Your privacy is important to us. This Privacy Policy explains how wintoto collects, uses, stores, and protects the personal data of all registered players and visitors to the wintoto platform. Please read it carefully alongside our Terms & Conditions.
All personal data held by wintoto is protected using 256-bit SSL encryption for transmission and access-controlled storage. We apply security-by-design principles across every system that handles your data.
wintoto does not sell, rent, or trade your personal data to third parties for their own marketing purposes. Your information is used only for the purposes described in this Privacy Policy.
Registered players have the right to access, correct, and in certain circumstances request deletion of their personal data held by wintoto, subject to our legal obligations under applicable law.
wintoto collects only the personal data necessary for the specific, legitimate purposes described in this Policy. Data is not processed beyond those stated purposes without your consent or a lawful basis.
wintoto retains personal data only for as long as is necessary for the purpose it was collected, or as required by applicable legal or regulatory obligations, including our obligations under international gaming authority oversight.
In the unlikely event of a data breach that is likely to result in a high risk to your rights and freedoms, wintoto will notify affected players without undue delay and take immediate remedial action.
wintoto ("wintoto", "we", "us", "our") is the operator of the online gaming platform accessible at wintoto.one. For the purposes of applicable data protection legislation, wintoto acts as the data controller in respect of the personal data of its registered players and platform visitors.
This Privacy Policy applies to all personal data collected through the wintoto Platform, including via registration, gameplay, deposits, withdrawals, customer support interactions, and any communications between you and wintoto. It should be read alongside our Terms & Conditions and Responsible Gaming Policy.
wintoto collects the following categories of personal data from players and platform visitors:
2.1 Registration & Identity Data. When you register a wintoto account, we collect your full name, date of birth, country and state of residence, email address, and mobile phone number. During mandatory KYC (Know Your Customer) verification, we collect copies of identity documents — such as your Malaysian MyKad or passport — and proof of address documentation.
2.2 Financial Data. wintoto collects information relating to deposits and withdrawals, including payment method type (e.g., Touch n Go eWallet, Boost, Maybank, CIMB), transaction amounts, and transaction timestamps. We do not store full bank account or card numbers on our systems; payment processing is handled by certified payment service providers.
2.3 Gaming & Activity Data. We collect records of your gaming activity on wintoto, including games played, bet amounts, game results, session durations, and account balance history. This data is collected for game operation, account integrity, responsible gaming monitoring, and fraud prevention purposes.
2.4 Technical & Device Data. When you access the wintoto Platform, we automatically collect technical data including your IP address, browser type and version, device type, operating system, referring URLs, and session data. This data is used for security, fraud detection, and platform optimisation purposes.
2.5 Communications Data. If you contact wintoto's customer support — via live chat, email, or any other channel — we retain records of those communications, including the content of messages and the date and time of contact.
wintoto uses the personal data we collect for the following purposes:
wintoto processes personal data on the following legal bases as applicable under data protection law:
wintoto does not sell or rent your personal data to third parties. We share personal data only in the following limited circumstances:
5.1 Service Providers. We engage trusted third-party service providers to support platform operations, including payment processors (handling Touch n Go eWallet, Boost, GrabPay, and bank transfer transactions), KYC verification services, fraud detection providers, cloud infrastructure providers, and customer support tooling. All such providers are contractually bound to process your data only on our instructions and in accordance with applicable data protection law.
5.2 Regulatory & Law Enforcement. wintoto may disclose personal data to regulatory authorities, law enforcement agencies, or gaming licensing authorities where required to do so by law, court order, or regulatory direction. We will notify affected players of such disclosures to the extent permitted by law.
5.3 Business Transfers. In the event of a merger, acquisition, or sale of all or substantially all of wintoto's assets, personal data held by wintoto may be transferred to the acquiring entity, subject to equivalent privacy protections. Affected players will be notified of any such transfer.
5.4 Responsible Gaming Partners. Where required under our gaming authority obligations, wintoto may share limited player data with approved responsible gaming bodies for the administration of cross-operator self-exclusion programmes.
wintoto uses cookies and similar tracking technologies on the Platform for the following purposes:
You may manage cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of the wintoto Platform. wintoto does not use third-party advertising cookies or cross-site tracking technologies for advertising purposes.
wintoto implements a comprehensive set of technical and organisational security measures to protect your personal data against unauthorised access, loss, destruction, or alteration:
While wintoto takes all reasonable steps to protect your data, no security system is entirely impenetrable. In the event of a security incident affecting your personal data, wintoto will act promptly in accordance with our breach notification obligations.
wintoto retains personal data for the following periods, unless a longer retention period is required by applicable law or regulatory obligation:
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with wintoto's data disposal procedures.
Subject to applicable data protection law, registered wintoto players have the following rights in respect of their personal data:
You may request a copy of the personal data wintoto holds about you. We will respond within 30 days of a verified request.
You may request correction of inaccurate personal data held by wintoto. Updates to standard account details can be made directly within your account settings.
You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to our overriding legal and regulatory retention obligations.
In certain circumstances, you may request that wintoto restrict the processing of your personal data — for example, while a data accuracy dispute is being resolved.
Where processing is based on your consent or a contract, you may request your personal data in a structured, machine-readable format for transfer to another service.
You may object to processing based on wintoto's legitimate interests, including profiling for fraud prevention, where you have grounds relating to your particular situation.
To exercise any of these rights, please contact our Data Privacy team at [email protected] with a description of your request. We may require identity verification before processing your request.
The wintoto Platform is strictly intended for persons aged 21 and above. wintoto does not knowingly collect personal data from individuals under the age of 21. Our KYC age verification process is designed to prevent under-age registration. If wintoto becomes aware that personal data has been collected from a person under 21, that account will be immediately closed and the personal data deleted, subject to any overriding regulatory obligations.
If you believe that a person under 21 has registered with wintoto, please notify us immediately at [email protected] so that we can take prompt action.
wintoto's primary infrastructure is hosted in data centres that may be located outside Malaysia. Where personal data is transferred internationally, wintoto ensures that appropriate safeguards are in place to protect your data to a standard equivalent to that applicable in Malaysia, including contractual clauses requiring overseas recipients to comply with applicable data protection standards.
By registering with wintoto and accepting these terms, you acknowledge that your personal data may be transferred to and processed in jurisdictions outside Malaysia, subject to the safeguards described above.
wintoto reserves the right to update this Privacy Policy from time to time to reflect changes in our data practices, the services we offer, or applicable legal requirements. The most current version of this Privacy Policy will always be available at wintoto.one/privacy-policy.
Where changes are material, wintoto will notify registered players via the contact details held on their accounts before the changes take effect. Continued use of the wintoto Platform following notification of material changes constitutes your acceptance of the revised Privacy Policy.
If you have any questions, concerns, or requests relating to this Privacy Policy or wintoto's handling of your personal data, please contact us at:
Our Data Privacy team aims to acknowledge all privacy-related enquiries within 5 business days and to provide a substantive response within 30 days. For urgent matters relating to potential data security incidents, please contact us via the 24/7 live chat function in your wintoto account dashboard for the fastest response.
We protect your privacy so you can focus on what matters — enjoying Malaysia's best online casino experience. 21+ only. Play responsibly.
Access Your wintoto Account