Reference

How dexwin Protects Your Personal Data

Your personal data belongs to you — we collect only what we need to run your account, process payments via DANA, OVO, GoPay, and QRIS, and respond to…

Data encrypted at rest and in transitDANA, OVO, GoPay & QRIS payment data handled separatelyRetention period capped at 5 yearsAccount deletion on written requestNo data sold to third parties
dexwin How dexwin Protects Your Personal Data
PRIVACY CONTACT PATHS

How to Reach Our Privacy Team

If you want to review the personal data we hold, request a correction, or ask us to delete your account entirely, our privacy support team is reachable around the clock. You can also contact us from Bandung or anywhere else in Indonesia — response times are the same regardless of your city. Send your request through any of the three channels below and we aim to respond within 48 hours.

Team online

Live Chat

Open the chat widget on dexwin.best and type 'privacy request' to reach a dedicated data-handling agent. Available 24 hours a day, 7 days a week, including Indonesian public holidays.

Email

Send a written data request to our privacy inbox at [email protected]. Include your registered account email and the specific action you need — correction, export, or deletion — and we will confirm receipt within 24 hours.

In-Account Request Form

Log in, go to Account Settings, choose 'Privacy & Data', and submit your request directly. This method links your identity automatically, so processing is typically faster than the email route.

DATA HANDLING PRACTICES

Six Ways We Keep Your Data Safe

We have structured our data-handling around six core practices that cover everything from the moment you open an account to the day you ask us to close it.

Account Registration Data

When you open an account, we collect your email address, chosen username, and country of residence. We do not ask for your full national ID unless a withdrawal verification step requires it under applicable regulation.

Payment Data Handling

Deposits via DANA, OVO, GoPay and QRIS are routed through a PCI-DSS-compliant payment gateway. We store only the transaction reference and timestamp — never your full wallet credentials or card number.

Cookie & Tracking Policy

We use session cookies to keep you logged in and analytics cookies to understand which pages load slowly on mobile. You can disable analytics cookies in your browser settings without affecting your ability to deposit or withdraw.

Account Security Measures

Your account password is hashed using bcrypt before storage — we cannot read it. We also support two-step login verification via email OTP, which we recommend enabling from the Security section of your account settings.

Data Retention Period

We keep your account data for up to 5 years after your last login, in line with Indonesian financial-record requirements. After that window, data is automatically purged from our production database unless a regulatory hold applies.

Third-Party Data Sharing

We share your data only with payment processors (for DANA, OVO, GoPay, QRIS transactions), fraud-detection services, and regulators where local law requires disclosure. We do not sell or rent your data to marketing agencies.

Your Privacy Questions, Answered by dexwin

We have gathered the questions our account holders ask most often about data privacy, cookies, and their right to access or delete personal information. If your question is not covered below, use the Live Chat or email channels listed on this page.

We collect your email address, chosen username, and country of residence at registration. If a withdrawal requires identity verification under local regulation, we may ask for a government-issued ID at that step only — not upfront.

No. When you deposit via DANA, OVO, GoPay, or QRIS, only the transaction reference number and timestamp are stored in our system. Your full wallet credentials stay within the respective payment provider's encrypted environment.

Log in to your account, navigate to Account Settings, then 'Privacy & Data', and select 'Request Data Export'. We will send a structured file to your registered email within 5 business days of the confirmed request.

Yes. Submit a written deletion request via the in-account Privacy form or email [email protected]. We will close the account and purge personal data within 30 days, except records we are required to retain under Indonesian financial regulation.

We use session cookies (required for login) and optional analytics cookies. You can disable analytics cookies through your browser settings at any time. Disabling them will not prevent you from depositing via QRIS or accessing your account normally.

We share data only with payment processors handling DANA, OVO, GoPay and QRIS transactions, fraud-screening services, and regulatory authorities where local law requires it. We do not sell your data to advertisers or any marketing third party.

We retain account data for up to 5 years after your last verified login, in line with Indonesian financial-record requirements. Once that period ends, your data is automatically removed from our active database unless a regulatory hold is in place.