1. Introduction
mywinbox ("mywinbox", "we", "us", "our") is committed to protecting the privacy and personal data of every individual who accesses or uses the mywinbox Platform at mywinbox.club (the "Platform"). This Privacy Policy ("Policy") sets out in clear terms how we collect, use, store, share, and safeguard the personal information of our members, including Malaysian players and all other users of our services.
This Policy applies to all personal data processed by mywinbox in connection with the operation of the Platform, including account registration, identity verification, payment processing, gaming activity, customer support interactions, and marketing communications. It should be read alongside the mywinbox Terms & Conditions and Responsible Gaming Policy.
By registering an account with mywinbox or continuing to use the Platform, you acknowledge that you have read and understood this Policy and that you consent to the processing of your personal data as described herein. If you do not agree with this Policy, you should cease using the Platform and contact us to request account closure.
2. Data Controller
mywinbox is the data controller responsible for the personal data collected through the Platform. As data controller, mywinbox determines the purposes and means of processing your personal data and is accountable for ensuring that such processing complies with applicable data protection laws and regulations.
For all privacy-related enquiries, requests, or complaints, you may contact the mywinbox Data Protection team at the contact details provided in Section 15 of this Policy.
3. Data We Collect
3.1 Registration & Identity Data
When you create a mywinbox account, we collect personal data including your full legal name, date of birth, residential address, email address, and chosen username. Where required for Know Your Customer (KYC) verification, we also collect copies of government-issued identification documents, proof of address, and payment instrument verification documentation.
3.2 Financial Data
mywinbox collects and processes information relating to your financial transactions on the Platform, including deposit amounts, withdrawal requests, payment method identifiers (such as e-wallet account references), transaction timestamps, and transaction history. Full card numbers are never stored by mywinbox — payment card processing is handled exclusively by certified third-party payment processors.
3.3 Gaming Activity Data
We record your gaming activity on the Platform, including games played, bets placed, wagers won and lost, session durations, and bonus usage. This data is used for account management, regulatory compliance, responsible gaming monitoring, and service improvement purposes.
3.4 Technical & Device Data
We automatically collect certain technical data when you access the Platform, including your IP address, device type and operating system, browser type and version, screen resolution, session timestamps, pages visited, and referring URLs. This data is collected through standard server logs and, where cookies are accepted, through cookie-based tracking mechanisms.
3.5 Communications Data
Where you contact mywinbox customer support via live chat, email, or any other communication channel, we retain records of those communications, including the content of messages, timestamps, and the identity of the support agent involved. This data is used for quality assurance, training, and dispute resolution purposes.
3.6 Marketing Preferences
Where you have consented to receive marketing communications from mywinbox, we record your marketing preferences and any interaction you have with promotional materials, including email open rates and click-through activity.
4. How We Use Your Data
mywinbox uses the personal data we collect for the following purposes:
- To create and manage your member account and verify your identity;
- To process deposits, withdrawals, and other financial transactions;
- To provide access to and operate the Platform's gaming products;
- To comply with Know Your Customer, anti-money laundering, and other regulatory obligations;
- To detect, investigate, and prevent fraud, cheating, collusion, and other prohibited conduct;
- To monitor gaming activity for responsible gaming purposes and to apply player-protection measures where appropriate;
- To communicate with you regarding your account, transactions, and support queries;
- To send marketing communications where you have provided consent;
- To improve the Platform, personalise your experience, and conduct internal analytics;
- To comply with any court order, legal obligation, or regulatory requirement applicable to mywinbox.
5. Legal Basis for Processing
mywinbox processes your personal data on the following legal grounds:
- Contractual necessity — Processing required to perform the services you have contracted with mywinbox to receive, including account management, payment processing, and game access;
- Legal obligation — Processing required for compliance with applicable laws, including KYC, AML, and gaming licensing regulations;
- Legitimate interests — Processing necessary for mywinbox's legitimate business interests, including fraud prevention, security monitoring, and service improvement, where such interests are not overridden by your fundamental rights;
- Consent — Processing of data for marketing communications and optional analytics, where you have given freely obtained, specific, and informed consent. You may withdraw consent at any time without detriment to your account status.
6. Data Sharing & Disclosure
mywinbox does not sell, rent, or trade your personal data to third parties for commercial purposes. We may share your personal data with the following categories of recipients in the circumstances described:
- Payment processors — To facilitate deposits, withdrawals, and payment verification through approved channels including Touch 'n Go, Boost, Maybank FPX, CIMB, and cryptocurrency processors;
- KYC and identity verification providers — To verify your identity and comply with AML regulations;
- Game software providers — Limited technical data shared with licensed game providers such as Pragmatic Play, PG Soft, and Evolution Gaming to facilitate gameplay;
- Regulatory and law enforcement authorities — Where required by applicable law, court order, or to report suspected illegal activity;
- Professional advisers — Including legal counsel, auditors, and compliance consultants, under strict confidentiality obligations;
- Business successors — In the event of a merger, acquisition, or sale of all or substantially all of mywinbox's assets, your data may be transferred to the successor entity, subject to equivalent data protection standards.
All third parties with whom mywinbox shares personal data are required to implement appropriate technical and organisational measures to protect that data and to process it only for the purposes for which it was shared.
7. Cookies & Tracking Technologies
mywinbox uses cookies and similar tracking technologies to operate the Platform, analyse usage patterns, and deliver a personalised experience. Cookies are small text files stored on your device when you visit the Platform. We use the following categories of cookies:
- Strictly necessary cookies — Essential for Platform operation, including session management and security. These cannot be disabled;
- Analytics cookies — Used to collect aggregated data on how players use the Platform, helping us improve navigation and content;
- Preference cookies — Used to remember your display preferences and settings across sessions;
- Marketing cookies — Used where consent has been given to track engagement with mywinbox promotional materials.
You may manage or disable non-essential cookies through your browser settings. Disabling certain cookies may affect the functionality of the Platform.
8. Data Retention
mywinbox retains personal data for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable legal and regulatory obligations. In practice, this means:
- Account data and KYC documentation are retained for a minimum of five years following account closure, in compliance with AML record-keeping requirements;
- Transaction and gaming activity records are retained for the same period;
- Customer support communication records are retained for up to three years;
- Marketing preference data is retained until consent is withdrawn or the account is closed.
Following the expiry of applicable retention periods, personal data is securely deleted or anonymised in accordance with mywinbox's data disposal procedures.
9. Data Security
mywinbox implements a comprehensive suite of technical and organisational security measures to protect your personal data against unauthorised access, loss, destruction, alteration, or disclosure. These measures include, but are not limited to:
- SSL/TLS encryption for all data transmitted between your device and the mywinbox servers;
- Encrypted storage of sensitive personal data at rest;
- Role-based access controls limiting data access to authorised personnel with a demonstrated need;
- Regular security audits and penetration testing of Platform infrastructure;
- Multi-factor authentication requirements for internal system access;
- Incident response and data breach notification procedures compliant with applicable regulatory requirements.
Notwithstanding these measures, no data transmission over the internet is entirely risk-free. mywinbox cannot guarantee the absolute security of data transmitted to the Platform, and you accept that some risk is inherent in any online interaction. You are responsible for maintaining the security of your own account credentials.
10. Your Rights
Subject to applicable data protection law, you have the following rights with respect to your personal data held by mywinbox:
- Right of access — You may request a copy of the personal data mywinbox holds about you;
- Right to rectification — You may request correction of inaccurate or incomplete personal data;
- Right to erasure — You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to overriding legal retention obligations;
- Right to restriction — You may request that mywinbox restrict the processing of your data in certain circumstances;
- Right to data portability — You may request that your personal data be provided in a structured, machine-readable format;
- Right to object — You may object to processing based on legitimate interests or for direct marketing purposes;
- Right to withdraw consent — Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact the mywinbox Data Protection team using the contact details in Section 15. mywinbox will respond to all verified data subject requests within 30 days.
11. Children's Privacy
The mywinbox Platform is strictly intended for adults aged 21 years and above. mywinbox does not knowingly collect or process personal data from individuals below this age threshold. Where mywinbox becomes aware that personal data has been collected from an underage individual, that account will be immediately suspended, the data will be deleted, and any funds on account will be returned to their source following investigation. If you believe that an underage individual has registered on the Platform, please notify us immediately.
12. International Data Transfers
mywinbox operates internationally and may transfer your personal data to servers, processors, or service providers located outside your country of residence, including jurisdictions that may not provide equivalent levels of data protection to those applicable in your jurisdiction. Where such transfers occur, mywinbox implements appropriate safeguards — including standard contractual clauses and data processing agreements — to ensure that your personal data receives a level of protection consistent with this Policy and applicable data protection law.
13. Third-Party Services
The mywinbox Platform integrates services provided by licensed third-party game developers, payment processors, and KYC providers. Each of these third parties operates under their own privacy policies and data processing terms, which mywinbox has reviewed as part of its vendor onboarding process. mywinbox is not responsible for the privacy practices of third-party services operating independently of the Platform. Where data is shared with third parties, it is done under contractual data processing agreements that impose obligations consistent with this Policy.
14. Changes to This Privacy Policy
mywinbox reserves the right to update or amend this Privacy Policy at any time to reflect changes in applicable law, regulatory guidance, or our data processing practices. Where material changes are made, mywinbox will notify registered members via email or prominent on-platform notification prior to the changes taking effect. The date of the most recent revision is displayed at the top of this page. Continued use of the Platform following notification of policy changes constitutes acceptance of the updated Policy.
15. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data by mywinbox, please contact our Data Protection team. Our customer support team is available 24 hours a day, 7 days a week via live chat on the Platform, or by email at the address below. Formal data subject requests will receive a written response within 30 days.
Data Protection & Privacy Enquiries: [email protected]