Cookie Notice
The cookie banner you accept on first visit reflects the same categories described here: strictly necessary, preference, and analytics. Marketing cookies stay off until you opt in.
This is the qqmacan privacy policy — a plain read of what we collect when you open an account, why we keep it, and how long it stays...
We process your details under the rules that apply where local law permits, and we limit collection to what your account actually needs: identity check fields, contact handle, device signal, and the wallet reference you pick at cashier. Your DANA, OVO, GoPay or QRIS handle is held only to route the transaction and reconcile your balance. We do not sell your data.
Third-party processors that touch your record — KYC, payment rails, fraud screening — are bound by written terms in supported regions. You can ask us to export, correct or erase your record at any time, subject to retention rules we must follow.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
Reach our privacy desk through any of the channels below. We answer in Bahasa Indonesia or English, and we log every request so you have a paper trail.
Our policy text is reviewed each quarter by an internal editor who checks that wording matches actual practice in the cashier, KYC flow and lobby cookie banner you see today.
External counsel familiar with Indonesia data rules signs off material changes before we publish, so what you read here is not a template lifted from another brand.
Every revision carries a date stamp at the foot of this page. You can ask support for an older version if you want to compare what changed between two sign-in dates.
We keep a current list of sub-processors handling your account data, payment routing and fraud checks. The list is shared on request through the privacy inbox.
If your record is ever exposed, we notify you by email and on-site banner with the facts we know, the scope, and the steps we are taking — no marketing language, no delay.
Anyone on our team who can see your account data completes privacy training before access is granted, and re-certifies annually so handling stays consistent across shifts.
The cookie banner you accept on first visit reflects the same categories described here: strictly necessary, preference, and analytics. Marketing cookies stay off until you opt in.
Our terms reference this policy by name when account data is involved, so the two documents do not contradict each other on retention or third-party sharing.
The identity check screen restates which document fields we keep, how long, and why — matching the retention table further down this policy.
At deposit and withdrawal, the cashier shows which wallet handle we store and links back to this page so you can re-read before confirming.
Email and push opt-ins are managed from your account panel, and our outbound messages match the consent state recorded in the same database referenced here.
When a partner refers you, the tracking parameters they pass are described in the cookie notice and aligned with the data minimisation stance written into this policy.
Closing your account triggers the retention clock described below, and the closure confirmation email repeats the same window so there is no surprise.