For merchants
Account security and closure
How to protect your sign-in, and how to close the account once your money is paid out.
Password and 2FA live in Settings → Security. Signed-in devices and the account deletion request live in Settings → Account. In the dashboard these menus are labelled Pengaturan → Keamanan and Pengaturan → Akun.
Security and closure rules
| Two-factor authentication (2FA) | Optional for every account, whatever the role. The owner can require it for all members of the merchant. |
|---|---|
| Recovery codes | 8 codes, shown once when 2FA is turned on. Each code signs you in once. |
| Wrong 2FA codes | After 5 wrong codes in 15 minutes, codes are refused for a while, even the right one. |
| New-device login email | Sent after a successful sign-in from a device or browser this account has never used. It shows the time (WIB) and the IP address. |
| Password | At least 8 characters. Changing it signs out every other device and sends you an email. |
| Reset link (Forgot password) | Valid for 1 hour. Using it signs out every device. |
| Closing the account | Balance paid out first, then an admin reviews the request. After approval there are 30 days in which you can still cancel. |
| Data kept after closing | Identity file (full name, NIK, KTP photo, selfie) for 5 years. Transaction and payout records, without your name, for as long as the law requires. |
Turning on 2FA
- Install an authenticator app on your phone, such as Google Authenticator, Aegis or 1Password.
- Open Pengaturan → Keamanan and press Aktifkan 2FA. Scan the QR code, or type in the key shown under it.
- Enter the 6-digit code from the app and press Konfirmasi dan aktifkan.
- Save the 8 recovery codes somewhere other than that phone, then press Sudah saya simpan. They are not shown again.
- From now on, every sign-in asks for a code after your password. Lost the phone? Enter a recovery code instead.
We email you whenever 2FA is turned on or off. Turning it off needs one valid code, from the app or a recovery code. Turning it on again issues 8 new recovery codes and the old ones stop working.
If you think someone else got into your account
- Pengaturan → Akun → Sesi aktif: press Keluar on any device you don't recognise, or Keluar dari semua perangkat lain.
- Pengaturan → Keamanan → Ubah password: set a new password. Every other device is signed out.
- Turn on 2FA if it is not on yet.
- If you are the owner: check the member list in Pengaturan → Tim, and if an API key may have been seen, rotate it in Pengaturan → Developer. How rotation affects a live integration is in API authentication.
- Can't sign in any more? Use Lupa password? on the sign-in page. If you also lost access to your email, or lost both your authenticator and your recovery codes, write to halo@kasera.id from the email address registered on the account. The support team must verify your identity manually before access is restored.
How to close the account
- Get the money out first. The request waits while there is a balance not yet paid out, a payout still on its way, a payment request still waiting to be paid or to expire, or a reconciliation check still open. A balance can only be paid out once verification (KYC) is complete and a payout bank account is added.
- Open Pengaturan → Akun, go to Permintaan hapus akun and press Ajukan permintaan hapus akun. Read Ketentuan penghapusan, tick the box, press Kirim permintaan and enter the 6-digit code we email you.
- Sending the request signs you out on every device. You can sign in again, for example to finish what is still blocking it. Your API keys and webhook keep working until the account is actually erased.
- If something still has to be settled, the status shows Menunggu. Once it is settled the request goes to review by itself. You don't need to ask again.
- An admin reviews the request. You get an email either way, with the erasure date if approved or the reason if rejected. Nothing is erased before approval.
- After approval, the account is erased once 30 days have passed. Until then you can press Batalkan permintaan penghapusan. We send one last email when the erasure is done.
| Erased | Kept |
|---|---|
| Email, phone number, password and sessions | Full name, NIK, KTP photo and selfie: 5 years after the account closes, then destroyed |
| Business name, payout bank account, payment page, API keys and webhook | Transaction and payout records (amounts, fees, status, dates), no longer linked to your name, for as long as the law requires |
| Buyers' names, emails and phone numbers on your transactions | — |
Business data, API keys and webhook are erased only for a merchant you are the last member of. The full retention table is in the Privacy Policy. The ways to start a deletion, including without signing in, are on Account Deletion.
Common questions
Is 2FA required for owners or developers?
No role requires it automatically. It becomes required only when the owner ticks Wajibkan 2FA untuk semua anggota merchant ini in Pengaturan → Keamanan. A member without 2FA can then only open the setup screen until they turn it on. Only the owner can change that setting.
What does the “Login baru ke akun Kasera Pay Anda” email mean?
If it was you, on a new phone, browser or computer, ignore it. If not, follow the steps above right away: sign out the other devices, change your password, turn on 2FA. The email is not sent for your very first sign-in, or for failed attempts.
What if I lost my phone and my recovery codes?
The dashboard cannot turn 2FA off without a valid code. Write to halo@kasera.id from the email address registered on the account. The support team must verify your identity manually before 2FA is reset.
Can I close the account while there is still a balance?
You can send the request, but it waits until the balance has reached your bank. A remaining balance is never deleted along with the account.
How long does the admin review take?
There is no fixed time. The 30-day wait starts only when the request is approved, not when you send it.
What happens to a merchant that has other team members?
Only your own account is closed. If other members have joined, the merchant, its API keys and its records carry on. If you were its only owner, the longest-standing active member becomes the owner when your account is erased.