Privacy Policy and Personal Data Protection
Last updated: October 26, 2025
Version: 3.2
Introduction
Mostbet (hereinafter โ "We", "Our Company", "Platform") takes the privacy and personal data of its users seriously. This Privacy Policy sets out how we collect, use, store, transmit, and protect your personal data:
- โ GDPR (General Data Protection Regulation, EU 2016/679) โ for European Union users
- โ CCPA (California Consumer Privacy Act) โ for users in California, USA
- โ UK Data Protection Act 2018 โ for UK users
- โ Curaรงao data protection law โ the jurisdiction of our license
- โ Local data protection laws in the countries where we operate
By using our services (website, mobile application, software), you agree to the terms of this Privacy Policy.
Important: If you don't accept the terms of how we process your data, please don't use our platform.
Data Controller
Personal data controller:
Bizbon N.V.
Abraham de Veerstraat 9
Willemstad, Curaรงao
Registration number: 152125
Email: privacy@mostbetapk.asia
Data Protection Officer (DPO):
Email: dpo@mostbetapk.asia
Response time: within 72 hours
What personal data we collect
We gather only the data needed to deliver our services, keep things secure, and meet legal requirements.
1๏ธโฃ Identification data
Data that lets us identify you as a unique user:
- Full name (first name, last name, father's name)
- Date of birth (to confirm you're 18+)
- Citizenship and country of residence
- Identity document number (passport, ID card, driver's license)
- Registration address and actual residential address
- Mobile phone number (with country code)
- Email address
Source: supplied by you at registration and verification (KYC).
2๏ธโฃ Financial data
Details about your transactions and payment methods:
- Deposit history: date, amount, payment method, status
- Withdrawal history: date, amount, withdrawal method, status
- Source of funds (for AML compliance)
- Banking details: account number, IBAN, SWIFT (for transfers only)
- Electronic wallet numbers: Skrill, Neteller, WebMoney, and so on
- Cryptocurrency wallet address: Bitcoin, USDT, Ethereum, and so on
Important: We don't store full bank-card details (CVV, the complete card number). Payment data is handled by PCI DSS Level 1 certified processors. We keep only:
- The first 6 and last 4 digits of the card number (masked)
- The card expiration date
- The card type (Visa, Mastercard, etc.)
Source: supplied by you during deposits/withdrawals; received from payment providers.
3๏ธโฃ Gaming activity
Details about how you use the platform:
- Betting history: date, time, bet type, amount, odds, result
- Casino games history: games played, bets, winnings
- Bonus: activated bonus, wagering conditions, status
- Responsible-gaming limits: the restrictions you've set
- Gaming session time: duration, frequency
Source: generated automatically by our platform.
4๏ธโฃ Technical data
Details about your device and connection:
- IP address (for geolocation and security)
- Device type: smartphone, tablet, computer
- Operating system: Android, iOS, Windows, macOS (version)
- Browser: Chrome, Safari, Firefox (version)
- Screen resolution and language settings
- Unique device identifier (Device ID)
- Connection details: provider, speed, stability
Source: collected automatically as you use the platform.
5๏ธโฃ Communications
Records of your interactions with us:
- Live chat messages (conversation history)
- Emails (incoming and outgoing)
- Phone calls (recorded for quality control, with your consent)
- Telegram, WhatsApp, Viber messages (when you reach support)
- Reviews and complaints
Source: supplied by you during conversations with support.
6๏ธโฃ Marketing preferences
Details about your interests and consents:
- Consent to receive promotional material (email, SMS, push)
- Product types that interest you: sports, casino, live games
- Click history on email newsletters and push notifications
- Preferred communication language
Source: supplied by you at registration; updated through profile settings.
7๏ธโฃ Cookies and analytics data
Data collected by web technologies (see the "Cookies" section below):
- Pages you visited on our website
- Time spent on each page
- Traffic source: direct access, search engines, ad campaigns
- Clicks on interface elements and buttons
- Behavior patterns: scrolling, hovering, clicking
Source: collected automatically via cookies, Google Analytics, pixels.
Why we use your data
We process your personal data strictly for legitimate purposes, which include:
1๏ธโฃ Service provision (Contract fulfillment)
- Registering and managing your account
- Processing deposits and withdrawals
- Placing bets and taking part in games
- Calculating bonuses and wagering
- Providing technical support
Legal basis: fulfillment of the contract (User Agreement).
2๏ธโฃ Legal compliance (Legal obligation)
- Identity verification (KYC) โ confirming age 18+, preventing multi-accounting
- Anti-money laundering (AML) โ checking the source of funds, monitoring suspicious transactions
- Sanctions-list checks โ OFAC, UN, EU, Interpol
- Regulatory reporting โ passing data to the Curaรงao Gaming Control Board
- Cooperation with law enforcement โ during official inquiries
Legal basis: meeting our legal obligations.
3๏ธโฃ Security and fraud prevention (Legitimate interest)
- Spotting and stopping fraudulent transactions
- Detecting bonus-hunting and abuse
- Guarding against account compromise (bruteforce, phishing)
- Monitoring DDoS attacks
- Detecting bots and automated betting systems
Legal basis: our legitimate interest in protecting the platform and its users.
4๏ธโฃ Marketing and personalization (Consent)
- Sending promotional email newsletters about bonuses, promotions, and new games
- Sending SMS and push notifications about special offers
- Targeted advertising through partners (Google Ads, Facebook Ads)
- Personalized game and betting offers
Legal basis: your explicit consent (which you can withdraw at any time).
5๏ธโฃ Analytics and service improvement (Legitimate interest)
- Analyzing user behavior to refine the interface
- A/B testing new features
- Studying which games and sports are most popular
- Optimizing load speed and performance
Legal basis: our legitimate interest in raising the quality of our service.
Who we share your data with
We don't sell your personal data to third parties. We may, however, pass data to these categories of recipients:
1๏ธโฃ Payment processors
For handling deposits and withdrawals:
- Venson Ltd (Cyprus) โ our main payment operator
- Skrill, Neteller, ecoPayz โ electronic wallets
- Visa, Mastercard processors โ bank cards
- Coinbase, Binance Pay โ cryptocurrency transactions
Data shared: name, email, transaction amount, payment method.
Protection: every processor holds PCI DSS Level 1 certification.
2๏ธโฃ Game and sports data providers
For delivering content:
- Evolution Gaming, Pragmatic Play, NetEnt โ live casino and slots
- Sportradar, Betradar โ sports data and odds
- Spribe โ the Aviator game
Data shared: user ID (pseudonymized), game history.
Protection: data-protection agreements (DPA โ Data Processing Agreements).
3๏ธโฃ Verification and control services (KYC/AML)
For regulatory compliance:
- Sumsub, Onfido โ biometric document verification
- ComplyAdvantage, Dow Jones โ sanctions-list and PEP checks
- SEON, Sift โ fraud monitoring
Data shared: name, date of birth, document number, document photo.
Protection: GDPR compliant, ISO 27001 certified.
4๏ธโฃ Analytics and marketing platforms
For analysis and advertising:
- Google Analytics โ web-traffic analysis
- Facebook Pixel, TikTok Pixel โ retargeting
- AppsFlyer, Adjust โ mobile-traffic attribution
- Mailchimp, SendGrid โ email newsletters
Data shared: IP address, cookies, web behavior, email (hashed for targeting).
Protection: data-protection agreements, with an opt-out option.
5๏ธโฃ Cloud hosting providers
For data storage:
- Amazon Web Services (AWS) โ servers in Ireland (EU), Singapore, Virginia (USA)
- Cloudflare โ CDN and DDoS protection
Data shared: all platform data.
Protection: encryption at rest (AES-256) and in transit (TLS 1.3).
6๏ธโฃ Regulators and law enforcement
During lawful requests:
- Curaรงao Gaming Control Board โ the regulator of our license
- Financial Intelligence Units (FIU) โ where money laundering is suspected
- Interpol, national police โ during official investigation requests
- Tax authorities โ under local law upon request
Data shared: any data requested within the scope of the lawful request.
Protection: we check that each request is lawful.
7๏ธโฃ Responsible gaming partners
For providing support (only with your consent):
- GamCare, BeGambleAware, Gamblers Anonymous
Data shared: only at your request, anonymously or with your consent.
International data transfers
Mostbet serves users across 93 countries. Your data may be sent and processed outside your jurisdiction in other countries, including:
- ๐ European Economic Area (EEA): Ireland (AWS servers)
- ๐ USA: Virginia (AWS servers)
- ๐ Singapore: AWS servers for Asian users
- ๐ Curaรงao: our main headquarters
Safeguards for international transfers:
- โ Standard Contractual Clauses (SCC) โ approved by the European Commission
- โ Binding Corporate Rules (BCR) โ the corporate group's internal rules
- โ Adequacy decisions โ countries the EU recognizes as safe (e.g., Switzerland)
- โ Encryption in transit โ all data encrypted during transfer (TLS 1.3)
How we protect your data
We put comprehensive technical and organizational measures in place to safeguard your personal data:
๐ Technical measures:
- โ SSL/TLS 256-bit encryption โ all data between your device and our servers is encrypted
- โ Encryption at rest โ the database is encrypted with AES-256
- โ Two-factor authentication (2FA) โ available to every user
- โ Payment-data tokenization โ bank cards are swapped for tokens
- โ Firewalls โ multi-layer server protection
- โ Intrusion detection systems (IDS/IPS) โ 24/7 anomaly monitoring
- โ DDoS protection โ Cloudflare Enterprise
- โ Penetration testing โ every 6 months
๐ Organizational measures:
- โ Restricted access โ only authorized staff can reach data (the principle of least privilege)
- โ Non-disclosure agreements (NDA) โ every employee signs one
- โ Staff training โ ongoing data-protection education
- โ Access logging โ every action on data is recorded in audit logs
- โ Incident-response procedures โ an action plan for data breaches
- โ Regular audits โ external ISO 27001 reviews
Security statistics:
- ๐ Zero data-breach incidents across 15 years of operation
- ๐ 99.98% uptime โ server stability
- ๐ PCI DSS Level 1 certification โ the highest payment-security standard
How long we keep your data
We hold your personal data only as long as the processing purposes require:
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Identification data | 5 years after account closure | AML/KYC legislation |
| Financial data | 7 years after the last transaction | Tax legislation, AML |
| Gaming and betting history | 5 years after account closure | Regulatory requirements, disputes |
| Support communications | 3 years after the last contact | Service quality, disputes |
| Technical logs (IP, Device ID) | 1 year | Security, fraud |
| Cookies | Up to 2 years (by type) | Marketing, analytics |
| Marketing data | Until consent is withdrawn or 2 years of inactivity | User consent |
Once the retention period ends:
- The data is permanently deleted (secure deletion)
- Or anonymized for statistical use (so you can no longer be identified)
Your rights regarding personal data
Under GDPR and other data-protection laws, you hold the following rights:
1๏ธโฃ Right to access
You can request a copy of all the data we hold about you.
How to exercise it:
- Personal panel โ Settings โ Privacy โ "Download my data"
- Or send a request to privacy@mostbetapk.asia with the subject "Data Access Request"
Provision deadline: within 30 days (usually 3-5 days).
Format: CSV/JSON files in a ZIP archive.
2๏ธโฃ Right to rectification
You can update or correct any inaccurate data.
How to exercise it:
- Personal panel โ Settings โ Profile โ Edit
- Or write to support@mostbetapk.asia
Important: Changing your name or date of birth calls for fresh verification (KYC).
3๏ธโฃ Right to erasure ("Right to be forgotten")
You can request that your data be deleted.
Conditions:
- โ The account is closed and there are no active obligations (debts, disputed transactions)
- โ The retention period for regulatory purposes has expired
- โ Data can't be deleted if it's still needed to fulfill the contract or meet legal obligations (AML, taxes)
How to exercise it:
- Write to privacy@mostbetapk.asia with the subject "Data Deletion Request"
Processing deadline: within 30 days.
4๏ธโฃ Right to restriction of processing
You can pause the processing of your data in certain situations (for example, while a dispute over the data's accuracy is ongoing).
How to exercise it:
- Write to privacy@mostbetapk.asia with your reasoning
5๏ธโฃ Right to data portability
You can obtain your data in a structured, machine-readable format (CSV, JSON) to move it to another provider.
How to exercise it:
- Personal panel โ Download my data
- Or send a request to privacy@mostbetapk.asia
6๏ธโฃ Right to object
You can object to your data being processed for marketing purposes or under legitimate interest.
How to exercise it:
- For marketing: the "Unsubscribe" button in every email or your profile settings
- For other purposes: write to privacy@mostbetapk.asia
7๏ธโฃ Right to withdraw consent
Where processing rests on your consent, you can take it back at any time.
How to exercise it:
- Personal panel โ Settings โ Privacy โ Consent management
Important: Withdrawing consent doesn't affect the lawfulness of processing carried out before the withdrawal.
8๏ธโฃ Right to lodge a complaint
You can file a complaint with a data-protection supervisory authority.
Contacts:
- EU: your national data-protection authority (list)
- UK: Information Commissioner's Office (ICO) โ ico.org.uk
- USA (California): California Privacy Protection Agency โ cppa.ca.gov
Cookies and web technologies
What are cookies?
Cookies are small text files saved on your device when you visit our website. They help to:
- Remember your settings (language, currency)
- Keep you signed in (no need to enter your password on every visit)
- Analyze how the website is used
- Show you relevant advertisements
Types of cookies we use:
1๏ธโฃ Strictly necessary cookies
Purpose: keeping core website functions running (login, security, cart).
- session_id โ session identifier
- csrf_token โ protection against CSRF attacks
- auth_token โ authentication token
Duration: until the browser closes (session) or 30 days.
Can they be disabled? โ No โ the website wouldn't work.
2๏ธโฃ Performance cookies
Purpose: gathering anonymous information about website use (which pages are popular, where users run into trouble).
- _ga, _gid โ Google Analytics
- _hjid โ Hotjar (session recordings, heatmaps)
Duration: 1-2 years.
Can they be disabled? โ Yes โ through cookie settings.
3๏ธโฃ Functionality cookies
Purpose: remembering your settings to personalize your experience.
- language โ the language you selected
- currency โ the currency you selected
- theme โ light/dark theme
Duration: 1 year.
Can they be disabled? โ Yes โ but the website won't remember your settings.
4๏ธโฃ Targeting/advertising cookies
Purpose: tracking your behavior to show you relevant advertisements.
- _fbp โ Facebook Pixel
- _gcl_au โ Google Ads
- _ttp โ TikTok Pixel
- IDE โ DoubleClick (Google Display Network)
Duration: up to 2 years.
Can they be disabled? โ Yes โ through cookie settings or NAI opt-out (optout.networkadvertising.org).
Cookie management
In website settings:
- Click the "Cookie settings" banner (on your first visit)
- Or: website footer โ "Cookie preferences"
- Turn cookie categories on or off
In browser settings:
- Chrome: Settings โ Privacy โ Cookies
- Firefox: Settings โ Privacy โ Cookies
- Safari: Settings โ Privacy โ Cookies
- Edge: Settings โ Cookies and permissions
Important: Turning off all cookies may stop the website from working (you might lose access).
Other web technologies
Alongside cookies, we use:
- Tracking Pixels: invisible 1x1 images that track when email newsletters are opened and clicked.
- Local Storage: storing settings locally on HTML5 devices.
- Device Fingerprinting: collecting device configuration details for identification without cookies (resolution, fonts, plugins) (used to prevent fraud).
Marketing and newsletter unsubscribe
Types of marketing messages:
We may send you:
- ๐ง Email newsletters: bonuses, promotions, new games, tournaments
- ๐ฑ SMS: urgent offers, verification codes
- ๐ Push notifications: (in the app) live events, bonus alerts
How to unsubscribe:
Email:
- The "Unsubscribe" button in the footer of every email
- Or: Personal panel โ Settings โ Communication โ turn off "Promotional emails"
SMS:
- Reply "STOP" to any SMS
- Or: profile settings
Push notifications:
- App settings โ Notifications โ turn off "Promo"
- Or: OS settings (Android/iOS)
Important: You'll still receive transactional messages (deposit confirmations, withdrawals, password changes) โ they're essential for the service to function.
Children protection
Mostbet strictly forbids registration and use of the service by anyone under 18 (and under 21 in some jurisdictions).
Protection Measures:
- Compulsory age verification (KYC)
- Blocking the account where minors are suspected
- We don't knowingly collect children's data
If you discover a registered child:
- Write to compliance@mostbetapk.asia right away
- We'll delete the account and all data within 24 hours
Privacy Policy changes
We may update this Policy from time to time to reflect changes in the law or our own experience.
For significant changes:
- โ We'll notify you by email 30 days before the effective date
- โ We'll post a notice on the website and in the app
- โ We'll ask for fresh consent (where GDPR requires it)
How to track changes:
- The last-updated date appears at the start of the document
- The policy version appears at the start of the document
- Change history is available on request at privacy@mostbetapk.asia
Contacts for privacy questions
If you have questions, requests, or complaints about how your data is processed:
Email Contacts:
- ๐ง General questions: privacy@mostbetapk.asia
- ๐ง Data Protection Officer (DPO): dpo@mostbetapk.asia
- ๐ง Data deletion requests: privacy@mostbetapk.asia (subject "Data Deletion Request")
- ๐ง Data access requests: privacy@mostbetapk.asia (subject "Data Access Request")
Other Contact Methods:
- ๐ฌ Live chat: open 24/7 in the personal panel ("Privacy" section)
- ๐ Phone: support line (numbers by country)
Response times:
- Email: within 72 hours
- Access/deletion requests: within 30 days
- Live chat: 1-5 minutes
Mailing address:
Bizbon N.V.
Abraham de Veerstraat 9
Willemstad, Curaรงao
Attn: Data Protection Officer
Conclusion
Mostbet is dedicated to protecting your privacy and handling your data in a transparent, lawful, and fair way. We rely on advanced technology and hold firmly to international data-protection standards.
Your trust is our foundation.
By using our platform, you confirm that you've read this Privacy Policy and accept its terms.
Mostbet โ your data has been kept securely since 2009.