Privacy Policy

Your privacy is fundamental to everything we do at api22. This policy explains exactly what data we collect, why we collect it, and how we keep it secure.

Last Updated: 1 January 2026

Our Core Privacy Commitments

Six principles that govern how api22 handles every piece of information you share with us.

End-to-End Encryption

All data in transit between your browser and our servers is protected by 256-bit SSL/TLS encryption — the same standard used by international banks.

Minimal Data Collection

We collect only the data strictly necessary to operate your account, process transactions in Indonesian Rupiah (IDR), and comply with our anti-fraud obligations.

No Third-Party Sale of Data

api22 does not sell, rent, or trade your personal information to third-party advertisers or data brokers — ever, under any circumstance.

Your Right to Access & Rectify

You may request a full copy of the personal data we hold on you at any time, and ask us to correct inaccuracies within a reasonable timeframe.

Right to Erasure

Subject to legal-retention requirements, you may request deletion of your account data. We will process valid erasure requests within 30 days.

Opt-Out Controls

Withdraw consent for marketing communications at any time via your account dashboard or by contacting our support team — no penalty, no questions asked.

1 Introduction and Scope

This Privacy Policy ("Policy") is issued by api22 ("api22", "we", "our", or "us"), the operator of the online betting and live casino platform accessible at https://api22.cam. This Policy applies to all users who register, browse, or otherwise interact with the platform, including individuals accessing the site from Indonesia and any other jurisdiction where the platform is made available.

By creating an account or continuing to use api22, you acknowledge that you have read and understood this Policy and consent to the data practices described herein. If you do not agree with any part of this Policy, you must discontinue use of the platform immediately and close your account in accordance with our Terms & Conditions.

This Policy should be read alongside our Terms & Conditions and our Responsible Gaming guidelines, which together govern your relationship with api22.

Jurisdiction Notice: api22 serves users who are 21 years of age or older and who are legally permitted to access online betting services under the laws applicable to them. By using this platform, you confirm that your use complies with all applicable local laws.

2 Definitions

The following terms carry the meanings assigned to them wherever they appear in this Policy:

Term Meaning
Personal Data Any information that identifies or can reasonably identify you as a natural person, including your name, email address, phone number, bank account details, IP address, and device identifiers.
Processing Any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, erasure, or destruction.
Data Controller api22, which determines the purposes and means of Processing your Personal Data.
Data Processor A third party that Processes Personal Data on behalf of api22 under a contractual data-processing agreement (e.g., payment gateway providers).
Consent A freely given, specific, informed, and unambiguous indication of your agreement to the Processing of your Personal Data.
Cookie A small text file placed on your device by a web server to store preferences and session information.

3 Data We Collect

We collect Personal Data in three primary ways: information you provide directly, information generated by your use of the platform, and information received from third parties.

3.1 Information You Provide

  • Full legal name (as it appears on your government-issued identification).
  • Date of birth (to verify you are at least 21 years of age).
  • Email address and mobile phone number.
  • Residential address within Indonesia (e.g., Jakarta, Surabaya, Bandung, Bali, Medan).
  • Bank account details for Indonesian banks including BCA, BRI, BNI, Mandiri, CIMB Niaga, OCBC NISP, BSI, and Bank Permata — used exclusively for deposits and withdrawals.
  • E-wallet identifiers for OVO, DANA, GoPay, ShopeePay, and LinkAja.
  • Copies of identification documents submitted during KYC (Know Your Customer) verification, including national ID (KTP), passport, or driver's licence.
  • Proof of payment source documents.

3.2 Automatically Collected Data

  • IP address and approximate geolocation.
  • Browser type, version, operating system, and language preferences.
  • Device identifiers and screen resolution.
  • Pages visited, time spent on each page, click-stream data, and referring URLs.
  • Session tokens and authentication logs (timestamps of login and logout events).
  • Betting activity records, game history, stake amounts, and transaction logs denominated in IDR.

3.3 Data from Third Parties

  • Identity verification results from KYC service providers.
  • Fraud-risk scores from payment-processing partners.
  • Publicly available sanctions and politically exposed persons (PEP) screening data.

4 Purposes of Processing and Legal Bases

The table below sets out each Processing activity, the data categories involved, and the legal basis on which we rely.

Processing Activity Data Categories Legal Basis Purpose Tag
Account registration and authentication Name, email, phone, date of birth, password hash Contractual necessity OPS
KYC / identity verification ID documents, selfie, address proof Legal obligation LEGAL
Deposits and withdrawals (IDR) Bank / e-wallet details, transaction amounts Contractual necessity OPS
Anti-fraud and AML screening IP address, device fingerprint, transaction patterns Legitimate interests / legal obligation FRAUD
Responsible Gaming monitoring Betting frequency, session duration, deposit amounts Legal obligation / legitimate interests LEGAL
Customer support communications Email, chat transcripts, account history Contractual necessity OPS
Platform analytics and performance monitoring Clickstream, page views, session data Legitimate interests ANALYTICS
Promotional and bonus communications Email, phone number, betting preferences Consent ANALYTICS
Note on Consent Withdrawal: Where Processing is based on your consent (e.g., marketing messages), you may withdraw that consent at any time without affecting the lawfulness of Processing that occurred prior to withdrawal.

5 Cookies and Tracking Technologies

api22 uses cookies and similar tracking technologies to provide a functional, personalized, and secure platform experience. Cookies are small text files stored on your device when you visit our site. They are not used to collect personally identifiable information beyond what is described in this Policy.

We deploy three categories of cookies:

  • Strictly Necessary Cookies: Required for core platform functions such as authentication sessions, security tokens, and load-balancing. These cannot be disabled without breaking the platform.
  • Functional Cookies: Remember your preferences — language settings, display preferences, and your last-used deposit method (e.g., BCA mobile transfer vs. GoPay).
  • Analytics Cookies: Collect aggregated, anonymized data about how users navigate api22 — page popularity, funnel drop-off points, and feature engagement. This helps us improve the platform.

You may manage cookie preferences through your browser settings. Disabling analytics cookies will not affect your ability to place bets, deposit, or withdraw funds. Disabling strictly necessary cookies will impair core functionality and we cannot guarantee platform stability under those conditions.

6 Data Sharing and Disclosure

api22 does not sell, rent, or trade your Personal Data to any third party for their independent commercial purposes. We share Personal Data only in the following limited circumstances:

  • Payment Processors: We share transaction data with licensed payment gateway operators to facilitate deposits and withdrawals via BCA, BRI, BNI, Mandiri, OVO, DANA, GoPay, ShopeePay, and LinkAja. These processors are bound by contractual data-processing agreements and applicable financial regulations.
  • KYC and Fraud-Prevention Providers: Identity verification and sanctions-screening services receive document images and identity data solely for the purpose of verifying your eligibility to hold an account.
  • Technology Infrastructure Providers: Cloud hosting, content delivery, and platform-security vendors process certain technical data (logs, IPs) under strict confidentiality obligations. No vendor receives full access to your account data.
  • Regulatory and Law-Enforcement Authorities: We will disclose Personal Data to competent authorities when required by a valid legal order, court process, or regulatory directive. We will notify you of any such disclosure to the extent legally permissible.
  • Corporate Transactions: In the event of a merger, acquisition, or asset sale, your Personal Data may be transferred to a successor entity, subject to equivalent privacy protections and advance notice to you.

All third-party Data Processors engaged by api22 are contractually required to process your data only on our documented instructions, maintain appropriate technical and organizational security measures, and return or securely delete data upon termination of the engagement.

7 Data Retention

We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. The general retention schedule is as follows:

  • ACCOUNT DATA — Retained for the duration of your active account, plus a minimum of five (5) years after account closure to satisfy anti-money-laundering record-keeping obligations.
  • TRANSACTION LOGS — Retained for seven (7) years in accordance with standard financial-record requirements.
  • KYC DOCUMENTS — Retained for five (5) years from the date of your last transaction or account closure, whichever is later.
  • COMMUNICATIONS — Support chat logs and email correspondence retained for two (2) years from the date of the interaction.
  • ANALYTICS DATA — Aggregated and anonymized within twelve (12) months of collection; anonymized data may be retained indefinitely for statistical analysis.
  • MARKETING CONSENT — Records of consent retained for the duration of the marketing relationship plus three (3) years as evidence of lawful basis.

Upon expiry of the applicable retention period, Personal Data is securely deleted or irreversibly anonymized using industry-standard data-erasure protocols. We do not retain data speculatively beyond the periods set out above.

8 Your Rights as a Data Subject

Regardless of your location within Indonesia — whether you are based in Jakarta, Surabaya, Bali, Medan, Bandung, or elsewhere — you have the following rights in relation to your Personal Data held by api22:

  • Right of Access: Request a copy of all Personal Data we hold about you, delivered in a structured, machine-readable format.
  • Right to Rectification: Ask us to correct inaccurate or incomplete Personal Data. We will action valid requests within fifteen (15) business days.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your Personal Data where it is no longer necessary, consent has been withdrawn, or Processing is unlawful — subject to legal-retention obligations that may override this right.
  • Right to Restrict Processing: Request that we limit how we use your data while a dispute or correction request is being resolved.
  • Right to Data Portability: Receive your account and transaction data in a portable format (CSV or JSON) to facilitate transfer to another service provider, where technically feasible.
  • Right to Object: Object to Processing carried out on the basis of legitimate interests (including profiling for responsible-gaming monitoring) where your personal circumstances justify this.
  • Right to Withdraw Consent: Where Processing relies on your consent, withdraw it at any time via your account settings or by contacting us at the email below. Withdrawal does not affect prior lawful Processing.

To exercise any of these rights, please contact our Data Protection team at [email protected]. We will acknowledge your request within five (5) business days and provide a substantive response within thirty (30) days. We do not charge a fee for reasonable requests.

9 Information Security

api22 maintains a comprehensive information security program designed to protect Personal Data against unauthorized access, disclosure, alteration, and destruction. Our technical and organizational measures include:

  • 256-bit TLS encryption for all data in transit between your device and our servers.
  • AES-256 encryption at rest for sensitive fields including bank account numbers and identity document images.
  • Salted cryptographic hashing of account passwords — plaintext passwords are never stored.
  • Multi-factor authentication (MFA) available for all accounts and mandatory for administrative access.
  • Role-based access controls ensuring that only personnel with a documented business need can access Personal Data.
  • Regular third-party penetration testing and vulnerability assessments of our platform.
  • A 24/7 security operations function monitoring for anomalous access patterns and potential data incidents.
  • Formal data-breach response procedures, including notification to affected users within seventy-two (72) hours of confirming a breach involving their data.

While we implement robust security controls, no online platform can guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and should notify us immediately at [email protected] if you suspect unauthorized access to your account.

10 Minors and Age Verification

api22 is strictly an adults-only platform. We do not knowingly collect Personal Data from individuals under the age of 21. During account registration, you are required to confirm that you are 21 years of age or older, and your identity documents are verified against this declaration as part of our KYC process.

If we become aware that Personal Data has been collected from an individual under 21 — whether through a false declaration or any other means — we will immediately suspend the associated account, reverse any pending transactions, and delete the relevant Personal Data from our systems as quickly as technically possible.

Parents and guardians who believe that a minor may have registered an account on api22 are encouraged to contact us at [email protected] immediately so that we can investigate and take appropriate action.

11 International Data Transfers

api22 operates infrastructure across multiple data-center locations. This means your Personal Data may be transferred to, stored in, or processed in a country other than Indonesia. Wherever such transfers occur, we ensure that:

  • The recipient jurisdiction provides an adequate level of data protection, or
  • Appropriate safeguards are in place, such as standard contractual clauses, binding corporate rules, or equivalent contractual protections.

All Data Processors in third countries handling api22 user data are contractually required to comply with data-protection standards equivalent to those described in this Policy and to implement the technical security measures outlined in Clause 9.

12 Changes to This Privacy Policy

api22 reserves the right to update or amend this Privacy Policy at any time. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Display a prominent notice on the api22 platform for a minimum of fourteen (14) days following the change.
  • Send an email notification to the address registered on your account if the changes materially affect your rights or how your Personal Data is used.

Your continued use of api22 after the effective date of a revised Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you should cease using the platform and submit a data-erasure request in accordance with Clause 8.

We recommend reviewing this Policy periodically, particularly before making deposits or engaging with new platform features. Archived versions of previous policies are available on request from our support team.

13 Contact and Data Inquiries

For any questions, concerns, or requests relating to this Privacy Policy or the Processing of your Personal Data, please contact our Data Protection team using the details below. All inquiries are handled in English.

Data Controller: api22
Platform: https://api22.cam
Email: [email protected]

We aim to acknowledge all privacy-related inquiries within five (5) business days and to resolve them within thirty (30) days. Complex or high-volume requests may take longer, in which case we will notify you of the extended timeline. Our support agents are available around the clock, including Indonesian-speaking agents operating on WIB (UTC+7).

Prefer to browse our other policies? Read our Terms & Conditions for the full contractual framework, or visit our Responsible Gaming page for tools to help you stay in control of your betting activity.

Everything You Need to Know

Our policies are designed to be transparent and fair. Explore related pages or head back to the homepage to get started.