LEGAL REFERENCE

Your Privacy at 388hero login

388hero login handles account data, payment references and session activity across our casino, sportsbook and slot rooms built for Indonesia. This policy explains exactly what we collect, why...

Data You ControlSecure StorageTransparent UseIndonesia-Ready PolicyRegular Review
388hero login Your Privacy at 388hero login

Privacy

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

HELP CHANNELS

Reach Our Privacy Team Directly

Questions about how your data is handled, requests for copies of your records, or deletion requests can all be directed to our...

Email Privacy Team Send a detailed message to our dedicated privacy...
Live Chat Support Open the chat widget inside your account dashboard...
Help Centre Ticket Submit a structured ticket through the Help Centre...
REVIEW SIGNALS

How We Maintain Policy Integrity

Our privacy policy is not a static document. We operate a structured review cycle, apply encryption standards across all stored data, and keep our practices aligned with applicable regulations in every supported...

Scheduled Policy Reviews

We audit this policy on a fixed cycle, not just when incidents arise. Every review checks whether data categories, retention periods and third-party references still reflect how the platform actually operates today.

Encryption at Rest and Transit

Account data, payment method references — including DANA, OVO, GoPay and QRIS identifiers — and session logs are encrypted both in storage and during transmission using current cipher standards applied consistently across our infrastructure.

Minimal Data Collection

We collect only what is necessary to operate your account and process payments. If a data field stops serving a clear function, it is removed from our collection forms in the next scheduled update cycle.

Access Controls

Internal access to personal data is role-restricted. Staff who manage payments, for example, cannot access support chat histories, and vice versa. Separation of data access is enforced at the system level automatically.

Breach Response Protocol

We maintain a documented incident response plan. If a data breach is detected, affected account holders in supported regions are notified promptly and the relevant supervisory contacts are informed as required under applicable local law.

Jurisdiction-Aware Wording

Where local law in Indonesia or other supported regions imposes specific data handling obligations, our policy reflects those requirements. We do not apply a single global template when regional rules demand a different standard.

Privacy Policy Consistency Across Our Pages

Our privacy commitments appear consistently whether you access them from the main lobby, the sportsbook section or account settings. The table below shows how this policy page aligns...

Data Collection ScopeThe same categories of data — account details, payment references and session logs — are listed identically on this page and referenced consistently in every account-facing section of our platform.
Payment Method ReferencesDANA, OVO, GoPay and QRIS are named specifically in this policy, matching the payment options displayed in the account deposit and withdrawal sections without discrepancy.
Retention Period StatementsRetention language on this page mirrors what is stated in our account terms. We do not apply shorter retention windows on one page and longer ones on another for the same data category.
Third-Party Disclosure RulesOur position on not selling personal data is stated here and echoed in the account terms section. No other page on the platform contradicts this commitment or introduces exceptions not covered here.
Contact Channel AvailabilityThe privacy contact paths listed on this page — email, live chat and help ticket — are the same channels promoted in the account support section, ensuring you always reach the correct team.
Jurisdiction LanguagePhrases such as 'supported regions' and 'where local law permits' appear in both this policy and in access-related notices across the platform, keeping the language coherent and legally consistent.
Update Notification MethodThis policy states that material changes are communicated via your registered contact channel. That same notification method is described in the account terms, so there is no conflicting update process on any sibling page.

How This Policy Page Is Structured

We designed the layout of this privacy policy so you can locate the section most relevant to your situation without reading everything in sequence. Each structural...

Data Collection Block

The first substantive section lists every category of information we collect, from account registration fields to DANA, OVO, GoPay and QRIS payment identifiers, so nothing is ambiguous about the scope of collection.

Retention Schedule

A dedicated segment covers how long each data category is kept. Retention periods are tied to account status and applicable regulation in supported regions, not set arbitrarily or buried in footnotes elsewhere.

Your Rights Section

We give your rights their own clearly labelled section: the right to access, correct, export or delete your personal data. Instructions on exercising each right appear there alongside the relevant contact path.

Third-Party Sharing Scope

A specific block names the categories of third parties — payment processors, security services — that may receive limited data, and explains what data each category receives and the contractual safeguards we require of them.

Cookie and Session Data

Session identifiers, device type and login timestamps are covered in their own segment separate from account data. You can see exactly what automatic data collection occurs when you access the platform from any device.

Policy Update Log

The final section of this policy carries a version date and a plain-language summary of what changed from the previous version, so you can quickly assess whether a new revision affects your account in a meaningful way.

Privacy Policy Questions Answered

We collect your name, contact details, and payment method identifiers — including references linked to DANA, OVO, GoPay and QRIS. Session data such as device type and login timestamps is captured automatically to maintain account security.

No. We do not sell your personal data. Limited data is shared only with payment processors and security service providers under strict contractual agreements, solely to operate your account in supported regions where local law permits.

Retention periods depend on account status and applicable regulation in supported regions. Active account data is kept while your account remains open. Data tied to closed accounts is retained only as long as required by applicable local law.

Yes. You can request a full export of your personal data by contacting our privacy team via email, live chat or a Help Centre ticket. We aim to fulfil verified data access requests within 14 calendar days of receipt.

Submit a deletion request through any of the three contact paths listed on this page. We will verify your identity, process the request and confirm deletion in writing, subject to any retention obligations imposed by applicable regulation in supported regions.

Payment identifiers linked to DANA, OVO, GoPay and QRIS are encrypted both in storage and during transmission. Access to payment data is restricted to authorised personnel only, with role-based controls enforced at the system level automatically.

We notify you of material changes through your registered contact channel — typically email or an in-account message. Each updated version carries a revision date and a plain-language summary of what changed from the previous version.