1. Data Controller
For the purposes of this Privacy Policy, the data controller responsible for the personal data of wondawin players is the operating entity behind the wondawin platform ("wondawin", "we", "us", "our"), operating under an international gaming authority licence. Questions or requests regarding the processing of your personal data by wondawin should be directed to our Data Protection team via the support contact details provided in Section 12 of this Policy.
This Privacy Policy applies exclusively to personal data processed in connection with your use of the wondawin platform at wondawin.club and any associated wondawin services. It does not apply to third-party websites or services that may be referenced or linked from the wondawin platform, over which wondawin has no control.
2. Personal Data We Collect
wondawin collects personal data through several channels, including the account registration process, ongoing use of the wondawin platform, financial transactions, customer support interactions, and automated technical collection. The categories of personal data that wondawin may collect include:
2.1 Identity & Contact Data
- Full legal name and date of birth (required for age verification and KYC compliance);
- Residential address, including city and postcode (e.g. Kuala Lumpur, Penang, Johor Bahru, Petaling Jaya);
- Email address and contact telephone number;
- Government-issued identification documents submitted during KYC verification, such as MyKad or passport.
2.2 Financial Data
- Payment method details, including Touch n Go eWallet account identifiers, Boost account details, bank account or card details for Maybank, CIMB, Public Bank, and FPX transactions;
- Transaction history on the wondawin platform, including deposits, withdrawals, wager amounts, and winnings;
- Anti-money laundering (AML) screening data as required under wondawin's regulatory obligations.
2.3 Technical & Usage Data
- IP address, device type, browser type and version, operating system;
- Pages visited on wondawin, session duration, game play history, and betting patterns;
- Cookies and similar tracking technologies as described in Section 8 of this Policy;
- Geolocation data, where permitted by your device settings, used to verify jurisdictional eligibility.
2.4 Communications Data
- Records of your communications with the wondawin support team, including live chat transcripts, support ticket content, and email correspondence;
- Preferences and opt-in choices regarding promotional communications from wondawin.
3. How wondawin Uses Your Personal Data
wondawin processes personal data for the following purposes:
- Account Management: To create, maintain, and verify your wondawin account, including processing your wondawin login credentials securely.
- Service Delivery: To provide access to wondawin Casino games, the sportsbook, slots, Plinko, Mix Parlay, and all other wondawin products and services.
- Financial Processing: To process deposits and withdrawals via your chosen payment method, conduct fraud detection, and comply with anti-money laundering obligations.
- Regulatory Compliance: To fulfil obligations under wondawin's international gaming authority licence, including KYC verification, age verification, and responsible gaming monitoring.
- Customer Support: To respond to enquiries, resolve disputes, and provide assistance through the wondawin support team.
- Marketing Communications: Where you have provided consent, to send promotional offers, bonus notifications, and news relevant to your wondawin account. You may withdraw this consent at any time through your account settings.
- Platform Improvement: To analyse usage patterns on wondawin for the purpose of improving platform performance, game selection, and user experience for Malaysian players.
- Responsible Gaming: To monitor gaming behaviour patterns that may indicate problem gambling and to trigger appropriate responsible gaming interventions or outreach.
4. Legal Basis for Processing
wondawin processes personal data on the following legal bases:
- Contractual Necessity: Processing required to perform the contract between you and wondawin, including account management, service delivery, and financial transaction processing.
- Legal Obligation: Processing required to comply with wondawin's obligations under its gaming licence, anti-money laundering regulations, and applicable data protection laws.
- Legitimate Interests: Processing in pursuit of wondawin's legitimate business interests, including fraud prevention, platform security, and responsible gaming monitoring, where those interests are not overridden by your rights and freedoms.
- Consent: Processing for marketing communications, where you have given explicit consent. Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
5. Sharing Your Personal Data
wondawin does not sell your personal data to third parties. We may share your personal data with the following categories of recipient where necessary and proportionate:
- Payment Processors: Entities processing your financial transactions on wondawin, including Touch n Go eWallet, Boost, FPX operators, and banking partners, who receive only the data necessary to execute and verify your transaction.
- Game Studios & Software Providers: Licensed third-party game studios providing games accessible through the wondawin platform, who may receive anonymised usage data for game performance purposes.
- KYC & Identity Verification Providers: Specialist verification services that assist wondawin in fulfilling its regulatory obligations to verify player identity and age.
- Regulatory Authorities: wondawin's gaming licence regulator and any other relevant regulatory or law enforcement authority where wondawin is legally required to disclose personal data.
- Fraud Prevention Services: Third-party fraud detection and AML screening services used to protect the integrity of the wondawin platform and its player community.
All third parties with whom wondawin shares personal data are contractually required to process that data only for the specified purpose and to maintain security standards commensurate with the sensitivity of the data.
6. Data Retention
wondawin retains personal data for as long as is necessary to fulfil the purposes for which it was collected, subject to any longer retention periods required by regulatory or legal obligations applicable to the wondawin operating licence.
- Account data and transaction records are retained for a minimum of five (5) years following account closure, as required under AML and gaming licence obligations.
- KYC verification documents are retained for the period required by applicable regulatory requirements, typically a minimum of five (5) years from the date of verification.
- Marketing preference and consent records are retained for the duration of your wondawin account and for a period of three (3) years following account closure.
- Technical and usage data collected through cookies and analytics tools is retained in accordance with the specific data retention settings of the tools employed, typically for periods of between 90 days and 24 months.
Upon expiry of the applicable retention period, personal data will be securely deleted or anonymised in accordance with wondawin's data destruction procedures.
7. Security Measures
wondawin implements technical and organisational security measures proportionate to the risk of processing personal data on an online gaming platform. These measures include:
- SSL/TLS encryption across all wondawin platform communications, including the wondawin login process and all financial transactions;
- Encrypted storage of account credentials — wondawin does not store passwords in plain text;
- Role-based access controls limiting internal staff access to personal data on a need-to-know basis;
- Regular security assessments and penetration testing of the wondawin platform infrastructure;
- Two-factor authentication (2FA) available to all wondawin account holders as an additional login security layer.
Notwithstanding these measures, no internet-based transmission or storage system can be guaranteed to be completely secure. In the event of a personal data breach that poses a risk to your rights and freedoms, wondawin will notify affected players and the relevant regulatory authority in accordance with applicable obligations.
8. Cookies & Tracking Technologies
wondawin uses cookies and similar tracking technologies to operate the platform effectively and to improve the experience of Malaysian players. The categories of cookies used on wondawin include:
- Strictly Necessary Cookies: Required for the wondawin platform to function, including session management cookies that maintain your wondawin login state. These cannot be disabled without impairing platform functionality.
- Performance & Analytics Cookies: Used to collect anonymised data about how players use wondawin, enabling us to improve page performance, navigation, and game loading times.
- Functional Cookies: Enable wondawin to remember your preferences, such as language settings and display options, to personalise your experience.
- Marketing Cookies: Used, with your consent, to deliver relevant promotional content about wondawin products. These cookies may track your browsing activity across sessions.
You may manage your cookie preferences through your browser settings at any time. Disabling certain categories of cookies may affect the functionality of the wondawin platform.
9. Your Data Protection Rights
Subject to the legal basis on which wondawin processes your personal data and applicable data protection law, you may have the following rights in relation to your personal data held by wondawin:
- Right of Access: To request a copy of the personal data that wondawin holds about you.
- Right to Rectification: To request correction of inaccurate or incomplete personal data held in your wondawin account.
- Right to Erasure: To request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to any overriding legal obligations requiring retention.
- Right to Restrict Processing: To request that wondawin limits its processing of your personal data in certain circumstances.
- Right to Data Portability: To receive a copy of your personal data in a structured, machine-readable format where processing is based on consent or contract.
- Right to Object: To object to wondawin's processing of your personal data for direct marketing purposes at any time, with immediate effect.
To exercise any of the above rights, please contact the wondawin Data Protection team using the contact details in Section 12. wondawin will respond to all verified data subject requests within 30 days of receipt.
10. Minors
The wondawin platform is strictly intended for individuals who are 21 years of age or older. wondawin does not knowingly collect personal data from individuals under the age of 21. If wondawin becomes aware that personal data has been collected from a person under 21, that account will be immediately closed and all associated personal data deleted, except to the extent that retention is required by regulatory obligations.
If you have reason to believe that a person under 21 has registered a wondawin account, please notify wondawin support immediately at the contact details provided in Section 12.
11. Changes to This Privacy Policy
wondawin reserves the right to update this Privacy Policy at any time to reflect changes in our data processing practices, legal obligations, or platform operations. When a material change is made to this Privacy Policy, wondawin will notify registered players by email to the address associated with their wondawin account, or by displaying a prominent notice on the wondawin platform prior to the change taking effect.
The "Last updated" date at the top of this page will always reflect the date of the most recent revision. We recommend that you review this Privacy Policy periodically to remain informed of how wondawin processes your personal data.
How wondawin Protects You
SSL Encryption
Every wondawin session — including your login, game play, and financial transactions — is protected end-to-end with SSL/TLS encryption.
No Data Selling
wondawin does not sell your personal data to advertisers or data brokers. Your information is used only to operate the platform and meet regulatory requirements.
Your Rights, Respected
Access, correct, or delete your wondawin personal data by contacting our Data Protection team. All verified requests are handled within 30 days.
Licensed & Audited
wondawin's data practices are subject to oversight under our international gaming authority licence, which includes periodic compliance audits covering data protection standards.
2FA Account Security
Enable two-factor authentication on your wondawin account for an extra layer of login security — particularly recommended for players with significant account balances.
Cookie Control
Manage your cookie preferences on wondawin at any time via your browser settings. Strictly necessary cookies cannot be disabled; all others are optional.