Reference

How kl sore Protects Your Personal Data

At kl sore, your personal data — from account registration details to payment records linked to DANA, OVO, GoPay and QRIS — is handled under a clear, documented…

Encrypted account storageDANA, OVO, GoPay, QRIS transaction privacyData access on requestNo third-party sale of your dataRetention schedule disclosed
kl sore How kl sore Protects Your Personal Data
PRIVACY CONTACT PATHS

How to Reach Us About Your Data

If you have a question about this privacy policy, want to correct information on your account, or need to submit a data deletion request, our privacy support team is reachable through the…

Live Chat Available 08:00–23:00 WIB daily. Start a chat from the account dashboard and select Privacy Request from the topic menu — a privacy officer picks it up within minutes during operating hours.
Email Support Send your data access or deletion request to our privacy inbox. We confirm receipt within four hours and deliver a full written response within two business days, including a summary of what we hold.
Account Settings Path Log in, navigate to Settings → Privacy & Data, and submit a self-service data export or correction request directly. The export file arrives in your registered email within 24 hours of submission.
DATA HANDLING STANDARDS

Six Ways We Keep Your Information Safe

Our privacy practices are built around six concrete commitments — covering how your data moves through our systems, how long we keep it, and what controls you hold over it.

End-to-End Encryption

All data in transit between your device and our servers uses TLS 1.3 encryption. This applies whether you are depositing via DANA on a mobile browser or checking your withdrawal history on desktop.

Cookie Transparency

We use session cookies to keep you logged in and analytics cookies to improve page performance. You can review and revoke non-essential cookie consent from the Privacy & Data section of your account settings at any time.

Account Security Controls

Two-step verification is available for every account. We recommend enabling it under Settings → Security. Login attempts from unrecognised devices trigger an email alert to your registered address before access is granted.

Data Retention Schedule

Transaction records — including QRIS and GoPay payment references — are retained for 24 months to support reconciliation. After that period, records are anonymised and removed from active systems unless local law requires longer retention.

No Third-Party Data Sale

We do not sell, rent or trade your personal information to any third party for marketing purposes. Data shared with payment processors like OVO is limited to the minimum fields required to complete your specific transaction.

Your Right to Request Changes

You may request correction, export or deletion of your personal data at any time. Requests submitted before 17:00 WIB on a business day are actioned the same day; later submissions are processed by noon the following business day.

Frequently Asked Questions About Your Privacy

These are the questions we receive most often about how kl sore manages personal data. Each answer reflects our actual policy procedure — not a generic placeholder — so you know exactly what to expect when you interact with your account or submit a privacy request.

We collect your name, email address, date of birth, and a masked reference from your chosen payment method — DANA, OVO, GoPay or QRIS. We also log device identifiers and session timestamps to keep your account secure.

We share only the minimum data required with payment processors — for example, a transaction token with OVO to complete your deposit. We do not share your data with advertisers or sell it to any external party for any purpose.

Transaction records, including QRIS scan logs and GoPay payment references, are kept for 24 months. After that, they are anonymised and removed from active databases, except where local law requires a longer retention period.

Log in and go to Settings → Privacy & Data, then select 'Request Data Export'. A complete file of your personal data is delivered to your registered email address within 24 hours of submission — no form required.

Yes. Submit a deletion request via Settings → Privacy & Data or email our privacy inbox. We action requests within two business days. Deletion depends on local law — some transaction records must be retained for regulatory compliance before erasure.

We use strictly necessary session cookies to maintain your login, and optional analytics cookies to improve page speed. You can withdraw consent for non-essential cookies at any time from the Privacy & Data section of your account settings.

Contact our live chat team immediately — available 08:00–23:00 WIB — and select 'Security Issue' from the topic menu. We can freeze your account, audit access logs and issue a new verification code within minutes of your report.