Privacy vs Terms
Terms cover how you use the lobby; this policy covers how we use your data. The two documents reference each other and share definitions for account, session and verification.
This is the tata4 Privacy Policy page, written plainly so you know what we collect when you open an account and explore the lobby. We cover the data...
tata4 processes your personal data under the privacy framework that applies where local law permits in supported regions across Indonesia. We collect the identifiers needed to open your account — name, contact handle, date of birth, and the e-wallet reference you pick at cashier. Session logs, device fingerprint, and IP are retained for fraud screening only. We never sell your data to
third-party marketers. Payment metadata is shared strictly with the wallet rail you choose so the transaction clears. You can request access, correction, or deletion of your profile through the channels listed further down this privacy page.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
If you have a question about this Privacy Policy, a data request, or a concern about how your tata4 profile is handled, reach us through the channels below. We answer privacy queries...
This Privacy Policy is reviewed by people, not just legal templates. Below are the editorial signals that shape how we draft, update and publish the wording you're reading now on tata4.
Our policy team revisits this page every quarter to match new wallet partners, new lobby features, and any updates to Indonesian data rules. The revision date sits at the foot of the page so you can audit it.
We rewrite legalese into Southeast-Asian English you can scan on a phone. If a clause needs a dictionary, it gets sent back to the drafting desk before the policy ships to your tata4 account screen.
A single Data Protection lead signs off every change to this Privacy Policy. That role is staffed internally, not outsourced, so accountability for your account data stays inside the tata4 team.
Every material edit to this policy is recorded with a date stamp and a short note explaining what moved. You can request the full change log through the privacy inbox listed in the support section above.
We state plainly which regions this policy covers and where local law permits us to operate. If your area isn't supported, the policy tells you rather than burying the limitation in a footnote.
The wallet rails and infrastructure vendors that touch your data are named in the policy rather than hidden behind vague language. You see exactly who processes which field for your tata4 account.
This Privacy Policy aligns with the other legal pages on tata4 so the wording you read here matches what appears in Terms, Cookies and KYC notices. Use the table below to see...
Terms cover how you use the lobby; this policy covers how we use your data. The two documents reference each other and share definitions for account, session and verification.
Cookies are a subset of data covered here. The Cookies page lists each tag by name; this page sets the legal basis for setting any cookie on your device in the first place.
KYC describes the documents we ask for at verification. This policy explains how those documents are stored, who can view them, and when they are purged from tata4 systems.
AML rules tell us when to inspect transactions. This policy tells you which transaction fields we retain and how long they stay attached to your account for compliance review.
Marketing preferences live inside your account dashboard. This policy explains the legal basis for any opt-in message and how withdrawal of consent takes effect across tata4 channels.
The Cashier page lists supported wallets. This policy explains which payment metadata is shared with each wallet partner so a DANA, OVO, GoPay or QRIS movement can clear.
Account closure rules sit in Terms; data retention after closure sits here. We state the holding window in months and the legal trigger that allows full erasure of your profile.
Rather than burying clauses, we surface the parts of this Privacy Policy you're most likely to scan for. The cards below map to specific sections so...
A field-by-field list of every identifier tied to your tata4 account, from sign-up handle through to session device. Each row notes whether the field is mandatory or optional at account opening.
For every data field, the policy states the lawful basis — contract, legitimate interest, or consent. This block is written so you can match each purpose against the field in plain English.
Clear timeframes for how long each data category stays on tata4 servers, including the gap between account closure and full erasure. Numbers are stated in months rather than vague ranges.
The exact buttons and forms inside your account that let you exercise access, correction, portability and erasure rights. Each control links straight to the screen rather than asking you to email first.
A named list of the vendors that receive a slice of your data, including the wallet rails behind DANA, OVO, GoPay and QRIS, plus the role each partner plays in the transaction.
How tata4 tells you when this policy changes — banner on first login, email to your registered address, and a revision note at the foot of this page so nothing slips by quietly.