Privacy Policy
Last updated: February 2026
What This Covers
This policy explains how WinWin collects, uses, stores, and protects your personal information when you use our casino and sports betting platform. We operate in Zambia and process data according to international standards.
Creating an account means you agree to this policy. If you disagree with our data handling, don't sign up. You can request your data or ask for corrections anytime.
Information We Collect
Account Information
When you register, we collect your full name, date of birth, email, phone number, and address. This creates your account, verifies you're 18+, and meets anti-money laundering requirements.
During verification, we collect ID photos (national ID, passport) and proof of address (utility bill, bank statement). These confirm your identity and prevent fraud. Used only for verification.
Payment Data
We record transaction amounts, dates, payment methods (MTN Mobile Money, Airtel Money, cards), and transaction IDs. We don't store your mobile money PIN or card CVV. Payment processors handle those under their security protocols.
Usage Data
Systems automatically collect IP address, device type, browser, pages viewed, games played, bet amounts, and session times. This improves the platform, fixes bugs, and identifies security threats.
We use cookies to keep you logged in, remember preferences, and analyze traffic. More in the Cookies section below.
Communications
Chat and email conversations are recorded. This resolves repeat issues faster and helps train support staff.
How We Use Your Information
Account Management
Personal information creates and maintains your account, processes deposits and withdrawals, verifies identity before payouts, prevents fraud, and enforces terms.
Communication
We send transactional emails about deposits, withdrawals, password resets, verification updates, and security alerts. These are mandatory for security.
With consent, we send promotional emails about bonuses and new games. Unsubscribe anytime via the link in emails. Transactional emails continue.
Platform Improvement
Usage data analysis shows popular games, navigation patterns, technical problems, and performance optimization needs. This uses aggregated, anonymized data — patterns, not individuals.
Legal Compliance
Law requires us to verify identities, keep financial records, report suspicious transactions, and cooperate with legal investigations.
Data Security
SSL/TLS encryption protects all communication between your device and our servers. This prevents credential and payment detail interception.
Data is stored on secure servers with firewalls, intrusion detection, and restricted access. Only authorized personnel access personal information under confidentiality agreements.
We never store mobile money PINs or card CVVs. Payment processors handle those under PCI DSS standards. We only keep transaction references for tracking.
Who We Share Data With
Service Providers
Limited information goes to payment processors (MTN, Airtel, card networks), game providers (usually just player IDs), hosting services, support tools, and fraud prevention services.
These companies sign contracts requiring data protection and use only for services they provide. They can't sell your information.
Legal Requirements
We may disclose information if legally required, by court order, to prevent fraud or crime, or to enforce terms. We only share what's required and notify you if possible.
No Selling
We don't sell your data to advertisers or brokers. Your information stays with us and necessary service providers.
Your Rights
Access and Correction
Request copies of your data by emailing [email protected] with "Data Access Request" in subject. We'll provide it within 30 days. Update incorrect information in account settings or contact support.
Deletion
Request account and data deletion by contacting support. We'll delete what we can, but law requires keeping some records for tax, fraud prevention, and regulation. These stay secure and unused for other purposes.
Accounts with pending withdrawals, active bonuses, or disputes can't be deleted until resolved.
Marketing Opt-Out
Stop promotional emails via unsubscribe links or by contacting support. Essential account emails continue.
Cookies
What They Do
Cookies are small text files keeping you logged in, remembering preferences, tracking sessions for security, analyzing traffic, and detecting fraud.
Types
Essential cookies enable core functionality — login, security, basics. Can't use the site without them. Analytical cookies show usage patterns for improvements. Don't identify you personally. Marketing cookies track ad sources. Blockable without affecting functionality.
Managing Cookies
Browser settings let you block or delete cookies. Blocking essential cookies breaks login and betting. Blocking analytical and marketing cookies is fine.
Data Retention
We keep personal information while your account is active. After closure, data is retained as legally required — typically five years for financial records, IDs, and transactions. This is legally mandated for tax, anti-money laundering, and disputes.
After legal retention expires, we permanently delete or anonymize data. Anonymized data can't be traced to you and may be kept indefinitely for statistics.
International Transfers
WinWin operates internationally, so data may be processed or stored outside Zambia. We ensure adequate protection standards wherever data goes. Transfers only happen when necessary for services.
Children's Privacy
WinWin is 18+ only. We don't knowingly collect information from minors. Accounts created by underage users are closed immediately with data deleted.
Parents believing their child created an account should contact support immediately for verification and action.
Policy Changes
We may update this policy when practices change, laws require it, or features are added. Significant changes announced via email or site banner. "Last updated" date shows current version.
Continuing to use WinWin after updates means you accept changes. If you disagree, close your account and request deletion.
Data Breaches
Despite security measures, no system is attack-proof. If a breach compromises your information, we'll notify you immediately explaining what was affected, our fix actions, and your protective steps.
Relevant authorities get notified as legally required. Transparent breach communication maintains trust.
Contact About Privacy
Questions about data handling? Want to exercise rights? Need clarification? Email [email protected] with "Privacy" in subject. We'll respond promptly and address concerns.