nekototoPrivacy Policy

This page describes what we collect when you use nekototo and how we keep that data protected. We gather information to operate our platform, verify your identity, process payments, and comply with anti-money-laundering (AML) regulations in supported jurisdictions. Our commitment is to handle your personal and financial data securely, transparently, and in accordance with applicable law.

We collect data through account registration, identity verification (KYC), payment processing, and your activity on our platform (slot tournaments, live-dealer sessions, sportsbook markets, esports betting). We use encryption, access controls, and regular audits to protect this data. We do not sell your personal information to third parties for marketing. We share data only with payment processors, banking partners, and regulatory authorities when legally required to do so.

This policy explains our data practices in detail. If you have questions about how we handle your information or wish to exercise your privacy rights, contact our support team through our FAQ page or use the contact methods listed below.

What Data We Collect and Store on nekototo

When you create an account on nekototo, we collect your email address, full name, date of birth, and residential address. We gather this information to verify your identity, confirm you meet local eligibility requirements, and prevent fraud. We also collect phone number, payment method details (card number, bank account, or e-wallet information), and identity document information (passport, ID card, or driver's license) during Know Your Customer (KYC) verification.

Beyond registration, we collect behavioural data as you use our platform. This includes your game activity (which slots you play—Aviator, Sweet Bonanza, Gates of Olympus, Fortune Tiger, Mahjong Ways—and your spins, wins, and tournament participation), your sportsbook and live-dealer activity, your deposit and withdrawal transactions, your login history, and your device information (IP address, browser type, operating system). We also log your interactions with customer support and any disputes you raise.

KYC data
Personal identity information collected during account verification to confirm eligibility and prevent fraud.
Transaction data
Records of all deposits, withdrawals, and game activity linked to your account.
Device data
IP address, browser type, operating system, and device identifier collected automatically during your sessions.
Communication data
Emails, support tickets, and chat logs created when you contact our team.

We retain account data for the duration of your relationship with nekototo. After you close your account, we retain records for a minimum of five years to comply with anti-money-laundering regulations in supported jurisdictions. Payment and transaction records are retained according to banking and tax requirements, typically five to seven years. We delete or anonymise data beyond these retention periods unless legal obligation requires us to keep it longer.

How We Use Your Data on nekototo

We use personal and behavioural data for the following purposes: account creation and verification, payment processing via DANA, e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, online payment, and e-wallet, fraud detection and prevention, AML compliance, tournament settlement and leaderboard calculation, customer support, legal and regulatory compliance, and service improvement.

We do not use your data for automated decision-making that significantly affects you (such as account suspension without investigation). If we suspend your account due to suspected fraud or breach, we notify you and provide an opportunity to respond before taking final action.

Note: We do not sell, trade, or rent your personal information to marketing companies. We share data only with payment processors and regulatory authorities when legally required.

Our Data Security and Third-Party Processors

We encrypt all personal and financial data in transit using TLS (Transport Layer Security) and store data at rest using AES-256 encryption. Our servers are located in secure data centres with access controls, surveillance, and redundancy measures. We restrict access to personal data to authorised personnel only. We conduct regular security audits and penetration tests to identify and fix vulnerabilities.

Payment data is processed by licensed payment partners: DANA, e-wallet, mobile banking, local payment, online payment, e-wallet, and banks including mobile banking, local payment, online payment, and e-wallet. We do not store full credit card or bank account numbers—only tokens that allow us to reference your payment method without exposing it. This tokenisation aligns with Payment Card Industry (PCI) Data Security Standard requirements.

Our servers may be located outside your jurisdiction. By using nekototo, you consent to your data being transferred to and processed in countries other than your country of residence. These countries may have data-protection laws different from your own. We ensure that data transfers comply with applicable international standards and that our processors maintain adequate safeguards.

Your Rights and Data Subject Requests on nekototo

You have the right to request access to your personal data, request correction of inaccurate information, and request deletion of your data (subject to legal retention requirements). You may also request that we stop processing your data for marketing purposes, though we will continue to process it for essential account and payment functions.

To exercise any of these rights, submit a formal request through our support portal on our FAQ page or contact our data-protection officer. We aim to respond within the timeframe specified by applicable privacy law in your jurisdiction—typically 30 days. If we cannot fulfil your request, we explain why in writing.

Cookies and Tracking on nekototo

We use cookies and similar tracking technologies to maintain your session, remember your preferences, and analyse platform usage. Essential cookies allow you to stay logged in and are necessary for the platform to function. Analytical cookies help us understand how users interact with nekototo so we can improve our service. We do not use cookies for third-party advertising or tracking beyond our platform.

You can control cookies through your browser settings. Disabling cookies may limit your ability to use certain features of nekototo. We do not sell cookie data to advertisers.

If you access nekototo from cities including Jakarta, Surabaya, Bandung, Medan, or Semarang and have questions about our privacy practices, our support team responds in English and provides detailed explanations of how we handle your regional data. We remain committed to transparency and to respecting your privacy rights across all supported jurisdictions.

Legal and Jurisdictional Framework

Service availability

We at nekototo provide our gaming and sportsbook services only in jurisdictions where such services are legal and permitted by local law. We do not operate in regions where online gaming, slot play, live-dealer tables, or sports wagering are prohibited. Our service availability is determined by the legal framework of each territory; we do not publicly declare any region as legal or illegal. Instead, we rely on payment-provider geofencing, IP filtering, and user-declaration mechanisms to restrict access to supported jurisdictions. Services are provided only where we believe we hold sufficient regulatory authorisation and where local law expressly permits online gaming and wagering. Our payment partners—DANA, OVO, GoPay, ShopeePay, LinkAja, QRIS, BCA, Mandiri, BRI, and BNI—enforce geographic restrictions on their own platforms, which further limits access to prohibited regions. If a jurisdiction's laws change or if a payment partner withdraws service from a region, we update our availability status immediately and notify affected users. Any user discovered accessing nekototo from a restricted jurisdiction may have their account suspended, and any remaining balance may be subject to regulatory hold or forfeiture according to local law. We cooperate fully with law-enforcement requests and regulatory inquiries regarding jurisdiction-restricted access.

Account eligibility

To open an account on nekototo, you must meet the minimum age and legal status requirements established by the gaming regulator in your jurisdiction. We do not set a universal global age threshold; instead, we comply with the applicable age requirement for each region where we operate. During account registration, you declare that you meet your jurisdiction's legal age to participate in online gaming and that you are not subject to any legal prohibition against gambling—such as a court-ordered exclusion, regulatory ban, or inclusion on a national account controls registry. We perform Know Your Customer (KYC) identity verification during account creation, which includes name verification, address confirmation, payment-method validation, and in some cases proof of age. This verification may take one to two business days. We may request additional documentation before processing large withdrawals or if we detect unusual account activity. Accounts opened by minors or by persons subject to gambling prohibitions are suspended immediately upon discovery, and any funds are held pending investigation. We do not knowingly permit underage access. Minors attempting to open accounts or use our services breach our terms and may face legal consequences under their jurisdiction's gaming laws. We reserve the right to request proof of age and eligibility at any time during your account lifetime.

Local-law responsibility

You are solely responsible for verifying that your access to and use of nekototo comply with the laws applicable to your jurisdiction. We provide services only in jurisdictions where we believe such services are legal; however, we do not provide legal advice regarding local gaming legislation. It is your personal duty to research whether online slots (Aviator, Sweet Bonanza, Gates of Olympus, Fortune Tiger, Mahjong Ways), tournaments, live-dealer tables, sportsbook markets, and esports wagering are lawful in your location before accessing our platform. If you are uncertain about the legality of our services in your territory, you should consult a local attorney, gaming regulator, or legal authority before creating an account or depositing funds. By opening an account and using nekototo, you certify that you have verified local legality and understand the legal risks. You accept full legal and financial responsibility for any breach of your jurisdiction's gaming laws resulting from your decision to use our platform. nekototo, its directors, staff, payment partners, and affiliates assume no liability for regulatory fines, account suspension, fund confiscation, legal prosecution, or other consequences arising from your use of our services in a jurisdiction where they are prohibited. We reserve the right to suspend your account, forfeit your balance, or report your activity to relevant authorities if we discover that you are accessing our services from a prohibited jurisdiction.

Data and privacy scope

We collect personal data during account creation and verification to operate nekototo and comply with anti-money-laundering (AML) and know-your-customer (KYC) regulations. Data collected includes name, address, date of birth, email, phone number, payment method details, and identity document information. We also collect behavioural data—gaming history, tournament results, deposit and withdrawal patterns, login activity, and device information—to detect fraud, prevent abuse, and improve our services. This privacy policy describes our full data-handling practices. Data collected during identity verification is retained according to regulatory requirements, typically for a minimum of five years after your account is closed. We share data with payment processors (DANA, OVO, GoPay, ShopeePay, LinkAja, QRIS, BCA, Mandiri, BRI, BNI), banking partners, and regulatory authorities only when legally required. We do not sell customer data to third parties for marketing or commercial purposes. All personal data is encrypted in transit and at rest, and access is restricted to authorised personnel only. You have the right to request access to your personal data, request correction of inaccurate information, or request deletion (subject to legal retention obligations) by contacting our support team. We aim to respond to data-access requests within the timeframe stipulated by applicable privacy law in your jurisdiction. If you believe your data has been mishandled or compromised, you may lodge a complaint with our data-protection officer or your local data-protection authority.

Contact for legal inquiries

Users with legal questions, data-protection concerns, jurisdiction-related inquiries, or privacy complaints may contact our legal team and data-protection officer through our official support channels. Visit our FAQ page and select "Legal Inquiry" or "Data Protection Request" from the category menu, or use the contact information available on our About us section. We aim to respond to legal and privacy enquiries within five business days. For urgent matters—such as suspected data breaches, account suspension due to jurisdiction concerns, or formal regulatory violations—mark your message "URGENT" and include your account ID and a clear description of the issue. Our legal and data-protection team will prioritise such cases and respond within two business days. Requests for account information required by law enforcement or regulatory bodies are processed according to our legal-hold procedures and applicable jurisdiction requirements. We may disclose user data to authorities without prior notification if required by court order or legal process. If you are subject to a legal proceeding related to your use of nekototo or believe your privacy has been violated, you may submit a formal complaint through our support channels. All legal communications are treated as confidential and stored securely according to applicable law. By using nekototo, you agree to our privacy practices and acknowledge that we may be required to disclose information to authorities without your consent if legally compelled.