YOUR PRIVACY MATTERS TO winnox. This Privacy Policy explains how winnox collects, uses, stores, and protects your personal data when you access or use the Platform at https://winnox.net. Please read it carefully alongside our
Terms & Conditions. By registering an account or using the Platform, you acknowledge that you have read and understood this Policy.
1. Introduction
Overview
1.1 This Privacy Policy is issued by winnox ("winnox", "we", "our", "us") and applies to all personal data processed in connection with the winnox Platform, including the website https://winnox.net and any associated mobile or web-based interfaces.
1.2 winnox is committed to protecting the privacy and security of all personal data entrusted to it by account holders and platform users, in accordance with applicable data protection legislation and the requirements of its international gaming licence.
1.3 This Policy applies to all individuals whose personal data winnox processes, including registered account holders, prospective customers, and visitors to the Platform. It should be read together with the Terms & Conditions and Responsible Gaming Policy.
1.4 The winnox Platform is directed exclusively at adults aged 21 years and above. We do not knowingly collect or process personal data relating to persons under this age. If we become aware that data has been collected from a person under 21, it will be deleted immediately.
2. Data We Collect
Data Categories
2.1 winnox collects personal data from you directly (when you register, make deposits, contact support, or use platform features) and automatically (through your use of the Platform). The categories of data collected are as follows:
2.1 Identity & Contact Data
- Full legal name as it appears on your government-issued identification document;
- Date of birth (collected for mandatory age verification);
- Email address (used as primary account identifier and for communications);
- Residential address (required for regulatory compliance and KYC purposes);
- Copy of government-issued photo ID (MyKad for Malaysian nationals, or valid passport).
2.2 Financial Data
- Payment method details sufficient to process transactions (e-wallet account identifiers, bank account numbers where used for transfers);
- Transaction history including deposit amounts, withdrawal requests, and dates;
- Account balance and bonus balance history.
2.3 Technical & Usage Data
- IP address and approximate geographic location derived from it;
- Device type, operating system, browser type and version;
- Session data including login timestamps, pages visited, games played, and bet history;
- Cookies and similar tracking technologies (see Section 6).
2.4 Communications Data
- Content of communications with winnox support (live chat transcripts, email correspondence);
- Records of marketing preferences and consent status.
| Data Category | Collected At | Purpose |
| Identity (name, DOB, ID) | Registration / KYC | Age verification, legal compliance |
| Contact (email, address) | Registration | Account management, communications |
| Financial (payment methods, transactions) | Deposits / Withdrawals | Payment processing, AML compliance |
| Technical (IP, device, session) | Platform use | Security, fraud prevention, service improvement |
| Communications (support chat, emails) | Support interactions | Query resolution, quality assurance |
3. How We Use Your Data
Processing Purposes
3.1 winnox processes your personal data for the following purposes:
- Account Registration and Management: To create and maintain your winnox account, verify your identity and age, and administer your use of the Platform;
- Payment Processing: To process deposits, withdrawals, and refunds through your chosen payment method (Touch n Go eWallet, Boost, Maybank, CIMB, Public Bank, GrabPay, or USDT TRC20);
- KYC and Regulatory Compliance: To verify your identity and age as required by our gaming licence, and to comply with applicable anti-money laundering (AML) and counter-terrorism financing (CTF) obligations;
- Service Delivery: To provide you access to games, sportsbook markets, account features, and customer support;
- Security and Fraud Prevention: To detect, investigate, and prevent fraudulent transactions, account abuse, and security threats;
- Responsible Gaming: To administer self-exclusion requests, deposit limits, and other responsible gaming tools you activate on your account;
- Marketing Communications: To send promotional offers and platform updates where you have given consent or where we have a legitimate interest in doing so — subject always to your right to opt out;
- Platform Improvement: To analyse usage patterns and improve the winnox Platform's performance, design, and game offering;
- Legal Obligations: To comply with applicable laws, regulatory requirements, and lawful requests from competent authorities.
3.2 winnox does not use your personal data for automated decision-making that produces legal or similarly significant effects, except where required by anti-fraud or AML compliance processes, in which case you have the right to request human review of any decision.
4. Legal Basis for Processing
4.1 winnox processes your personal data on the following legal grounds:
- Performance of a Contract: Processing necessary to create and operate your winnox account and deliver the services you have requested;
- Legal Obligation: Processing required to comply with KYC, AML/CTF, and gaming licence regulatory requirements;
- Legitimate Interests: Processing for fraud prevention, platform security, responsible gaming administration, and service improvement, where these interests are not overridden by your rights;
- Consent: Processing for marketing communications, where your explicit consent has been obtained. You may withdraw consent at any time by contacting support or updating your account preferences.
5. Data Sharing & Third Parties
Third Parties
5.1 winnox does not sell your personal data to third parties. We share personal data only in the following circumstances:
- Payment Processors: We share necessary financial data with our payment processing partners to facilitate deposits and withdrawals. These processors are contractually bound to use your data only for transaction processing;
- Game Providers: Certain technical data (session tokens, game round identifiers) is shared with licensed game providers to deliver game content. No personal identity data is shared beyond what is technically required;
- KYC and Identity Verification Providers: Identity documents submitted for age verification are processed by contracted identity verification service providers subject to strict data handling agreements;
- Regulatory Authorities: We may be required to share account and transaction data with our gaming licensing authority, law enforcement agencies, or other regulatory bodies pursuant to lawful requests or our regulatory obligations;
- IT and Infrastructure Providers: Hosting, cloud infrastructure, and analytics service providers who process data on our behalf under data processing agreements with appropriate contractual safeguards;
- Professional Advisers: Legal, accounting, and compliance advisers where necessary to protect our legal rights or meet regulatory obligations.
5.2 winnox does not transfer your personal data to third-party marketing companies or data brokers.
6. Cookies & Tracking Technologies
6.1 The winnox Platform uses cookies and similar tracking technologies to enhance your user experience, maintain your session state, detect fraud, and analyse Platform performance.
Types of Cookies Used
- Strictly Necessary Cookies: Required for the Platform to function. These include session cookies that maintain your login state and security cookies that protect against CSRF attacks. They cannot be disabled without affecting Platform functionality;
- Performance / Analytics Cookies: Used to collect anonymised information about how visitors use the Platform, which pages are most visited, and where errors occur. This data informs our ongoing development work;
- Functional Cookies: Remember your preferences such as language settings and responsible gaming tool configurations you have set on your account;
- Marketing / Targeting Cookies: Used where you have consented to receive personalised promotional content based on your activity on the Platform. You may withdraw this consent at any time through your account settings.
6.2 You may control cookie settings through your browser's privacy controls. Note that disabling certain categories of cookies may affect Platform functionality, including the ability to maintain a logged-in session.
Malaysian Players Note: winnox complies with applicable data protection requirements. Your cookie preferences are respected across all sessions. No cookies classified as strictly necessary can be disabled as they are integral to platform security and session management.
7. Data Retention
7.1 winnox retains personal data for as long as necessary to fulfil the purposes for which it was collected, subject to the following retention guidelines:
- Active Accounts: Personal data associated with an active account is retained for the duration of the account relationship;
- Closed Accounts: Following account closure, winnox retains identity, financial, and transaction records for a minimum of five (5) years to comply with AML/CTF regulatory requirements and gaming licence obligations. After this period, data is securely deleted or anonymised;
- KYC Documents: Identity documents submitted for verification are retained for a minimum period as required by applicable regulations — typically five years from the date of the last transaction;
- Support Communications: Chat and email records are retained for a minimum of two (2) years for quality assurance and dispute resolution purposes;
- Marketing Consent Records: Records of consent and opt-out requests are retained for the duration of the relationship and for a period thereafter sufficient to demonstrate compliance.
8. Your Rights
Player Rights
8.1 Subject to applicable data protection law, you have the following rights in relation to your personal data held by winnox:
- Right of Access: You may request a copy of the personal data winnox holds about you;
- Right to Rectification: You may request correction of any inaccurate or incomplete personal data held about you;
- Right to Erasure: You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to our legal retention obligations;
- Right to Restrict Processing: You may request that we restrict processing of your data in certain circumstances (e.g. while accuracy is contested);
- Right to Data Portability: You may request a machine-readable copy of personal data you have provided to us for transfer to another controller;
- Right to Object: You may object to processing based on legitimate interests, including direct marketing communications;
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
8.2 To exercise any of these rights, please contact winnox at [email protected]. We will respond within 30 days of receiving a verified request. We may require identity verification before processing your request to protect against unauthorised data access.
8.3 Note that certain rights are subject to limitations where processing is necessary for legal compliance — for example, we cannot delete transaction records that we are required to retain under AML regulations.
9. Data Security
9.1 winnox implements industry-standard technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- SSL/TLS encryption for all data transmitted between your browser and the winnox Platform;
- Encryption of sensitive data at rest, including payment method details and identity documents;
- Access controls limiting personal data access to winnox staff with a legitimate operational need;
- Regular security assessments and penetration testing of the Platform infrastructure;
- Two-factor authentication support for account access to prevent unauthorised login;
- Anomaly detection systems monitoring for unusual login patterns or transaction behaviour.
9.2 In the event of a personal data breach that poses a risk to the rights and freedoms of affected individuals, winnox will notify relevant regulatory authorities and affected account holders in accordance with applicable legal obligations.
9.3 While winnox takes reasonable steps to secure your data, no internet transmission is completely secure. You are responsible for maintaining the security of your account credentials and should notify winnox immediately at [email protected] if you suspect any unauthorised access to your account.
10. Children's Privacy
21+ Only
10.1 The winnox Platform is strictly intended for use by adults aged 21 years and above. We do not knowingly solicit or collect personal data from individuals under this age.
10.2 If we become aware that personal data has been collected from a person under 21, we will immediately delete the associated account and all personal data collected in connection with it, and will report the incident to our licensing authority if required.
10.3 If you have reason to believe that a minor is using or has registered on the winnox Platform, please contact us immediately at [email protected].
11. International Data Transfers
11.1 The winnox Platform is operated by an entity incorporated under the jurisdiction of its international gaming licence. Your personal data may therefore be processed in, and transferred to, countries outside Malaysia as part of normal platform operations — including for hosting, payment processing, and game delivery.
11.2 Where personal data is transferred internationally, winnox ensures appropriate safeguards are in place, which may include standard contractual clauses, binding corporate rules, or adequacy decisions applicable to the recipient country.
11.3 By using the winnox Platform, you acknowledge that your personal data may be processed outside of Malaysia as described in this Policy.
12. Changes to This Policy
12.1 winnox may update this Privacy Policy from time to time. Where changes are material, we will notify registered account holders by email or in-platform notification with reasonable advance notice prior to the changes taking effect.
12.2 The most current version of this Privacy Policy is always accessible at https://winnox.net/privacy-policy. The "Last updated" date at the top of this page reflects the date of the most recent revision. Your continued use of the Platform following notification of changes constitutes acceptance of the revised Policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data by winnox, please contact our data protection team:
- Email: [email protected]
- Live Chat: Available 24/7 via the winnox Platform for registered users
- Response: We aim to respond to all privacy-related queries within 5 business days, and to formal data subject access requests within 30 days as required by applicable law.
This Privacy Policy was last reviewed on 1 June 2026 and supersedes all previous versions.
SSL Encrypted Platform
All data transmitted between you and the winnox Platform is protected by SSL/TLS encryption. Your personal and financial data is never sent in plain text.
No Third-Party Data Sales
winnox does not sell or rent your personal data to third-party advertisers or data brokers. Your information is used only to provide and improve the winnox service.
You Control Your Data
Malaysian players have the right to access, correct, or request deletion of their personal data. Submit a request anytime via support and we will respond within 30 days.