Reference

Explore Your Legal Rights at boom138

boom138 operates under a clear legal framework designed to protect your account, your data, and your transactions — whether you deposit via DANA, OVO, GoPay or QRIS.

Jurisdiction-clear termsDANA, OVO, GoPay, QRIS coveredData privacy enforcedAccount security documentedContact path always open
boom138 Explore Your Legal Rights at boom138
LEGAL CONTACT PATHS

Open a Legal Query With Our Compliance Team

If you have a question about our terms, a data access request, or a complaint about how your account information has been handled, our compliance team is reachable through three direct channels. We aim to acknowledge every legal query within 24 hours and resolve it within 7 business days. Response times may vary during Indonesian public holidays.

Team online

Live Chat — Compliance Queue

Open the live chat widget from any page and select the Legal or Compliance topic. Available 07:00–23:00 WIB, seven days a week. An agent with policy access picks up within five minutes during operating hours.

Email — [email protected]

Send your legal request, data access query or account-closure instruction to our compliance inbox. We log every email with a ticket number and reply within one business day, Monday through Friday 08:00–17:00 WIB.

Account Settings — Rights Request Form

Log in, navigate to Account Settings, and select Privacy and Rights to submit a formal data request or correction. The form routes directly to our data officer and generates a reference number you can track in real time.

HOW WE HANDLE YOUR DATA

Switch Off Uncertainty — Security and Rights Explained

Our data handling practices follow a structured internal policy that covers how we collect, store, use and delete your personal information.

Data Encryption at Rest and Transit

All personal data you submit — including your ID documents and payment details for DANA, OVO, GoPay or QRIS — is encrypted using AES-256 at rest and TLS 1.3 in transit. No plain-text storage is permitted at any layer.

Cookie Policy and Opt-Out

We use functional and analytics cookies to keep your session active and measure page performance. You can adjust cookie preferences at any time via the footer cookie banner without losing access to your account or wallet.

Account Security — Two-Factor Authentication

Two-factor authentication is available for all accounts and strongly encouraged. You can enable it under Account Settings using an authenticator app. Any login from an unrecognised device triggers an automatic email alert.

Data Retention Schedule

We retain your account data for a minimum of five years from the date of last activity, in line with standard financial record-keeping obligations. After that period, inactive data is deleted or anonymised on a rolling quarterly cycle.

Your Right to Access and Correction

You may request a full export of the personal data we hold on your account at any time. Submit the request through the Account Settings form or by email, and we will deliver it in a machine-readable format within 14 days.

Compliance Officer Contact

Our designated data compliance officer reviews all formal legal requests personally. Write to [email protected] with the subject line 'Data Rights Request' and include your registered email so we can match it to your account instantly.

Get Answers to Your Legal Questions

The questions below cover the legal topics we hear most often from our account holders in Indonesia. If you do not see your question here, our compliance team is reachable via live chat from 07:00 to 23:00 WIB or by email at [email protected].

Access to boom138 depends on local law in your area. We encourage you to check the regulations that apply to your specific region before opening an account, as eligibility varies where local law permits.

Log in to your account, go to Account Settings, and select Privacy and Rights. Submit the data export request there, or email [email protected]. We will deliver your data in a readable format within 14 days of receiving the request.

Yes. Submit a deletion request via the Account Settings rights form or by emailing [email protected]. Note that we are required to retain certain transaction records for five years under standard financial obligations before full deletion can occur.

Payment information is never stored in plain text. All data for DANA, OVO, GoPay and QRIS transactions is encrypted using AES-256 at rest and TLS 1.3 during transfer, keeping your financial details inaccessible to unauthorised parties.

We use functional cookies to maintain your session and analytics cookies to measure site performance. You can review and adjust your cookie preferences at any time through the cookie banner in the site footer without affecting your account access.

We retain account data for a minimum of five years from your last account activity, following standard financial record-keeping requirements. After that, data is deleted or anonymised on a rolling quarterly schedule as outlined in our privacy policy.

Contact our compliance officer directly at [email protected] with the subject line 'Data Rights Request', or use the live chat legal queue available from 07:00 to 23:00 WIB. We acknowledge all formal complaints within 24 hours.