Terms of Use
Definitions of 'account', 'wallet' and 'session' match exactly between the terms page and this privacy policy, so you don't have to cross-reference two glossaries.
This is the merpati77 privacy policy in plain English. We wrote it so you can scan it on your phone before you open an account, not after. It...
merpati77 collects only the data we need to run your account: your name, contact handle, device fingerprint, and the wallet references tied to DANA, OVO, GoPay or QRIS top-ups. We process this where local law permits and within supported regions of Indonesia. Identity checks are handled by our compliance desk and stored in encrypted form. We don't sell your data to third
parties, and marketing pushes are opt-in only. If you close your account, transactional records remain on file for the retention window required by Indonesian financial regulation, after which they're purged from active systems.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
If you want to access, correct or delete the data we hold, our privacy desk handles it directly. Use any of the channels below and we'll route the request to the right...
We treat the privacy policy as a living document, not a one-time legal dump. Here's who reviews it and how often.
Our compliance lead re-reads this policy every quarter and flags any clause that no longer matches how the lobby actually works. Changes are dated at the bottom of the page.
We work with local counsel familiar with Indonesian data and e-wallet rules, so wording around DANA, OVO, GoPay and QRIS records stays accurate rather than copy-pasted from foreign templates.
Account credentials and KYC documents sit behind industry-standard encryption at rest and in transit. Access is limited to named reviewers, and every read is logged for audit purposes.
We deliberately avoid legalese where regular wording works. If a clause needs jargon, we explain it in the same paragraph so you don't have to open a dictionary mid-read.
Material changes are pushed to your registered email and shown as a banner the next time you sign in, giving you time to read before continuing to use the lobby.
Our retention windows and deletion processes are spot-checked by an external reviewer once a year, with findings folded back into the next quarterly policy refresh.
This privacy policy lives alongside our other legal pages. They share definitions, retention windows and contact paths so nothing contradicts.
Definitions of 'account', 'wallet' and 'session' match exactly between the terms page and this privacy policy, so you don't have to cross-reference two glossaries.
Cookie categories listed there map one-to-one onto the tracking section here. Opt-outs you set on the cookie banner are honoured across both.
Document lists and storage windows shown on the KYC page are repeated in this policy's retention clause, kept in sync at every quarterly review.
Payment record retention for DANA, OVO, GoPay and QRIS uses the same windows quoted in the wallet policy, so financial and privacy timelines never drift apart.
The closure flow described in account settings triggers the deletion process described here, with the same confirmation email template referenced in both places.
Opt-in toggles on the preferences page feed directly into the consent register described in this policy, so unticking a box stops the corresponding data flow.
The escalation ladder for privacy issues mirrors the general complaint path, ending at the same compliance lead so nothing gets lost between teams.
These are the visible elements that define how the policy reads on your screen, not payment options. We've designed each one so you can act on...
Each clause has a clickable anchor in the side rail, so you can jump straight to retention, KYC or marketing without scrolling through the whole document on a phone screen.
A dated stamp sits at the foot of the page and next to any clause changed in the last review, so you can see at a glance what's new since your previous visit.
Hover or tap any underlined term and a short definition appears. No need to flip back to a glossary page to remember what 'processor' or 'controller' means.
Access, correction and deletion buttons are embedded in the relevant clauses, so you can act on a right the moment you read it instead of hunting through settings.
A single-tap print view strips the navigation and renders the policy as a clean document, useful if you want a saved copy for your own records before opening an account.
Older versions of this policy are linked at the bottom, so you can compare what changed and when, rather than relying on us to summarise the differences for you.