This Privacy Policy explains how win28 collects, processes, stores, and discloses your personal data when you register and use the win28 platform. Please read this document carefully. By registering a win28 account, you acknowledge and consent to the practices described herein.
All data transmitted between your device and win28's servers is protected by 256-bit TLS/SSL encryption — the same standard used by major Malaysian banks for online banking.
win28 does not sell, rent, or trade your personal data to third-party marketing organisations. Your information is used solely for service delivery, legal compliance, and fraud prevention.
You have the right to access, correct, and request deletion of your personal data held by win28, subject to our legal retention obligations under applicable gaming licensing requirements.
Data handling at win28 is governed by the requirements of our international gaming authority licensing, including Know Your Customer (KYC) and Anti-Money Laundering (AML) obligations.
win28 uses cookies to maintain session state, improve platform performance, and understand usage patterns. Functional cookies are required for the platform to operate correctly.
For any privacy-related requests — including data access, correction, or deletion — contact win28 via the support ticket system. We aim to respond to all data requests within 30 days.
1.1 win28 ("the Platform", "we", "us", "our") acts as the data controller in respect of personal data collected from players and visitors who interact with the win28 platform at win28.club. win28 operates under international gaming authority licensing and is subject to the data protection requirements of its licensing jurisdiction.
1.2 For all privacy-related correspondence, including data subject access requests, correction requests, and deletion requests, players may contact win28 via the support ticket system. The contact email address for data privacy matters is [email protected] (plain text — not a clickable link).
1.3 This Privacy Policy applies to all personal data collected through the win28 website, any mobile-optimised interface, and all associated support and communication channels operated by win28.
win28 collects the following categories of personal data in the course of providing its services:
| Category | Data Elements | Required? |
|---|---|---|
| Identity Data | Full legal name, date of birth, gender, nationality, government-issued ID number (Malaysian MyKad or passport) | Mandatory (KYC) |
| Contact Data | Email address, Malaysian mobile number, residential address (including city: Kuala Lumpur, Penang, Johor Bahru, etc.) | Mandatory |
| Financial Data | Payment method type, masked payment account identifiers (e.g. Touch n Go account, bank name, last 4 digits), transaction history in MYR | Mandatory |
| Technical Data | IP address, device type and OS, browser type and version, session timestamps, login history | Automatic |
| Usage Data | Games played, wager amounts, bet history, sportsbook markets accessed, session duration | Automatic |
| KYC Documents | Copies of government-issued ID, proof of address documents, payment method verification documents | Mandatory (pre-withdrawal) |
| Communications Data | Records of support ticket correspondence, live chat transcripts, email communications with win28 | Automatic (when support used) |
win28 does not collect sensitive personal data such as racial or ethnic origin, political opinions, health data, or biometric data, except where expressly required by applicable licensing authority KYC mandates.
3.1 Directly from You. win28 collects personal data directly from you when you: register a win28 account; complete the KYC identity verification process; make a deposit or withdrawal; contact win28 customer support; or participate in promotions or surveys.
3.2 Automatically. When you access the win28 platform, technical and usage data is collected automatically through cookies, server logs, and platform analytics. This includes your IP address, device information, pages visited, games accessed, and session activity. This data is collected regardless of whether you are logged in to your win28 account.
3.3 From Third Parties. win28 may receive data about you from third-party sources including: identity verification service providers used for KYC processing; payment processors handling your Touch n Go, Boost, or bank transaction; fraud detection and AML screening services; and gaming regulatory authorities as required under licensing compliance obligations.
win28 processes your personal data for the following purposes:
win28 processes your personal data on the following legal bases:
6.1 win28 does not sell your personal data to third parties. win28 may share your data with the following categories of recipient, strictly for the purposes described in this Policy:
6.2 All third parties with whom win28 shares personal data are contractually obligated to process such data only for the specified purpose and to apply appropriate technical and organisational security measures.
7.1 win28 retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable legal and licensing obligations.
7.2 Account and transaction records, including KYC documents and financial data, are retained for a minimum of five (5) years following account closure, in compliance with anti-money laundering record-keeping requirements under win28's licensing framework.
7.3 Marketing communications data is retained until a Player withdraws their marketing consent, after which it is deleted or anonymised within thirty (30) days.
7.4 Technical and usage data collected via server logs and platform analytics is retained in identifiable form for up to twelve (12) months and thereafter retained in aggregated, anonymised form for statistical purposes without retention limits.
7.5 Following the applicable retention period, personal data is securely deleted or irreversibly anonymised using industry-standard data sanitisation methods.
8.1 win28 uses cookies and similar tracking technologies to provide, maintain, and improve its platform services. The following categories of cookies are used:
8.2 Players may manage cookie preferences through their browser settings. Disabling strictly necessary cookies will impair login functionality and access to the win28 platform. Disabling other cookie categories will not prevent platform access but may degrade personalisation features.
Subject to applicable law and win28's licensing obligations, you have the following rights regarding your personal data:
To exercise any of the above rights, contact win28 via the support ticket system with your registered email address and a description of your request. win28 may request identity verification before processing data subject rights requests.
10.1 win28 implements a range of technical and organisational security measures to protect personal data against unauthorised access, disclosure, alteration, and destruction, including:
10.2 Notwithstanding the above, no internet transmission or electronic storage method is completely secure. win28 cannot guarantee absolute security of data transmitted over the internet. Players are encouraged to use strong, unique passwords and to enable two-factor authentication on their win28 account.
11.1 win28 strictly enforces a minimum age requirement of 21 years. The win28 platform is not directed at, and does not knowingly collect personal data from, individuals under the age of 21.
11.2 Where win28 discovers or has reasonable grounds to believe that personal data has been collected from an individual under 21, the associated account will be immediately closed, funds returned where practicable, and the relevant personal data deleted in accordance with applicable licensing requirements.
11.3 If you believe that a minor has registered a win28 account, please contact win28 customer support immediately with the relevant account details.
12.1 win28 reserves the right to update this Privacy Policy at any time to reflect changes in applicable law, licensing requirements, or data processing practices. Material changes will be communicated to registered Players via their registered email address at least fourteen (14) days before the revised Policy takes effect.
12.2 The current version of this Privacy Policy, with its effective date, is always available at win28.club/privacy-policy. Continued use of the win28 platform following the effective date of an updated Privacy Policy constitutes acceptance of the revised terms.
This Privacy Policy was last reviewed and updated in June 2026. For privacy enquiries, contact win28 at [email protected] (plain text — not a clickable link). See also the Terms & Conditions and Responsible Gaming pages.
Our support team can address any privacy-related query, help you submit a data access request, or guide you through account security settings including two-factor authentication and responsible gaming controls.
Visit the win28 Login page to access your account. Review Terms & Conditions and Responsible Gaming for complete platform rules.