How We Handle Your Account Data
This is the ligasga privacy policy — the page that tells you, in plain English, what we collect when you open an account, how long we keep it...
Policy Posture and Jurisdiction Notes
Our privacy posture applies wherever local law permits you to hold a ligasga account. We collect the minimum needed to run your lobby session: your contact details, the wallet handle you sign deposits with, device fingerprints for fraud checks, and the transaction trail tied to DANA, OVO, GoPay and QRIS movements. We retain account records for the period Indonesian financial regulation expects,
then purge. You can ask us to export or erase your file at any time, and we honour that within the windows this policy sets out. Sub-processors are bound by the same posture, and cross-border transfers happen only where supported regions allow it.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
Editorial Trust Signals for This Policy
This policy is reviewed by humans, not auto-generated. Below is how the document is maintained, who signs off on changes, and the editorial checks we run before a new version goes live...
Named Owner
Our privacy officer signs every revision. Their name and contact sit at the foot of this page so you always know who to write to when something on the policy needs challenging.
Version History
Every edit lands with a date stamp and a short note explaining what moved. Older versions stay archived for two years so you can compare what changed between visits.
Legal Review
Indonesian counsel reads the document before any material change ships. Their notes drive the wording around financial retention windows and the QRIS transaction trail we are required to keep.
Plain Language Pass
After legal sign-off, an editor rewrites jargon into the en-ID English you're reading now. The goal is one read-through, no dictionary, no surprises buried in clauses.
Security Cross-Check
Our security lead verifies that retention claims match what the database actually does. If the policy says we purge after a window, the job that purges is tested before publication.
User Feedback Loop
Questions sent to the privacy inbox feed the next revision. If readers keep asking the same thing, that means the policy is unclear, and we rewrite the paragraph rather than the answer.
Consistency With Sibling Policy Pages
This privacy policy sits alongside our terms, cookie notice and account closure pages. Here is how the wording lines up so you don't have to cross-read four documents...
| Terms of Service | Terms govern what you agree to when opening an account; this policy governs what we do with the data that agreement produces. Definitions match across both. |
|---|---|
| Cookie Notice | Cookies are listed in their own notice. This policy references the categories but defers the per-cookie table to that page to avoid drift between the two. |
| Account Closure | Closure mechanics live on the account page; the retention window after closure is set here. Both pages cite the same number so there is no contradiction. |
| KYC Statement | Identity checks are summarised here under data collection and detailed in the KYC statement. Same lawful basis, same retention window, written for two audiences. |
| Marketing Preferences | Opt-in handling is described in this policy and controlled from the preferences screen. Both refer to the same consent record stored against your account. |
| Complaints Policy | Privacy complaints follow the route in this document; non-privacy complaints follow the general complaints policy. Escalation contacts are listed in both. |
| Sub-Processor List | Names of vendors handling your data are kept on a separate sub-processor page so it can refresh without rewriting this policy each quarter. |
What This Policy Page Shows You
These are the layout pieces you'll see as you read down this privacy policy — the chips, the version stamps, the contact blocks. We list them so nothing on the page feels decorative; every...