Reference

How level303 Protects Your Personal Data

Your personal data belongs to you, and we have built every step of your account flow — from registration through to DANA, OVO, GoPay and QRIS transactions —…

Encrypted account storageDANA, OVO, GoPay & QRIS data handled separatelyData access requests accepted via live chatRetention periods clearly definedCookie controls in account settings
level303 How level303 Protects Your Personal Data
PRIVACY CONTACT PATHS

How to Reach Us About Your Data

If you want to request a copy of your data, ask us to correct an error, or raise a concern about how your information is handled, our privacy team is reachable through three direct channels. Whether you are in Surabaya or anywhere else in Indonesia, responses to data requests are sent within 5 business days of receipt.

Team online

Live Chat

Available daily 08:00–23:00 WIB. Start a chat from any page on level303.xyz and ask to be connected to the privacy team directly — no ticket queue for data requests.

Email Support

Send your data request to the privacy address listed in your account dashboard. Include your registered email and the specific request type so we can action it without delays.

Account Settings Panel

Log in, navigate to Settings › Privacy, and submit a data access or deletion request directly. This path creates an auto-logged ticket and generates a reference number for you.

DATA HANDLING PRACTICES

Six Ways We Safeguard Your Account Data

Concrete practices — not abstract promises — define how we handle your information. Each of the six areas below reflects an actual operational control built into the level303 platform, from the moment…

End-to-End Encryption

All data transmitted between your device and our servers uses TLS 1.3. Account credentials, identity documents and payment references are encrypted both in transit and at rest on our infrastructure.

Cookie Controls

We use session cookies for login state, analytics cookies to measure lobby performance, and no advertising cookies from third-party ad networks. You can adjust or withdraw cookie consent at any time under Settings › Privacy.

Payment Data Isolation

DANA, OVO, GoPay and QRIS transaction data flows through each provider's own API. We store only the reference ID and timestamp — your full wallet number or bank detail is never written to our database.

Data Retention Schedule

Active account data is retained for the lifetime of your account plus 12 months. Identity verification documents are deleted 24 months after your account closes, unless a longer period is required by applicable regulation.

Access Request Fulfilment

You may request a full export of the personal data we hold on you via the Account Settings panel or by emailing our privacy team. We aim to deliver the export file within 5 business days.

Third-Party Disclosure Policy

We do not sell, rent or trade your personal data. Data is shared with payment processors and identity-verification providers only to the extent needed to run your account, and each partner is bound by a data-processing agreement.

Your Privacy Policy Questions

Below are the questions we hear most often from people managing their account privacy on level303. Each answer reflects the actual controls and processes in place — not boilerplate language.

We collect your name, email address, date of birth, country and preferred payment method. If identity verification is required by applicable rules, we also collect a government-issued ID document, which is encrypted and stored separately from your account profile.

No. When you transact via DANA, OVO, GoPay or QRIS, the payment is processed through each provider's secure API. We retain only the transaction reference ID and timestamp — your wallet number or card detail is never written to our systems.

Log in, go to Settings › Privacy, and select 'Request Data Export'. You will receive a structured file within 5 business days. Alternatively, contact the privacy team via live chat between 08:00 and 23:00 WIB.

Yes. Submit a deletion request through Settings › Privacy or email the privacy team. Deletion is processed within 10 business days. Note that certain transaction records may be retained longer where applicable regulation requires it.

We share data only with payment processors such as DANA, OVO, GoPay and QRIS, and with identity-verification providers, strictly to operate your account. Each partner signs a data-processing agreement. We never sell or trade your information.

Open Settings › Privacy on any device and adjust the cookie toggle. Session cookies required for login cannot be disabled, but analytics cookies can be switched off at any time and the change takes effect immediately on your current session.

Active account data is kept for 12 months after closure. Identity documents are deleted after 24 months unless a longer retention period is required under applicable regulation. You will receive a confirmation email when deletion is complete.