How timah33 Handles Your Account Data
This is the privacy policy that sits behind every timah33 account you open. We've written it in plain language so you can see exactly what we collect when...
Our Privacy Posture and Scope
We collect the information needed to run your timah33 account: your registration details, device fingerprint, session logs, and the transaction references attached to DANA, OVO, GoPay or QRIS deposits. We process this data where local law permits and only inside supported regions for Indonesia. KYC documents are encrypted at rest and shared only with licensed payment partners and regulators when a request
is formally filed. Marketing preferences stay opt-in. You can ask us to export, correct or erase your record at any time, and we'll action it within the windows your jurisdiction sets out for personal data handling.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
How We Review This Policy
Quarterly Legal Review
Our in-house legal team rereads this policy every quarter against Indonesia data protection updates, and we version-stamp the page so...
Encrypted Storage
Account credentials, KYC scans and payment metadata sit on encrypted volumes with rotating keys. Only the systems that need a...
Named Data Officer
A named data protection officer signs off on cross-border transfers and partner integrations. Their contact route is published inside this...
Vendor Vetting
Every payment, KYC and analytics vendor we add goes through a written assessment before they touch a single timah33 record...
Breach Protocol
If a privacy incident is detected, we have a 72-hour notification clock for affected accounts and the relevant authority, with...
Consent Logs
Every consent you give — marketing emails, cookie categories, SMS pings — is timestamped and reversible. We keep the log...