apidewa Casino & Sportsbook Data Care
This page describes what we collect when you use apidewa and how we keep that data protected. We operate across supported jurisdictions—Jakarta, Surabaya, Bandung, Medan, Semarang—and collect personal information necessary for account setup, payment processing, legal compliance, and service delivery. Our data practices reflect regional standards and your statutory rights.
We collect minimal information: email, verified identity documents (national ID, passport, driver's license), residential address, payment details (bank account or digital wallet identifiers), gameplay history, and support communications. We do not harvest behavioral data beyond what is necessary to operate the platform and comply with anti-money-laundering requirements.
Our data infrastructure sits partly in Indonesia and partly in regional partner facilities outside Indonesia. This geographic distribution supports service reliability but means your data may traverse borders. We encrypt all data in transit and at rest. You retain rights to request data deletion, portability, or correction under applicable law.
What We Collect and Why
We collect your personal data in four categories: account setup, financial, behavioral, and support records.
Account Setup Data
We collect your email address, full name, date of birth, national ID number (or equivalent), and residential address. These fields are mandatory for account creation. We require this information to verify your identity, prevent duplicate accounts, and comply with Know Your Customer (KYC) anti-money-laundering standards applicable in our operating jurisdictions. You provide this data directly when you register.
Financial Data
We collect payment method details: bank account numbers (BCA, e-wallet, mobile banking, local payment), digital wallet identifiers (online payment, e-wallet, mobile banking, local payment, online payment), and e-wallet account linkages. We store tokenized payment information—not full card numbers or full account credentials—to facilitate deposits and withdrawals. Payment processors (external third parties) handle the actual transaction; we retain only the reference tokens and transaction logs.
Behavioral Data
We log your gameplay history: games played, wagers placed, wins and losses, time of activity, device type (desktop/mobile), and approximate geographic location (via IP address). We use this data to calculate weekly cashback, track tier progression, detect fraud, and identify problem account patterns. We retain gameplay logs for seven years per financial regulatory requirements.
Support Records
We retain copies of live chat transcripts, emails to support, and phone call notes for quality assurance and dispute resolution. Support records are stored for two years after account closure or final interaction. We use support data to train our team and resolve account disputes fairly.
We do not sell your data
We never sell personal data to third parties. We share data only with payment processors, fraud-detection vendors, and financial authorities as required by law.
Where We Store Your Data
Our apidewa servers are located partly in Indonesia and partly in regional data centres outside Indonesia (e.g., Singapore, Malaysia). This geographic distribution ensures service uptime and redundancy. Your data may be processed and stored across multiple locations. All data is encrypted during transfer between locations and at rest in all facilities.
We employ industry-standard encryption protocols (TLS 1.2+). Access to stored data is restricted to apidewa staff on a need-to-know basis. Payment data is isolated in a separate, more heavily restricted facility. Database backups are encrypted and stored off-site; backups are deleted after 90 days.
We maintain contractual agreements with all data-processing vendors requiring them to meet or exceed our own security standards. Vendors cannot use your data for purposes other than delivering the service to apidewa.
Third Parties We Work With
We share your data with the following categories of third parties, each bound by confidentiality agreements:
- Payment processors: mobile banking, local payment, online payment, e-wallet, mobile banking, local payment operators, and your banks (online payment, e-wallet, mobile banking, local payment) receive necessary financial data to process your deposits and withdrawals.
- Fraud and compliance vendors: We use third-party services to detect suspicious account activity, money laundering patterns, and fraud. These vendors receive transaction logs and gameplay patterns.
- Financial regulators: We share data with applicable government authorities, central banks, and financial intelligence units when legally required by subpoena or regulatory request.
- Law enforcement: We comply with valid legal process from police or prosecutors requesting account information for investigations.
- Customer support platforms: We use cloud-hosted live chat and email systems; these platforms store your communications on our behalf.
All third parties are contractually obligated not to use your data beyond the scope of services we have contracted them to provide.
Your Rights Regarding Your Data
We recognize your right to access, correct, and in some cases delete your personal data. If you wish to exercise these rights, contact our support team via live chat or email with your request and account verification details.
Data Access
You may request a copy of all personal data we hold on you. We compile this within 30 days and provide it in a standard format. A copy is available to you without charge.
Data Correction
If you believe any data we store is inaccurate, notify us and we will verify and correct it. Corrected data typically updates within 24 business hours.
Data Deletion
You may request deletion of personal data, subject to legal retention requirements. Financial transaction records must be retained for seven years under anti-money-laundering law. After that period, they are deleted on request. Gameplay logs and support records are deleted within 30 days of closure or request (whichever is earlier).
Data Portability
You may request your data in machine-readable format (e.g., CSV) for transfer to another service. We provide this within 30 days of request.
Cookies and Tracking
Our apidewa website uses cookies for three purposes: session management, analytics, and user preference storage.
- Session cookies: Essential for login and account security. These expire when you close your browser. You cannot disable these and still access your account.
- Analytics cookies: We use Google Analytics to understand how members navigate our site, which pages are popular, and where users drop off. Analytics cookies store anonymized data; they do not track individual behavior directly. You may disable these via your browser settings.
- Preference cookies: We store your language preference, theme preference, and whether you have dismissed notification banners. These are entirely optional and can be cleared anytime.
We do not use tracking pixels, retargeting cookies, or cross-site behavioral tracking. Third parties (payment processors, fraud vendors) may deploy their own cookies on our pages; we do not control those. Consult their privacy policies for details.
How Long We Keep Your Data
We follow these data retention timelines:
- Active accounts: Personal and financial data retained while your account is active, plus 24 months after closure (for dispute resolution and regulatory audit).
- Gameplay logs: Retained for seven years (anti-money-laundering requirement).
- Support records: Retained for two years after final interaction.
- Backup copies: Deleted after 90 days; not retrieved unless system failure occurs.
- Email marketing lists: Deleted immediately upon unsubscribe.
After retention periods expire, we delete data securely (overwrite, shred, or incinerate). We do not archive old data indefinitely.
Our Security Practices
We protect your data through encryption, access controls, and regular audits. All apidewa login credentials are hashed (one-way encryption) so that even our staff cannot see your plaintext password. Payment data is encrypted both in transit and in storage. Access to sensitive data is logged and monitored for unusual patterns.
We conduct annual security audits and penetration testing. If we discover a data breach, we notify affected members within 30 days and provide guidance on protective steps. We maintain cyber insurance and comply with incident reporting laws in our operating jurisdictions.
We strongly recommend you use a strong, unique password for apidewa and enable two-factor authentication if available. Do not share your login credentials or one-time codes with anyone, including apidewa staff.
Contact and Policy Updates
If you have questions about our privacy practices or wish to exercise your data rights, contact our support team. We respond to data requests within 30 days. Our support team operates during business hours across Jakarta, Surabaya, Bandung, Medan, and Semarang time zones.
We update this privacy policy periodically to reflect legal changes or operational shifts. Updates are posted on this page with an updated effective date. Continued use of apidewa after an update means you accept the revised terms. Material changes (e.g., new data sharing) trigger a notification email to your registered address.
This privacy policy is governed by the laws applicable in our primary operating jurisdiction. If you believe we have violated your data rights, you may lodge a complaint with your local data protection authority or financial regulator. We cooperate fully with regulatory investigations.