Reference

How idxbig Protects Your Personal Data

At idxbig, every piece of personal information you share — from your account registration details to payment records via DANA, OVO, GoPay, and QRIS — is handled with…

Data encrypted at rest and in transitDANA, OVO, GoPay & QRIS transaction records securedYou can request data deletion within 30 daysNo data sold to third partiesIndonesian law compliance where local law permits
idxbig How idxbig Protects Your Personal Data
PRIVACY CONTACT PATHS

How to Reach Our Privacy Team

If you have a question about how your data is stored, want to correct an inaccuracy, or need to submit a formal deletion request, our privacy support team is reachable seven days…

Live Chat Available 24 hours a day, every day of the week. Use live chat for immediate questions about what data we hold on your account or to flag a suspected security issue without delay.
Email Privacy Request Send formal data-access or deletion requests to our dedicated privacy address. We acknowledge within one business day and resolve fully within 14 calendar days, as required by applicable rules.
Account Settings Panel Log in, navigate to Settings, then Privacy Controls to download your stored profile data or withdraw marketing consent. The self-service path works on both mobile and desktop without contacting support.
DATA HANDLING PRACTICES

Six Ways We Keep Your Data Safe

From the moment you complete a QRIS scan or link your OVO wallet, your data passes through encrypted channels — TLS 1.3 in transit and AES-256 at rest.

End-to-End Encryption

All data — including DANA and GoPay payment identifiers — is encrypted using TLS 1.3 during transmission and AES-256 when stored on our servers, making interception outside controlled channels functionally impossible.

Cookie Policy

We use session cookies to keep you logged in and analytics cookies to improve page performance. You can manage cookie preferences from the banner shown on your first visit or via browser settings at any time.

Account Security Alerts

Whenever a new device or IP address accesses your account, we send an automatic notification to your registered email. If the login was not you, the alert includes a one-click link to freeze your account immediately.

Data Retention Schedule

Account profile data is kept for as long as your account remains active plus five years for financial records, as required where local law applies. After that window closes, records are permanently deleted from all servers.

Third-Party Sharing Rules

We share data only with payment processors — including OVO, GoPay, DANA, and QRIS infrastructure providers — strictly to complete your transactions. We do not sell, rent, or trade your personal information with advertisers or data brokers.

Your Right to Correct or Delete

You may request a correction to any stored detail or ask for full account deletion at any time via email or the Settings panel. Deletion requests are executed within 30 days and confirmed by email once complete.

Your Privacy Questions, Answered

Below are the questions we hear most often about how idxbig handles personal data. If your question is not covered here, reach our privacy team through live chat or email — both channels are monitored daily, including weekends.

We collect your name, email address, mobile number, and the payment identifier for your chosen method — DANA, OVO, GoPay, or QRIS. We also record device type and IP address for account security purposes only.

We share data only with payment infrastructure partners — such as DANA and OVO processors — to complete your transactions. We do not share, sell, or transfer your information to advertisers, data brokers, or any unrelated third parties.

Send a data-access request to our privacy email or use the Settings panel inside your account. We acknowledge all requests within one business day and deliver a full data export within 14 calendar days.

Yes. Submit a deletion request via email or through Settings. We complete the process within 30 days and send a confirmation email. Financial records may be retained longer where local law requires it.

Payment identifiers are encrypted with AES-256 at rest and transmitted over TLS 1.3. Access to these records is restricted to verified internal roles, and we conduct quarterly security reviews to maintain that standard consistently.

We use session cookies for login continuity and analytics cookies for site performance. You can accept, reject, or customise cookie categories from the consent banner on first visit or through your browser settings at any time.

Contact our privacy team immediately via 24-hour live chat or email. For suspected account breaches, click the freeze link in the security alert email we send whenever an unrecognised device accesses your account.