Your privacy matters to us. This Privacy Policy explains exactly what personal data api36 collects, why we collect it, how we use and protect it, and what rights you have over your information as a player based in Indonesia.
Six principles that guide how api36 handles every piece of your personal information
All data transmitted between your device and api36 servers is protected by 256-bit TLS encryption. Stored personal data is encrypted at rest using AES-256, the same standard used by international financial institutions.
api36 collects only the personal data that is genuinely necessary for account operation, KYC verification, payment processing, and compliance. We do not collect data beyond what is required for these defined purposes.
api36 does not sell, rent, or trade your personal data to third parties for their own independent marketing or commercial purposes. Data shared with third parties is strictly limited to what is needed to deliver our services.
You retain meaningful rights over your data at all times — including the right to access, correct, restrict, or request deletion of your personal information. Requests can be submitted to our support team at any time.
api36 retains personal data only for as long as is necessary for the purpose for which it was collected, or as required by applicable AML, KYC, and international gaming regulations. Accounts closed more than seven years ago are purged from active systems.
In the unlikely event of a data security breach affecting your personal information, api36 commits to notifying affected Members promptly — within 72 hours of confirmed discovery — and taking immediate remedial action.
As an api36 member you hold the following rights in relation to your personal data
Request a full copy of the personal data api36 holds about you at any time. We will respond within 30 days of a verified request.
Ask us to correct any inaccurate or incomplete personal data held in your api36 account record without undue delay.
Request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
Request that we temporarily limit how we use your data while a correction request or objection is being assessed by our team.
Receive a structured, commonly used, machine-readable copy of the personal data you have provided to api36, suitable for transfer to another service.
Object to api36's processing of your personal data for direct marketing purposes at any time. We will honour such objections immediately upon receipt.
To exercise any of the rights listed above, please contact our Data Protection team at [email protected] with the subject line "Data Rights Request". We will verify your identity before processing the request and respond within 30 calendar days.
Important Notice: This Privacy Policy forms part of your agreement with api36. By creating an account or continuing to use the Platform, you acknowledge that you have read and understood how we collect and process your personal data as described herein. If you do not agree with this policy, please discontinue use of the Platform and contact us to close your account.
1.1 For the purposes of this Privacy Policy, api36 (operating at https://api36.onl) acts as the data controller responsible for the personal information collected from Members and visitors to the Platform. References to "api36", "we", "us", or "our" throughout this document refer to the api36 platform and its operators.
1.2 As the data controller, api36 determines the purposes and means by which your personal data is processed. We are committed to handling that data lawfully, transparently, and in accordance with internationally recognised data protection principles.
1.3 All data protection enquiries and rights requests should be directed to our support team at [email protected] with the subject line "Privacy – Data Protection Enquiry".
2.1 api36 collects personal data through several channels: directly from you when you register and use the Platform, automatically through technical systems as you interact with the site, and in limited circumstances from verified third parties. The categories of personal data we collect include:
| Category | Examples of Data Collected | Collection Method |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government-issued ID number (KTP, SIM, or passport number) | Registration form, KYC submission |
| Contact Data | Residential address in Indonesia, city (e.g., Jakarta, Surabaya, Bandung), email address, mobile phone number | Registration form, account settings |
| Financial Data | Bank account details (BCA, BRI, BNI, Mandiri, CIMB Niaga, BSI, Bank Permata), e-wallet identifiers (OVO, GoPay, DANA, ShopeePay, LinkAja), deposit and withdrawal transaction records | Payment processing, transaction logs |
| Gaming Data | Bet history, game session records, wagering amounts (in IDR), bonus redemption history, win/loss records | Platform activity logs |
| Technical Data | IP address, device type, browser type and version, operating system, session duration, pages visited, referring URLs | Automatic collection via cookies and server logs |
| Communications Data | Records of live chat conversations, email correspondence, WhatsApp support messages, and any written complaints or feedback submitted to api36 | Customer support interactions |
| Verification Documents | Scanned copies or photographs of government-issued photo ID, proof-of-address documents, bank passbook cover images submitted for KYC purposes | KYC verification process |
2.2 Data You Choose to Provide. Certain data fields are mandatory for account registration and KYC. Declining to provide mandatory data will prevent account activation or withdrawal processing. Optional data fields are clearly labelled as such.
2.3 Sensitive Personal Data. api36 does not intentionally collect sensitive personal data such as racial or ethnic origin, religious beliefs, health information, or political opinions. In the event that such data is inadvertently submitted (for example, if a document provided for KYC purposes reveals religious affiliation), that data will not be processed beyond what is strictly necessary for the KYC verification purpose and will not be stored independently.
3.1 api36 processes your personal data on one or more of the following legal bases, depending on the specific processing activity:
4.1 api36 uses your personal data exclusively for the following defined purposes:
4.2 api36 does not use your personal data for automated decision-making that produces legal or similarly significant effects without human review, except where this is necessary for fraud detection, at which point a human compliance officer will review any significant adverse action before it is applied to your account.
5.1 api36 does not sell your personal data. We share personal data only in the following limited, controlled circumstances:
5.2 Any third party that receives personal data from api36 is required to handle it with at least the same level of protection that api36 applies, and to use it only for the specific purpose for which it was shared.
6.1 api36 uses cookies and similar tracking technologies to operate the Platform effectively. The types of cookies we deploy are as follows:
6.2 You can manage cookie preferences through your browser settings. Note that disabling strictly necessary cookies will affect your ability to log in and use core features of the api36 Platform. Instructions for managing cookies in common browsers are available through the help sections of Chrome, Firefox, Safari, and other major browsers.
7.1 api36 retains personal data for the minimum period necessary to fulfil the purpose for which it was collected, taking into account legal, regulatory, and business requirements. Our standard retention periods are as follows:
7.2 At the end of the applicable retention period, personal data is securely deleted or irreversibly anonymised. Anonymised data may be retained indefinitely for statistical and analytical purposes, as it can no longer be attributed to any identifiable individual.
8.1 api36 implements a comprehensive suite of technical and organisational security measures designed to protect your personal data against unauthorised access, disclosure, alteration, or destruction. Key measures include:
8.2 While api36 applies industry-leading security practices, no system is completely immune to risk. In the event of a data security incident that poses a risk to your personal data, api36 will notify affected Members within 72 hours of confirmed discovery and will provide clear guidance on any protective steps you should take.
9.1 api36 operates globally and may store or process your personal data on servers located outside Indonesia. Whenever personal data is transferred to a country that does not maintain the same level of data protection as Indonesia, api36 ensures that appropriate safeguards are in place. These safeguards include:
9.2 By using the api36 Platform, you consent to the transfer of your personal data to countries outside Indonesia for the purposes described in this Privacy Policy, subject to the safeguards outlined above.
10.1 The api36 Platform is strictly intended for adults aged 21 years and over. api36 does not knowingly collect personal data from individuals under the age of 21. Age verification is a mandatory step in the registration and KYC process.
10.2 If api36 becomes aware that personal data has been collected from an individual who is under 21 years of age, that account will be immediately suspended, all associated data will be reviewed, and the account will be permanently closed. Any funds deposited by a minor will be returned to the original payment source following a security review.
10.3 If you are a parent or guardian and believe that your child has registered an account on api36, please contact us immediately at [email protected]. We will investigate and take swift action.
11.1 The api36 Platform integrates with third-party services to deliver a complete gaming experience. These include game studios (Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, Pocket Games Soft), payment gateways, and customer communication tools. Each of these third parties operates under its own privacy policy as an independent data controller for the data it processes directly.
11.2 api36 is not responsible for the privacy practices of third-party game studios or payment providers. We encourage you to review the privacy policies of any third-party service you interact with in connection with your use of the api36 Platform.
11.3 The api36 Platform does not contain links to external third-party websites. Any pages accessible via api36 are operated directly by api36 and are subject to this Privacy Policy.
12.1 To exercise any of your data protection rights — including access, rectification, erasure, restriction, portability, or objection — please submit a written request to our support team using the contact details in Section 14. To protect your privacy, we will verify your identity before processing any data rights request.
12.2 api36 will respond to all verified data rights requests within 30 calendar days. In complex cases, this period may be extended by a further 30 days, in which case you will be notified of the extension and the reason for it.
12.3 There is no charge for exercising your data rights. However, if a request is manifestly unfounded or excessive (for example, repetitive requests for the same data), api36 reserves the right to charge a reasonable administrative fee or to decline the request, providing written reasons for such a decision.
12.4 Withdrawing Marketing Consent. If you wish to stop receiving promotional communications from api36, you may do so at any time by clicking the "unsubscribe" link in any marketing email, by contacting [email protected], or by updating your communication preferences in your account settings. Withdrawal of marketing consent does not affect the lawfulness of processing carried out prior to withdrawal.
13.1 api36 reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data practices, legal obligations, or the services we offer. When material changes are made, we will notify Members via a prominent notice on the Platform and by email to the address registered on the Member's account, at least 14 days before the changes take effect.
13.2 The "Last Updated" date at the top of this page reflects the date on which the current version was published. The most current version of this Privacy Policy is always available at https://api36.onl/privacy-policy. We encourage you to review this page periodically.
13.3 Your continued use of the api36 Platform after the effective date of any amendment constitutes your acceptance of the updated Privacy Policy. If you do not accept the revised policy, you must stop using the Platform and contact us to close your account.
14.1 If you have any questions, concerns, or complaints about this Privacy Policy or about how api36 handles your personal data, please contact us using the details below. All formal data protection correspondence should be submitted by email for documentation purposes.
api36 Data Protection & Privacy Team
Email: [email protected] — Subject: "Privacy – Data Protection Enquiry"
Live Chat: Available 24/7 via the Platform
WhatsApp Support: 08:00–24:00 WIB
We aim to resolve all privacy concerns promptly and fairly. Email enquiries are acknowledged within 48 hours and receive a substantive response within 7 business days. Data rights requests receive a full response within 30 calendar days of identity verification.
We are committed to protecting your privacy at every step. Have questions about your account, or ready to start playing? Our 24/7 support team is here to help.