🔒
Legal

Privacy Policy — How api28 Protects Your Data

At api28, your privacy is treated as a foundational responsibility, not an afterthought. This Privacy Policy explains precisely what personal data we collect when you use our platform, why we collect it, how it is stored and protected, who we share it with, and what rights you hold over your own information as an Indonesian player.

Last updated: January 2026

Your Privacy, Our Responsibility

This Privacy Policy ("Policy") applies to all personal data processed by api28 in connection with the api28.pro website and all associated gaming services. It governs the relationship between api28 ("we", "us", "our") and any individual ("you", "Player", "User") who visits, registers on, or interacts with the api28 platform.

By registering an account or continuing to use api28 services after this Policy has been published or updated, you acknowledge that you have read and understood how api28 handles your personal data. If you do not agree with any part of this Policy, please discontinue use of the platform and contact our support team to close your account and request data deletion where applicable.

Security commitment: All api28 connections are protected by 256-bit SSL/TLS encryption. Player data is stored on access-controlled, secured servers. api28 will never sell your personal information to unaffiliated third-party advertisers.

Section 1

Definitions

For clarity throughout this Policy, the following terms carry the meanings set out below:

  • "Personal Data" means any information relating to an identified or identifiable natural person — including name, email address, date of birth, government identification number, IP address, device identifiers, and financial transaction details.
  • "Processing" means any operation or set of operations performed on Personal Data, including collection, recording, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, erasure, or destruction.
  • "Data Controller" means api28, the entity that determines the purposes and means of processing Personal Data collected through the api28 platform.
  • "Data Processor" means any third party that processes Personal Data on behalf of api28 under a written contractual agreement — such as payment gateways, KYC verification providers, and fraud-prevention services.
  • "Consent" means any freely given, specific, informed, and unambiguous indication of the Player's agreement to the processing of their Personal Data for a stated purpose.
  • "KYC" means Know Your Customer — the identity verification process api28 uses to confirm the age, identity, and payment ownership of Players, particularly in connection with withdrawal approvals.
Section 2

Data We Collect

api28 collects Personal Data through several channels: directly from you when you register or interact with the platform, automatically through your device and browser when you access the site, and from trusted third-party verification and payment services. The categories of data we collect are set out in the table below:

Category Examples Collection Method
Identity Data Full legal name, date of birth, gender, nationality, KTP / passport number Provided by you during registration or KYC verification
Contact Data Email address, mobile phone number, city of residence (e.g., Jakarta, Surabaya, Bandung) Provided by you during registration or account updates
Financial Data Bank account details (BCA, BRI, BNI, Mandiri, CIMB Niaga), e-wallet identifiers (OVO, DANA, GoPay, ShopeePay, LinkAja), deposit and withdrawal transaction records in IDR Provided by you when initiating transactions; confirmed by payment processors
Technical Data IP address, browser type, operating system, device model, screen resolution, session timestamps Collected automatically via server logs and cookies
Usage Data Pages visited, games played (slots, live casino, togel draws, sportsbook wagers), session durations, bet amounts, win/loss history Collected automatically via platform analytics
Communications Data Live chat transcripts, support email correspondence, survey responses Recorded when you contact api28 support
Verification Data Scanned or photographed identity documents, selfie images submitted for liveness checks Provided by you during KYC; processed by our identity verification partner

api28 does not collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, or health data, except where age and identity verification incidentally involves such categories in the course of reviewing official government identification documents.

Section 3

How We Use Your Data

api28 processes your Personal Data only for specific, lawful purposes. We do not use your data in ways that are incompatible with the purposes for which it was originally collected. The primary purposes for which api28 processes Personal Data are:

  • Account creation and management: To register your account, verify your identity and age (21+), and maintain your account in good standing on the platform.
  • Payment processing: To facilitate deposits and withdrawals in IDR via supported Indonesian banks (BCA, BRI, BNI, Mandiri, and others) and e-wallets (OVO, DANA, GoPay, ShopeePay, LinkAja), and to maintain accurate transaction records.
  • Service delivery: To provide access to api28 gaming products — including slots, live casino, sportsbook, and togel (Indonesia's traditional numbers lottery) — and to personalise your platform experience.
  • Fraud prevention and security: To detect, investigate, and prevent fraudulent activity, money laundering, unauthorised account access, multi-accounting, and other prohibited conduct as defined in our Terms & Conditions.
  • Regulatory compliance: To comply with applicable anti-money-laundering (AML) obligations, identity verification requirements, and any lawful requests from competent authorities.
  • Customer support: To respond to your queries, complaints, and requests in a timely and effective manner, and to maintain records of interactions for quality and training purposes.
  • Responsible gaming: To monitor gameplay patterns, identify potential problem gambling behaviours, and apply self-exclusion, deposit limit, or cooling-off tools where necessary to protect player welfare.
  • Marketing communications: To send you promotional offers, bonus notifications, and platform updates by email or in-platform message — only where you have given explicit consent or where we have a legitimate interest in keeping you informed about services materially similar to those you already use. You may opt out of marketing communications at any time.

api28 will never use your Personal Data to make fully automated decisions that produce legal or similarly significant effects on you without human review. Any account restriction or suspension decision may be contested by contacting our support team.

Section 5

Data Sharing & Third Parties

api28 does not sell, rent, or trade your Personal Data to any third party for their own independent marketing purposes. We share Personal Data only in the circumstances and with the categories of recipient described below:

  • Payment processors and banking partners: Indonesian banks (BCA, BRI, BNI, Mandiri, CIMB Niaga, Bank Permata, BSI, OCBC NISP, Bank Danamon) and e-wallet operators (OVO, DANA, GoPay, ShopeePay, LinkAja) receive the minimum financial data necessary to authorise and complete your transactions.
  • Identity verification providers: Our KYC partner receives copies of identity documents and verification images strictly for the purpose of confirming your age and identity as part of the account verification process.
  • Game content suppliers: Third-party studios including Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, and Pocket Games Soft may receive anonymised session and gameplay data to ensure game functionality and resolve technical disputes.
  • Fraud prevention and security services: Specialist third-party services receive relevant transaction and behaviour data to assist in detecting and preventing fraudulent activity on the platform.
  • Regulatory and law enforcement authorities: We will disclose Personal Data to government bodies, regulators, or law enforcement agencies where we are legally required to do so or where disclosure is necessary to protect the rights, property, or safety of api28, its Players, or the public.
  • Professional advisers: Lawyers, auditors, and accountants engaged by api28 may access Personal Data on a strictly need-to-know basis and are bound by professional confidentiality obligations.

All third-party Data Processors engaged by api28 are required to enter into written data processing agreements committing them to process Personal Data only in accordance with api28's documented instructions and to implement appropriate technical and organisational security measures.

Section 6

Data Retention

api28 retains Personal Data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our standard retention periods are as follows:

  • Account and identity data: Retained for the duration of your active account relationship with api28, plus a minimum of five (5) years following account closure — to satisfy AML record-keeping obligations and to resolve any disputes that may arise after closure.
  • Financial transaction records: Retained for a minimum of five (5) years from the date of each transaction, in line with standard financial record-keeping practice.
  • KYC documents: Retained for the duration of your account relationship plus five (5) years after account closure, or for longer periods where required by specific regulatory obligations.
  • Support communications: Retained for three (3) years from the date of the most recent interaction in a given thread, to enable ongoing complaint resolution and quality assurance.
  • Technical and usage data: Aggregated and anonymised after thirteen (13) months; individual-level logs retained for up to thirteen (13) months for security and fraud investigation purposes.
  • Marketing consent records: Retained for the duration of your consent plus three (3) years thereafter, to demonstrate compliance with consent obligations.

Upon expiry of the applicable retention period, Personal Data is securely deleted or irreversibly anonymised in accordance with api28's data lifecycle management procedures.

Section 7

Security Measures

api28 implements a layered set of technical and organisational security measures designed to protect your Personal Data against unauthorised access, accidental loss, alteration, or disclosure. These measures include:

  • Encryption in transit: All data exchanged between your browser or app and api28 servers is encrypted using TLS 1.2 or TLS 1.3 with 256-bit SSL certificates.
  • Encryption at rest: Sensitive data fields — including identity document images, bank account details, and password hashes — are encrypted at rest using AES-256 encryption on secured server infrastructure.
  • Access controls: Access to systems holding Personal Data is restricted to authorised api28 personnel and approved Data Processors on a strict need-to-know basis, enforced through role-based access control and multi-factor authentication.
  • Network security: api28 infrastructure is protected by enterprise-grade firewalls, intrusion detection systems, and regular vulnerability assessments conducted by qualified security professionals.
  • Incident response: api28 maintains a documented data breach response procedure. In the event of a confirmed breach that poses a material risk to your rights, you will be notified promptly with details of the nature of the incident and the steps api28 has taken in response.

While api28 implements industry-standard security measures, no internet-based system is wholly immune to risk. You play an important role in protecting your own account by using a strong, unique password, enabling any available two-step verification options, and notifying api28 immediately if you suspect unauthorised access to your account.

Section 8

Cookies & Tracking Technologies

api28 uses cookies and similar tracking technologies (such as local storage objects and pixel tags) to operate and improve the platform experience. Cookies are small text files placed on your device by your browser when you visit api28.pro. The categories of cookies we use are:

  • Strictly necessary cookies: Required for the platform to function — including maintaining your login session, remembering your language and currency preferences, and ensuring security tokens are correctly transmitted. These cookies cannot be disabled without breaking core platform functionality.
  • Performance and analytics cookies: Used to collect anonymised data about how Players navigate and use the api28 platform, allowing us to identify high-traffic pages, measure feature engagement, and optimise site performance. Data collected through these cookies is aggregated and does not personally identify you.
  • Functional cookies: Used to remember choices you make on the platform — such as your preferred deposit method or game lobby filter settings — to provide a more personalised experience on return visits.
  • Marketing cookies: Where you have provided consent, these cookies may track your visit across the api28 domain to allow us to serve relevant promotional content within the platform. api28 does not use third-party cross-site advertising cookies that track you beyond our own domain.

You may manage your cookie preferences through your browser settings at any time. Note that disabling strictly necessary cookies may impair your ability to log in or use platform features. For further information about cookies, please refer to your browser's help documentation.

Section 9

Your Privacy Rights

As an api28 Player, you hold the following rights in respect of your Personal Data. To exercise any of these rights, please contact our support team using the details provided in Section 13. api28 will respond to all verified data rights requests within thirty (30) calendar days of receipt.

Your Data Rights at api28

These are the specific rights you hold over your Personal Data. Contact our support team at any time to exercise them — no fees apply to standard requests.

Right of Access

Request a copy of all Personal Data api28 holds about you, along with information on how it is being processed and for what purposes.

Right to Rectification

Request correction of any inaccurate or incomplete Personal Data we hold about you, including updates to contact details or name changes after legal documentation.

Right to Erasure

Request deletion of your Personal Data where there is no longer a lawful basis for us to retain it — subject to our legal obligation to retain certain records for AML and compliance purposes.

Right to Restrict Processing

Request that api28 limits the processing of your data to storage only — for example, while the accuracy of data is being contested or a processing objection is being assessed.

Right to Data Portability

Request a machine-readable copy of the Personal Data you have provided to api28, where processing is based on your consent or a contractual agreement with you.

Right to Object

Object to processing based on api28's legitimate interests — including profiling for marketing purposes. We will cease such processing unless we can demonstrate compelling legitimate grounds that override your interests.

Section 10

Children & Minors

The api28 platform is strictly intended for adults aged 21 years and older. api28 does not knowingly collect, solicit, or process Personal Data from any person under the age of 21. If api28 discovers or has reason to believe that a registered account belongs to a person under 21, we will immediately suspend that account, void any associated transactions, and securely delete the Personal Data in question.

If you believe that a minor has gained access to the api28 platform and submitted Personal Data, please contact our support team at once so we can investigate and take appropriate action without delay. Parents and guardians are encouraged to use device-level parental control tools to prevent minors from accessing online gaming services.

Section 11

International Data Transfers

api28 operates as an internationally oriented gaming platform. In the course of delivering our services to Indonesian players across Jakarta, Surabaya, Medan, Bandung, Bali, and other cities, your Personal Data may be processed on servers or by service providers located in jurisdictions outside Indonesia.

Whenever Personal Data is transferred outside the country where it was collected, api28 takes steps to ensure that the recipient provides an adequate level of protection for that data — whether through appropriate contractual safeguards, recognised certification frameworks, or other mechanisms consistent with applicable data protection standards. api28 will not transfer your Personal Data to jurisdictions that do not offer an adequate level of protection without first putting in place appropriate safeguards.

Section 12

Changes to This Policy

api28 may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or platform features. When we make material changes to this Policy, we will notify you by email to your registered address and/or by displaying a prominent notice on the platform for a reasonable period before the changes take effect.

The "Last updated" date displayed at the top of this page indicates when the most recent revision was made. We encourage you to review this Policy periodically to stay informed about how api28 protects your Personal Data. Your continued use of the api28 platform following the effective date of any revision constitutes your acknowledgement of the updated Policy.

Section 13

Contact & Data Requests

For any questions about this Privacy Policy, to exercise your privacy rights, or to submit a formal data request, please reach our dedicated support team through the following channel:

  • Email: [email protected] (displayed as plain text — not a clickable link)
  • Live Chat: Available 24 hours a day, 7 days a week via the in-platform chat widget, staffed by agents fluent in both English and Indonesian.
  • Subject line: Please include "Privacy Request" or "Data Rights" in the subject of your email so our team can route it to the appropriate department promptly.

api28 will acknowledge all privacy-related requests within five (5) business days (WIB, UTC+7) and will aim to resolve requests fully within thirty (30) calendar days. If a request is complex or we receive a high volume of requests simultaneously, we may extend the response period by a further thirty (30) days, in which case we will notify you of the extension and the reason for it.

This Policy should be read alongside the api28 Terms & Conditions, which govern the overall relationship between api28 and its Players, and the Responsible Gaming page, which explains the tools and support available to Players who feel their gambling may be causing harm.

Our Privacy Commitments

Six principles that guide how api28 treats your personal data across every interaction on our platform.

256-bit SSL Encryption

Every connection between your device and api28 is secured with TLS 1.3 and 256-bit SSL certificates. Your login credentials, financial data, and account details are never transmitted in plain text.

No Data Sales — Ever

api28 will never sell, rent, or trade your personal information to any unaffiliated third party for their own marketing or commercial purposes. Your data is used solely to deliver and improve your platform experience.

Strict KYC Standards

Identity and age verification are handled by accredited third-party KYC providers under strict contractual data-processing agreements. Document images are encrypted at rest and never accessed without a valid operational reason.

Defined Retention Periods

api28 retains your data only for as long as legally required or operationally necessary. Account data is securely deleted or anonymised after defined retention windows, with no indefinite storage of unnecessary records.

Opt-Out Marketing

Promotional emails and in-platform notifications are opt-in by default. You can withdraw marketing consent at any time through your account settings or by contacting support, with no impact on your access to platform services.

Responsive Data Team

Our support team handles all data rights requests — access, rectification, deletion, portability — within 30 calendar days. Native Indonesian-speaking agents are available 24/7 to assist you in your preferred language.

Explore api28 with Confidence

Your privacy is protected at every step. Ready to enjoy Indonesia's widest range of slots, live casino, sportsbook, and togel games — all in IDR with instant e-wallet support?

21+ only. Gambling can be addictive — please play responsibly.