Privacy Data Policy

Cbet Privacy Policy

This notice sets out which categories of personal information Cbet handled, the purposes served by that handling, and the choices available to registered u

This notice sets out which categories of personal information Cbet handled, the purposes served by that handling, and the choices available to registered users. It is written to be read by players rather than by lawyers.

Last updated:

Categories of information handled

Registration produces identity details: full name, date of birth, residential address, email address, telephone number, and preferred currency. Verification adds copies of government-issued identification and, in some cases, a recent utility bill or bank statement confirming residence.

Financial records cover deposits, withdrawals, payment method identifiers in truncated form, and the transaction reference numbers supplied by processors. Full card numbers are never stored on Cbet infrastructure; they remain with the certified payment providers handling the transaction.

Technical information is captured automatically and includes IP address, browser type and version, device model, operating system, screen dimensions, session duration, and pages visited. Support tickets, live chat transcripts, and email correspondence are also retained as part of the account record.

Grounds and purposes for use

The primary purpose is contractual: operating the account, crediting balances, settling game outcomes, and executing payouts cannot happen without the data above. Refusing to supply mandatory fields makes account operation impossible.

A second purpose is regulatory. Anti-money-laundering rules and the conditions of Curacao licence 365/JAZ require source-of-funds checks, sanctions screening, and retention of transaction histories that can be produced to a supervisory body on request.

A third purpose is legitimate operational interest: detecting duplicate registrations, identifying bonus abuse, blocking automated agents, investigating suspected collusion, and maintaining service stability. Marketing communications rest on consent alone and can be withdrawn at any point without affecting account access.

Disclosure to third parties

Information is shared with payment processors, identity-verification vendors, game content suppliers, cloud hosting providers, and customer-communication platforms strictly to the extent each requires in order to perform its function under a written processing agreement.

Disclosure to regulators, law enforcement, tax authorities, or courts occurs where a valid legal instrument compels it. In insolvency, a court-appointed administrator may lawfully take custody of records as part of the estate.

Personal information is not sold to advertisers or data brokers. Where analytics providers receive event data, identifiers are truncated or hashed before transmission wherever the analytics function permits it.

Storage location, security, and retention

Servers are located within the European Economic Area and in Curacao. Transfers outside those territories rely on standard contractual clauses or an equivalent recognised safeguard, which Canadian users may request a summary of.

Protective measures include TLS encryption in transit, encryption at rest for verification documents, role-based access limited to personnel with an operational need, mandatory two-factor authentication for administrative consoles, and logged access to identity files.

Records tied to financial transactions and verification are kept for the period demanded by licensing conditions, generally not shorter than five years after the account closes. Marketing preferences and non-essential analytics are erased far sooner, typically within twelve months of the last recorded activity.

Your entitlements and cookies

Account holders may request a copy of the personal information held about them, ask for factual corrections, object to profiling used for marketing, request erasure where no retention duty overrides the request, and receive a portable export of their data. Identity confirmation precedes any such request being actioned.

Canadian users retain rights under PIPEDA and, in Quebec, under Law 25, including recourse to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information where a response is unsatisfactory.

Cookies fall into three groups: strictly necessary cookies enabling login and session integrity, preference cookies remembering language and odds format, and analytics cookies measuring aggregate usage. The latter two can be declined through the consent banner or cleared through browser settings; declining necessary cookies prevents the site from functioning.

  • Cbet data protection enquiries — submitted through the privacy request form in the account settings area
  • Office of the Privacy Commissioner of Canada — 1-800-282-1376 for complaints concerning personal information handling
  • Curacao Gaming Control Board — complaint channel for matters connected to licence 365/JAZ
This notice describes practices in force while cbet.gg was operating under licence 365/JAZ issued to AK Global N.V. Insolvency proceedings commenced against that company in January 2025 and the platform was shut down on 30 March 2026; requests concerning personal information held from that period may need to be directed to the appointed administrator rather than to the former operational team.