Six Commitments malbat Makes to Every Player
Our privacy programme is built on these core principles — they govern every decision we make about your personal data.
Data Rights Every malbat Player Holds
The following rights are available to all malbat account holders. To exercise any right, email [email protected] with your registered username and a description of your request.
1 Introduction
This Privacy Policy ("Policy") describes how malbat ("the Platform", "we", "us", "our") collects, uses, stores, discloses, and protects personal data relating to individuals ("you", "the User", "the Player") who access or use the malbat website at malbat.bio and any associated services, mobile interfaces, or subdomains.
malbat is committed to handling personal data responsibly, transparently, and in accordance with recognised data protection principles. This Policy is intended to give you a clear understanding of our data practices so that you can make informed decisions about using the Platform.
This Policy should be read alongside the malbat Terms & Conditions, which form part of the overall agreement between you and malbat. Defined terms used but not defined in this Policy carry the meaning given to them in the Terms & Conditions. This Policy is effective as of 1 January 2026.
2 Data We Collect
2.1 Registration Data
When you create a malbat account, we collect the personal information you provide during the registration process. This includes your full legal name, date of birth, email address, mobile phone number, and residential address. This data is required to verify your identity, confirm your eligibility to use the Platform (including the 18+ age requirement), and to establish your account.
2.2 Identity Verification (KYC) Data
As part of our Know Your Customer process, malbat may collect copies of government-issued identity documents (such as a National ID card, passport, or driving licence), proof of residential address (such as a utility bill or bank statement dated within the last three months), and confirmation of payment method ownership. These documents are collected to meet responsible gaming and anti-money-laundering obligations and are handled with the highest level of confidentiality.
2.3 Financial and Transaction Data
malbat collects records of all deposits, withdrawals, bets, game sessions, and bonus transactions associated with your account. This includes transaction amounts in Bangladeshi Taka (৳), timestamps, payment method identifiers (e.g., your bKash or Nagad wallet reference), and transaction status. Full payment card numbers are never stored on malbat servers — payment processing is handled by PCI-DSS compliant third-party processors.
2.4 Technical and Usage Data
When you access malbat, we automatically collect certain technical data including your IP address, browser type and version, operating system, device type and identifiers, referring URL, pages visited, session duration, and clickstream data. This information is used for platform security, fraud prevention, performance optimisation, and aggregate analytics. It does not, on its own, identify you as a specific individual but may be combined with account data for security and compliance purposes.
2.5 Communication Data
We retain records of communications between you and the malbat support team, including emails sent to [email protected], live chat transcripts (where applicable), and any dispute or complaint correspondence. These records are maintained to resolve disputes, improve service quality, and meet regulatory obligations.
2.6 Responsible Gaming Data
Where you utilise malbat's responsible gaming tools — such as setting deposit limits, requesting a cooling-off period, or initiating self-exclusion — we collect and retain records of those requests. This data is essential to honour your instructions and to protect your wellbeing as a player. It is processed with a high degree of sensitivity and is accessible only to relevant compliance and support personnel.
2.7 Data You Provide Voluntarily
From time to time you may provide additional data voluntarily, for example when completing a player survey, entering a promotion, or providing feedback. Such data is used solely for the stated purpose of the interaction and is not added to your core account profile without your explicit consent.
3 How We Use Your Data
malbat uses the personal data we collect for the following specific purposes:
| Purpose | Data Used |
|---|---|
| Account creation and management | Registration data, KYC documents |
| Identity and age verification (18+) | Name, date of birth, KYC documents |
| Processing deposits and withdrawals | Financial data, payment method identifiers |
| Fraud detection and prevention | Technical data, transaction data, IP address |
| Responsible gaming compliance | Transaction data, responsible gaming records |
| Customer support and dispute resolution | Communication data, account data |
| Platform security and integrity | Technical data, usage data |
| Promotional communications (with consent) | Email address, account preferences |
| Legal and regulatory compliance | All categories as required |
| Platform analytics and improvement | Aggregated, anonymised usage data |
malbat does not use your personal data for any purpose not listed above without first obtaining your explicit consent or being required to do so by applicable law.
4 Legal Basis for Processing
malbat processes personal data on one or more of the following legal bases depending on the nature of the processing activity:
- Contractual necessity: Processing required to perform the contract between you and malbat — for example, creating your account, processing your deposits, and settling your bets;
- Legal obligation: Processing required to comply with applicable laws — for example, identity verification (KYC), anti-money-laundering obligations, and responsible gaming requirements;
- Legitimate interests: Processing conducted for malbat's legitimate business interests — for example, fraud prevention, platform security, and aggregate analytics — provided these interests are not overridden by your rights and freedoms;
- Consent: Processing based on your explicit, freely given consent — for example, sending you promotional emails or personalised offers. You may withdraw consent at any time by contacting [email protected] or using the communication preferences settings in your account.
5 Data Sharing & Disclosure
5.1 Third-Party Service Providers
malbat engages carefully selected third-party service providers who process personal data on our behalf strictly to enable us to deliver the Platform. These providers include payment processors (for bKash, Nagad, Rocket, Upay, Visa, and Mastercard transactions), identity verification and KYC services, fraud prevention and anti-money-laundering analytics providers, cloud infrastructure and hosting services, and customer support tooling. All such providers are contractually bound to process data only on malbat's documented instructions and to maintain appropriate technical and organisational security measures.
5.2 Game Studio Providers
Certain casino and live casino games on the malbat platform are operated by third-party game studios including Evolution Gaming, Pragmatic Play, NetEnt, Microgaming, Habanero, Spribe, and Ezugi. To facilitate game play, these studios may receive limited session data (such as a pseudonymous session token and account tier information). malbat does not transmit your full name, contact details, or financial data to game studios.
5.3 Legal Disclosures
malbat may disclose personal data to competent regulatory, judicial, or law enforcement authorities where required to do so by applicable law, court order, or where malbat has a good-faith belief that such disclosure is reasonably necessary to protect the rights, property, or safety of malbat, its players, or the public. In such cases, malbat will disclose only the minimum data required to satisfy the legal obligation.
5.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of malbat's business assets, personal data held by malbat may be transferred to the acquiring entity. If such a transfer occurs, malbat will notify affected users via email or a prominent notice on the Platform prior to the transfer taking effect, and the acquiring entity will be required to honour the commitments set out in this Policy.
5.5 No Commercial Data Sales
malbat does not sell, rent, lease, or otherwise commercially exploit your personal data to any third party for their own marketing or commercial purposes. This commitment applies without exception and is a core principle of the malbat privacy programme.
6 Cookies & Tracking Technologies
6.1 What Are Cookies?
Cookies are small text files placed on your device by a website when you visit it. They allow the website to remember information about your visit — such as your language preferences, login session, or items in a basket — and to collect usage analytics. malbat uses cookies and similar technologies including local storage and session storage to operate and improve the Platform.
6.2 Types of Cookies Used by malbat
- Strictly necessary cookies: These cookies are essential for the Platform to function correctly. They enable core features such as session authentication, account security, and navigation. These cookies cannot be disabled without impairing your ability to use malbat.
- Analytical cookies: These cookies allow malbat to measure and analyse how visitors use the Platform — for example, which pages are most visited, how long sessions last, and where users encounter errors. The data collected is aggregated and anonymised.
- Functional cookies: These cookies remember choices you make — such as your preferred language or display settings — to provide a more personalised experience.
- Marketing and preference cookies: Where you have given consent, these cookies allow malbat to deliver more relevant promotional communications and to measure the effectiveness of marketing campaigns.
You may manage cookie preferences via your browser settings. Disabling certain categories of cookies may affect the functionality of the malbat platform. Strictly necessary cookies cannot be disabled.
7 Data Retention
malbat retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, or for as long as required by applicable law. The following general retention principles apply:
- Active account data: Retained for the full duration of your account relationship with malbat;
- Closed account data: Following account closure, core identity and transaction records are retained for a minimum period required to meet anti-money-laundering and responsible gaming regulatory obligations — typically between 5 and 7 years from the date of closure;
- KYC documents: Retained for the duration of the account relationship plus the legally mandated post-closure period;
- Communication records: Customer support communications are retained for 3 years from the date of the last interaction, or longer where they relate to an unresolved dispute;
- Technical and usage data: Aggregated analytics data may be retained indefinitely in anonymised form. IP address logs and session data are retained for up to 12 months for security and fraud prevention purposes.
Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised in accordance with malbat's internal data destruction procedures.
8 Data Security
malbat implements a comprehensive set of technical and organisational security measures designed to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. Key security measures include:
- 256-bit SSL/TLS encryption for all data in transit between your device and malbat servers;
- Encryption at rest for all sensitive personal data and financial records stored on malbat infrastructure;
- Access controls: Personal data is accessible only to malbat personnel and authorised third-party processors who have a documented need to access it for the performance of their specific role. All access is logged and subject to regular audit;
- Multi-factor authentication required for all malbat staff accounts with access to production systems;
- Regular security assessments including vulnerability scanning and penetration testing conducted by independent security professionals;
- Incident response plan: malbat maintains a documented data breach response plan that defines the steps to be taken in the event of a confirmed or suspected security incident, including notification timelines.
While malbat takes all reasonable steps to protect your personal data, no method of electronic transmission or storage is 100% secure. Players are reminded to use strong, unique passwords for their malbat account and to enable any available two-factor authentication features. You are responsible for maintaining the security of your login credentials.
9 Your Rights
As a user of the malbat platform, you hold the following rights in respect of your personal data. To exercise any of these rights, please submit a written request to [email protected] with your registered username and a clear description of your request. malbat will acknowledge your request within 5 business days and provide a substantive response within 30 calendar days. In complex cases, this period may be extended by a further 30 days, and you will be informed of any such extension.
- Right of access: You may request a copy of all personal data malbat holds about you, free of charge;
- Right to rectification: You may request correction of any inaccurate or incomplete personal data without undue delay;
- Right to erasure: You may request deletion of your personal data where it is no longer necessary for its original purpose, subject to malbat's legal obligations to retain certain records;
- Right to restrict processing: You may request that malbat temporarily pause processing of your data while accuracy or lawfulness is assessed;
- Right to data portability: You may request your personal data in a structured, commonly used, machine-readable format, and have it transmitted to another data controller where technically feasible;
- Right to object: You may object to processing based on legitimate interests or for direct marketing purposes at any time. malbat will cease such processing immediately upon receipt of a valid objection unless compelling legitimate grounds exist that override your interests;
- Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
Please note that certain rights are subject to limitations. For example, the right to erasure does not apply where malbat is legally required to retain certain records. malbat will explain any applicable limitation clearly in its response to your request.
10 Children's Privacy
The malbat platform is strictly intended for adults aged 18 years and above. malbat does not knowingly collect personal data from individuals under the age of 18. During the registration process, all users are required to confirm their date of birth, and age verification is conducted as part of the KYC process. If malbat becomes aware that it has inadvertently collected personal data from a person under the age of 18, it will take immediate steps to delete that data, close the associated account, and refund any deposits made by the underage individual. If you have reason to believe that a minor has registered on the malbat platform, please notify us immediately at [email protected].
11 Third-Party Links
The malbat website may contain links to third-party websites or services, for example in the context of payment method information or game studio descriptions. malbat does not control and is not responsible for the privacy practices of those third-party sites. This Privacy Policy applies solely to the malbat platform at malbat.bio. We encourage you to review the privacy policies of any third-party services you visit before providing them with your personal data.
12 Changes to This Policy
malbat reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data practices, legal obligations, or regulatory requirements. Where a material change is made, malbat will provide reasonable prior notice to registered users via email and/or a prominent notice on the Platform. The effective date at the top of this Policy will be updated to reflect the date of the most recent revision. Your continued use of the malbat platform following the effective date of any revision constitutes your acceptance of the updated Policy. If you do not agree to the updated Policy, please discontinue use of the Platform and request account closure by contacting support.
13 Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or to malbat's data protection practices, please contact the malbat privacy team. malbat is committed to resolving privacy queries promptly and transparently. Our support team serves players across Bangladesh including those in Dhaka, Chittagong, Sylhet, Khulna, Rajshahi, Barisal, Rangpur, and Mymensingh.
Email: [email protected]
Please include your registered username, a clear description of your query or request, and the right(s) you wish to exercise in your correspondence. If your request relates to a suspected data breach or unauthorised access to your account, please mark your subject line URGENT — DATA SECURITY to ensure prioritised handling. malbat aims to acknowledge all privacy-related correspondence within 5 business days.
Your Privacy is Protected — Now Explore the Platform
You have reviewed the malbat Privacy Policy. Log in to your account, browse live cricket outright markets, explore the casino, or check the FAQ if you have further questions. 18+ only. Please play responsibly.