bdtoto666 Privacy Policy

This page describes what we collect when you use bdtoto666 and how we keep that data protected. We collect personal information only to operate our platform, process your payments, verify your identity, and comply with law. We do not sell your data to third parties and apply encryption to all sensitive details.

When you register an account on bdtoto666, deposit funds, or withdraw winnings, you provide us with name, email, phone number, and banking details. We use this information solely to operate your account, prevent fraud, and fulfil regulatory obligations. Our servers handle encrypted transmission of all sensitive data—passwords, payment information, identity documents.

This policy outlines the categories of data we collect, how we use them, how long we retain them, and your rights regarding your personal information. Our services are available only where local law permits, and we comply with data protection regulations in all jurisdictions where we operate.

What Data We Collect and Why

When you open an account on bdtoto666, we collect your legal name, date of birth, email address, and phone number. These details are necessary to create and secure your account, contact you regarding your account status, and verify your identity before withdrawals. We also collect your IP address and device identifiers (e.g., Android/iOS device ID) to detect fraud, prevent duplicate accounts, and track account access patterns.

When you deposit or withdraw funds, we collect payment details—your bank account number, e-wallet credentials, or QRIS account identifier. We tokenize these details (convert them into secure reference tokens) so our servers never store full account numbers in plaintext. Payment processors like e-wallet, mobile banking, local payment, online payment, e-wallet, and your bank (mobile banking, local payment, online payment, e-wallet) handle the actual transaction; we retain only encrypted payment confirmation records.

We collect gameplay data—your wagers, game outcomes, timestamps, and dealer names—to generate your Result Table and account history. This data allows you to review past sessions and helps us resolve disputes. We also log support interactions (chat messages, emails) to track issues and improve our service.

Account registration
Name, date of birth, email, phone, IP address, device ID.
Payment information
Tokenized bank / e-wallet details. Full numbers never stored.
Game activity
Wagers, outcomes, timestamps, dealer IDs logged to Result Table.
KYC documents
Photo ID (passport / national ID) stored encrypted for verification.

How We Use Your Data

We use your data for these purposes: (1) Account operations—creating accounts, processing logins, managing your balance, recording transactions. (2) Payment processing—communicating with banks and e-wallet providers to complete deposits and withdrawals. (3) Fraud prevention—detecting duplicate accounts, monitoring for suspicious activity, and verifying your identity before withdrawals. (4) Legal compliance—responding to regulatory requests, maintaining audit trails, and upholding anti-money-laundering (AML) obligations.

We do not use your data for marketing or selling to third parties. We do not share your gameplay history with other users or public platforms. We do not track your off-platform behaviour or sell your information to data brokers. Any communication we send is account-related (password reset, withdrawal confirmation, support replies) or regulatory (KYC requests).

If you access bdtoto666 from Jakarta, Surabaya, Bandung, Medan, or Semarang during major events like Idul Fitri or Idul Adha, we may use aggregate analytics (overall transaction volume, peak hours) to improve platform stability—but this is anonymized and does not reveal individual user patterns.

How Long We Keep Your Data

We retain your account data (name, email, phone) as long as your account exists and for a retention period thereafter (typically 12 months after account closure) for dispute resolution and regulatory compliance. Payment transaction records are kept for the same period to verify withdrawal history and prevent fraud. Your KYC documents (identity photos) are retained for the full retention period and then securely deleted.

Game outcome data (Result Table entries) is retained permanently so you can review your session history at any time. This permanent retention supports dispute resolution—if a question arises about a specific hand months later, the record remains available. Deleted accounts no longer have access to their data, but records are archived separately for compliance purposes.

Support chat logs are retained for 12 months. Server logs (IP addresses, connection timestamps) may be retained for shorter periods (typically 90 days) for security purposes. We do not retain data longer than necessary for each stated purpose.

How We Protect Your Data

All data transmitted between your device and our servers is encrypted using SSL/TLS (Secure Sockets Layer / Transport Layer Security). This means login credentials, payment details, and personal information are scrambled in transit and cannot be intercepted. Your password is hashed using strong algorithms; we do not store plaintext passwords.

Our servers use AES-256 encryption for data at rest. Payment information is tokenized—our systems never see or store full card numbers or bank account numbers, only secure tokens. Access to your account data is restricted to authorized bdtoto666 staff only (support agents, operations team) and is logged for audit purposes.

We implement multi-factor authentication options—you can enable additional security verification on login. If you suspect unauthorized access, contact our support team immediately; we can lock your account, reset your password, and review access logs from that moment onward.

Third-Party Processors and Data Sharing

We work with third-party service providers who process your data on our behalf: payment processors (banks, e-wallet operators), cloud hosting providers (who store our encrypted database), and customer support platforms. These processors are contractually bound to protect your data and use it only for the services we request. They do not sell or share your information.

We may disclose your data if required by law—for example, if a court orders us to provide information during a legal proceeding, or if a regulatory authority requests data to investigate fraud. We will notify you of such requests where legally permitted.

We do not share your data with marketing partners, advertisers, or analytics companies. Aggregate statistics (total active users, game distribution) may be published internally or to partners for platform reporting, but these contain no personally identifiable information.

Your Rights Regarding Your Data

You have the right to request access to all personal data we hold about you on bdtoto666. Contact our support team with a data-access request and we will provide a copy of your information within 30 days. You also have the right to request correction if your information is inaccurate—for example, if your phone number is out of date, we will update it upon verification.

You may request deletion of your account and associated data. We will delete most information (email, phone, payment details) within 30 days, though we may retain transaction records where required by law or for fraud prevention. Your deletion request is final; we cannot recover a deleted account.

You have the right to data portability—we can export your account data (transaction history, Result Table entries) in machine-readable format. You also have the right to object to certain uses of your data; contact us if you have concerns about how we process your information.

Key privacy practices on bdtoto666

  • We collect only data necessary to operate your account and process payments
  • All data transmission is encrypted (SSL/TLS); sensitive data at rest is encrypted (AES-256)
  • We do not sell your data to third parties or use it for marketing
  • Payment details are tokenized—full card/bank numbers never stored
  • Game outcomes remain permanently available for your review and dispute resolution
  • You may request access, correction, deletion, or export of your data
  • We comply with legal requests from regulatory authorities

Cookies and Tracking Technologies

We use cookies to maintain your login session and remember your preferences (language, theme, interface layout). These cookies are essential for platform functionality—without them, you would need to log in on every page load. Cookies remain on your device and do not collect personal information; they store encrypted session tokens.

We do not use third-party cookies for advertising or behavioural tracking. We do not participate in retargeting campaigns or sell behavioural data to advertisers. Our analytics are internal only—we track aggregate metrics (page load times, feature usage) to improve performance, not to profile individual users.

You can disable cookies in your browser settings, but this will prevent bdtoto666 from functioning properly. If you clear cookies, your session will end and you will need to log in again.

International Data Transfers

Our servers and databases may be located outside your jurisdiction (e.g., data stored in a data centre in Singapore while you access from Indonesia). By using bdtoto666, you consent to your data being stored and processed internationally. We apply the same encryption and protection standards regardless of server location.

If you have concerns about your data being stored outside your country, contact our support team. We can discuss data residency options where legally feasible, though cross-border processing is sometimes necessary for platform operations and payment processing.

Changes to This Privacy Policy

We may update this privacy policy periodically. Changes take effect when posted to this page. If changes significantly affect how we process your data, we will notify you via email. Your continued use of bdtoto666 after policy changes constitutes acceptance of the updated policy.

Contact Us About Privacy

If you have questions about how we handle your data, wish to exercise your rights (access, correction, deletion, portability), or have privacy concerns, contact our support team via in-app messaging or email. We respond to privacy requests within 30 days. For data-access requests, we may ask for additional verification to ensure you are the account holder.

If you believe we have violated your privacy rights or handled your data unlawfully, you may escalate to the relevant data protection authority in your jurisdiction. We cooperate with such investigations and take privacy concerns seriously.

Related pages