Summary: api89 collects only the personal data necessary to operate a safe, compliant, and personalised gaming service for players in Indonesia. We do not sell your data. We do not share your data with advertisers. We protect it with enterprise-grade encryption. This policy explains everything in plain, professional language — please read it in full.
Section 01
Introduction
This Privacy Policy ("Policy") describes how api89 ("we", "us", "our") collects, processes, stores, and protects personal data submitted by users ("you", "your") of the api89 platform at https://api89.vip. It applies to all visitors, registered users, and former users of the platform, regardless of the device or connection method used to access it.
api89 is committed to handling your personal information with the highest standards of data protection, transparency, and integrity. This Policy is an integral part of the api89 Terms & Conditions. By registering an account or using any service on api89, you acknowledge that you have read and understood this Policy and consent to the data-processing activities described
herein.
api89 serves players primarily based in Indonesia. Where this Policy references local context — such as Indonesian Rupiah (IDR / Rp), local banks (BCA, BRI, BNI, Mandiri, CIMB Niaga), e-wallets (GoPay, OVO, DANA, ShopeePay, LinkAja), or Indonesian cities — these references reflect our primary operating market and are used solely to deliver a relevant, localised service experience to you.
Applicable Standard: api89 applies internationally recognised data-protection principles — including purpose limitation, data minimisation, storage limitation, integrity, and confidentiality — to all personal data we process, irrespective of the specific legal framework in force in any individual jurisdiction.
Section 02
Data We Collect
api89 collects personal data in the following categories. We collect only what is strictly necessary for the purpose stated against each category.
2.1 Identity & Registration Data
Full Legal Name
Date of Birth
Email Address
Mobile Number
Username
Hashed Password
Collected at the point of account registration. This data is required to create and authenticate your account, verify your age (21+ requirement), and communicate with you about your account activity.
2.2 Identity Verification (KYC) Data
Government-Issued ID (KTP / Passport / SIM)
Proof of Address
Selfie / Liveness Check
Collected during Know Your Customer (KYC) verification, which is mandatory before your first withdrawal and may be requested at any time thereafter. KYC documents are processed by our regulated identity verification partner and are not stored in plain form on api89's primary application servers.
2.3 Financial Data
Bank Account Details
E-Wallet Account IDs
Transaction Histories
Deposit / Withdrawal Amounts (IDR)
Collected to process deposits and withdrawals via local Indonesian banking channels (BCA, BRI, BNI, Mandiri, CIMB Niaga) and e-wallets (GoPay, OVO, DANA, ShopeePay, LinkAja). Financial data is also used for anti-money-laundering (AML) monitoring and fraud prevention. We do not store full card numbers or complete bank account credentials on our servers; payment processing is handled by PCI-DSS-compliant payment processors.
2.4 Gaming & Betting Activity Data
Game Sessions
Bets Placed & Outcomes
Wagering History
Bonus Redemptions
Collected automatically as part of the service. Gaming activity data is used to calculate winnings, apply bonus wagering requirements, generate account statements, and identify patterns consistent with problem gambling so that we may proactively offer responsible gaming tools.
2.5 Technical & Device Data
IP Address
Device Type & OS
Browser Type & Version
Approximate Geolocation
Session Timestamps
Collected automatically via server logs and analytics tools when you access the platform. This data is used for security monitoring, fraud detection, geographic access controls, platform performance optimisation, and regulatory compliance.
2.6 Communications Data
Live Chat Transcripts
Email Correspondence
Promotional Preferences
Collected when you contact our support team or interact with our promotional communications. Support transcripts are retained for quality assurance, dispute resolution, and staff training purposes.
Section 03
How We Collect Data
api89 collects personal data through the following channels:
Direct Input
Information you provide voluntarily when registering an account, completing KYC, making a deposit or withdrawal, contacting support, or participating in a promotion.
Automated Collection
Technical and device data collected automatically via server logs, session tracking, and platform analytics tools whenever you access or use the api89 platform.
Cookies & Pixels
Small data files placed on your device by the api89 platform to maintain session state, remember preferences, and collect anonymised usage analytics. See Section 7 for full cookie details.
Payment Processors
Confirmation data (transaction reference, amount, timestamp, payment method type) returned by our Indonesian payment partners — including GoPay, OVO, DANA, BCA, and BRI — upon completion of a deposit or withdrawal transaction.
KYC Providers
Verification outcomes (pass/fail/pending), risk scores, and document validity flags returned by our regulated third-party KYC and AML screening service providers.
Fraud Detection Systems
Device fingerprints, behavioural anomaly scores, and risk signals generated by our internal and third-party fraud-detection infrastructure to protect the integrity of the platform and its users.
Section 04
How We Use Your Data
api89 uses collected personal data exclusively for the following purposes:
- Account Management: To create, authenticate, and maintain your api89 account, including resetting credentials and managing account security settings.
- Service Delivery: To process bets, calculate payouts, credit winnings to your balance, and operate all games, sportsbook markets, and casino products available on the platform.
- Payment Processing: To execute deposit and withdrawal transactions in Indonesian Rupiah (IDR) via your selected bank (BCA, BRI, BNI, Mandiri, CIMB Niaga) or e-wallet (GoPay, OVO, DANA, ShopeePay, LinkAja).
- Identity & Age Verification: To verify that you are who you say you are and that you meet the 21+ age requirement before allowing withdrawals or continued access to the platform.
- Regulatory Compliance: To fulfil our obligations under applicable anti-money-laundering (AML), know-your-customer (KYC), and counter-terrorist-financing (CTF) standards.
- Fraud Prevention & Security: To detect and prevent unauthorised account access, fraudulent transactions, bonus abuse, and other prohibited conduct as defined in our Terms & Conditions.
- Responsible Gaming: To monitor gaming activity patterns that may indicate problem gambling behaviour and to proactively offer responsible gaming tools, including deposit limits, cooling-off periods, and self-exclusion options.
- Customer Support: To respond to your queries, resolve disputes, and maintain records of support interactions for quality assurance purposes.
- Promotions & Communications: To send you promotional offers, bonus notifications, and platform updates, subject to your communication preferences. You may opt out of marketing communications at any time.
- Platform Improvement: To analyse anonymised usage data and improve the performance, reliability, and user experience of the api89 platform.
No Data Selling: api89 does not sell, rent, or trade your personal data to any third party for their own marketing or commercial purposes under any circumstances. This is an unconditional commitment.
Section 05
Legal Basis for Processing
api89 processes your personal data on the following legal bases, consistent with internationally recognised data-protection principles:
Contractual Necessity
Processing required to perform our contract with you — namely, to provide the betting, casino, and payment services you have registered to use. Without this data, we cannot operate your account.
Legal Obligation
Processing required to comply with AML, KYC, and CTF obligations under the international licensing and regulatory standards to which api89 is subject.
Legitimate Interests
Processing carried out in our legitimate interests — including fraud prevention, platform security, responsible gaming monitoring, and product improvement — where those interests are not overridden by your fundamental rights.
Consent
Processing of data for marketing communications and non-essential cookies, where we have obtained your explicit, freely given, and revocable consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
Section 06
Data Sharing & Disclosure
api89 shares personal data with third parties only to the minimum extent necessary and only with parties who are contractually bound to protect your data to the same standard as api89. The categories of third parties with whom we may share your data are as follows:
6.1 Payment Processors
We share transaction data with Indonesian payment processing partners — including the operators of GoPay, OVO, DANA, ShopeePay, LinkAja, and the interbank transfer networks used by BCA, BRI, BNI, Mandiri, and CIMB Niaga — strictly as necessary to execute your deposit and withdrawal instructions.
6.2 KYC & AML Service Providers
Identity documents and personal data submitted during KYC verification are shared with our regulated, accredited third-party identity verification and AML screening partners. These partners process your data only on our instructions and are prohibited from using it for any other purpose.
6.3 Game Content Providers
When you play a game hosted by a third-party studio — such as Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, or Pocket Games Soft — your session data (player ID, bet amounts, game outcomes) is shared with that provider solely to facilitate your gaming session and calculate results. These providers do not receive your name, contact details, or financial data.
6.4 Fraud Detection Partners
Technical and device data (IP address, device fingerprint, session behaviour) may be shared with specialist fraud-detection service providers to protect the platform and its users against fraudulent activity.
6.5 Legal & Regulatory Authorities
api89 will disclose personal data to law enforcement, regulatory authorities, or courts of competent jurisdiction where we are legally required to do so, or where disclosure is necessary to protect the rights, property, or safety of api89, its users, or the public.
6.6 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of api89's assets, personal data held by api89 may be transferred to the acquiring entity as part of that transaction. We will notify affected users via email and an in-platform notification before any such transfer occurs and before your data becomes subject to a materially different privacy policy.
All third-party data processors engaged by api89 are subject to data processing agreements (DPAs) that obligate them to process your data only on our documented instructions, to implement appropriate technical and organisational security measures, and to delete or return your data upon termination of the engagement.
Section 07
Cookies & Tracking Technologies
api89 uses cookies and similar tracking technologies (local storage, session storage, pixel tags) to operate the platform, maintain your session, and collect anonymised analytics. The cookies we use fall into the following categories:
Strictly Necessary
Essential for the platform to function. These include session authentication tokens, CSRF protection tokens, and load-balancer routing cookies. They cannot be disabled without preventing you from using the platform.
Functional
Used to remember your preferences, such as your preferred language, display settings, and responsible gaming tool configurations. Disabling these cookies may affect your experience but will not prevent access to core services.
Analytics
Used to collect anonymised, aggregated data about how users navigate the api89 platform — including page visit counts, session durations, and feature usage rates. This data is used solely to improve the platform and is never linked to your personal identity.
Security
Used to detect and mitigate fraudulent sessions, bot activity, and credential-stuffing attacks. These cookies assign a risk score to each session based on behavioural signals and are a core component of our fraud-prevention infrastructure.
api89 does not use third-party advertising cookies or cross-site tracking technologies. You may manage cookie preferences through your browser settings, though disabling strictly necessary cookies will prevent you from logging in to your account.
Section 08
Data Retention
api89 retains personal data only for as long as is necessary for the purpose for which it was collected, or as required by applicable law and regulatory obligations. The following retention periods apply:
Active Account Data
Retained for the duration of your active account relationship with api89, plus a minimum of five (5) years after account closure to satisfy AML and regulatory record-keeping requirements.
KYC Documents
Retained for a minimum of five (5) years from the date of verification, in accordance with internationally recognised AML standards. After this period, documents are securely deleted unless a longer retention period is required by applicable law.
Financial Transaction Records
Retained for a minimum of five (5) years from the date of each transaction for AML compliance and dispute resolution purposes.
Support Communications
Retained for two (2) years from the date of each interaction for quality assurance, dispute resolution, and staff training purposes.
Technical / Server Logs
Retained for ninety (90) days in a rolling window for security monitoring, incident investigation, and platform performance analysis. After 90 days, logs are either anonymised or securely deleted.
Marketing Preferences
Retained until you withdraw consent or close your account, whichever comes first. Evidence of consent (timestamp, version of policy accepted) is retained for five (5) years to demonstrate regulatory compliance.
When the applicable retention period expires, api89 will securely delete or irreversibly anonymise your personal data using industry-standard data destruction methods.
Section 09
Data Security
api89 implements a comprehensive, layered security architecture to protect your personal data against unauthorised access, disclosure, alteration, or destruction. Our security measures include, but are not limited to:
- 256-Bit SSL/TLS Encryption: All data transmitted between your device and api89's servers is encrypted in transit using TLS 1.2 or higher, preventing interception by third parties.
- Encrypted Data Storage: Sensitive data fields — including passwords (hashed with bcrypt), KYC document references, and payment method identifiers — are encrypted at rest using AES-256 encryption.
- Access Controls: Access to personal data within api89's systems is granted on a strict need-to-know basis. All staff access is authenticated, logged, and subject to regular access review.
- Two-Factor Authentication (2FA): api89 supports 2FA for user accounts and mandates it for all staff with administrative access to production systems.
- Penetration Testing: api89's platform undergoes regular independent penetration testing and security audits to identify and remediate vulnerabilities before they can be exploited.
- Incident Response: api89 maintains a documented data breach incident response plan. In the event of a breach affecting your personal data, we will notify affected users without undue delay and in accordance with applicable legal requirements.
- PCI-DSS Compliance: All payment data flows through PCI-DSS-compliant processors. api89 does not store raw card numbers or full bank account credentials on its own infrastructure.
Your Role in Security: While api89 takes all reasonable technical measures to protect your data, you are responsible for keeping your account credentials confidential. Use a unique, strong password, enable 2FA, and contact us immediately at
[email protected] if you suspect any unauthorised access to your account.
Section 10
Your Rights
As a data subject, you hold the following rights with respect to the personal data api89 holds about you. To exercise any of these rights, please contact us at [email protected] with the subject line "Privacy Rights Request — [Your Username]". We will respond within thirty (30) calendar days of receiving a verified request.
- Right of Access: You have the right to request a copy of the personal data api89 holds about you, together with information about the purposes for which it is processed, the categories of data held, and the recipients with whom it has been shared.
- Right to Rectification: You have the right to request correction of any inaccurate or incomplete personal data we hold about you. Some data (such as KYC-verified legal name) may require re-submission of supporting documentation before it can be amended.
- Right to Erasure: You have the right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, where you have withdrawn consent, or where processing is unlawful. This right is subject to overriding retention obligations (see Section 8), particularly AML and regulatory record-keeping requirements.
- Right to Restriction: You have the right to request that api89 restricts the processing of your personal data in certain circumstances — for example, while a rectification request is being investigated.
- Right to Data Portability: You have the right to receive a copy of the personal data you have provided to api89 in a structured, commonly used, machine-readable format (JSON or CSV), and to request that this data be transmitted directly to another controller where technically feasible.
- Right to Object: You have the right to object to processing of your personal data for direct marketing purposes at any time, with immediate effect. You may also object to processing based on legitimate interests, subject to api89's ability to demonstrate compelling grounds that override your interests.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
api89 will verify your identity before processing any privacy rights request to prevent unauthorised access to another user's data. Requests that cannot be verified within a reasonable timeframe will be declined pending successful identity confirmation.
Section 11
Children's Privacy
api89 is strictly an adult-only platform. No person under the age of 21 is permitted to register an account or use any service on api89. We do not knowingly collect personal data from anyone under the age of 21.
If api89 becomes aware that personal data has been collected from a person under 21 — whether through a false age declaration at registration or any other means — we will immediately suspend the relevant account, void any gaming activity conducted through it, and securely delete all personal data associated with that account, subject only to any minimum retention obligations imposed by applicable AML regulations.
If you are a parent or guardian and believe that a person under 21 in your care has registered an account on api89, please contact us immediately at [email protected]. We will investigate and take appropriate action within 48 hours of receiving a verified report.
21+ Only. Gambling is for adults. api89 actively supports parental controls and age-verification technology. We encourage parents to use internet filtering software to prevent minors from accessing gambling platforms.
Section 12
Policy Amendments
api89 reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data-processing practices, legal obligations, or platform features. When material changes are made, we will notify registered users via email and an in-platform notification at least seven (7) calendar days before the updated Policy takes effect.
The effective date at the top of this Policy will be updated whenever a new version is published. Your continued use of the api89 platform after the effective date of any amendment constitutes your acceptance of the revised Policy. If you do not agree with any amendment, you may close your account in accordance with the account closure procedure described in our Terms & Conditions.
The most current version of this Privacy Policy is always available at https://api89.vip/privacy-policy. We recommend reviewing this page periodically to stay informed of any updates.
Section 13
Contact & Complaints
If you have any questions, concerns, or complaints regarding this Privacy Policy or the way api89 handles your personal data, please contact our Data Protection team through any of the following channels:
Subject Line
Use "Privacy Policy Enquiry — [Your Username]" for general questions, or "Privacy Rights Request — [Your Username]" for formal data-subject rights requests.
Live Chat
Available 24/7 via the chat widget on the api89 platform. For sensitive privacy matters, we recommend using the email channel to ensure a written record is created.
Response Time
api89 acknowledges all privacy-related enquiries within 48 hours and aims to resolve substantive requests within 30 calendar days. Complex requests may take up to 90 days, in which case we will notify you of the extended timeline.
Support Hours
24 hours a day, 7 days a week, 365 days a year — including all Indonesian public holidays. Support is available in English and Bahasa Indonesia.
If you are not satisfied with api89's response to a privacy complaint, you have the right to escalate your complaint to the relevant data-protection supervisory authority or regulatory body in your jurisdiction. api89 will cooperate fully with any such regulatory investigation.