How rgocash Handles Your Account Data
This is the rgocash privacy policy — the document that explains what we collect when you open an account, why we hold it, and how long it stays...
Our Policy Posture and Jurisdiction Notes
We process your personal data under the privacy rules of your jurisdiction, applied where local law permits. That means your name, contact details, device fingerprint and wallet identifiers are held only for the purposes we set out: account verification, fraud checks, payout routing and policy compliance. For supported regions in Indonesia, we map wallet linkage data from DANA, OVO, GoPay and QRIS
to your single rgocash account, never to third-party advertising profiles. You can request access, correction or deletion of your record at any time, and we respond inside the windows our policy commits to. Cross-border transfers occur only with safeguards in place, and we never sell your data.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
Privacy Contact Paths
If a clause is unclear or you want to action a data right, reach our privacy desk directly. These channels are staffed by the team that owns this policy, not the general...
How This Policy Is Reviewed
Our privacy text isn't a one-time upload. A named team revisits it on a fixed cadence, signs off changes, and publishes a dated version note so you can track what shifted between...
Named Reviewer
A data protection lead signs every revision of this policy. Their role title appears in the changelog footer so you know the clauses have a human owner, not just a template.
Quarterly Audit
We audit the policy each quarter against current Indonesia personal data rules and the wallet-side terms published by DANA, OVO, GoPay and QRIS, then patch any drift before the next release.
Version History
Each published policy carries a version number and a short summary of what changed. Older versions remain accessible on request so you can compare against the text in force when you signed up.
External Counsel
Material clauses — data retention, cross-border transfer, breach notification — are reviewed by external counsel familiar with Indonesia jurisdiction before we ship them to the live policy page.
Breach Protocol
A written incident protocol governs how we notify you if account data is exposed. Timelines, channels and remediation steps are fixed in the policy rather than improvised after the event.
Staff Training
Anyone who touches your record completes annual privacy training. Access is logged, scoped to job function, and reviewed against the principles this policy commits us to upholding for your account.
Consistency Across Our Policy Pages
We keep this privacy text aligned with the sibling legal pages so you don't get conflicting answers depending on which document you opened.
What Defines This Policy Page
A privacy page only works if you can actually read it. We've shaped this one around scannable structure rather than legal density, so the clauses that affect your...