Official Documents

Privacy Policy Royale36
Data Protection for Malaysian Members

At royale36, your privacy is not merely a legal obligation — it is our genuine commitment to every member. This document clearly explains what data we collect, why it is needed, how it is protected, and what rights you have as the owner of that data.

Last Updated: 1 January 2026

Six Pillars of royale36 Privacy Protection

We take your personal data seriously. Here are the core principles that guide how we handle member information.

Enterprise-Grade Data Encryption

All members' personal and financial data is protected with 256-bit SSL encryption — the same standard used by leading banking institutions. Your information cannot be read by any unauthorised party during transmission.

No Sale of Data to Third Parties

Royale36 has never and will never sell, rent, or transfer members' personal data to any third party for marketing or commercial purposes without your explicit consent. Your data belongs to you.

Full Control in Your Hands

You have the full right to access, correct, or request deletion of your personal data at any time. Our customer support team is ready to assist you in managing your data within 24 business hours.

Minimum Data Collection

We only collect data that is strictly necessary for service operations, identity verification, and legal compliance. There is no excessive data collection or collection for purposes unrelated to our services.

Clear Data Retention Periods

Your data is retained only for as long as required for service purposes or legal compliance. Once that period ends, data will be securely deleted in accordance with established procedures.

Malaysia Legal Compliance

Our Privacy Policy fully complies with Malaysia's Personal Data Protection Act 2010 (PDPA) and relevant international data protection regulations. We continuously update our practices in line with legislative changes.

1 Introduction

Welcome to the royale36 Privacy Policy. We, the royale36 management team, understand that member trust is the most valuable asset we hold. This document is written in plain language because we believe every member has the right to know exactly how their personal information is handled — not just wade through tedious legal jargon.

This Privacy Policy applies to all information you provide to royale36 when registering an account, using our gaming platform, making deposits or withdrawals, contacting customer support, or simply browsing our website at royale36.win. This includes our web platform, mobile app, and all official communication channels.

As a legally operating online gaming platform, royale36 is subject to Malaysia's Personal Data Protection Act 2010 (PDPA) as well as the anti-money laundering (AML) and know-your-customer (KYC) compliance requirements set by our licensing authority. These requirements partly determine the types of data we need to collect and how long we retain it.

Quick Summary: We collect only what's needed, keep it secure, never sell it, and you can request access or deletion at any time. That's the bottom line.
2 Data We Collect

Royale36 collects your personal data through several different channels. We divide data types into three main categories to make it easier for you to understand:

A. Data You Provide Directly

  • Registration information: full name, date of birth, identity card number (MyKad) or passport, phone number, and email address.
  • Address information: current residential address for identity verification purposes.
  • Financial information: bank account number, bank name, and e-wallet details (Touch 'n Go, Boost) used for transactions.
  • KYC documents: copies of your identity card, passport, utility bill, or bank statement uploaded for verification purposes.
  • Communications: live chat records, support emails, and feedback you send to us.

B. Data Collected Automatically

  • Device data: device type, operating system, phone model, screen resolution, and browser version.
  • Network data: IP address, internet service provider (ISP) name, and approximate geographic location based on IP.
  • Activity data: pages visited, games played, total bets, session duration, and general usage patterns.
  • Cookie data: session information, language preferences, and login status (see Section 5 for details).

C. Data from Authorised Third Parties

  • Identity verification information from recognised third-party KYC service providers.
  • Risk assessment data from payment processors for fraud detection purposes.
  • Information from gambling blacklist databases approved by statutory bodies.
Data Categories Example Primary Purpose
Identity Name, MyKad, date of birth Age and identity verification (KYC)
Contact Email, phone number Communications and account recovery
Financial Bank account, e-wallet Deposit and withdrawal processing
Technical IP address, device type Security and fraud detection
Usage Gaming history, betting records Responsible gambling compliance
3 How We Use Your Data

Every piece of data we collect has a clear and legitimate purpose. Royale36 does not use your data for purposes unrelated to the services we offer. Below is a full breakdown of how your data is used:

  • Account Management: To create, verify, and maintain your member account, including processing registration, identity verification, and password resets.
  • Transaction Processing: To process all deposits, withdrawals, and financial transactions securely and accurately via DuitNow, FPX, Touch 'n Go, Boost, Maybank, CIMB, and other supported payment methods.
  • Service Delivery: To allow you to seamlessly access all games, sports betting, and platform features available at royale36.
  • Legal Compliance: To fulfil KYC, AML, and reporting obligations required by Malaysian law and our licensing authority.
  • Fraud Detection: To identify and prevent fraudulent activity, money laundering, and system abuse through transaction pattern analysis.
  • Responsible Gaming: To monitor gambling patterns and identify members who may need additional support or protection, in line with our commitment to Responsible Gaming.
  • Service Communications: To send important notifications related to your account, transactions, terms updates, and security information.
  • Marketing (With Consent): To send you promotional information, bonus offers, and the latest royale36 news — but only if you have agreed to receive such communications. You may unsubscribe at any time.
  • Service Improvement: To analyse usage data in aggregate (without individual identification) to improve platform performance, user experience, and game offerings.
Legal Basis: Our use of your data is based on: (i) fulfilment of the service contract between you and royale36; (ii) compliance with legal obligations; (iii) legitimate interests in fraud prevention; and (iv) your consent for marketing communications.
4 Data Sharing and Disclosure

Royale36 does not sell or trade members' personal data. However, in certain limited situations, we may need to share your data with the following parties:

  • Recognised Service Providers: Payment service providers, KYC service providers, third-party gaming platforms (such as slot game and Live Casino providers), and technical service providers who help us operate the platform. All parties are bound by strict confidentiality agreements.
  • Regulatory and Law Enforcement Bodies: When required by law, court order, or directive from a competent authority, including the Royal Malaysia Police (PDRM), the Malaysian Anti-Corruption Commission (MACC), or other relevant regulatory bodies.
  • Fraud Prevention Bodies: Agencies and databases used for fraud detection, prevention, and anti-money laundering purposes, including relevant international enforcement lists.
  • Business Transfer: In the event of a merger, acquisition, or business asset transfer, member data may be transferred as part of those assets. You will be notified in advance in such situations.
Our Guarantee: In all data sharing situations, royale36 ensures that data recipients are bound by confidentiality agreements that meet or exceed the protection standards we offer our members. We do not share data beyond what is necessary for the stated purpose.
5 Cookies and Tracking Technologies

The royale36 website uses cookies and similar tracking technologies to enhance your experience and ensure platform features function correctly. Below are the types of cookies we use:

  • Essential Cookies: Required for core website functions such as login authentication, session security, and language preference memory. These cookies cannot be disabled without affecting platform functionality.
  • Performance Cookies: Anonymously collecting information on how visitors use our website, such as the most frequently visited pages. This data helps us improve the platform.
  • Functionality Cookies: Allows the website to remember your preferences (such as username and display settings) to provide a more personalised experience.
  • Security Cookies: Used for fraud detection and suspicious activity monitoring, including identifying unusual login patterns.

You can manage or delete cookies through your browser settings at any time. However, disabling essential cookies may affect your ability to fully use certain features of the royale36 platform.

6 Data Security

Royale36 invests seriously in data security infrastructure to ensure your personal information is always protected. The technical and organisational measures we implement include:

  • 256-bit SSL/TLS encryption for all data transmitted between your device and our servers.
  • Sensitive personal data stored in our databases is encrypted using the latest industry standards.
  • Strict access controls — only authorised staff with a genuine need-to-know basis may access member personal data.
  • 24/7 security monitoring and an active intrusion detection system.
  • Regular security audits by independent third parties to identify and patch system vulnerabilities.
  • Two-factor authentication (2FA) is available for account login for added protection.
  • Regular cybersecurity awareness training for all royale36 staff who handle personal data.
Data Breach: In the event of a data breach affecting your information, royale36 will notify you within 72 hours of confirming the breach, in line with international best practices. We will also take immediate steps to contain and remediate any adverse effects.
7 Your Rights as a Data Owner

Under Malaysia's Personal Data Protection Act 2010 and royale36's commitment to privacy, you have the following rights regarding your personal data:

Access Rights

You may request a copy of the personal data we hold about you at any time.

Right to Rectification

You may request correction of inaccurate or incomplete data held in our records.

Right to Erasure

You may request deletion of your personal data, subject to our legal data retention obligations.

Right to Object

You may object to the processing of your data for direct marketing purposes at any time.

Right to Data Portability

You may request your data in a machine-readable format for transfer to another provider.

Right to Restriction

You may request that we restrict the processing of your data in certain circumstances as provided by law.

To exercise any of the above rights, please contact the royale36 customer support team via 24/7 live chat or email at [email protected]. We will process your request within 14 business days.

8 Data Retention Period

Royale36 does not retain your personal data longer than necessary. Below are our data retention guidelines by data category:

  • Active Account Data: Retained for the duration your account remains active at royale36, plus any additional period required by law after account closure.
  • Financial Transaction Records: Retained for seven (7) years from the transaction date, in line with Malaysia's accounting and AML legal requirements.
  • KYC Documents: Retained for five (5) years after account closure or termination of the business relationship, in accordance with AML legal requirements.
  • Support Communication Logs: Retained for two (2) years for service improvement purposes and resolution of any disputes.
  • Cookie and Session Data: Session cookies expire when you close your browser; persistent cookies are stored for no more than twelve (12) months.

Once the specified retention period expires, data will be securely deleted or anonymised so it can no longer be linked to any individual.

9 Changes to This Privacy Policy

Royale36 reserves the right to update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service improvements. When we make significant changes, we will:

  • Updating the "Last Updated" date at the top of this document.
  • Displaying a clear notice on the royale36.win homepage at least seven (7) days before changes take effect.
  • Sending email notifications to your registered address for material changes.

We encourage you to review this page periodically. Your continued use of the royale36 platform after any changes take effect will be considered your acceptance of the updated Privacy Policy.

10 Contact Us Regarding Privacy

If you have any questions, concerns, or wish to exercise your privacy rights, the royale36 Data Protection Officer (DPO) team is ready to assist you:

  • Privacy Email: [email protected]
  • Live Chat: Available 24/7 via the chat icon at the bottom of royale36.win
  • Response Time: We aim to respond within 24 business hours for all privacy-related enquiries.
Complaints to Authorities: If you are not satisfied with how we handle your privacy complaint, you have the right to lodge a complaint with the Malaysia Department of Personal Data Protection or the relevant regulatory body.

Frequently Asked Questions about the Royale36 Privacy Policy

No, absolutely not. Royale36 has never and will never sell, rent, or transfer members' personal data to any third party for marketing or commercial purposes. Your data is only shared with service providers who help us operate the platform (bound by confidentiality agreements) and with authorities when required by law.

You can submit a data access request via our 24/7 live chat at royale36.win or by emailing [email protected]. Please state clearly that you wish to exercise your data access right. We will process your request and send a copy of your data within 14 business days upon completion of identity verification.

Yes, you may request the deletion of your personal data. However, please note that some data may need to be retained for a specified period to fulfil legal obligations such as AML requirements and financial records. We will clearly inform you which data can be deleted immediately and which must be retained, along with the reasons.

Yes. The royale36 mobile app applies the same security standards as the web platform, including 256-bit SSL encryption for all data communications. In addition, our app supports biometric authentication (fingerprint or facial recognition) as an extra layer of security to protect your account on mobile devices.

When your account is closed, we will immediately stop using your data for marketing purposes. However, certain data will be retained for periods required by law — for example, financial transaction records are kept for seven years and KYC documents for five years after account closure. After these periods, all data will be securely deleted.

Join Royale36 with Complete Confidence

Your privacy and data security are our top priority. Join thousands of Malaysian members who have trusted royale36 as their online gaming platform of choice — backed by world-class data protection.

256-bit SSL Encryption Malaysia PDPA Compliance 24/7 Support
Bahasa Melayu