Effective Date: 1 January 2026 · Last Updated: 11 June 2026 · Applies to all mr138.win users
These cards highlight how mr138 approaches data privacy. They are a summary only — the full policy below is the binding document.
mr138 uses industry-standard SSL/TLS encryption for all data in transit. Stored personal data is secured using access controls and encrypted at rest. We do not sell your personal information to third parties.
mr138 members have the right to access, correct, export, or request deletion of their personal data. Submit requests via live chat or email and our team will respond within the timelines set out in this policy.
mr138 does not sell, rent, or trade your personal data to advertising networks or data brokers. Data is shared only with licensed service providers strictly necessary for platform operation and regulatory compliance.
mr138 uses cookies for authentication, security, and platform performance. We do not use third-party advertising cookies. You can manage cookie preferences through your browser settings at any time.
As a licensed gaming operator, mr138 is required to collect identity verification data (KYC) and retain transaction records for regulatory and AML compliance purposes. This is a legal obligation, not optional.
mr138 sends promotional emails and SMS messages only to members who have opted in. You can withdraw marketing consent at any time from your account settings or by contacting support. Transactional communications are unaffected.
This Privacy Policy ("Policy") describes how mr138 ("mr138", "we", "us", "our"), the operator of mr138.win, collects, uses, discloses, stores, and protects personal data in connection with your use of our website and services. mr138 is committed to handling your personal data responsibly and in accordance with applicable data protection principles and the requirements of our international gaming licence.
By registering an account on mr138.win or otherwise using the platform, you acknowledge that you have read and understood this Policy. If you do not agree to this Policy, you must discontinue use of the platform.
This Policy applies to all users of mr138.win regardless of location. Users accessing the platform from Malaysia should be aware that local laws — including the Personal Data Protection Act 2010 (PDPA) — may also apply to the processing of their personal data. mr138 aims to meet PDPA principles where they are applicable to its operations.
mr138 collects the following categories of personal data:
| Category | Examples |
|---|---|
| Identity Data | Full legal name, date of birth, MyKad / passport number, nationality |
| Contact Data | Email address, Malaysian mobile number, registered address |
| Financial Data | Bank account details, e-wallet identifiers (Touch n Go / Boost), transaction history, deposit and withdrawal records |
| KYC / Verification Data | Identity document images, proof of address documents, selfie or liveness verification |
| Account Data | Username, account preferences, login history, session activity, game play history |
| Technical Data | IP address, device type, browser type, operating system, screen resolution |
| Communications Data | Live chat transcripts, support emails, feedback submissions |
We do not intentionally collect sensitive personal data such as health information, racial or ethnic origin, or political opinions except where strictly required by our AML obligations or expressly provided by you.
mr138 collects personal data through the following methods:
mr138 uses your personal data for the following purposes:
mr138 processes your personal data on the following legal bases:
mr138 does not sell, rent, or trade your personal data. We may share data with the following categories of recipients strictly on a need-to-know basis:
All third-party service providers are contractually required to handle mr138 member data confidentially and solely for the specified purpose. mr138 does not permit service providers to use member data for their own purposes.
mr138.win uses the following types of cookies:
mr138 does not use third-party advertising or tracking cookies. You can manage cookie preferences through your browser settings. Disabling strictly necessary cookies will prevent you from logging in to your mr138 account.
mr138 retains personal data for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal, regulatory, and contractual obligations. Specific retention periods include:
Upon expiry of applicable retention periods, personal data is securely deleted or anonymised.
Subject to applicable law and verification of your identity, mr138 members have the following rights regarding their personal data:
To exercise any of these rights, contact mr138 support via live chat or by email at [email protected]. mr138 will respond to data rights requests within 30 days. Where requests are complex or numerous, this period may be extended by a further 30 days with notification to you.
10.1 mr138 implements technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, disclosure, or destruction. These measures include SSL/TLS encryption for all data in transit, encrypted storage for sensitive data at rest, role-based access controls limiting staff access to personal data on a strict need-to-know basis, regular security assessments and penetration testing, and multi-factor authentication for administrative platform access.
10.2 While mr138 takes reasonable steps to protect your data, no internet transmission or electronic storage system is completely secure. In the event of a data breach affecting your personal data, mr138 will notify you and relevant authorities in accordance with applicable legal obligations.
mr138 does not knowingly collect or process personal data from individuals under the age of 21. The platform is strictly for adults 21 years and above. If mr138 discovers that personal data has been collected from an individual under 21, the account will be closed immediately and the data deleted, except where retention is required for regulatory compliance purposes.
As an international gaming operator, mr138 may transfer personal data to countries outside Malaysia, including to Curaçao where our gaming licence is held, and to the locations of our service providers. Where data is transferred internationally, mr138 ensures appropriate safeguards are in place — including contractual protections — to maintain the security and integrity of your personal data consistent with the standards described in this Policy.
mr138 may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or platform operations. Material changes will be communicated by prominent notice on the platform or by email to your registered address at least 7 days before they take effect. The effective date of the current version is displayed at the top of this Policy.
For any questions, concerns, or requests relating to this Privacy Policy or mr138's handling of your personal data, please contact us via:
This Privacy Policy was last reviewed and updated on 11 June 2026.
Our 24/7 support team can assist with data access requests, marketing opt-outs, or any account query — typically within 3 minutes via live chat.
🔞 21+ only · Your data is protected · Play responsibly