1. Introduction
This Privacy Policy ("Policy") describes how w2win ("w2win", "we", "us", "our"), the operator of the online gaming platform at w2win.net, collects, uses, stores, shares, and protects personal data relating to users of our platform ("you", "your", "Member"). This Policy applies to all services offered through w2win.net, including the sportsbook, live casino, slots, Fisher Game, and any account or support functions.
w2win is committed to handling your personal data responsibly and in accordance with applicable data protection principles, including those consistent with international gaming authority data protection requirements. By registering an account or otherwise using the w2win platform, you acknowledge that you have read and understood this Policy.
This Policy should be read alongside our Terms & Conditions and Responsible Gaming policy, both of which are incorporated by reference.
2. Data We Collect
w2win collects personal data from you through several channels. The categories of data we collect include:
Registration & Identity Data:
- Full legal name as it appears on your government-issued identity document
- Date of birth (used to verify that you are 21 years of age or older)
- Malaysian IC number (MyKad) or equivalent national identity document number
- Email address and contact telephone number
- Residential address
- Username and hashed password credentials
Financial & Transaction Data:
- Deposit and withdrawal transaction records, including amounts, timestamps, and payment method references
- Payment method identifiers (e.g. registered e-wallet account identifiers for Touch n Go eWallet, Boost; bank account references for Maybank, CIMB, Public Bank; FPX transaction references)
- Note: w2win does not store full card numbers, CVVs, or online banking credentials. Payment data passes directly through the relevant payment provider's secure gateway.
Gaming Activity Data:
- Bet history, game session records, win/loss records, and bonus usage history across all w2win products
- Responsible gaming tool settings and usage (deposit limits, self-exclusion records)
Technical & Usage Data:
- IP address, device type, operating system, and browser information
- Login timestamps, session duration, and pages visited on the platform
- Cookie identifiers and similar tracking technology data (see Section 5)
Communications Data:
- Records of customer support interactions (live chat transcripts, email correspondence)
- Any information you voluntarily provide in complaints, feedback, or survey responses
3. How We Use Your Data
w2win uses the personal data we hold about you for the following purposes:
- Account Management: To create, maintain, and administer your w2win account, including processing login authentication and securing your account with two-factor authentication where enabled.
- Identity Verification (KYC): To verify your identity and age in compliance with international gaming authority Know Your Customer requirements. Members from Kuala Lumpur, Penang, Johor Bahru, and all other Malaysian locations are subject to the same KYC standards.
- Transaction Processing: To process deposits and withdrawals in MYR via your chosen payment method, and to maintain accurate financial records of all transactions on your account.
- Gaming Services Delivery: To provide access to and operate the w2win sportsbook, live casino, slots, Fisher Game, EPL betting, and all other platform products.
- Regulatory Compliance: To meet anti-money laundering (AML) obligations, fraud detection requirements, and responsible gaming obligations including age verification and self-exclusion enforcement.
- Customer Support: To respond to your support queries, resolve disputes, and process complaints.
- Marketing Communications: To send promotional offers, bonus notifications, and platform updates where you have opted in to receive such communications. You may withdraw marketing consent at any time via your account settings.
- Platform Improvement: To analyse anonymised usage patterns and improve the performance, security, and features of the w2win platform.
- Fraud Prevention & Security: To detect, investigate, and prevent fraudulent activity, unauthorised account access, and abuse of bonus offers.
4. Legal Basis for Processing
w2win processes your personal data on the following legal bases:
- Contractual Necessity: Processing required to perform the contract established when you accept our Terms & Conditions — including account creation, transaction processing, and gaming services delivery.
- Legal Obligation: Processing required to comply with applicable laws and regulations, including KYC/AML obligations imposed by international gaming authority licensing conditions.
- Legitimate Interests: Processing for fraud prevention, platform security, and business analytics, where such interests are not overridden by your fundamental rights and freedoms.
- Consent: Processing for marketing communications and non-essential cookies, where you have given explicit and freely withdrawable consent.
5. Cookies & Tracking Technologies
w2win uses cookies and similar technologies (such as web beacons and local storage) to operate the platform, remember your preferences, and analyse platform usage. The categories of cookies we use are:
- Essential Cookies: Strictly necessary for the platform to function — session management, login authentication, and security tokens. These cannot be disabled without impairing platform functionality.
- Functional Cookies: Store your preferences such as language settings, remembered username, and responsible gaming tool configurations.
- Analytics Cookies: Collect anonymised data about how members use the platform — pages visited, session duration, game preferences — to help us improve the product. Used only with your consent.
- Marketing Cookies: Track engagement with promotional content and assist in delivering relevant offers to logged-in members. Used only with your consent.
You can manage cookie preferences via your browser settings or through the w2win cookie preference centre accessible from the platform. Note that disabling essential cookies will prevent access to the platform.
w2win does not use cookies to collect sensitive personal data, and does not sell cookie data to third parties for their own marketing purposes.
6. Data Sharing & Disclosure
w2win does not sell your personal data. We may share your data with third parties only in the following limited circumstances:
- Payment Processors: Transaction data shared with approved payment service providers (including Touch n Go, Boost, Maybank, CIMB, Public Bank, and FPX gateway operators) solely to process your deposit and withdrawal instructions.
- Identity Verification Providers: Identity documents and related data shared with licensed KYC/AML verification service providers to fulfil our regulatory obligations.
- Game Software Providers: Game session data shared with licensed gaming software providers (whose games appear on the w2win platform) to the extent necessary to operate and audit those games.
- Regulatory & Legal Authorities: Data disclosed to gaming regulators, law enforcement agencies, tax authorities, or courts where required by applicable law or court order.
- Corporate Transactions: In the event of a merger, acquisition, or sale of assets, member data may be transferred to the successor entity, subject to equivalent privacy protections.
- Fraud Prevention Networks: Anonymised risk signals may be shared with shared fraud prevention services to protect the w2win platform and other members.
All third parties with whom w2win shares personal data are required to maintain appropriate technical and organisational security measures and are prohibited from using your data for purposes beyond those specified in their data processing agreements with w2win.
7. International Data Transfers
w2win's primary data processing infrastructure is located within secure data centre environments. Where data is processed by service providers outside of Malaysia, w2win ensures that adequate safeguards are in place — including contractual protections consistent with internationally recognised data transfer mechanisms — to maintain the same level of protection as applies under this Policy.
Payment data processed through Malaysian payment providers (Touch n Go eWallet, Boost, Maybank, CIMB, Public Bank) is subject to the data protection practices of those providers, which are regulated under Malaysian law.
8. Data Retention
w2win retains your personal data for as long as necessary to fulfil the purposes set out in this Policy, subject to the following minimum retention periods:
- Account & Identity Data: Retained for the duration of your active membership and for a minimum of 5 years following account closure, to comply with AML record-keeping obligations.
- Transaction Records: Retained for a minimum of 7 years from the date of the transaction, consistent with financial record-keeping requirements.
- Self-Exclusion Records: Retained for the duration of the self-exclusion period and for a minimum of 5 years thereafter, to prevent re-registration during exclusion periods.
- Marketing Preferences: Retained until you withdraw consent or close your account, whichever is earlier.
- Support Interaction Records: Retained for 3 years from the date of the interaction, or longer where a dispute remains unresolved.
Upon expiry of the applicable retention period, data is securely deleted or anonymised in accordance with w2win's data disposal procedures.
9. Your Rights
Subject to applicable law and w2win's legitimate interests and legal obligations, you have the following rights regarding your personal data held by w2win:
- Right of Access: Request a copy of the personal data w2win holds about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to our legal retention obligations.
- Right to Restrict Processing: Request that we limit how we use your data in certain circumstances.
- Right to Data Portability: Request a structured, machine-readable copy of data you provided to w2win.
- Right to Object: Object to processing based on legitimate interests, including profiling for direct marketing purposes.
- Right to Withdraw Consent: Withdraw consent for marketing communications or non-essential cookies at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact w2win's Data Protection team at [email protected]. Requests will be acknowledged within 5 business days and fulfilled within 30 days, or we will notify you if an extension is required.
10. Children's Privacy
The w2win platform is strictly intended for persons aged 21 years and above. w2win does not knowingly collect personal data from individuals under 21 years of age. Age verification is conducted during registration as a mandatory step. If w2win becomes aware that personal data has been collected from a person under the age of 21, that account will be immediately suspended and the data will be deleted or anonymised promptly.
If you are a parent or guardian and believe a minor has registered on the w2win platform, please contact us immediately at [email protected] for prompt investigation and account closure.
11. Security Measures
w2win implements a range of technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, and destruction:
- 256-bit SSL/TLS encryption for all data in transit between your device and w2win's servers.
- Encryption at rest for sensitive stored data including identity documents and financial records.
- Two-factor authentication (2FA) available to all members for account access.
- Role-based access controls restricting w2win staff access to personal data to those with a legitimate operational need.
- Regular penetration testing and security audits conducted by independent third parties.
- Automated anomaly detection for login attempts, transaction patterns, and account activity.
Despite these measures, no online platform can guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, w2win will notify affected members as required under applicable data breach notification obligations.
12. Third-Party Links
The w2win platform may contain references or links to third-party content. This Privacy Policy applies only to the w2win platform and its services. w2win is not responsible for the privacy practices or content of any third-party websites or services. We encourage you to review the privacy policies of any third parties whose services you access in connection with your use of the w2win platform.
13. Policy Amendments
w2win reserves the right to update this Privacy Policy at any time. Material changes will be notified to active members via email to the registered account address and/or via a prominent notice on the platform, no less than 14 days before the revised Policy takes effect. The effective date at the top of this page will be updated accordingly.
Your continued use of the w2win platform after the effective date of any revision constitutes your acceptance of the updated Policy. If you do not agree to the revised Policy, you must cease using the platform and may request account closure.
14. Contact Us
For questions, concerns, or requests relating to this Privacy Policy or w2win's data practices, please contact our Data Protection team:
- Email: [email protected] (plain text only — not a clickable link)
- Subject Line: Use "Privacy Request – [your username]" for faster routing
- Live Chat: Available 24/7 from within your w2win account for general privacy queries
- Response Time: Privacy requests acknowledged within 5 business days; full response within 30 days
w2win's support team operates on Malaysian Standard Time (GMT+8) with extended coverage to provide 24-hour service for members across Kuala Lumpur, Penang, Johor Bahru, Petaling Jaya, Bangsar, and all regions of Malaysia.