This Privacy Policy explains how winbat collects, processes, stores, and protects the personal data of users who access our platform. We are committed to handling your information with transparency, security, and respect for your rights as a Bangladeshi player.
Your Privacy Matters: winbat does not sell, rent, or trade your personal data to third-party advertisers or data brokers under any circumstances. This Policy is written in plain, accessible English so that every player on our platform — from Dhaka to Chittagong to Cox's Bazar — fully understands how their information is used. Please read it carefully before creating an account or using any winbat Service.
1.1 Data Controller. This Privacy Policy is issued by winbat, the operator of the online casino and sports betting platform accessible at winbat.app. winbat acts as the data controller for all personal information collected from users of the Platform. References to "winbat", "we", "us", or "our" in this Policy refer to the winbat platform and its operating entity.
1.2 Scope. This Policy applies to all personal data collected from individuals who visit the winbat website, create an account, make a deposit or withdrawal, place a bet, interact with a winbat casino game, contact winbat customer support, or otherwise engage with any feature of the Platform. It applies regardless of the device or network used to access the Platform.
1.3 Bangladesh Market. The winbat Platform is operated primarily for players based in Bangladesh. This Policy reflects our commitment to responsible data management within the context of the Bangladeshi digital market. All account balances and financial transactions are processed in Bangladeshi Taka (৳).
1.4 Relationship with Other Policies. This Privacy Policy should be read alongside the winbat Terms & Conditions and Responsible Gaming Policy, both of which are incorporated by reference into the overall agreement governing your use of the Platform.
winbat collects the minimum data necessary to operate the Platform safely, verify player identities, process financial transactions, and comply with our responsible gaming obligations. The categories of data we collect are described below.
| Data Category | Examples | Required? |
|---|---|---|
| Identity Data | Full legal name, date of birth, National ID number, passport number, photograph | Yes — KYC |
| Contact Data | Mobile number, email address, residential address (district, division) | Yes — Registration |
| Financial Data | bKash/Nagad/Rocket/Upay account numbers, bank account details, transaction history, deposit and withdrawal records in BDT | Yes — Transactions |
| Account Data | Username, hashed password, account balance, bonus balances, preferences, notification settings | Yes — Platform Use |
| Gaming & Betting Data | Game history, bet amounts, win/loss records, sports betting selections, session duration, wagering activity | Yes — Service Delivery |
| Technical Data | IP address, device type, browser/OS version, mobile network (Grameenphone, Banglalink, etc.), cookies, session tokens | Yes — Security |
| Communications Data | Support chat logs, email correspondence with the winbat team, complaint records | Where applicable |
| Responsible Gaming Data | Deposit limits set, self-exclusion status, cooling-off periods, responsible gaming tool usage | Where applicable |
winbat does not collect sensitive categories of data such as racial or ethnic origin, political opinions, religious beliefs, trade union membership, biometric data, or health data, except where a player voluntarily discloses health-related information in the context of a responsible gaming self-exclusion request.
3.1 Directly from You. The majority of personal data winbat holds is provided directly by you when you register an account, complete KYC verification, make a deposit or withdrawal request, contact customer support, or interact with any Platform feature that requires account authentication.
3.2 Automatically via the Platform. When you visit or use the winbat website, our systems automatically log certain technical data including your IP address, device characteristics, browser type, and session activity. This data is collected using server logs, cookies, and similar tracking technologies as described in Section 9 of this Policy.
3.3 From Payment Service Providers. When you make a deposit or withdrawal via bKash, Nagad, Rocket, Upay, or a Bangladeshi bank, winbat receives confirmation data from the payment provider necessary to verify the transaction. This typically includes the sender's registered mobile number or account reference, transaction amount in BDT, and a transaction ID. winbat does not receive or store your full payment account credentials or PIN.
3.4 From Identity Verification Partners. During the KYC process, winbat may use a third-party identity verification service to cross-reference the documents you submit against authoritative records. These partners process your identity data solely for the purpose of verification and are contractually prohibited from using it for any other purpose.
3.5 From Game Providers. Third-party game studios integrated into the winbat Platform — including Pragmatic Play, Evolution Gaming, Microgaming, NetEnt, Spribe, and Ezugi — may share anonymised or session-level gameplay data with winbat for the purposes of game integrity monitoring and responsible gaming analysis.
winbat processes personal data only for clearly defined, legitimate purposes. We do not use your data in ways that are incompatible with the purposes described below:
winbat processes personal data on one or more of the following legal bases, depending on the specific processing activity involved:
6.1 No Sale of Personal Data. winbat does not sell, rent, or trade your personal data to third-party advertisers, data brokers, or marketing agencies. Your data is shared only in the circumstances described in this section.
6.2 Payment Service Providers. To process deposits and withdrawals, winbat shares necessary transaction data with payment partners including bKash, Nagad, Rocket, Upay, and participating Bangladeshi banks (Dutch-Bangla Bank, City Bank, BRAC Bank, Islami Bank, Sonali Bank). These providers process your data solely to facilitate the specific payment transaction requested.
6.3 Identity Verification Partners. During KYC verification, relevant identity documents and personal details are shared with our contracted identity verification provider. These partners are bound by strict data processing agreements that limit use of your data to the verification purpose only.
6.4 Game Studios. Third-party game providers integrated into the winbat Platform receive the minimum session data necessary to deliver their games, including your account session token and stake/win values for the current round. Game providers do not receive your full identity data or payment details.
6.5 Legal and Regulatory Disclosure. winbat may disclose personal data to law enforcement agencies, financial intelligence units, courts, or other regulatory authorities where required by applicable law, pursuant to a lawful order, or where winbat reasonably believes disclosure is necessary to prevent financial crime or protect the safety of users.
6.6 Business Transfers. In the event of a merger, acquisition, or sale of all or part of the winbat business, personal data held by winbat may be transferred to the acquiring entity as part of the transaction assets. winbat will notify affected users prior to any such transfer where reasonably practicable.
6.7 Service Providers. winbat engages a limited number of third-party service providers (such as cloud infrastructure providers and customer support software vendors) who process data on winbat's behalf under contractual data processing agreements. These providers act only on winbat's documented instructions and are not permitted to use your data for their own purposes.
7.1 Active Accounts. winbat retains personal data for as long as your account remains active. During this period, account data, transaction records, and gaming history are retained to enable service delivery, support queries, and regulatory compliance.
7.2 Closed Accounts. Following account closure — whether initiated by you or by winbat — personal data is retained for a minimum period of five (5) years to satisfy anti-money laundering (AML) record-keeping obligations and to handle any residual disputes, regulatory inquiries, or legal claims that may arise.
7.3 KYC Documents. Identity documents submitted for KYC verification are retained for a minimum of five (5) years from the date of submission, consistent with AML compliance requirements. After this period, such documents are securely deleted from winbat's systems.
7.4 Marketing Data. If you have opted in to marketing communications, your marketing preferences and contact data used for that purpose will be retained until you withdraw consent. Upon withdrawal of consent, your data will be suppressed from marketing systems within 72 hours.
7.5 Self-Exclusion Records. Where a player has activated self-exclusion, a suppression record is retained indefinitely to prevent re-registration during the exclusion period and to support responsible gaming obligations even after account closure.
7.6 Secure Deletion. Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised in accordance with industry-standard data destruction practices.
8.1 Encryption in Transit. All data transmitted between your browser or mobile application and the winbat Platform is encrypted using 256-bit SSL/TLS technology. This prevents interception or tampering by any third party during transmission.
8.2 Encryption at Rest. Sensitive data stored on winbat's servers — including account credentials, financial records, and KYC documents — is encrypted at rest using AES-256 encryption. Account passwords are stored exclusively as salted cryptographic hashes; winbat staff cannot view your password in plain text.
8.3 Access Controls. Access to personal data within the winbat organisation is restricted on a strict need-to-know basis. Staff members access only the data categories required to perform their specific role. All internal data access is logged and audited.
8.4 Payment Security. winbat does not store full payment credentials (bKash PIN, bank passwords, card numbers) on its primary servers. Payment data is processed through certified payment gateway integrations that operate independently of winbat's core infrastructure.
8.5 Security Monitoring. winbat operates continuous security monitoring across its platform infrastructure, including intrusion detection systems, anomaly detection for account activity, and regular penetration testing by independent security professionals.
8.6 Data Breach Response. In the event of a personal data breach that poses a risk to your rights or interests, winbat will notify affected users promptly by email, providing details of the breach, the data affected, and the steps taken to mitigate the impact. winbat will also notify relevant authorities as required by applicable law.
8.7 Your Responsibility. While winbat applies robust technical and organisational security measures, the security of your account also depends on you. You are responsible for maintaining the confidentiality of your winbat Login credentials and for ensuring your registered mobile device and email account are secured with strong passwords and, where available, two-factor authentication.
9.1 What Are Cookies. Cookies are small text files placed on your device when you visit the winbat website. They allow the Platform to recognise your device across sessions, maintain your login state, and collect analytical data about how the Platform is used.
9.2 Cookies winbat Uses.
9.3 Managing Cookies. You can control non-essential cookies through your browser settings. Most modern browsers allow you to view, block, or delete cookies. Please note that blocking strictly necessary cookies will prevent you from logging in to your winbat account. For detailed guidance on managing cookies in your specific browser, refer to your browser's help documentation.
9.4 No Third-Party Advertising Cookies. winbat does not permit third-party advertising networks to place tracking cookies on the winbat Platform. You will not be tracked across other websites for retargeting or behavioural advertising purposes based on your winbat activity.
As a winbat user, you have the following rights in relation to your personal data. To exercise any of these rights, contact us at . winbat will respond to all valid requests within 30 days.
11.1 Strictly Adults Only. The winbat Platform is intended exclusively for adults aged 18 and above. winbat does not knowingly collect, process, or retain personal data from individuals under the age of 18. The 18+ age requirement is enforced at the point of registration and verified during the KYC process.
11.2 Discovery of Minor's Data. If winbat discovers or is notified that personal data belonging to a person under 18 has been collected — for example, through the use of a false date of birth during registration — that account will be immediately suspended, all associated data will be securely deleted, and any deposits made will be returned to the originating payment account after verification, in accordance with our Terms & Conditions.
11.3 Parental Responsibility. If you are a parent or guardian and believe a person under 18 has created a winbat account using your payment method or personal device, please contact us immediately at . We will investigate and act promptly to close the account and erase the associated data.
12.1 Policy Updates. winbat reserves the right to update this Privacy Policy at any time to reflect changes in our data practices, applicable law, or Platform features. When we make material changes, we will notify registered users via the email address on file or via a prominent notice displayed on the Platform prior to the changes taking effect. The "Last Updated" date at the top of this Policy will reflect the date of the most recent revision.
12.2 Continued Use. Your continued use of the winbat Platform following notification of an update to this Privacy Policy constitutes your acceptance of the revised terms. If you do not accept the revised Policy, you must cease using the Platform and may request account closure.
12.3 Contact Us. If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a potential data protection concern, please contact the winbat team at . Our support team is available 24 hours a day, seven days a week, on Bangladesh Standard Time (BST, UTC+6).
12.4 Complaints. If you are not satisfied with winbat's response to a data rights request or privacy concern, you have the right to escalate your complaint through the appropriate legal channels available in your jurisdiction.
Privacy Queries
To exercise your data rights or ask questions about this Policy, contact the winbat team at . Available 24/7 on Bangladesh Standard Time (BST, UTC+6).
Our data protection commitments are built into every layer of the winbat Platform — from the moment you register to every transaction you make.
Every connection between your device and the winbat Platform is secured with 256-bit SSL/TLS encryption. Your personal and financial data is never transmitted in plain text, regardless of whether you are using mobile data or Wi-Fi.
winbat does not share your personal data with advertising networks, social media platforms, or data brokers. Your gambling activity and personal details are never used to build marketing profiles for third parties.
Deposits and withdrawals via bKash, Nagad, Rocket, Upay, and Bangladeshi bank partners are processed through certified payment gateways. winbat never stores your full payment credentials on its own servers.
Identity verification at winbat is a single, one-time process. Documents submitted for KYC are handled by contracted verification partners under strict data processing agreements, and are retained only as long as legally required.
winbat sends promotional communications — including Eid, Pohela Boishakh, and BPL season offers — only to players who have explicitly opted in. You can withdraw consent at any time through your account settings with immediate effect.
Access, correct, export, restrict, or request deletion of your personal data at any time by contacting the winbat support team. All valid requests are handled within 30 days by our dedicated data management team.
Your data is protected. Now discover everything winbat has to offer — from live cricket betting to premium casino games and card games.