WinWin Privacy Policy
This Privacy Policy explains the collection, processing, protection, disclosure, and secure destruction of personal data on this online service. It sets out how information is handled for account management, payments, security, and compliance. Use of personal information is based on user consent, along with other lawful grounds. By using this website, users acknowledge this document and agree to the practices described here.
Privacy and Data Protection
Personal data we collect
- Identity and contact details: name, date of birth, address, email, mobile number.
- Account and usage data: username, preferences, login timestamps, activity on services, support history.
- Device and technical data: IP address, browser type, operating system, language, approximate location.
- Verification data: KYC documents and information needed for age, identity, and address checks.
- Payment and transaction records: limited card or account details processed by payment providers, deposits, withdrawals.
Why we collect this information
- To provide online services, manage accounts, and process transactions.
- To verify identity, prevent fraud, and meet anti-money laundering obligations.
- To improve websites and apps through analytics and service feedback.
- To communicate service updates, security notices, and policy changes.
Protection measures
- Encryption in transit and at rest, role-based access controls, and staff authentication.
- Network and application monitoring, secure development practices, and periodic security testing.
- Vendor risk assessment and contractual confidentiality obligations for all processors.
User rights
- Access: request a copy of personal information.
- Correction: fix inaccurate or incomplete data.
- Deletion: request removal where allowed by law.
- Restriction and objection: limit or object to certain processing.
- Portability: receive data in a structured, machine-readable format where applicable.
Compliance
- Operations follow Bangladesh laws relevant to privacy and security, including the Cyber Security Act 2023, the Money Laundering Prevention Act 2012, Bangladesh Bank and BTRC directives, and internationally recognised standards such as GDPR principles where applicable.
Use of Collected Information
Purposes of processing
- Account servicing: registration, login, profile management, customer support.
- Transactions: deposits, withdrawals, and payment reconciliation through authorised providers.
- Service improvement: performance monitoring, troubleshooting, and feature development.
- Personalisation: language, content settings, and user preferences.
- Marketing: emails or notifications based on consent, with opt-out controls at any time.
- Analytics: aggregated statistics to improve online performance and reliability.
- Compliance: KYC, AML, sanctions screening, reporting to competent authorities.
Lawful bases
- Consent: for marketing and certain optional features.
- Contract: to deliver requested services and process transactions.
- Legal obligation: to meet financial crime and regulatory duties.
- Legitimate interests: to secure systems, prevent abuse, and improve user experience, balanced against user rights.
Processing is conducted lawfully, fairly, and transparently, and limited to the purposes described in this policy.
Access to Information
How to access and update
- Users can review and edit profile details in account settings when available.
- Additional requests can be made by contacting [email protected].
Deletion and correction procedures
- Submit a request describing the information to be corrected or deleted.
- A response is provided within 30 days, subject to identity verification.
- Some records must be kept for statutory periods to comply with AML and financial reporting rules.
Security checks and payments
- By using this service, the user consents to necessary security checks, identity verification, sanctions screening, and processing of payment data by authorised providers for fraud prevention and regulatory compliance.
Protection of Children’s Privacy
- This service is intended for adults aged 18 or older.
- The operator cannot confirm age without identity documents during verification.
- If a parent or legal guardian believes a minor has provided personal information, they may request deletion. Once appropriate documentation is received and verified, associated data will be removed, subject to any legal retention duties.
International Data Transfers
- Personal information may be processed in other countries where technology, payments, analytics, verification, and support partners operate.
- Use of the website constitutes consent to such transfers, subject to contractual safeguards and security controls.
- Confidentiality and integrity are protected by encryption, access controls, and data processing agreements that require partners to protect personal data to internationally accepted standards.
Legal Disclaimer
- This policy explains how personal information is collected, used, stored, and shared. It is not legal advice and does not override mandatory law.
- Where a disclaimer is needed to clarify the scope or effect of a rule, that clarification applies once the user accepts this policy by registering, ticking an acceptance box, or continuing to use the service.
- If any part of this document conflicts with applicable law, the law prevails to the extent of the conflict.
Use of Cookies
- Cookies are small text files stored on a device to remember settings and improve online services.
- We use cookies for statistics, behaviour analysis, personalisation, and site improvement.
- Types include essential, performance, functional, and advertising cookies.
- Retention: up to 1 year, unless a shorter period is needed for the stated purpose.
- Users can manage preferences in the browser or available on-site tools and may withdraw consent for non-essential cookies at any time.
Acceptance of Privacy Policy
- Using this website means full acceptance of this Privacy Policy and any future updates published here.
- The current version of the policy prevails over any previous version from the time it is posted.
- Last updated: 11 December 2025.
Third-Party Privacy Practices
- Personal data may be shared with third parties when required by law, for dispute resolution, to enforce agreements, or to provide services such as payments, identity verification, fraud prevention, hosting, analytics, and customer support.
- The website may list core service providers. If not listed, users are informed of the purpose and scope before or at the point of collection where feasible.
- Providing information for these purposes constitutes consent to processing by the relevant third party under its own privacy notice.
Links to Other Websites
- The site may contain links to external websites that have their own privacy policies and security practices.
- Responsibility for personal information handled by external websites lies with those parties.
- Users should review the privacy policies of any linked sites before providing personal data.
Updated: