epicwin Casino & Sportsbook Data Care
This page describes what we collect when you use epicwin and how we keep that data protected. We understand that your privacy matters—whether you are logging in on Android, accessing via iOS browser, or managing your account on desktop. We collect only the information needed to operate our service, comply with law, and keep your account secure.
Our data handling is governed by international privacy standards and local regulations where applicable. We do not sell your personal information to third parties. We encrypt your password, store your KYC documents (ID, selfie, address proof) separately from your login credentials, and use third-party payment processors only for transaction processing. When you use epicwin, your data lives on our secure servers; we keep logs of your activity for fraud prevention and dispute resolution.
We outline below what personal data we collect, how we use it, how long we keep it, and what rights you have over your information.
What data we collect when you use epicwin
We collect your email address, password (hashed, never plaintext), full name, date of birth, and phone number during account registration. We collect your government-issued ID number, a copy of your ID document, a selfie, and proof of address during KYC verification. We collect your payment method details (bank account number, wallet identifier, or card suffix) when you deposit. We do not store full credit card numbers—we only record the last four digits and payment provider confirmation.
When you use epicwin on Android or iOS, we collect your device identifier, operating system version, app version, and push notification settings. We collect your IP address and approximate location (city-level, not street address) for fraud detection. We log all your gameplay activity—every bet placed, game round ID, amount wagered, result, and timestamp. We record all login sessions, password changes, and account recovery requests. We do not collect or store video, audio, or any other biometric data beyond your submitted selfie for KYC.
How we use your data on epicwin
We use your email to send account confirmations, password reset links, deposit receipts, and withdrawal confirmations. We use your name, ID number, and KYC documents to verify your age and prevent underage access. We use your phone number for optional two-factor authentication (2FA) during login and withdrawal. We use your payment method details solely to process deposits and withdrawals via our payment partners (DANA, e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, online payment, e-wallet).
We use your gameplay data to calculate winnings, settle bets, generate your bet history, and resolve disputes. We use your device identifier and IP address to prevent duplicate accounts, detect fraud, and enforce our terms (e.g., blocking access from prohibited jurisdictions). We use your account activity logs to investigate complaints, review bonus abuse, and comply with regulatory inquiries. We do not use your data for marketing to other parties, and we do not build profiles about you for sale or sharing.
- KYC document
- Government-issued ID, selfie, and address proof. We encrypt and store these separately from your login credentials. Deleted upon account closure.
- Hashed password
- Your password is never stored in plaintext. We use cryptographic hashing so that even our staff cannot read it.
- Payment partner
- mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, local payment. They process transactions but do not retain your account balance or gameplay data.
- Fraud flag
- Our system logs underage attempts, stolen payment methods, and access from prohibited jurisdictions. Flagged accounts are suspended pending review.
Third-party processors and data transfers
Our payment partners (online payment, e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, online payment, e-wallet) process deposits and withdrawals on our behalf. They receive your name, account number, and transaction amount only—they do not receive your password, KYC documents, or gameplay history. Our email provider sends transactional emails (confirmations, password resets, receipt notices). Our hosting provider stores our servers, which contain encrypted data including your KYC documents. Our fraud-detection vendor analyzes your IP address and device identifier to flag suspicious activity.
All third-party processors sign data-protection agreements requiring them to use your data only for the specified purpose and to delete it when no longer needed. We audit our partners' security practices annually. Our servers may sit outside your jurisdiction (we operate globally); however, data transfers are encrypted in transit. If your jurisdiction has specific data residency laws, we comply where required by law.
How long we keep your data
We keep your account data (email, name, phone, password hash) as long as your account exists. If you close your account, we retain account data for up to five years for dispute resolution and regulatory compliance. We keep your KYC documents (ID copy, selfie, address proof) as long as your account is active and for one year after closure, then delete them permanently. We keep gameplay logs for seven years to resolve disputes and comply with anti-money-laundering (AML) regulations. We keep login and payment transaction logs for five years for fraud investigation.
We delete push notification logs, device identifiers, and IP address records after 90 days unless a fraud flag is active (in which case we retain them until investigation is closed). We delete cookies after your browser session ends unless you select "Remember me" during login. Any data associated with a closed account is securely deleted or anonymized after retention periods end.
Your rights and data access on epicwin
You can view your account data anytime by logging into your epicwin account. You can download your bet history, deposit/withdrawal records, and login activity via the Account Settings section. You can request a copy of all data we hold about you (your "data subject access request") by emailing our support team. We respond within 30 days with an encrypted file containing your personal data.
You can update your email address, phone number, and password anytime in Account Settings. You can disable push notifications in Settings without losing account functionality. You can request deletion of your account by contacting support; we close your account within 7 days and delete your personal data after required retention periods end (typically one year). You cannot withdraw data about other players, bets you wagered on, or regulatory logs—those are not your personal data.
Key takeaways
- We collect email, password, name, date of birth, phone, ID documents, payment method, and gameplay logs
- We encrypt passwords and store KYC documents separately from login credentials
- Payment partners (mobile banking, local payment, online payment, etc.) process transactions only; they do not see your gameplay data
- We keep account data during account life plus up to five years after closure for compliance
- You can access, update, or request deletion of your data via Account Settings or by contacting support
Cookies and tracking on our epicwin platform
Our epicwin website and app use cookies to maintain your login session, remember your preferences (language, notification settings), and detect fraud. Session cookies expire when you close your browser or log out manually. Persistent cookies (if you select "Remember me") last up to 30 days. We do not use cookies for advertising or third-party tracking.
Our Android app and iOS browser do not use traditional cookies; instead, we use app-level tokens stored locally on your device. These tokens expire after inactivity (typically 24 hours) and are deleted when you log out or uninstall the app. We do not allow third-party SDKs (ad networks, analytics services) to run inside our app—we handle analytics in-house using only aggregated, non-identifying data.
Jurisdiction notice and contact
Our services are available only where local law permits. We do not operate in Indonesia or any jurisdiction where online wagering is prohibited. If you access epicwin from a prohibited jurisdiction, we suspend your account and forfeit your balance. We comply with applicable privacy laws in supported jurisdictions. Our data handling is transparent—we do not engage in hidden tracking, secondary sales, or undisclosed third-party sharing.
If you have questions about our privacy practices, want to request your data, or wish to delete your account, contact our support team via the in-app help section. We respond typically within 48 hours. You may also contact us via email for complex requests (data subject access, disputes about data retention, jurisdiction-specific rights). We take your privacy seriously and treat all requests with care.
Summary: Your privacy on epicwin
We collect personal data (email, name, ID documents, payment details, gameplay logs) needed to operate epicwin and comply with law. We encrypt your password and store your KYC documents separately from login credentials. We do not sell your data, and we share it with third-party payment partners only for transaction processing.
You can access all your data, update your account details, and request deletion anytime via Account Settings or by contacting support. We retain account data during active account life and for up to five years after closure for compliance. Cookies and app tokens are used solely for session management and fraud prevention—not for advertising or external tracking.
Our services are available only where local law permits. If you have privacy questions, requests for your data, or concerns about how we handle your information, reach out to our support team via the in-app help section or email. We respond within 48 hours and take your privacy as seriously as we take account security.