Terms of Service
Defines the agreement; this policy fills in the data half. Both use the same definitions for account, lobby and session so language stays aligned.
This is the galan4d privacy policy, written in plain language so you know exactly what we keep on file when you open an account with us. We cover...
We collect only the account details we genuinely need: your name, contact, verification documents and the lobby actions tied to your session. Where local law permits in supported Indonesia regions, we keep this data on encrypted servers and limit internal access to staff handling your account or compliance checks. You can ask us to export, correct or delete your record at any
time, and we'll respond within a reasonable window. Third parties only see your data when a payment rail or regulator legitimately requires it, and never for resale or unrelated marketing. This policy sits alongside our terms — together they describe the full agreement between you and galan4d.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
If anything in this policy is unclear, or you want to act on a privacy right, our team is reachable through three direct channels — pick whichever suits how you prefer to...
This policy is reviewed by people, not just templates. Here's who looks over the wording before it reaches you and how we keep it accurate over time.
Our legal counsel checks every clause against current Indonesian data rules and the licences we operate under, flagging anything that needs softer wording or a clearer reader explanation.
The compliance lead signs each version, confirming the policy matches what our internal systems actually do with your account data — no aspirational language, only what we can demonstrate.
A copy editor rewrites legal phrasing into the second-person voice you're reading now, because a policy you can't follow is a policy that doesn't really protect you.
Our security team validates the storage, encryption and access claims in this document quarterly, so the protections described here line up with the controls running on our servers.
Every revision is dated and archived. If you need to see the policy that applied when you first opened your account, we can produce that exact version on request.
When you tell us a paragraph is confusing, we log it and rewrite. Several sections of this page exist in their current form because of questions sent through our chat.
Our privacy policy sits in a small family of legal pages. Here's how it stays consistent with the others so you don't get conflicting answers.
Defines the agreement; this policy fills in the data half. Both use the same definitions for account, lobby and session so language stays aligned.
Covers browser-side tracking specifically. This policy points to it rather than duplicating, keeping cookie detail in one authoritative place.
Explains identity verification rules. We reference it when describing why we hold documents, so the reasons match across both pages.
Sets the route for disputes. Privacy escalations follow the same timing windows you'll see described there for fairness.
Lists how you opt in or out of contact. This policy describes what we do with the preference; that page is where you change it.
Explains the deletion path step by step. We summarise it here and link out, so the procedure has one canonical home.
Describes the technical controls. Our policy summarises outcomes for the reader; the security statement is where engineers go for specifics.
A few design choices shape how this policy reads. They're meant to make the page genuinely usable, not to bury the important parts.