This Privacy Policy explains how my36 collects, uses, stores, discloses, and protects the personal data of Members and visitors to the my36 Platform. By using the Platform, you acknowledge that you have read and understood this Policy.
my36 takes the privacy and security of Member personal data seriously. We operate the my36 Platform — an online casino and sportsbook serving players primarily based in Malaysia, including Kuala Lumpur, Penang, Johor Bahru, Petaling Jaya, Bangsar, and other regions — and in doing so we process personal data as a data controller.
This Policy describes what personal data my36 collects, why we collect it, the legal grounds on which it is processed, how long it is retained, with whom it may be shared, and the rights available to data subjects in respect of their personal data. my36's data practices are aligned with the principles of Malaysia's Personal Data Protection Act 2010 ("PDPA") and internationally recognised data protection standards.
If you have any questions about how my36 processes your personal data, you may contact us via the details set out in Section 13 of this Policy.
my36 collects personal data in the following categories, depending on your interaction with the Platform:
| Category | Examples | When Collected |
|---|---|---|
| Identity Data | Full legal name, date of birth, MyKad / passport number, selfie / ID photograph | Registration; KYC verification |
| Contact Data | Email address, Malaysian mobile phone number, residential address | Registration; KYC verification |
| Financial Data | Bank account numbers, e-wallet identifiers (Touch 'n Go, Boost, GrabPay), card last-four digits, transaction history | Deposit and withdrawal processing |
| Gaming Data | Bet history, game session logs, win/loss records, bonus usage, responsible gaming tool activations | Continuous, during Platform use |
| Technical Data | IP address, device identifiers, browser type and version, operating system, session timestamps, login history | Automatic, on each Platform visit |
| Correspondence Data | Live chat transcripts, support email content, survey responses, feedback submissions | When you contact my36 support |
my36 does not collect special categories of sensitive personal data (such as racial origin, health data, or biometric data beyond identity document photographs required for KYC) unless specifically required for legal compliance and with appropriate safeguards in place.
my36 collects personal data through the following means:
my36 processes personal data on the following legal bases under applicable data protection law:
my36 uses the personal data it collects for the following purposes:
To register and maintain your my36 account; process deposits and withdrawals; verify your identity and age (21+) via KYC; settle bets and game outcomes; apply bonus credits; and provide access to all Platform products including Sportsbook, Slots, my36 Casino, and Lottery Magnum.
To authenticate login sessions; detect and prevent unauthorised account access, bonus abuse, multi-accounting, and money laundering; monitor for unusual betting patterns; and maintain the integrity of the Platform for all Members.
To enforce the 21+ age restriction; process responsible gaming tool requests (deposit limits, session timers, self-exclusion); monitor for indicators of problem gambling; and, where appropriate, proactively reach out to Members exhibiting concerning usage patterns.
To fulfil my36's obligations under applicable law, including AML screening, regulatory reporting, responding to lawful requests from competent authorities, and maintaining records as required by applicable retention schedules.
To analyse aggregate usage patterns, optimise Platform performance, test new features, and improve the overall member experience — using anonymised or pseudonymised data wherever possible.
To send promotional offers, bonus notifications, and relevant Platform updates to Members who have opted in to marketing communications. Marketing preferences can be managed from Account Settings or by contacting support. Withdrawing marketing consent does not affect your account or service entitlements.
my36 does not sell, rent, or trade your personal data to third parties for their own marketing purposes. Personal data may be shared in the following circumstances only:
Where personal data is transferred outside Malaysia to service providers in other jurisdictions, my36 ensures appropriate contractual safeguards are in place to maintain an equivalent level of data protection.
The my36 Platform uses cookies and similar technologies to support core Platform functionality and improve the member experience. The categories of cookies used include:
my36 does not use third-party advertising cookies or share browsing behaviour with advertising networks. Cookie preferences (for non-essential cookies) can be managed via the cookie banner presented on first visit to the Platform.
my36 retains personal data for as long as necessary to fulfil the purposes for which it was collected, subject to the following retention guidelines:
Following the expiry of applicable retention periods, personal data is securely deleted or anonymised in a manner that prevents re-identification.
my36 implements technical and organisational measures appropriate to the risk posed by processing Member personal data. Security measures include:
Notwithstanding these measures, no transmission of data over the internet is completely secure. In the event of a personal data breach that poses a risk to Member rights, my36 will notify affected Members and relevant authorities in accordance with applicable data protection law without undue delay.
Subject to applicable law and identity verification, my36 Members have the following rights in respect of their personal data:
To exercise any of these rights, contact my36 via live chat on the Platform or by email at [email protected]. my36 will respond within 30 days of receiving a verified request. Requests may require identity verification before processing.
The my36 Platform is strictly for adults aged 21 and above. my36 does not knowingly collect personal data from individuals under the age of 21. If my36 becomes aware that personal data has been collected from a person under 21 years of age, the account will be closed and associated data deleted in accordance with applicable law.
If you believe that a person under 21 has registered a my36 account, please contact my36 support immediately via live chat so that appropriate action can be taken without delay.
my36 reserves the right to update this Privacy Policy at any time to reflect changes in our data practices, applicable law, or Platform features. When material changes are made, my36 will publish the updated Policy on this page with a revised "Last Updated" date and, where appropriate, notify Members via email or an in-Platform notification.
Continued use of the my36 Platform after the effective date of any revision constitutes acceptance of the updated Privacy Policy. If you do not agree with the revised Policy, you should discontinue use of the Platform and close your account.
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact my36 through the following channels:
my36 aims to acknowledge all privacy-related requests within 48 hours and to resolve them within 30 days. For complex requests that require additional time, we will notify you of the expected timeline within the initial 30-day window.
Every page of the my36 Platform is served over HTTPS with 256-bit SSL encryption. This is the same standard used by Malaysian banks and financial institutions. Your login credentials, personal information, and payment details are never transmitted in unencrypted form under any circumstances.
my36 never stores member passwords in plain text. All passwords are processed through bcrypt with individual salting before storage. This means that even in a worst-case scenario involving database compromise, your actual password cannot be recovered from stored data. Changing your password regularly remains a good personal security practice.
my36 does not sell, rent, or trade member personal data to third-party advertisers, data brokers, or marketing networks. Member data is used exclusively to operate the Platform, fulfil legal obligations, and — with your consent — send my36's own promotional communications. Your betting behaviour and financial data are never monetised externally.
my36's data processing practices are aligned with Malaysia's Personal Data Protection Act 2010 (PDPA) and the principles of internationally recognised data protection frameworks. We collect only the minimum data necessary for each purpose, process it on a lawful basis, and retain it only for as long as required by legal obligation or legitimate need.
Marketing consent, cookie preferences, and communication settings can be adjusted from your my36 Account Settings at any time without contacting support. Data subject rights requests — access, correction, erasure, portability — are handled by the my36 team within 30 days of a verified request submitted via live chat or email.
my36 does not hold personal data indefinitely. Defined retention schedules govern how long each data category is kept — from active account data (5 years post-closure) to transaction records (7 years) and support correspondence (3 years). Data is securely deleted or anonymised at the end of applicable retention periods.
Confident in how we handle your data? The full my36 platform is ready — sports betting, live casino, slots, and lottery, with 24/7 Malaysian support and fast, fee-free withdrawals.
21+ only. Please gamble responsibly.