Reference

How nagasaon Handles Your Personal Data

At nagasaon, we collect only the data we need to run your account and process transactions through DANA, OVO, GoPay, and QRIS — nothing more.

Data collected only as neededDANA, OVO, GoPay & QRIS contextYour right to request deletionIndonesia-based data handling24/7 privacy contact channel
nagasaon How nagasaon Handles Your Personal Data
PRIVACY CONTACT PATHS

How to Reach Our Privacy Team

Our dedicated privacy team is reachable every day from 08:00 to 24:00 WIB, and you can reach us through three direct channels.

Live Chat Open the chat widget in the bottom-right corner of any nagasaon page.
Email Privacy Desk Send your request to our dedicated privacy address with your registered email in the…
In-Account Request Form Log in, navigate to Account Settings, then select Privacy & Data.
HOW WE PROTECT YOUR DATA

Data Handling, Cookies, and Account Security

We layer technical and procedural controls across every stage of data handling — from the moment you submit a QRIS code to the moment your session token expires.

Encryption in Transit

Every data exchange between your device and our servers uses TLS 1.3 encryption. This covers account login, payment initiation via DANA or OVO, and any form submission — so data cannot be read if intercepted in transit.

Cookie Policy

We use strictly necessary cookies to maintain your session, and optional analytics cookies to understand how pages are navigated. You can withdraw consent for optional cookies at any time through the cookie banner on our site without affecting your account access.

Data Retention Schedule

Transaction records tied to GoPay and QRIS payments are retained for five years to meet financial audit requirements. Session logs are automatically purged at 90 days. Account profile data is deleted within 30 days of a confirmed account-closure request.

Access Controls

Internal access to your personal data is restricted to staff whose role specifically requires it — for example, payment reconciliation agents or account-security reviewers. We log every internal data access event and audit those logs quarterly.

Third-Party Sharing

We share data with our payment processors — DANA, OVO, GoPay, QRIS — only to the extent needed to complete your transaction. We do not sell personal data to advertisers or unaffiliated third parties under any circumstance.

Your Right to Correction and Deletion

You may request a full export of your stored data, ask us to correct inaccurate records, or initiate a deletion request at any time via Account Settings or our email privacy desk. We confirm completion in writing within seven working days.

Frequently Asked Privacy Questions

Below are the questions we receive most often about how nagasaon handles personal data. If your question is not listed here, reach us through live chat (08:00–24:00 WIB) or our email privacy desk — both channels are staffed by agents trained specifically on data and privacy matters.

We collect your name, email, phone number, and device identifiers at registration. Once you transact via DANA, OVO, GoPay, or QRIS, we also log transaction references and timestamps for wallet reconciliation. We do not collect payment credentials directly.

Transaction records — including those linked to DANA, OVO, GoPay, and QRIS payments — are retained for a minimum of five years to meet financial audit requirements. Session logs are purged after 90 days. Profile data is removed within 30 days of account closure.

Yes. Log in, go to Account Settings, and select Privacy & Data to submit a data-export request. We process exports within seven working days and deliver the file to your registered email address. No fee applies for standard export requests.

We share data only with payment processors — DANA, OVO, GoPay, QRIS — to the minimum extent required to complete your transaction. We do not sell data to advertisers. Any third-party access is governed by a data-processing agreement that mirrors our own privacy standards.

Submit a deletion request via Account Settings under Privacy & Data, or email our privacy desk with your registered email in the subject line. We acknowledge within four business hours and complete verified deletions within 30 days, sending a written confirmation.

We use strictly necessary cookies to keep your session active and optional analytics cookies to improve page navigation. You can withdraw optional-cookie consent through the cookie banner at any time. Withdrawing consent does not affect your account login or payment functionality.

Your data is handled consistently across Indonesia — whether you access from Surabaya, Bandung, or elsewhere. Eligibility for certain account features depends on local law, and we apply the same encryption, retention, and access-control standards to all accounts regardless of region.