Notice: By registering an account with mi888, accessing the mi888 platform, or using any service offered by mi888, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein. If you do not consent, you must not use the mi888 platform.
1 Introduction & Scope
1.1 This Privacy Policy ("Policy") describes the privacy practices of mi888 ("we", "us", "our", or the "Platform") in relation to personal data collected through the mi888 website at mi888.win, any associated mobile-optimised interfaces, and all related services including sportsbook, live casino, slots, mix parlay, and lottery products.
1.2 This Policy applies to all persons who interact with mi888, including registered Members, prospective Members who browse the platform, and any other individuals whose personal data mi888 processes in connection with its services.
1.3 mi888 is committed to handling personal data in accordance with applicable data protection laws and the requirements of its international gaming authority licence. Our data processing practices are designed to ensure that your information is collected only for legitimate purposes, retained only as long as necessary, and protected against unauthorised access, disclosure, or misuse.
1.4 This Policy should be read in conjunction with mi888's Terms & Conditions and Responsible Gaming Policy, which are available on the mi888 website.
2 Data Controller
2.1 For the purposes of applicable data protection legislation, mi888 is the data controller responsible for the personal data of its Members and platform users. mi888 determines the purposes and means of processing personal data collected through the mi888 platform.
2.2 mi888 operates under an international gaming authority licence. As a licensed operator, mi888 is subject to regulatory obligations that may require the processing of personal data for compliance, anti-money laundering, and fraud prevention purposes, independently of Member consent.
2.3 Where mi888 engages third-party processors to handle personal data on its behalf — for example, payment processors, identity verification providers, or fraud prevention services — mi888 ensures that appropriate data processing agreements are in place that bind those processors to confidentiality and security obligations no less protective than those applicable to mi888 itself.
3 Personal Data We Collect
3.1 mi888 collects the following categories of personal data from Members and platform users:
| Category | Data Types | Purpose |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government-issued ID number (MyKad / passport) | KYC verification, age verification, AML compliance |
| Contact Data | Email address, mobile telephone number, residential address | Account communications, security alerts, regulatory correspondence |
| Financial Data | Bank account details, e-wallet identifiers (TnG, Boost), transaction history, deposit and withdrawal records | Payment processing, withdrawal verification, AML monitoring |
| Technical Data | IP address, device identifiers, browser type and version, operating system, session data, login timestamps | Platform security, fraud detection, session management |
| Usage Data | Betting history, game play records, product preferences, session duration, click-path data | Responsible gaming monitoring, product improvement, personalisation |
| Communications Data | Records of live chat conversations, support ticket content, email correspondence with mi888 | Customer support, dispute resolution, quality assurance |
| Verification Documents | Copies of government-issued identification, proof of address documents, source of funds documentation | KYC compliance, age verification, AML obligations under licence |
3.2 mi888 does not collect special categories of sensitive personal data (such as racial origin, health data, or biometric data) except where expressly required by applicable law or regulatory authority instruction.
4 How We Collect Your Data
4.1 mi888 collects personal data through the following channels:
- Direct registration: Information you provide when creating a mi888 account, completing KYC verification, or updating your account profile;
- Transaction activity: Data generated when you make deposits, place bets, request withdrawals, or redeem bonuses on the mi888 platform;
- Automated technical collection: Data collected automatically when you access mi888.win, including IP addresses, cookie data, device fingerprints, and session logs;
- Customer support interactions: Information you provide when contacting mi888 via live chat, email, or any other support channel;
- Third-party verification providers: Identity and fraud risk data received from KYC and AML service providers engaged by mi888 in connection with Member verification;
- Responsible gaming tools: Data generated when you set deposit limits, request cooling-off periods, or activate self-exclusion.
5 Legal Basis for Processing
5.1 mi888 processes your personal data on the following legal bases:
- Contractual necessity: Processing required to perform the contract between mi888 and the Member — including account management, bet settlement, payment processing, and withdrawal fulfilment;
- Legal obligation: Processing required to comply with applicable laws and regulations, including KYC identity verification, AML reporting obligations, and age verification requirements imposed by mi888's international gaming authority licence;
- Legitimate interests: Processing undertaken in pursuit of mi888's legitimate business interests, including fraud prevention, platform security, responsible gaming monitoring, and business analytics, where such interests are not overridden by your privacy rights;
- Consent: Where mi888 relies on your consent to process personal data — for example, for optional marketing communications — you may withdraw that consent at any time by contacting mi888 support or updating your account communication preferences.
6 How We Use Your Personal Data
6.1 mi888 uses the personal data it collects for the following purposes:
- To create, verify, and maintain your mi888 member account;
- To process deposits, settle bets, and fulfil withdrawal requests to your verified payment method;
- To conduct KYC identity and age verification as required under mi888's international gaming authority licence;
- To detect, investigate, and prevent fraud, money laundering, and other financial crime;
- To monitor betting and gaming activity for responsible gaming purposes, including identification of potentially problematic behaviour patterns;
- To send you transactional communications, security alerts, and account notifications that are necessary for the operation of your account;
- Where you have consented, to send you promotional communications about mi888 products, bonuses, and offers that may be of interest to you;
- To analyse platform usage data in aggregate to improve mi888's products, interface design, and customer experience;
- To comply with legal and regulatory obligations, including responding to lawful requests from regulatory authorities and law enforcement agencies;
- To resolve disputes, enforce mi888's Terms & Conditions, and pursue or defend legal claims.
6.2 mi888 does not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you, except as required for regulatory compliance purposes and with the safeguards described in applicable law.
7 Data Sharing & Disclosure
7.1 mi888 does not sell your personal data to third parties. mi888 shares personal data only in the following circumstances and only to the extent necessary for the stated purpose:
Regulatory and Law Enforcement Authorities
mi888 is required to report certain transactions and Member data to its licensing regulatory authority and to financial intelligence units as required under AML and counter-terrorism financing obligations. Such disclosures are made pursuant to legal obligation and do not require Member consent.
Identity Verification and KYC Providers
mi888 shares identity documentation and personal data with third-party KYC and AML service providers for the purpose of verifying Member identity and assessing fraud risk. These providers are bound by data processing agreements that restrict their use of your data to the verification purpose only.
Payment Processors
Personal and financial data necessary to process deposits and withdrawals is shared with mi888's payment processing partners, including Touch n Go eWallet, Boost, and Malaysian banking partners. Payment processors receive only the data strictly necessary to execute the relevant transaction.
IT Infrastructure and Security Providers
mi888 engages cloud infrastructure and cybersecurity service providers who may process personal data on mi888's behalf in the course of providing their services. All such providers are subject to contractual data processing obligations.
Intra-Group Transfers
Where mi888 operates as part of a corporate group, personal data may be shared with affiliated entities within that group for internal administrative purposes, subject to equivalent data protection standards.
7.2 Other than as described above, mi888 will not disclose your personal data to any third party without your express prior consent, except where required to do so by law, court order, or binding regulatory direction.
8 Cookies & Tracking Technologies
8.1 mi888 uses cookies and similar tracking technologies on mi888.win to operate the platform, analyse usage patterns, and improve the user experience. Cookies are small data files placed on your device when you access the website.
8.2 mi888 uses the following categories of cookies:
- Strictly necessary cookies: Essential for the operation of the mi888 platform, including session authentication, account security, and load balancing. These cookies cannot be disabled without impairing platform functionality;
- Analytics cookies: Used to collect aggregate, anonymised data about how Members use mi888.win, including page visit frequency, navigation paths, and feature engagement. This data is used solely to improve the platform;
- Functional cookies: Used to remember your preferences, language settings, and game lobby configurations to provide a more personalised experience;
- Security cookies: Used to detect and prevent fraudulent login attempts, bot activity, and other security threats.
8.3 You may manage cookie preferences through your browser settings. Please note that disabling strictly necessary cookies will impair your ability to use the mi888 platform. mi888 does not currently use advertising or cross-site tracking cookies.
9 Data Retention
9.1 mi888 retains personal data for the period necessary to fulfil the purposes for which it was collected, and in any event for the minimum period required by applicable law and its regulatory licence obligations.
9.2 As a general principle, mi888 retains Member account data and transaction records for a minimum of five (5) years following account closure or the last date of account activity, in compliance with AML record-keeping requirements under its international gaming authority licence.
9.3 Identity verification documents are retained for a minimum of five (5) years following the completion of the KYC process or the closure of the Member's account, whichever is later.
9.4 Communications data, including live chat transcripts and support correspondence, is retained for a period of up to three (3) years from the date of the communication, or longer where the communication is relevant to an outstanding dispute or legal claim.
9.5 Technical and usage data generated by platform analytics tools is retained in anonymised or pseudonymised form for up to two (2) years for platform improvement purposes.
9.6 Where data is no longer required for any lawful retention purpose, mi888 will securely delete or anonymise it in accordance with its data disposal procedures.
10 Data Security
10.1 mi888 implements appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. Security measures applied by mi888 include, but are not limited to:
- 256-bit SSL/TLS encryption for all data transmitted between your device and mi888's servers;
- Encryption of stored personal data and financial records at rest;
- Access controls limiting internal access to personal data to employees and contractors with a legitimate need-to-know;
- Multi-factor authentication for administrative access to systems holding personal data;
- Regular security audits, penetration testing, and vulnerability assessments conducted by independent third parties;
- Incident response procedures for detecting, containing, and reporting data security incidents in accordance with applicable law.
10.2 In the event of a data security incident that poses a risk to your rights and freedoms, mi888 will notify the relevant regulatory authority and, where required, affected Members, within the timeframes prescribed by applicable law.
10.3 Whilst mi888 takes all reasonable measures to protect your data, no data transmission over the internet or electronic storage system is entirely secure. You acknowledge that the transmission of personal data to mi888 is at your own risk, and you are responsible for maintaining the security of your mi888 login credentials.
11 Your Privacy Rights
11.1 Subject to applicable law and the limitations of mi888's regulatory obligations, you hold the following rights in respect of your personal data held by mi888:
- Right of access: You may request a copy of the personal data mi888 holds about you;
- Right to rectification: You may request that mi888 correct any inaccurate or incomplete personal data it holds about you;
- Right to erasure: You may request that mi888 delete your personal data where it is no longer necessary for the purpose for which it was collected, subject to mi888's legal retention obligations;
- Right to restriction of processing: You may request that mi888 temporarily restrict its processing of your data in certain circumstances, for example where you contest the accuracy of the data;
- Right to data portability: Where processing is based on your consent or contractual necessity, you may request that mi888 provide your personal data in a structured, machine-readable format;
- Right to object: You may object to mi888's processing of your personal data for legitimate interests purposes, including direct marketing;
- Right to withdraw consent: Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
11.2 Please note that certain of these rights are subject to limitations under applicable law. In particular, mi888's obligations under its international gaming authority licence and AML legislation may require mi888 to retain certain data and process it in certain ways, regardless of a Member's exercise of the above rights.
11.3 To exercise any of your rights, please contact mi888 via [email protected]. mi888 will respond to verified requests within 30 days.
12 Children & Minors
12.1 The mi888 platform is strictly for persons aged 21 years or above. mi888 does not knowingly collect personal data from persons under the age of 21.
12.2 If mi888 becomes aware that it has collected personal data from a person under the age of 21, it will take immediate steps to delete that data and close the associated account. The regulatory authority under which mi888 is licensed will be notified as required.
12.3 Parents and guardians who believe that a minor may have registered a mi888 account or provided personal data to mi888 are encouraged to contact mi888 support immediately at [email protected].
13 Third-Party Links
13.1 The mi888 website may contain links to third-party websites, tools, or resources. This Privacy Policy applies only to mi888.win and the services operated directly by mi888. mi888 is not responsible for the privacy practices of any third-party websites and encourages you to review the privacy policies of any third-party sites you visit.
13.2 The inclusion of a link to a third-party website does not constitute endorsement of that website or its practices by mi888.
14 Amendments to This Policy
14.1 mi888 may update this Privacy Policy from time to time to reflect changes in data processing practices, applicable law, or regulatory requirements. The date of the most recent update is stated at the top of this document.
14.2 Where an amendment is material, mi888 will notify Members via the email address registered to their account, or by displaying a prominent notice on the mi888 platform, prior to the amendment taking effect.
14.3 Continued use of the mi888 platform following notification of an amendment constitutes your acceptance of the updated Privacy Policy. If you do not accept the updated Policy, you must cease using the platform and close your account by contacting mi888 support.
15 Contact & Complaints
15.1 For any privacy-related queries, requests to exercise your data rights, or complaints regarding mi888's handling of your personal data, please contact mi888's data protection team:
Email: [email protected]
Response time: mi888 acknowledges privacy-related requests within 5 business days and provides a substantive response within 30 days.
15.2 If you are not satisfied with mi888's response to a privacy complaint, you may escalate the matter to the relevant data protection authority or the regulatory body under whose authority mi888's gaming licence is issued. Details of the applicable authority are available from mi888 support upon request.