01Scope
This policy governs all data collected or processed in the course of using BetPin's website, applications, and services. Using the platform constitutes awareness of the provisions of this document.
02Data We Collect
- Account information — email, name, country, and display settings.
- Transaction data — amounts, blockchain networks, wallet addresses, and deposit/withdrawal times.
- Activity data — betting history, login sessions, and account security events.
- Technical data — IP address, device and browser type, and technical error logs.
The platform collects only the data necessary to provide its services and meet its legal obligations (the data-minimization principle).
03Basis and Purposes of Processing
Your data is processed only on the following bases:
- Performance of a contract — providing account, betting, and settlement services.
- Legal obligations — complying with anti-money-laundering requirements and responding to competent authorities.
- Legitimate interests — preventing fraud, ensuring security, and improving service quality.
Your data is never sold or rented to third parties for marketing purposes.
04Storage and Retention Period
Data is stored on servers encrypted to the AES-256 standard. In line with legal requirements, account data and transaction records are retained for up to 7 years after an account is closed and are then permanently and irreversibly deleted.
Note: Upon receiving an official order from competent authorities, the platform is obliged to provide the relevant information.07Your Rights
Under the GDPR and similar frameworks, you have the right to:
- Receive a copy of your data (the right of access and portability).
- Request correction of inaccurate or incomplete data.
- Request deletion of your account and related data (the right to be forgotten) — except where retention is a legal requirement.
- Request restriction of, or object to, certain processing.
To exercise any of these rights, send your request to [email protected]. A response is provided within a maximum of 30 days.
08Data Security
Passwords are hashed with the bcrypt algorithm and are never stored in plain text. All network communications are encrypted with TLS 1.3. Staff access to data is restricted on a least-privilege basis, and all access is logged and auditable.
09Data Breach Notification
In the event of a security incident that puts user data at risk, the platform is obliged to notify the competent authorities and affected users within a maximum of 72 hours and to report the remedial measures transparently.
10Minors
The platform does not knowingly collect any data from persons under 18 years of age. If an account is found to belong to a minor, it is immediately suspended and the balance is returned to the legal guardian after the official process.
11Updates to This Policy
Any change to this policy is announced at least 30 days before it takes effect via email and in-app notification, and the new date and version are noted at the top of this page.