What We Collect
- Account data — mobile number, password (hashed), date of birth, full name (KYC).
- Identity data — Aadhaar & PAN images and selfie, retained for regulatory KYC.
- Payment data — UPI/Paytm/PhonePe/wallet identifiers, last 4 digits of cards. We never store full card numbers.
- Activity data — bets placed, deposits, withdrawals, login timestamps, device/IP.
- Communications — Telegram chat history, support tickets, live chat transcripts.
Why We Collect It
- To operate your account — process bets, deposits, withdrawals.
- To verify identity — comply with KYC and anti-money-laundering regulations.
- To prevent fraud — detect multi-accounting, bonus abuse, payment fraud.
- To improve the platform — analyze aggregate usage to improve UX and game selection.
- To meet legal obligations — respond to lawful requests from authorities.
Who We Share With
We share data only when necessary, only with:
- Payment providers (UPI, Paytm, PhonePe, Google Pay, card processors) — to settle transactions.
- KYC partners — to verify Aadhaar & PAN authenticity.
- Game providers (Evolution, Pragmatic, JILI, etc.) — minimum data to launch and settle games.
- Regulators — under legal compulsion only.
We never sell, rent, or trade your data to advertisers or data brokers.
How We Secure It
- Bank-grade 256-bit SSL/TLS across the entire platform.
- Passwords stored as bcrypt hashes — we cannot see your password.
- KYC documents stored encrypted at rest with restricted internal access.
- Payment data tokenized; no full card numbers on our servers.
- Annual third-party penetration testing.
Cookies
We use cookies for:
- Essential — keeping you logged in, remembering your wallet currency.
- Analytics — anonymized traffic analysis (no personal identifiers).
- Marketing — only with explicit consent (you can decline).
Your Rights
You can at any time:
- Access — request a copy of all data we hold on you.
- Correct — fix anything we have wrong.
- Delete — close your account and have data erased (subject to KYC retention law: 5 years after last activity).
- Object — opt out of marketing communications anytime.
To exercise any right, message us on Telegram or via the contact page.
Data Retention
- Active accounts — for the lifetime of the account.
- Closed accounts — 5 years (regulatory minimum), then permanent deletion.
- KYC documents — 5 years post-closure, then deleted.
- Marketing data — until you withdraw consent.
Changes to This Policy
We may update this policy. Material changes are notified via in-app banner. Continued use of DMWIN after a change constitutes acceptance.
Contact
For any privacy question, message us on Telegram or visit the Contact page.