LEGAL REFERENCE

How We Handle Your Account Data

This is the gelastoto privacy policy — the short version of how we treat the details you share when you open an account with us. We tell you...

Plain-English PolicyIndonesia-AwareAccount-Level ControlsUpdated Regularly
gelastoto How We Handle Your Account Data

Policy Posture and Your Rights

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

HELP CHANNELS

Privacy Contact Paths

Three doors lead to our privacy desk. Pick whichever feels right for the question you're asking.

Team online

Privacy Inbox

Email the privacy desk directly for data export requests, correction notes or account deletion. We acknowledge within one business day and resolve within the window your jurisdiction sets.

In-Account Form

Sign in and open the privacy panel under account settings. The short form routes straight to the reviewer handling Indonesia files, so nothing sits in a general queue.

Live Chat Escalation

Start with chat if you're unsure which request you need. The agent will tag the ticket as a privacy matter and hand it to the desk that owns your data file.

TRUST MARKERS

Editorial Trust Signals for This Policy

Here's how this page gets written, checked and kept current.

Named Reviewer

Every revision is signed off by a named compliance lead, not an anonymous template. If wording shifts, the person responsible is on record inside our internal change log.

Plain Language Pass

Before publication, an editor rewrites legalese into the same English you'd use over coffee. Clauses you can't read aren't clauses you can act on.

Indonesia Counsel Input

Local counsel reviews wording that touches Indonesian residents, especially around wallet references and identity verification, so the text reflects how things actually run here.

Version History

We keep dated versions of this policy. If something changed last quarter, you can ask for the previous text and compare it line by line with what's on screen now.

Scoped Access

Only staff with a documented reason can open your file. Access events get logged automatically, and audit pulls happen on a regular cadence we don't skip.

Breach Protocol

If a data event happens, our written protocol triggers notifications to affected account holders inside the window local regulators expect. No hidden delays, no quiet patches.

Consistency Across Our Policy Pages

This privacy page lines up with the rest of our policy library so nothing contradicts itself.

Terms of ServiceDefines your account contract. The privacy page tells you what data that contract touches; terms tells you what behaviour the contract expects from both sides.
Cookie NoticeCovers browser-side tracking only. Anything stored on our servers is governed by this privacy page, not the cookie notice, so the two pages cover different surfaces.
KYC StatementExplains identity checks. This privacy page describes what happens to those documents after the check clears and how long they sit in storage.
AML PolicyLists the monitoring we're required to do. Privacy explains the data side of that monitoring — what's kept, who sees it, when it's purged.
Complaints ProcedureRoutes general account complaints. Privacy-specific complaints get a separate lane described above, since the reviewer set is smaller and more specialised.
Retention ScheduleInternal document referenced here. Each data category has a maximum hold period; this page summarises the headline numbers without reproducing the full grid.
Marketing PreferencesLives inside your account settings. This privacy page explains the lawful basis we rely on; the preferences panel is where you actually toggle contact channels.
PLATFORM SNAPSHOT

What This Policy Page Shows You

Six elements shape the policy side of our brand. Each one is built so you can find what you need without scrolling for ten minutes.

Section Anchors Jump links sit at the top of the page so...
Last Updated Stamp A visible date marker tells you when the policy last...
Glossary Inline Technical terms get a short definition the first time they...
Request Buttons Inline buttons launch the export, correction and deletion forms straight...
Mobile Layout The page reflows cleanly on phones so policy reading on...
Print View A print-friendly version strips the navigation chrome so you can...

Privacy Questions We Hear Often

We hold your identity check, login signals, device fingerprint and the wallet reference you chose at cashier. Nothing decorative, nothing speculative — only the fields needed to run your account and meet our compliance duties in supported regions.

Sign in, open the privacy panel under account settings, and submit the export request. We acknowledge within one business day and deliver the file inside the window your jurisdiction expects, usually well under thirty days.

Yes. Send the deletion request from inside your account or by email to the privacy desk. We close the file, purge what we're allowed to purge, and retain only what local law requires us to keep for audit reasons.

Access is scoped to staff with a documented reason — compliance reviewers, the privacy desk and senior support on escalation. Every open is logged automatically, and audit pulls happen on a regular cadence we don't quietly skip.

Each data category has its own hold period set by our retention schedule. Identity documents sit longer than session logs. The headline numbers are summarised in this policy; the full grid is available on request.

Our written breach protocol triggers notifications to affected account holders inside the window your local regulator expects. We don't sit on news — the named compliance lead signs off the disclosure and the timeline is logged internally.

It covers the wallet reference we store on your account profile. The payment providers themselves run under their own privacy notices, which you'll see when you confirm a transaction inside their app or QRIS flow.