At to228, your personal data is handled with the same care we give to platform security. This Privacy Policy explains exactly what information we collect, why we collect it, how we use it, and the rights you hold as a Member. We keep it straightforward — no legal maze, no surprises.
All data transmitted between your device and to228 is protected by 256-bit SSL encryption at all times.
to228 does not sell, rent, or trade your personal information to third-party marketers under any circumstances.
You may request access, correction, or deletion of your personal data at any time by contacting our support team.
We retain personal data only for as long as required to operate the platform and meet legal obligations.
Six core principles that shape every data decision we make at to228, from account registration through to account closure.
to228 collects the minimum personal data necessary to operate the platform, verify your identity (KYC), process IDR transactions, and comply with applicable regulatory requirements. We do not collect data gratuitously.
Your data is stored in encrypted databases with access controls limited to authorised to228 personnel. All platform traffic is served over HTTPS with industry-standard TLS protocols. Payment data is handled by PCI-DSS compliant processors.
Personal data is shared only with trusted third parties who are contractually obligated to handle it securely — specifically our KYC verification partner, payment processors (BCA, BRI, BNI, Mandiri, OVO, DANA, GoPay), and fraud prevention services.
Promotional emails, SMS notifications, and WhatsApp messages are sent only to Members who have opted in to marketing communications. You may withdraw consent at any time by updating your notification preferences in the account dashboard or by contacting support.
We keep your personal data for as long as your account is active and for a period of 5 years after closure to meet financial record-keeping obligations. After this period, personal identifiers are deleted or anonymised. Transaction logs may be retained longer where required by law.
As a to228 Member, you have the right to access a copy of your data, correct inaccurate records, request deletion of data no longer needed, and withdraw consent for marketing at any time. Submit requests to [email protected] with subject "Data Rights Request".
to228 ("we", "us", "our") is committed to protecting the privacy and personal data of all Members and visitors who interact with the to228 platform at to228.pro. This Privacy Policy describes our practices regarding the collection, use, storage, disclosure, and protection of personal information in connection with the operation of the to228 online betting and casino services.
This Policy applies to all data collected through the to228 website, mobile-optimised platform, customer support channels (live chat, email, WhatsApp), and any other interaction you have with to228 in connection with the Services. It covers all Members resident in Indonesia as well as any other individuals who access the platform.
We design our data practices around a simple principle: collect what is necessary, protect it rigorously, use it transparently, and give Members genuine control over their information.
For the purposes of this Privacy Policy, to228 is the data controller responsible for the personal data processed in connection with the platform's operation. All data protection queries, subject access requests, and privacy concerns should be directed to the to228 Data Protection contact at [email protected] with the subject line "Privacy / Data Protection".
The categories of personal data that to228 collects, depending on the nature of your interaction with the platform, are set out in the table below:
| Data Category | Specific Data Points | Purpose |
|---|---|---|
| Identity Data | Full legal name, date of birth, Indonesian National Identity Card (KTP) number, passport number (if applicable) | Account registration; KYC identity verification; age verification (21+) |
| Contact Data | Email address, Indonesian mobile phone number, residential address (city, province, postal code) | Account communication; withdrawal verification; customer support |
| Financial Data | Bank account number and bank name (BCA, BRI, BNI, Mandiri, etc.); e-wallet identifiers (OVO, DANA, GoPay, ShopeePay, LinkAja); deposit and withdrawal transaction records | Processing IDR deposits and withdrawals; fraud detection; AML compliance |
| KYC Documentation | Scanned or photographed copies of KTP or passport; selfie photographs; bank statement or account screenshot | Mandatory identity and ownership verification before first withdrawal |
| Technical / Device Data | IP address; device type and operating system; browser type and version; device fingerprint identifiers; session timestamps | Platform security; duplicate account detection; fraud prevention; service improvement |
| Behavioural / Usage Data | Games played; bet and wager history; deposit and withdrawal frequency; session duration; platform navigation patterns | Responsible gaming monitoring; personalised promotions (with consent); product improvement |
| Communications Data | Live chat transcripts; email correspondence; WhatsApp messages exchanged with to228 support | Customer service; dispute resolution; quality assurance |
| Marketing Preferences | Opt-in or opt-out status for email, SMS, and WhatsApp marketing communications | Sending promotional offers only to Members who have consented |
to228 collects personal data through the following means:
to228 uses your personal data for the following specific purposes:
Your identity, contact, and financial data are used to create and manage your account, verify your eligibility (age 21+, Indonesian residency), process deposits and withdrawals in IDR, settle bets and winnings, and deliver the full range of to228 Services.
KYC documentation and identity data are used to verify that each Member is who they claim to be, to prevent underage gambling, and to satisfy our obligations under applicable anti-money laundering (AML) and know-your-customer (KYC) frameworks.
Technical and behavioural data are used to detect duplicate accounts, identify suspicious betting patterns, prevent bonus abuse, and protect the integrity of the to228 platform and its Members. This includes automated monitoring and, where warranted, manual review by the to228 compliance team.
Behavioural and usage data are used to monitor for signs of problem gambling — including unusual increases in deposit frequency, session duration, or loss levels — and to trigger responsible gaming interventions such as account alerts, cooling-off recommendations, and support outreach. This processing is in the legitimate interest of Member welfare.
Communications data is used to resolve support queries, handle formal complaints, and maintain records of our interactions with Members for quality assurance and dispute resolution purposes.
Where you have given explicit consent, we may use your contact data and usage profile to send personalised promotional offers, bonus notifications, and platform news via email, SMS, or WhatsApp. You may withdraw this consent at any time at no cost to your account standing.
Aggregated and anonymised usage data is used to analyse platform performance, understand Member preferences, and develop new product features. Individual Members are not identifiable from this aggregated analysis.
to228 processes your personal data on the following legal bases:
to228 does not sell personal data. We share personal data only in the following controlled circumstances:
| Recipient Category | Purpose of Sharing | Data Shared |
|---|---|---|
| KYC Verification Partner | Identity document verification and age confirmation | Name, date of birth, KTP/passport images, selfie |
| Payment Processors (banks, e-wallets) | Processing IDR deposits and withdrawals | Name, bank account number, transaction amount |
| Fraud & Risk Prevention Services | Detecting fraudulent accounts and transactions | IP address, device fingerprint, transaction patterns |
| IT & Hosting Infrastructure Providers | Hosting the to228 platform securely | Encrypted account data within secured environments |
| Legal & Regulatory Authorities | Compliance with lawful requests or court orders | Data as specified in the legal request |
All third-party recipients are required by contract to handle personal data securely, to use it only for the purpose for which it was shared, and to apply data protection standards equivalent to those maintained by to228.
8.1 What Are Cookies. Cookies are small text files placed on your device by the to228 platform when you visit. They help us recognise your browser, maintain your login session, remember your preferences, and analyse how the platform is used.
8.2 Types of Cookies We Use.
8.3 Managing Cookies. You can manage or disable non-essential cookies via your browser settings. Note that disabling cookies may affect the functionality of certain platform features. Consent for analytics and marketing cookies can also be managed via your account notification preferences dashboard.
9.1 to228 retains personal data for as long as your account remains active and for a period of 5 years after account closure, to meet our financial record-keeping, AML compliance, and dispute resolution obligations.
9.2 KYC documents (identity cards, selfie verification images) are retained for the same 5-year post-closure period to satisfy identity verification audit requirements.
9.3 Marketing data and communication preferences are retained until you withdraw consent or close your account, after which they are deleted within 90 days.
9.4 After the applicable retention period, personal data is either securely deleted or irreversibly anonymised such that it can no longer be associated with you as an individual. Anonymised, aggregated analytics data may be retained indefinitely for platform improvement purposes.
to228 applies industry-standard technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:
While to228 applies robust security measures, no internet-based platform can guarantee absolute security. You play an important role in keeping your account secure by maintaining a strong, unique password and by notifying us immediately if you suspect unauthorised access to your account.
As a to228 Member, you have the following rights in relation to your personal data:
To exercise any of these rights, submit a written request to [email protected] with subject line "Data Rights Request — [Your Account Username]". to228 will acknowledge your request within 2 business days and provide a full response within 30 business days (WIB). Some requests may require identity verification before we can process them to protect your account security.
The to228 platform is strictly intended for adults aged 21 and above. to228 does not knowingly collect personal data from individuals under 21 years of age. If we become aware that personal data has been submitted by a person under 21, that account will be immediately closed, the data deleted, and any deposited funds returned to the originating payment method subject to verification.
If you are a parent or guardian and believe a minor has registered a to228 account, please contact us immediately at [email protected]. We will investigate and take appropriate action within 24 hours.
13.1 to228 primarily stores and processes Member data on servers located in secure data centres serving the Asia-Pacific region. In the course of operating the platform, your data may be accessed by or transferred to our service providers in other countries, including for KYC processing, payment infrastructure, and technical hosting.
13.2 Where personal data is transferred outside Indonesia to a country that may not provide the same level of data protection, to228 ensures appropriate safeguards are in place through contractual data protection agreements with those service providers, binding them to handle your data with standards equivalent to those described in this Policy.
14.1 to228 reserves the right to update this Privacy Policy at any time to reflect changes in our data practices, legal obligations, or platform functionality. Material changes will be communicated to registered Members via email or in-platform notification at least 14 days before the updated Policy takes effect.
14.2 The "Last Updated" date at the top of this page reflects the most recent revision. Your continued use of the to228 platform after the effective date of any changes constitutes acceptance of the revised Privacy Policy. If you do not accept the updated Policy, you may request account closure and the return of your verified account balance.
14.3 We recommend reviewing this page periodically. Archived previous versions of this Policy are available on request by contacting support.
For any questions, concerns, or formal requests relating to this Privacy Policy or to228's data protection practices, please contact us using the details below:
Our support team includes Indonesian-speaking agents available around the clock (24/7, WIB). For formal data rights requests, please use email to ensure a documented trail. to228 commits to acknowledging all privacy-related correspondence within 2 business days and responding substantively within 30 business days.
to228 combines robust data protection with Indonesia's best online betting experience — sportsbook, live casino, and 500+ slots, all in IDR. Transparent policies, fast withdrawals, and 24/7 Indonesian-speaking support. 21+ only. Play responsibly.