide a response within 30 days. If we cannot fully grant your request, we will explain why and offer what assistance we can. This privacy policy may be updated occasionally to reflect new features, laws, or security practices—we will notify users by email of material changes and give you 30 days to review before the new policy takes effect.