Privacy Policy – How mari44 Collects, Uses & Protects Your Data
This Privacy Policy explains how the mari44 Platform collects, processes, stores, and protects personal data belonging to registered Users and visitors. mari44 is committed to handling your personal information responsibly, in accordance with applicable data protection principles.
Your Data, Your Rights
Key privacy commitments mari44 makes to every registered player
Data Security First
All data transmitted between your device and the mari44 Platform is protected by 256-bit SSL encryption — the same standard applied by major Malaysian banks. Data at rest is stored in encrypted form on access-controlled infrastructure. Security is not an afterthought at mari44; it is a design requirement.
No Third-Party Data Sales
mari44 does not sell, rent, or trade your personal data to third-party advertisers or data brokers. Personal information shared with you during registration and gameplay is used exclusively for the purposes described in this Policy — account management, KYC, payments, and service improvement.
KYC Data Handled Carefully
Identity documents submitted for KYC verification — including MyKad copies, passport scans, and bank statements — are processed solely for identity verification and anti-money laundering compliance. These documents are stored securely and are accessible only to authorised compliance personnel.
Right to Access & Correction
You have the right to request a copy of the personal data mari44 holds about you and to request correction of inaccurate information. Submit a data access or correction request to the support team at any time. mari44 will respond within a reasonable timeframe consistent with applicable data protection obligations.
Cookies & Analytics
The mari44 Platform uses session cookies necessary for login functionality and performance cookies to analyse Platform usage patterns. No third-party advertising cookies are deployed. You may disable non-essential cookies in your browser settings; doing so will not impair core Platform functionality.
Marketing Opt-Out
Promotional communications from mari44 are sent only to Users who have opted in during registration or subsequently through account settings. You may unsubscribe from marketing communications at any time via the unsubscribe mechanism in any communication or by updating your account preferences.
1. Introduction
1.1 This Privacy Policy ("Policy") is issued by the operator of the mari44 Platform ("the Operator", "we", "us", "our") and applies to all personal data collected from individuals ("Users", "you") who visit, register on, or interact with the Platform accessible at mari44.net and associated sub-domains.
1.2 The Operator processes personal data in accordance with applicable international data protection principles, including principles equivalent to those enshrined in Malaysia's Personal Data Protection Act 2010 ("PDPA") where relevant, as well as the data protection requirements imposed under the Operator's international online gaming licensing obligations.
1.3 By registering an Account on the mari44 Platform, you acknowledge that you have read and understood this Policy and consent to the processing of your personal data as described herein. If you do not agree with any part of this Policy, you should not register an Account or use the Platform.
1.4 This Policy should be read alongside the mari44 Terms & Conditions, which govern the overall relationship between you and the Operator.
2. Data Controller
2.1 The data controller responsible for personal data collected through the mari44 Platform is the Operator entity incorporated and licensed under international online gaming regulations to operate the Platform. For all data protection enquiries, contact details are provided in Section 15 of this Policy.
2.2 Where third-party service providers (including payment processors, KYC verification partners, and game studios) process personal data on behalf of the Operator, they do so as data processors acting under contractual instructions from the Operator and subject to appropriate data protection safeguards.
3. Personal Data We Collect
The Operator collects personal data in the following categories:
- Identity Data: Full legal name, date of birth, nationality, government-issued identification number (MyKad number or passport number), and copies of identity documents submitted for KYC purposes.
- Contact Data: Registered email address, mobile telephone number, and residential address (including city, state, postcode, and country).
- Financial Data: Payment method details (e-wallet identifiers, bank account references, USDT wallet addresses), transaction amounts, deposit and withdrawal history, and source of funds information provided during enhanced due diligence.
- Account Data: Username, encrypted password hash, account settings and preferences, responsible gaming tool settings (deposit limits, session time settings, self-exclusion status), and account correspondence history.
- Gaming Data: Bet history, game session records, wagering activity, bonus participation records, and win/loss records.
- Technical Data: IP address, device identifier, browser type and version, operating system, time zone, referring URL, pages visited, session duration, and connection speed.
- Communications Data: Records of customer support interactions, including live chat transcripts, email correspondence, and support ticket history.
4. How We Collect Personal Data
The Operator collects personal data through the following means:
- Direct collection: Information you provide during Account registration, KYC submission, deposit/withdrawal requests, customer support interactions, and promotional opt-ins.
- Automated technical collection: Server logs, session cookies, and Platform analytics tools record Technical Data automatically when you access the Platform.
- Third-party sources: Identity verification partners may provide the results of document and biometric verification checks. Payment processors confirm transaction statuses. Fraud prevention services may provide risk scoring data associated with your IP address or device identifier.
5. Purposes of Processing
The Operator processes personal data for the following purposes:
- Account registration, maintenance, and authentication;
- KYC identity verification and ongoing anti-money laundering monitoring;
- Processing deposits, withdrawals, and internal account transactions in MYR;
- Providing and improving Platform services, including game delivery and sportsbook functionality;
- Customer support, dispute resolution, and account query management;
- Fraud detection, security monitoring, and prevention of prohibited conduct as defined in the Terms & Conditions;
- Responsible gaming monitoring — including detection of potentially problematic gambling patterns and enforcement of self-exclusion and deposit limit settings;
- Regulatory compliance, audit obligations, and responses to lawful requests from licensing or law enforcement authorities;
- Sending transactional communications (bet confirmations, deposit receipts, withdrawal notifications, security alerts);
- Sending promotional communications to Users who have opted in to receive them.
6. Legal Basis for Processing
6.1 Contract performance: Processing necessary to fulfil the Terms & Conditions agreement between you and the Operator — including account management, game provision, and payment processing.
6.2 Legal obligation: Processing required to comply with KYC, AML, and regulatory reporting obligations imposed under the Operator's international gaming licence.
6.3 Legitimate interests: Processing for fraud prevention, security monitoring, Platform analytics, and responsible gaming oversight, where such processing is proportionate and does not override your fundamental data rights.
6.4 Consent: Marketing communications are sent on the basis of your affirmative opt-in consent. You may withdraw this consent at any time.
7. Data Sharing
7.1 The Operator does not sell, rent, or otherwise commercially transfer your personal data to third parties for their own marketing purposes.
7.2 Personal data may be shared with the following categories of third parties, strictly for the purposes described in Section 5:
- KYC and identity verification providers — to verify identity documents and conduct liveness checks;
- Payment processors and e-wallet operators — including but not limited to Touch 'n Go eWallet, Boost, GrabPay, DuitNow, FPX partner banks, and USDT processing infrastructure — to process deposits and withdrawals;
- Game studio providers — who may receive pseudonymised session data necessary to deliver live dealer and RNG game services;
- Fraud prevention and security services — to detect and prevent prohibited conduct and financial crime;
- Regulatory and licensing authorities — where disclosure is required under licensing conditions or law enforcement requests backed by appropriate legal authority;
- Customer support platform providers — who process support ticket and live chat data on behalf of the Operator under contractual data processing terms.
7.3 All third-party data processors engaged by the Operator are bound by contractual data processing agreements that restrict their use of personal data to the specific purpose for which it was shared.
8. International Data Transfers
8.1 The Operator operates internationally and some of the third-party service providers described in Section 7 may be located in jurisdictions outside Malaysia. Where personal data is transferred to such jurisdictions, the Operator will ensure that appropriate safeguards are in place, such as contractual data processing clauses or the equivalent of standard contractual clauses.
8.2 By using the mari44 Platform, you acknowledge and consent to the transfer of your personal data to the jurisdictions in which the Operator and its service providers operate, subject to the safeguards described in this Section.
9. Data Retention
9.1 The Operator retains personal data for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal, regulatory, tax, and accounting obligations.
9.2 Account data and gaming history are retained for a minimum of five (5) years following account closure or last activity, in compliance with anti-money laundering record-keeping requirements typically applicable under international gaming licensing frameworks.
9.3 KYC documentation is retained for the period mandated by the Operator's licensing obligations, which is typically a minimum of five (5) years from the date of the last transaction or account closure, whichever is later.
9.4 Following expiry of the applicable retention period, personal data is securely deleted or anonymised such that it can no longer be linked to an identifiable individual.
10. Security Measures
10.1 The Operator implements appropriate technical and organisational security measures to protect personal data against unauthorised access, loss, destruction, or alteration. These measures include:
- 256-bit SSL/TLS encryption on all data in transit between users' devices and Platform servers;
- Encryption of sensitive personal data stored at rest, including KYC documents and payment method details;
- Role-based access controls limiting staff access to personal data on a need-to-know basis;
- Two-factor authentication options for User accounts;
- Regular security assessments and penetration testing of Platform infrastructure;
- Monitoring and alerting systems for anomalous access patterns and potential data breaches.
10.2 In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, the Operator will notify you without undue delay after becoming aware of the breach, to the extent required by applicable data protection obligations.
11. Cookies & Tracking Technologies
11.1 The mari44 Platform uses the following categories of cookies:
- Strictly necessary cookies: Required for session management, authentication, and security. These cannot be disabled without impairing core Platform functionality.
- Performance/analytics cookies: Used to collect anonymised data on how Users navigate the Platform, which pages are visited, and where errors occur. This data is used to improve Platform performance and user experience.
- Functional cookies: Store User preferences such as language settings, display preferences, and responsible gaming tool configurations.
11.2 The Platform does not deploy third-party advertising cookies or tracking pixels for the benefit of external advertisers.
11.3 You may control cookie settings through your browser preferences. Disabling analytics or functional cookies will not prevent you from accessing the Platform but may affect some personalisation features.
12. Your Data Rights
Subject to applicable data protection law and the Operator's legal obligations (including AML and KYC record-keeping requirements), you have the following rights in respect of your personal data:
12.1 Right of Access: You may request a copy of the personal data the Operator holds about you. Such requests will be fulfilled within a reasonable period, typically within 30 days.
12.2 Right to Rectification: If the personal data we hold about you is inaccurate or incomplete, you may request that it be corrected. Updates to account details such as contact email address and postal address can be made directly in your account settings.
12.3 Right to Erasure: You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, and where no overriding legal obligation requires its retention. Note that KYC and transaction records are subject to mandatory retention periods under AML obligations and cannot be deleted during those periods.
12.4 Right to Withdraw Consent: Where processing is based on your consent (specifically, marketing communications), you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
12.5 To exercise any of the above rights, contact the mari44 data protection contact as described in Section 15.
13. Children & Minors
13.1 The mari44 Platform is strictly for adults aged 21 years and above. The Operator does not knowingly collect personal data from persons under the age of 21. Age verification is a mandatory component of the KYC process.
13.2 If the Operator becomes aware that personal data has been collected from a person under the age of 21 without parental consent, such data will be deleted promptly and the associated Account suspended. If you believe a minor has registered an Account on the mari44 Platform, please contact the support team immediately.
14. Amendments to this Policy
14.1 The Operator reserves the right to update this Privacy Policy at any time. Material changes will be communicated to registered Users via the email address associated with their Account and/or via an on-Platform notification prior to the amended Policy taking effect.
14.2 The date of the most recent revision is displayed at the top of this Policy. Continued use of the Platform following the effective date of any amendment constitutes your acknowledgement of the updated Policy.
15. Contact & Data Requests
For all data access requests, correction requests, erasure requests, consent withdrawal, or other privacy-related enquiries, please contact the mari44 support team. For formal data protection requests, please include "Data Protection Request" in the subject line of your communication and provide your registered Account email and the nature of your request.
Contact: [email protected]
Support available 24/7. Data requests will be acknowledged within 3 business days and fulfilled within 30 days where technically and legally feasible.
The contact address above is displayed as plain text only and is not a clickable link. Please copy and paste it to your email client.
Play at mari44 With Confidence
Your data is protected, your account is encrypted, and your privacy rights are respected. 500+ games, live casino, sportsbook — all in MYR. 21+ only.
By using the Platform you confirm you have read and accepted this Privacy Policy. Responsible Gaming tools available in your account. 21+ only.