Reference

How bonsaibola Handles Your Personal Data

At bonsaibola, every piece of information you share — from your account registration details to the payment method you choose (DANA, OVO, GoPay or QRIS) — is handled…

Data encrypted at rest and in transitNo third-party data salesDANA, OVO, GoPay & QRIS payment data protectedAccount deletion available on requestPolicy updated and dated on this page
bonsaibola How bonsaibola Handles Your Personal Data
PRIVACY CONTACT PATHS

Reach Our Data Team When You Need Answers

If you want to access, correct or delete any data bonsaibola holds about you, our privacy team is reachable through three direct channels. Response times are kept to a maximum of 72 hours on business days, and every request is logged with a ticket number so you can track its status. All channels are staffed Monday through Saturday, 09:00–22:00 WIB.

Team online

Email Privacy Request

Send a written data-access or deletion request to our dedicated privacy inbox. We acknowledge within 24 hours and resolve most requests within 72 hours on business days, Monday–Saturday 09:00–22:00 WIB.

Live Chat — Account Security

Open the live chat widget inside your bonsaibola account dashboard and select 'Privacy & Data' from the topic menu. A trained agent will verify your identity and log your request in real time during staffed hours.

WhatsApp Support Line

Message our WhatsApp number listed in the Help Centre for urgent data concerns. Share your registered email so we can locate your account record quickly and confirm the action taken within 72 hours.

HOW WE PROTECT YOU

Explore Our Data Handling and Security Practices

The six practices below cover the key areas Indonesian account holders ask about most: how we secure stored data, what cookies do on bonsaibola pages, how your account credentials are protected, how…

Encryption Standards

All personal data stored on our servers uses AES-256 encryption at rest. Data moving between your browser and our platform travels over TLS 1.3. Payment-specific fields (your DANA wallet ID, OVO mobile number) are masked in our back-end logs so staff cannot read the full value.

Cookie Policy

We use three categories of cookies: strictly necessary (session authentication), functional (language and currency preference), and analytics (aggregate page-view counts). We do not use advertising or cross-site tracking cookies. You can adjust cookie preferences from the footer settings link without losing your session.

Account Credential Security

Passwords are hashed with bcrypt before storage — we cannot read your password even internally. We recommend enabling two-step verification from the Security tab in your account settings. Suspicious login attempts from unrecognised devices trigger an automatic email alert to your registered address.

Data Retention Schedule

Active account data is kept for the duration your account remains open. After closure, identity records are held for a statutory period determined by applicable Indonesian law. Session logs and device tokens are purged on a rolling 90-day cycle regardless of account status.

Data Controller Contact

bonsaibola acts as the data controller for all information collected through bonsaibola.xyz. Questions about who holds your data, what purposes it serves, or which third-party processors handle QRIS and GoPay transactions can be directed to our privacy inbox listed in the Support section above.

Correction and Deletion Rights

You have the right to request a correction if any stored detail is inaccurate, or a full deletion where local law permits. Submit your request via live chat or email with your account email address as verification. We confirm completion in writing once the action is finalised.

Open the Answers to Common Privacy Questions

Below are the privacy questions we hear most from Indonesian account holders — covering data access, payment-detail storage, cookie controls, account closure, and how to get in touch when something does not look right. Every answer reflects the actual policy in place on bonsaibola.xyz today.

We collect your name, email address, date of birth, and the mobile number or wallet ID linked to the payment method you choose — DANA, OVO, GoPay or QRIS. We also record deposit and withdrawal timestamps for audit and fraud-prevention purposes.

No. When you make a deposit via DANA or OVO, the transaction is processed through that provider's own secure payment gateway. We receive a transaction reference and status code only — your full wallet credentials are never stored on our servers.

Identity and transaction records are retained for a statutory period after account closure, as required under applicable Indonesian data-protection and financial-record obligations. Session logs and temporary tokens are purged within 90 days. You may ask for a timeline specific to your account via email.

Yes. Send a data-access request to our privacy inbox or raise it through the live chat 'Privacy & Data' topic. We will compile and deliver a readable copy of your stored personal data within 72 hours on a business day, Monday–Saturday 09:00–22:00 WIB.

Click the cookie-settings link in the page footer to open our preference panel. You can disable functional and analytics cookies while keeping strictly necessary cookies active. Changes take effect immediately and your session will not be interrupted by adjusting these settings.

Contact our privacy team immediately via WhatsApp or live chat so we can investigate and, if needed, suspend the affected session. We will acknowledge security-related reports within 24 hours and notify you of findings as soon as our investigation is complete.

The core policy applies across Indonesia. Certain retention periods and disclosure obligations depend on local law — for example, financial-record requirements may affect how long transaction data is archived. We review the policy whenever relevant Indonesian regulations are updated and publish a revised date at the top of this page.