Reference

Your Rights and Our Legal Commitments

baja4d operates under a clear legal framework so you always know where you stand — from how your account data is stored to how disputes are handled.

Jurisdiction-Aware PolicyData Retention RulesAccount Security StandardsDANA · OVO · GoPay · QRIS ContextClear Dispute Path
baja4d Your Rights and Our Legal Commitments
LEGAL CONTACT PATHS

Reach Us About Any Legal or Policy Matter

If you have a question about our terms, a data-access request or a dispute related to a transaction, our compliance team is reachable through three direct channels.

Live Chat Open the chat widget from your account dashboard. Legal queries are tagged separately from gameplay support and routed to our compliance desk within two minutes during operating hours.
Email Support Send your request to our legal contact address listed in your account settings. We commit to a written acknowledgement within four hours and a full response within 24 hours on business days.
Account Help Centre Log in, head to Settings → Legal & Privacy, and submit a formal data-access or deletion request directly. The form timestamps your submission and triggers an automated case reference number.
POLICY HANDLING DETAIL

How baja4d Manages Data, Cookies and Account Security

Beyond the written terms, we want you to see the operational steps behind each policy area — from how cookies are scoped to how your account password is hashed.

Cookie Scope

We use session cookies for authentication and analytics cookies to measure page load times. You can reject analytics cookies from the Privacy settings tab in your account without affecting login functionality or DANA and OVO deposit flows.

Data Handling

Personal data — name, email, payment identifiers — is stored on encrypted servers. We apply AES-256 encryption at rest and TLS 1.3 in transit. No raw payment credentials from GoPay or QRIS sessions are held on our servers after a transaction completes.

Account Security

Passwords are hashed using bcrypt with a per-account salt. We enforce two-factor authentication as an option you can activate under Security settings, and we log every login attempt with IP, timestamp and device fingerprint for your review.

Data Retention

Account data is kept for as long as your account is active and for a statutory period after closure. You may request an export of all data we hold about you; we fulfil export requests within 30 days of verification.

Who to Contact

Our Data Protection contact is named in the Legal & Privacy section of your account settings. That contact handles formal data-access requests, objection notices and erasure requests in line with applicable privacy regulation where local law permits.

Requesting Changes

To correct, update or delete personal data, navigate to Settings → Legal & Privacy → Manage My Data. Submit the form and we issue a case reference within one hour. Changes are actioned within 14 days of identity verification.

Common Questions About Our Legal Terms

These are the questions we hear most often when it comes to legal policy, data rights and account access. Each answer reflects the actual process your account goes through — not a generic template. If your question is not covered here, use the live chat path described in the contact section above.

We do not sell your personal data. We share data only with payment processors such as DANA, OVO, GoPay and QRIS to complete your transactions, and with identity-verification providers as required by applicable regulation where local law permits.

Log in, go to Settings → Legal & Privacy → Manage My Data, and submit a data export request. We verify your identity, then deliver a structured data file to your registered email address within 30 days.

Yes. Submit an erasure request via the same Settings → Legal & Privacy path. We will delete personal data not required for statutory financial retention. Some transaction records linked to QRIS or bank transfers must be kept for the period required by financial regulation.

Our terms specify the governing jurisdiction in the full legal agreement available in your account. Where that conflicts with mandatory local law in Indonesia, local law prevails. You retain any statutory rights available to you under Indonesian consumer regulation.

We send an email to your registered address at least seven days before any material change takes effect. The email summarises what changed and links to the updated document so you can review it before the new terms apply to your account.

No raw payment credentials are stored after a transaction is complete. We retain a transaction reference and timestamp for your account history, but your GoPay wallet credentials and OVO account details remain solely with those payment providers.

Contact our compliance team immediately via live chat — available 08:00–23:00 WIB — or email the legal contact in your account settings. We log the report, issue a case reference within one hour, and begin an internal review within 24 hours.