Skip to content

Privacy Policy

ChainBETs.win — Blockchain Number Game on Arbitrum

Version 3.0 — June 2026 Last updated: 2026-06-23


1. Introduction

ChainBETs ("we", "us", "di Platform") dey respect your privacy. Dis Privacy Policy dey explain wetin personal data we dey collect, why we dey process am, how long we dey keep am, and who we dey share am with when you dey use di Platform.

Di Platform na for players wey dey Africa, Latin America and Southeast Asia we dey operate am. Access from di European Union, di United Kingdom and oda jurisdictions wey we list for our Terms of Service don dey block technically for di network edge.


2. Operator

Di operator wey dey responsible for personal data for di Platform na:

ChainBETs General contact: [email protected] Privacy contact: [email protected] [Operator legal entity & address — to be added by counsel]


3. Data We Dey Collect

3.1 Account Data

  • Wallet address (automatically generated via Web3Auth for signup)
  • Email address (from social login or wey you enter during profile completion)
  • First and last name (wey you enter during profile completion)
  • Date of birth (we need am for age verification)
  • Country of residence (we need am for jurisdictional compliance)
  • Phone number (optional)
  • Display name (optional, we dey use am for greetings and for leaderboard)

3.2 Authentication Data

  • Web3Auth login method (Google, Apple, Email)
  • Social login identifiers (provider's anonymized account ID)

3.3 KYC / Identity Verification Data

When identity verification dey required by our risk policy or by claim thresholds:

  • Government-issued identity document (passport, national ID, or driver's licence)
  • Selfie or live face capture for matching against di document
  • Optional source-of-funds documentation during Enhanced Due Diligence

KYC verification na our third-party provider didit.me dey perform am. didit dey operate di camera capture, OCR, liveness check, face match, and AML/PEP/sanctions screening for im own infrastructure. Once didit return verified result, we dey persist di extracted identity fields (first name, last name, date of birth, nationality, document number, AML status) for our database and archive di original document images for internal storage bucket with SHA-256 integrity hash. Di persisted record na append-only and na di regulatory source of truth — see our AML / KYC Statement for player-facing summary of how di verified record dey relate to your typed profile.

3.4 Gameplay Data

  • Ticket purchases (numbers wey you select, pool, amount, timestamp)
  • Winning numbers and match results
  • Transaction hashes (on-chain references)
  • Bonus and voucher history
  • Spending limits and self-exclusion settings

3.5 Technical Data

  • IP address (for fraud prevention and geo-blocking)
  • Device type and browser information
  • Push notification subscription data (only if you enable browser push)
  • Session cookies and locale preference

3.6 Communication Data

  • Support ticket content
  • Email correspondence
  • Marketing email preferences (newsletter opt-in and marketing-mail opt-out)

4. Why We Dey Process Your Data

We dey process personal data only for di specific purposes wey we list below:

Purpose Type of data wey we dey use
Dey operate your account and dey process ticket purchases / payouts Account, Authentication, Gameplay
Dey verify your age and identity, and dey meet AML obligations KYC, Account
Dey enforce spending limits, self-exclusion and responsible-gaming rules Account, Gameplay
Dey detect and prevent fraud, multi-account abuse and unauthorized access Technical, Gameplay, Account
Dey enforce geographic restrictions Technical
Dey notify you about wins, important changes, and support replies (transactional) Account, Communication
Dey send re-engagement and voucher-expiry reminder emails (marketing) Account, Communication, Gameplay
Dey improve di Platform via aggregated and anonymized analytics Gameplay, Technical

Transactional communications (win notifications, support replies, KYC status updates, withdraw confirmations, regulatory notices) we dey send am regardless of your marketing preferences because dem dey relate to di operation of your account.

Marketing communications (re-engagement and voucher-expiry reminders) we dey send am only while di marketing_emails_enabled preference for your account dey enabled. You fit switch am off anytime for your Account → Settings page.


5. How We Dey Use Your Data

5.1 Platform operation

  • Dey process ticket purchases and payouts
  • Dey manage your account and wallet
  • Dey enforce spending limits and self-exclusion across all wallets wey link to di same verified identity
  • Dey provide customer support and dey handle disputes
  • Dey verify your identity and age
  • Anti-money laundering (AML) screening, including PEP and sanctions matching
  • Dey respond to law enforcement or regulatory requests where law dey compel us
  • Dey maintain transaction and identity records for di periods wey we set for §8

5.3 Security and fraud prevention

  • Dey detect and prevent fraudulent activity
  • Dey enforce geographic restrictions
  • Dey link multiple wallets of di same person via biometric face-match to enforce limits and exclusions consistently
  • Dey protect against unauthorized access

5.4 Communications

  • Dey send transactional emails (wins, KYC status, withdraw confirms, support replies)
  • Dey send push notifications if you don enable am for Account → Settings
  • Dey send marketing emails (re-engagement when you don dey inactive, voucher-expiry reminders 3 days before bonus expire) — only while marketing dey opted in
  • Dey respond to support inquiries

5.5 Platform improvement

  • Dey analyze anonymized gameplay patterns
  • Dey improve user experience
  • Dey generate aggregated statistics (hot/cold numbers, win distribution)

6. Third-Party Data Sharing

We dey share personal data only with di processors wey dey below, and only to di extent wey necessary for dem to provide di service wey we dey use dem for. We no dey sell personal data.

Processor Data wey we share Purpose Hosting region
Web3Auth (Torus Labs) Social-login identifier Authentication & embedded wallet generation Global (vendor-managed)
didit.me Identity document images, selfie, name, DOB, nationality, document number KYC, AML/PEP/sanctions screening, biometric duplicate detection Vendor-managed (Europe)
Resend Email address, email subject, email body Transactional and marketing email delivery Global (vendor-managed)
Chainlink VRF v2.5 None (on-chain consumer contract address only) Verifiable random number generation for draws On-chain
Arbitrum / Alchemy Wallet address, on-chain transactions Blockchain RPC, on-chain reads Global (vendor-managed)
Arbiscan Wallet address and on-chain transactions (already public) Block explorer wey we dey use for transaction lookups Vendor-managed
Cloudflare IP address, request headers CDN, DDoS protection, geo-blocking for di network edge Global edge network
Amazon Web Services (AWS) All operational and persisted data (hosting) Infrastructure hosting (Frankfurt / eu-central-1) Frankfurt, Germany
Telegram (Bot API) Operational alerts only (no player content) Internal incident notifications for our on-call team Vendor-managed
Browser Web Push Push-subscription endpoint and keys (you supply dem by enabling push) Delivery of notifications wey you don explicitly opt into Browser-managed

We dey make reasonable effort to choose processors with appropriate security and confidentiality commitments. Processors dey bound by service agreements to use di data only for di purposes wey we instruct.


7. Blockchain Data

7.1 Public nature

Transactions for Arbitrum blockchain na public by design. Your wallet address, transaction amounts, and gameplay results dey recorded for public ledger and dem no fit delete or modify am.

7.2 Pseudonymity

Wallet addresses no dey directly tied to your real-world identity. With sufficient on-chain analysis, however, transactions fit potentially link to person.

7.3 Limits on data deletion

Because of di immutability of di blockchain, on-chain records no fit erase. Any request to delete personal data (see §9) dey apply only to off-chain data wey we hold (email, name, profile data, support tickets, etc.) and no be to on-chain transaction records.


8. Data Retention

Data type Retention period
Account data (name, email, DOB) Duration of account + 5 years after closure
Gameplay data (tickets, settlement results, ticket-tips) 5 years (AML record-keeping)
KYC verified-identity records (didit decision data, OCR fields) 5 years after di verification — append-only
Archived KYC document images and selfies (S3, hashed) 5 years after di verification — append-only
Withdraw records and transaction logs 5 years (financial record-keeping)
Support tickets 5 years after resolution
Audit log of regulatory decisions (kyc_audit_log) Append-only, retained as long as di account
Email send log 12 months
Push notification subscriptions Until you unsubscribe or close di account
IP and request logs (Cloudflare, app server) 30 days
On-chain transaction records Permanent (external, blockchain)
Session cookies and locale preference Per browser cookie lifetime

After di retention period di relevant off-chain data dey securely deleted or anonymized. On-chain data go remain visible for di blockchain.


9. Your Data Rights

You fit ask us to give you copy of di personal data wey we hold about you, to correct inaccurate data, or to delete data wey we no longer need to keep. To submit request, email [email protected] from di email address wey link to your account. We fit ask you to verify your identity before we act on request, and we go respond within 30 days.

Di most common requests na:

  • Access — get copy of your account, profile, gameplay, KYC and communication records.
  • Correction — fix inaccurate profile data. Most profile fields you fit also edit am directly for Account → Edit Profile.
  • Deletion — remove off-chain personal data. We go keep records wey AML/financial-services law require us to retain (see §8). On-chain transaction records dem no fit delete (see §7.3).
  • Opt out of marketing emails — toggle off "Marketing emails" for Account → Settings, or reply STOP / "unsubscribe" to any marketing email.
  • Withdraw consent for push notifications — disable push for Account → Settings or for your browser's notification settings.

10. International Operations

Our infrastructure dey hosted for Amazon Web Services for Frankfurt, Germany (eu-central-1 region). Some third-party processors wey we list for §6 dey operate globally and dem fit process data outside di country wey you dey. By using di Platform you dey acknowledge say personal data fit dey processed and stored for jurisdictions wey no be your own, subject to di security and confidentiality obligations of di processors wey we engage.


11. Data Security

We dey implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption in transit (TLS/HTTPS) and at rest (AWS-managed encryption, S3 SSE-AES256)
  • Database access wey dem restrict to di VPC (no public internet exposure)
  • Append-only database schema with explicit REVOKE of UPDATE/DELETE on regulatory tables
  • Document images wey dem archive for versioned, public-access-blocked S3 bucket with SHA-256 integrity hash per asset
  • Smart-contract-based fund custody (non-custodial architecture — we no dey hold player funds for operator wallets)
  • Continuous monitoring via automated watchdog jobs
  • Role-based access control for di admin panel, with separate roles for support, compliance officer and admin
  • Multi-region replication and daily backups of di relational database

No method of transmission over di Internet or electronic storage dey 100% secure. While we dey strive to use commercially acceptable means to protect your data, we no fit guarantee absolute security.


12. Data Breach Response

If we become aware of personal data breach wey likely go result in material risk to your rights or financial interests:

  • We go investigate and contain di incident
  • We go notify affected users without undue delay
  • We go notify di gaming regulator of our licence jurisdiction in accordance with di applicable rules
  • We go document di breach, im effects, and di remedial actions wey we take

13. Children's Privacy

Di Platform na for individuals wey don reach 18 years and above. We no dey knowingly collect personal data from minors. We dey use AI age estimation for first contact and full document-based age verification for higher-risk thresholds to keep minors off di Platform. If we become aware say minor don register, we go close di account and delete di associated off-chain data promptly.


14. Cookies and Local Storage

14.1 Essential cookies

We dey use small number of essential cookies and local-storage entries to keep you logged in, maintain your wallet session, and remember your language preference. Dem dey necessary for di Platform to function and dem no fit disable am.

14.2 No third-party advertising cookies

We no dey run advertising cookies and we no dey embed third-party advertising trackers.

14.3 Analytics

We fit run lightweight, anonymized analytics to understand Platform usage patterns. No personal data we dey share with analytics providers.

14.4 Managing cookies

You fit manage cookie preferences through your browser settings. If you disable essential cookies e go prevent di Platform from functioning correctly.


15. Changes to This Policy

We fit update dis Privacy Policy from time to time. Material changes we go communicate am through di Platform at least 14 days before dem take effect. Di "Last updated" date wey dey top of dis policy dey indicate di most recent revision.


16. Contact and Complaints

For privacy-related inquiries or to exercise your data rights:

If you believe say dem don mishandle your data and we never resolve your concern, you fit also contact di gaming regulator of our licence jurisdiction. Di regulator's contact details we go publish am for di Platform once we get di licence.


We last update dis Privacy Policy for 2026-06-23.