1. About This Policy
spider88 ("we", "us", "our") operates the online gaming platform at spider88.club ("Platform"). As the data controller for personal information collected via the Platform, spider88 is committed to handling your data responsibly, transparently, and in accordance with applicable data protection principles.
This Privacy Policy applies to all personal data collected from Members and visitors to the Platform, including data collected through the registration process, gameplay activity, financial transactions, customer support interactions, and your use of our website and any associated services.
This Policy should be read in conjunction with the spider88 Terms & Conditions, which form the broader framework governing your use of the Platform.
2. Personal Data We Collect
spider88 collects personal data in the following categories, depending on how you interact with the Platform:
2.1 Registration & Identity Data
- Full legal name as it appears on your government-issued identification;
- Date of birth (to verify the mandatory 21+ age requirement);
- Malaysian mobile phone number (registered in your name);
- Email address (if provided during registration);
- Residential address;
- Government-issued identification number (where required for KYC verification);
- Copies of identification documents submitted for KYC purposes (e.g., MyKad, passport).
2.2 Financial & Transaction Data
- Bank account details, e-wallet identifiers (Touch n Go, Boost, GrabPay, DuitNow), and FPX payment records associated with your account;
- Deposit and withdrawal transaction history, amounts, timestamps, and payment method references;
- All wagering activity including bet amounts, game types, outcomes, and timestamps;
- Bonus and promotion eligibility and redemption records.
2.3 Technical & Usage Data
- IP address and approximate geolocation derived therefrom;
- Device type, operating system, browser type and version;
- Session start and end times, pages visited, game sessions initiated;
- Login timestamps and device identifiers;
- Cookies and similar tracking technologies (see Section 7).
2.4 Communications Data
- Records of live chat, email, and support ticket communications between you and spider88 support;
- Survey responses and feedback you voluntarily submit;
- Records of any dispute or complaint you raise with spider88.
3. How spider88 Uses Your Personal Data
| Purpose | Categories of Data Used |
|---|---|
| Account registration and identity verification (KYC) | Identity Data, Financial Data |
| Processing deposits, withdrawals, and betting transactions | Financial & Transaction Data |
| Age verification (mandatory 21+ requirement enforcement) | Identity Data (date of birth, ID documents) |
| Fraud detection, AML compliance, and security monitoring | Identity Data, Financial Data, Technical Data |
| Responsible gaming monitoring and intervention | Transaction Data, Usage Data, Communications Data |
| Customer support and dispute resolution | All categories as relevant to the query |
| Platform improvement and product analytics | Technical & Usage Data (anonymised/aggregated) |
| Promotional communications (where consent is given) | Identity Data, contact details |
| Legal and regulatory compliance obligations | All categories as required by applicable law |
spider88 does not use your personal data for automated individual decision-making that produces significant legal effects without human review, except where required for real-time fraud prevention purposes.
4. Legal Basis for Processing
spider88 processes your personal data on the following legal bases:
- Contractual necessity: Processing required to perform the contract between you and spider88, including account management, payment processing, and game delivery;
- Legal obligation: Processing required to comply with applicable anti-money laundering requirements, age verification obligations, and regulatory reporting duties;
- Legitimate interests: Processing carried out to protect spider88's security, detect and prevent fraud, and improve the Platform — where these interests are not overridden by your fundamental rights and freedoms;
- Consent: Processing for marketing communications and non-essential cookies, where you have provided explicit consent. You may withdraw consent at any time by contacting spider88 support.
5. Data Sharing & Disclosure
spider88 does not sell, rent, or trade your personal data to third parties for commercial marketing purposes. We may share your data in the following limited circumstances:
5.1 Service Providers
spider88 engages third-party service providers who process data on our behalf under strict data processing agreements, including:
- Payment gateway providers processing MYR transactions (FPX, Touch n Go network, DuitNow infrastructure);
- Identity verification and KYC service providers;
- Game content providers (who receive anonymised session data for game integrity purposes);
- Cloud infrastructure and hosting providers;
- Customer support platform providers.
All service providers are contractually bound to process your data only for the specified purposes and in accordance with applicable data protection requirements.
5.2 Legal & Regulatory Disclosure
spider88 may disclose your personal data to regulatory authorities, law enforcement agencies, gaming regulators, or financial intelligence units where required by applicable law, court order, or regulatory direction — including in connection with AML investigations or fraud prevention measures.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of spider88's assets, your personal data may be transferred to the acquiring entity as part of that transaction. spider88 will notify affected Members in advance of any such transfer and ensure continuity of data protection standards.
6. Data Retention
spider88 retains your personal data for as long as necessary to fulfil the purposes for which it was collected, subject to the following retention framework:
- Account and identity data: Retained for the duration of your account membership plus a minimum of five (5) years following account closure, as required by applicable AML and gaming regulatory obligations;
- Transaction and financial records: Retained for a minimum of seven (7) years from the date of each transaction, in line with financial record-keeping requirements;
- Customer support communications: Retained for three (3) years from the date of the most recent interaction, or longer if related to an unresolved dispute;
- Technical and usage data: Retained in identified form for up to twenty-four (24) months; thereafter anonymised for aggregate analytics purposes;
- Self-exclusion records: Retained indefinitely to ensure that self-exclusion decisions are permanently honoured.
Following the expiry of applicable retention periods, personal data is securely deleted or anonymised in accordance with spider88's data disposal procedures.
7. Cookies & Tracking Technologies
spider88 uses cookies and similar tracking technologies on the Platform to support Platform functionality, security, and performance analytics. The categories of cookies we use are as follows:
- Strictly necessary cookies: Required for the Platform to function, including session management, login state, and security tokens. These cannot be disabled without disrupting Platform functionality;
- Functional cookies: Used to remember your preferences (e.g., language settings, preferred game lobby view) across sessions;
- Analytics cookies: Used to collect aggregated, anonymised data about how Members interact with the Platform, to inform product improvements. No personally identifiable information is transmitted via analytics cookies;
- Security cookies: Used to detect and prevent fraudulent access attempts, device fingerprinting for risk assessment, and session integrity verification.
spider88 does not use third-party advertising or retargeting cookies. You may manage cookie preferences through your browser settings; however, disabling strictly necessary cookies will impair your ability to use the Platform.
8. Data Security
spider88 implements industry-standard technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- 256-bit SSL/TLS encryption for all data transmitted between your device and spider88's servers;
- Encryption at rest for all sensitive personal and financial data stored on spider88 infrastructure;
- Access controls limiting personal data access to authorised personnel on a need-to-know basis;
- Two-factor authentication (2FA) available for all Member accounts;
- Continuous security monitoring and intrusion detection systems;
- Regular security audits and penetration testing by independent third-party security firms;
- Incident response procedures in place to address any confirmed or suspected data security breaches.
Notwithstanding the above, no internet transmission or electronic storage system is 100% secure. spider88 cannot guarantee absolute security of your data. You are responsible for maintaining the confidentiality of your account credentials and for notifying spider88 immediately upon becoming aware of any suspected unauthorised access to your account.
9. Your Data Rights
Subject to applicable law and spider88's legal obligations, you have the following rights in relation to your personal data held by spider88:
- Right of access: You may request a copy of the personal data spider88 holds about you;
- Right to rectification: You may request correction of any inaccurate or incomplete personal data;
- Right to erasure: You may request deletion of your personal data in certain circumstances, subject to spider88's legal retention obligations — particularly where retention is required by AML or gaming regulatory law;
- Right to restriction: You may request that spider88 restrict the processing of your data in certain defined circumstances;
- Right to data portability: You may request a copy of your personal data in a structured, machine-readable format where technically feasible;
- Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing;
- Right to object: You may object to processing carried out on the basis of legitimate interests, subject to spider88's overriding legitimate grounds.
To exercise any of the above rights, please contact spider88 support via 24/7 live chat on the Platform or by email at [email protected]. spider88 will respond to all valid data rights requests within a reasonable timeframe.
10. Children's Privacy
If spider88 becomes aware that personal data has been collected from an individual under the age of 21, we will take immediate steps to delete such data and close the associated account. If you believe that a person under 21 has provided personal data to spider88, please notify us immediately via support so that appropriate action can be taken.
11. Cross-Border Data Transfers
The operation of the spider88 Platform may involve the transfer of your personal data to service providers or infrastructure located outside of Malaysia — for example, to cloud hosting providers or game content delivery networks operating regionally across Southeast Asia. Where such transfers occur, spider88 ensures that appropriate data transfer safeguards are in place, including contractual protections equivalent to applicable data protection standards, to maintain the same level of data protection regardless of where data is processed.
12. Changes to This Privacy Policy
spider88 reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, legal obligations, or Platform features. When material changes are made, spider88 will provide advance notice to Members via the Platform or by communication to your registered contact details, no less than seven (7) days prior to the effective date of the updated Policy, except where immediate changes are required for legal or security reasons.
Your continued use of the spider88 Platform following the effective date of any revised Privacy Policy constitutes your acknowledgement of and consent to the updated terms. We encourage you to review this Policy periodically.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or spider88's data processing practices, please contact our Data Protection team: