WinWin Somalia Privacy Policy – Personal Data, Security and User Rights
Personal information can be collected when a visitor uses account features, sends a support request, submits verification details or interacts with technical services such as cookies and security logs. Privacy controls should focus on collecting only what is necessary, protecting it appropriately and keeping it only for as long as there is a valid reason.
Types of information that may be processed
- contact details such as email address or telephone number;
- account identifiers and security events;
- technical information such as browser, device and IP data;
- support messages and issue history;
- verification information when identity checks are required;
- payment references and transaction status where relevant.
Data collection should stay proportionate to a specific purpose. If an action can be completed with fewer details, there is no practical reason to request unrelated information.
For “Types of information that may be processed”, a useful rule is to provide no more data, money or permissions than the action requires and to stop when an important condition is unclear.
Why information may be used
Common purposes include operating account features, preventing fraud, responding to support requests, maintaining security, meeting legal or compliance requirements and improving technical stability. A purpose should be connected to a legitimate service need rather than an unlimited right to reuse information for unrelated reasons.
| Data category | Typical purpose |
| Contact details | Account notices, recovery and support |
| Security logs | Fraud prevention and suspicious-login review |
| Verification data | Identity, age and account-control checks |
| Transaction references | Payment reconciliation and dispute handling |
| Device information | Technical troubleshooting and security analysis |
Voluntary fields should contain only what is needed. General contact forms are not a suitable place for document numbers, full payment details or other sensitive information unless those details are explicitly required.
Identity documents
Identity documents contain sensitive information and should be submitted only through an official verification channel when required. Sending documents through social media, an unknown messaging account or an unverified email address increases the risk of misuse. A user should not disclose passwords or one-time security codes together with identity documents.
Different purposes should remain separate. Information needed for an account, security check, payment or support request should not automatically be reused for an unrelated purpose without a clear basis.
Data sharing
Some processing can involve payment providers, hosting services, security vendors or other processors needed to operate a service. Sharing should be limited to the information required for the relevant function. A payment provider, for example, may need transaction data without needing unrelated support history.
Data minimisation also applies to internal access. Limiting the number of people and systems that can view a record reduces the chance of accidental disclosure or use outside the original purpose.
Retention
Different records can require different retention periods. Security logs may be useful for investigating suspicious activity, while support records may be kept to resolve ongoing issues. Information should not be retained indefinitely without a business, legal or security reason.
Browser identifiers can support sessions, security or measurement. Their function and retention period matter more than the technical label, so essential and optional uses should be considered separately.
User choices and requests
Depending on applicable rules and the service involved, a person may be able to ask what personal information is held, request correction of inaccurate details or raise questions about processing. Some records cannot be deleted immediately when they must be retained for fraud prevention, dispute resolution or legal obligations.
VIEW GAMESTechnical logs help detect unusual access, faults and attempted abuse. They should contain only what is reasonably required for security, diagnostics and accountability.
Account and device security
Privacy also depends on the user’s own device. Shared browsers can retain login sessions, downloaded documents and autofill information. A strong screen lock, unique account password and careful handling of verification messages reduce accidental disclosure.
- do not reuse the same password across unrelated services;
- avoid storing identity documents permanently on shared devices;
- hide sensitive notification previews where necessary;
- log out after using a public or shared computer;
- report unexpected login or account-change notifications promptly.
Retention should match the original purpose. Once information is no longer needed, deletion or anonymisation is preferable unless there is a legitimate reason to keep it for a defined period.
Children and age restrictions
Gambling services are intended for adults and should not be used by anyone under 18. Age-verification controls are designed to prevent minors from opening or using gambling accounts. A parent or guardian who believes a minor’s information has been used should contact the relevant service through an official channel.
Security includes encryption, access control and change records. Users also need to protect the device, email account and recovery credentials connected to their account.
Security incidents
If an account holder suspects that personal information has been exposed, the first steps are to secure the email account, change compromised passwords, review active sessions and check recent transactions. Support should be contacted through a verified route if account activity appears unauthorized.
Access, correction and deletion requests work best when the user states exactly what is being requested. A precise request reduces the need to collect extra details during verification.
