How We Handle Your Account Data
This is the power77 privacy policy. We wrote it so you can see, in plain language, what we collect when you open an account, what we store while...
Policy Posture and Scope
power77 operates for supported regions where local law permits, and this policy reflects that scope. We collect identity details you give us at sign-up, device and session signals while you browse the lobby, and transaction references when you fund your account through DANA, OVO, GoPay or QRIS. We retain that data only for as long as your account is active or as
Indonesian record-keeping rules require. You can ask us to export, correct or delete your record at any time, and we'll respond inside the windows our regulators set. Third-party processors handling payments and live-table feeds are bound by written terms aligned with this notice.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
Privacy Contact Paths
If something about your data needs attention, here's how to reach our privacy desk directly.
How This Policy Is Reviewed
Editorial and legal eyes pass over this page on a fixed cadence so the wording matches what the lobby actually does.
Quarterly Legal Review
Our counsel re-reads this policy every quarter against current Indonesian data rules. Any change to retention windows or processor lists is dated and logged in the changelog at the foot.
Named Data Owner
One person on our team owns this document end to end. That accountability means questions get a real answer instead of a forwarded ticket trail through anonymous mailboxes.
Processor Register
We keep a written register of every vendor touching your data — payment routers, live-table providers, anti-fraud feeds — and update it before any new partner goes live in the lobby.
Encryption Standard
Account credentials and payment references sit behind transport encryption in flight and at rest. Keys rotate on a schedule, and access is limited to engineers with audited reasons to look.
Breach Protocol
If something goes wrong we tell affected accounts directly and notify the relevant Indonesian authority inside the statutory window. No silent patches, no quiet edits to this page.
Plain-Language Drafting
We write this notice the way we'd explain it to a friend opening their first account. Legal accuracy stays intact, but the sentences don't hide behind jargon you'd need a dictionary for.
Consistency Across Our Policy Pages
This privacy notice sits next to our terms, cookies and account pages. Here's how they line up so nothing contradicts.
What This Policy Page Includes
Quick map of the elements you'll find on this notice so you can jump to the part you came for.
Data We Collect
A clear list of identity, device and transaction fields tied to your account, with the lawful basis stated next to each category instead of buried in a footnote.
Retention Windows
Concrete timeframes — not vague phrases like 'as long as necessary'. You'll see months and years against each data category so the clock is visible.
Your Rights Panel
Access, rectification, erasure, portability and objection rights laid out with the exact request route for each one. No hunting through paragraphs to find the form.
Processor Index
The third parties that touch your record are named by category, with the country they operate from and the safeguard we have in place for transfers.
Cookie Summary
A short summary of cookie categories with a link straight to the preference centre, so you can adjust without re-reading the full cookies page.
Change Log
Every material change to this page is dated at the bottom with a one-line note explaining what shifted, so you're never guessing which version you agreed to.