Privacy Policy¶
ChainBETs.win — Blockchain Number Game on Arbitrum
Version 3.0 — June 2026 Last updated: 2026-06-23
1. Introduction¶
ChainBETs ("we", "us", "the Platform") respects your privacy. This Privacy Policy explains what personal data we collect, why we process it, how long we keep it, and with whom we share it when you use the Platform.
The Platform is operated for players in Africa, Latin America and Southeast Asia. Access from the European Union, the United Kingdom and other jurisdictions listed in our Terms of Service is technically blocked at the network edge.
2. Operator¶
The operator responsible for personal data on the Platform is:
ChainBETs General contact: [email protected] Privacy contact: [email protected] [Operator legal entity & address — to be added by counsel]
3. Data We Collect¶
3.1 Account Data¶
- Wallet address (automatically generated via Web3Auth on signup)
- Email address (from social login or entered during profile completion)
- First and last name (entered during profile completion)
- Date of birth (required for age verification)
- Country of residence (required for jurisdictional compliance)
- Phone number (optional)
- Display name (optional, used in greetings and on the leaderboard)
3.2 Authentication Data¶
- Web3Auth login method (Google, Apple, Email)
- Social login identifiers (provider's anonymized account ID)
3.3 KYC / Identity Verification Data¶
When identity verification is required by our risk policy or by claim thresholds:
- Government-issued identity document (passport, national ID, or driver's licence)
- Selfie or live face capture for matching against the document
- Optional source-of-funds documentation during Enhanced Due Diligence
KYC verification is performed by our third-party provider didit.me. didit operates the camera capture, OCR, liveness check, face match, and AML/PEP/sanctions screening on its own infrastructure. Once didit returns a verified result, we persist the extracted identity fields (first name, last name, date of birth, nationality, document number, AML status) in our database and archive the original document images in an internal storage bucket with a SHA-256 integrity hash. The persisted record is append-only and is the regulatory source of truth — see our AML / KYC Statement for a player-facing summary of how the verified record relates to your typed profile.
3.4 Gameplay Data¶
- Ticket purchases (numbers selected, pool, amount, timestamp)
- Winning numbers and match results
- Transaction hashes (on-chain references)
- Bonus and voucher history
- Spending limits and self-exclusion settings
3.5 Technical Data¶
- IP address (for fraud prevention and geo-blocking)
- Device type and browser information
- Push notification subscription data (only if you enable browser push)
- Session cookies and locale preference
3.6 Communication Data¶
- Support ticket content
- Email correspondence
- Marketing email preferences (newsletter opt-in and marketing-mail opt-out)
4. Why We Process Your Data¶
We process personal data only for the specific purposes listed below:
| Purpose | Type of data used |
|---|---|
| Operating your account and processing ticket purchases / payouts | Account, Authentication, Gameplay |
| Verifying your age and identity, and meeting AML obligations | KYC, Account |
| Enforcing spending limits, self-exclusion and responsible-gaming rules | Account, Gameplay |
| Detecting and preventing fraud, multi-account abuse and unauthorized access | Technical, Gameplay, Account |
| Enforcing geographic restrictions | Technical |
| Notifying you about wins, important changes, and support replies (transactional) | Account, Communication |
| Sending re-engagement and voucher-expiry reminder emails (marketing) | Account, Communication, Gameplay |
| Improving the Platform via aggregated and anonymized analytics | Gameplay, Technical |
Transactional communications (win notifications, support replies, KYC status updates, withdraw confirmations, regulatory notices) are sent regardless of your marketing preferences because they relate to the operation of your account.
Marketing communications (re-engagement and voucher-expiry reminders) are sent only while the marketing_emails_enabled preference on your account is enabled. You can switch it off at any time in your Account → Settings page.
5. How We Use Your Data¶
5.1 Platform operation¶
- Processing ticket purchases and payouts
- Managing your account and wallet
- Enforcing spending limits and self-exclusion across all wallets linked to the same verified identity
- Providing customer support and handling disputes
5.2 Legal and regulatory compliance¶
- Verifying your identity and age
- Anti-money laundering (AML) screening, including PEP and sanctions matching
- Responding to law enforcement or regulatory requests where legally compelled
- Maintaining transaction and identity records for the periods set out in §8
5.3 Security and fraud prevention¶
- Detecting and preventing fraudulent activity
- Enforcing geographic restrictions
- Linking multiple wallets of the same person via biometric face-match to enforce limits and exclusions consistently
- Protecting against unauthorized access
5.4 Communications¶
- Sending transactional emails (wins, KYC status, withdraw confirms, support replies)
- Sending push notifications if you have enabled them in Account → Settings
- Sending marketing emails (re-engagement when you have been inactive, voucher-expiry reminders 3 days before a bonus expires) — only while marketing is opted in
- Responding to support inquiries
5.5 Platform improvement¶
- Analyzing anonymized gameplay patterns
- Improving user experience
- Generating aggregated statistics (hot/cold numbers, win distribution)
6. Third-Party Data Sharing¶
We share personal data only with the processors below, and only to the extent necessary for them to provide the service we use them for. We do not sell personal data.
| Processor | Data shared | Purpose | Hosting region |
|---|---|---|---|
| Web3Auth (Torus Labs) | Social-login identifier | Authentication & embedded wallet generation | Global (vendor-managed) |
| didit.me | Identity document images, selfie, name, DOB, nationality, document number | KYC, AML/PEP/sanctions screening, biometric duplicate detection | Vendor-managed (Europe) |
| Resend | Email address, email subject, email body | Transactional and marketing email delivery | Global (vendor-managed) |
| Chainlink VRF v2.5 | None (on-chain consumer contract address only) | Verifiable random number generation for draws | On-chain |
| Arbitrum / Alchemy | Wallet address, on-chain transactions | Blockchain RPC, on-chain reads | Global (vendor-managed) |
| Arbiscan | Wallet address and on-chain transactions (already public) | Block explorer used by us for transaction lookups | Vendor-managed |
| Cloudflare | IP address, request headers | CDN, DDoS protection, geo-blocking at the network edge | Global edge network |
| Amazon Web Services (AWS) | All operational and persisted data (hosting) | Infrastructure hosting (Frankfurt / eu-central-1) | Frankfurt, Germany |
| Telegram (Bot API) | Operational alerts only (no player content) | Internal incident notifications for our on-call team | Vendor-managed |
| Browser Web Push | Push-subscription endpoint and keys (you supply them by enabling push) | Delivery of notifications you have explicitly opted into | Browser-managed |
We make a reasonable effort to choose processors with appropriate security and confidentiality commitments. Processors are bound by service agreements to use the data only for the purposes we instruct.
7. Blockchain Data¶
7.1 Public nature¶
Transactions on the Arbitrum blockchain are public by design. Your wallet address, transaction amounts, and gameplay results are recorded on a public ledger and cannot be deleted or modified.
7.2 Pseudonymity¶
Wallet addresses are not directly tied to your real-world identity. With sufficient on-chain analysis, however, transactions may potentially be linked to a person.
7.3 Limits on data deletion¶
Because of the immutability of the blockchain, on-chain records cannot be erased. Any request to delete personal data (see §9) applies only to off-chain data we hold (email, name, profile data, support tickets, etc.) and not to on-chain transaction records.
8. Data Retention¶
| Data type | Retention period |
|---|---|
| Account data (name, email, DOB) | Duration of account + 5 years after closure |
| Gameplay data (tickets, settlement results, ticket-tips) | 5 years (AML record-keeping) |
| KYC verified-identity records (didit decision data, OCR fields) | 5 years after the verification — append-only |
| Archived KYC document images and selfies (S3, hashed) | 5 years after the verification — append-only |
| Withdraw records and transaction logs | 5 years (financial record-keeping) |
| Support tickets | 5 years after resolution |
| Audit log of regulatory decisions (kyc_audit_log) | Append-only, retained as long as the account |
| Email send log | 12 months |
| Push notification subscriptions | Until you unsubscribe or close the account |
| IP and request logs (Cloudflare, app server) | 30 days |
| On-chain transaction records | Permanent (external, blockchain) |
| Session cookies and locale preference | Per browser cookie lifetime |
After the retention period the relevant off-chain data is securely deleted or anonymized. On-chain data remains visible on the blockchain.
9. Your Data Rights¶
You can ask us to give you a copy of the personal data we hold about you, to correct inaccurate data, or to delete data we are no longer required to keep. To submit a request, email [email protected] from the email address linked to your account. We may ask you to verify your identity before acting on a request, and we will respond within 30 days.
The most common requests are:
- Access — get a copy of your account, profile, gameplay, KYC and communication records.
- Correction — fix inaccurate profile data. Most profile fields can also be edited directly in Account → Edit Profile.
- Deletion — remove off-chain personal data. We will keep records we are required to retain by AML/financial-services law (see §8). On-chain transaction records cannot be deleted (see §7.3).
- Opt out of marketing emails — toggle off "Marketing emails" in Account → Settings, or reply STOP / "unsubscribe" to any marketing email.
- Withdraw consent for push notifications — disable push in Account → Settings or in your browser's notification settings.
10. International Operations¶
Our infrastructure is hosted on Amazon Web Services in Frankfurt, Germany (eu-central-1 region). Some third-party processors listed in §6 operate globally and may process data outside the country in which you reside. By using the Platform you acknowledge that personal data may be processed and stored in jurisdictions other than your own, subject to the security and confidentiality obligations of the processors we engage.
11. Data Security¶
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS/HTTPS) and at rest (AWS-managed encryption, S3 SSE-AES256)
- Database access restricted to the VPC (no public internet exposure)
- Append-only database schema with explicit
REVOKEofUPDATE/DELETEon regulatory tables - Document images archived in a versioned, public-access-blocked S3 bucket with a SHA-256 integrity hash per asset
- Smart-contract-based fund custody (non-custodial architecture — we do not hold player funds in operator wallets)
- Continuous monitoring via automated watchdog jobs
- Role-based access control on the admin panel, with separate roles for support, compliance officer and admin
- Multi-region replication and daily backups of the relational database
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
12. Data Breach Response¶
If we become aware of a personal data breach that is likely to result in material risk to your rights or financial interests:
- We will investigate and contain the incident
- We will notify affected users without undue delay
- We will notify the gaming regulator of our licence jurisdiction in accordance with the applicable rules
- We will document the breach, its effects, and the remedial actions taken
13. Children's Privacy¶
The Platform is for individuals aged 18 and older. We do not knowingly collect personal data from minors. We use AI age estimation at first contact and full document-based age verification at higher-risk thresholds to keep minors off the Platform. If we become aware that a minor has registered, we close the account and delete the associated off-chain data promptly.
14. Cookies and Local Storage¶
14.1 Essential cookies¶
We use a small number of essential cookies and local-storage entries to keep you logged in, maintain your wallet session, and remember your language preference. These are necessary for the Platform to function and cannot be disabled.
14.2 No third-party advertising cookies¶
We do not run advertising cookies and do not embed third-party advertising trackers.
14.3 Analytics¶
We may run lightweight, anonymized analytics to understand Platform usage patterns. No personal data is shared with analytics providers.
14.4 Managing cookies¶
You can manage cookie preferences through your browser settings. Disabling essential cookies will prevent the Platform from functioning correctly.
15. Changes to This Policy¶
We may update this Privacy Policy from time to time. Material changes will be communicated through the Platform at least 14 days before they take effect. The "Last updated" date at the top of this policy indicates the most recent revision.
16. Contact and Complaints¶
For privacy-related inquiries or to exercise your data rights:
- Email: [email protected]
- General support: [email protected]
If you believe your data has been mishandled and we have not resolved your concern, you may also contact the gaming regulator of our licence jurisdiction. The regulator's contact details will be published on the Platform once the licence is issued.
This Privacy Policy was last updated on 2026-06-23.