WinWin Somalia - main content

WinWin Somalia Privacy Policy – Personal Data, Security and User Rights

Personal information can be collected when a visitor uses account features, sends a support request, submits verification details or interacts with technical services such as cookies and security logs. Privacy controls should focus on collecting only what is necessary, protecting it appropriately and keeping it only for as long as there is a valid reason.

Types of information that may be processed

Data collection should stay proportionate to a specific purpose. If an action can be completed with fewer details, there is no practical reason to request unrelated information.

For “Types of information that may be processed”, a useful rule is to provide no more data, money or permissions than the action requires and to stop when an important condition is unclear.

Why information may be used

Common purposes include operating account features, preventing fraud, responding to support requests, maintaining security, meeting legal or compliance requirements and improving technical stability. A purpose should be connected to a legitimate service need rather than an unlimited right to reuse information for unrelated reasons.

Data categoryTypical purpose
Contact detailsAccount notices, recovery and support
Security logsFraud prevention and suspicious-login review
Verification dataIdentity, age and account-control checks
Transaction referencesPayment reconciliation and dispute handling
Device informationTechnical troubleshooting and security analysis

Voluntary fields should contain only what is needed. General contact forms are not a suitable place for document numbers, full payment details or other sensitive information unless those details are explicitly required.

Identity documents

Identity documents contain sensitive information and should be submitted only through an official verification channel when required. Sending documents through social media, an unknown messaging account or an unverified email address increases the risk of misuse. A user should not disclose passwords or one-time security codes together with identity documents.

Different purposes should remain separate. Information needed for an account, security check, payment or support request should not automatically be reused for an unrelated purpose without a clear basis.

Data sharing

Some processing can involve payment providers, hosting services, security vendors or other processors needed to operate a service. Sharing should be limited to the information required for the relevant function. A payment provider, for example, may need transaction data without needing unrelated support history.

Data minimisation also applies to internal access. Limiting the number of people and systems that can view a record reduces the chance of accidental disclosure or use outside the original purpose.

Retention

Different records can require different retention periods. Security logs may be useful for investigating suspicious activity, while support records may be kept to resolve ongoing issues. Information should not be retained indefinitely without a business, legal or security reason.

Browser identifiers can support sessions, security or measurement. Their function and retention period matter more than the technical label, so essential and optional uses should be considered separately.

User choices and requests

Depending on applicable rules and the service involved, a person may be able to ask what personal information is held, request correction of inaccurate details or raise questions about processing. Some records cannot be deleted immediately when they must be retained for fraud prevention, dispute resolution or legal obligations.

VIEW GAMES

Technical logs help detect unusual access, faults and attempted abuse. They should contain only what is reasonably required for security, diagnostics and accountability.

Account and device security

Privacy also depends on the user’s own device. Shared browsers can retain login sessions, downloaded documents and autofill information. A strong screen lock, unique account password and careful handling of verification messages reduce accidental disclosure.

Retention should match the original purpose. Once information is no longer needed, deletion or anonymisation is preferable unless there is a legitimate reason to keep it for a defined period.

Children and age restrictions

Gambling services are intended for adults and should not be used by anyone under 18. Age-verification controls are designed to prevent minors from opening or using gambling accounts. A parent or guardian who believes a minor’s information has been used should contact the relevant service through an official channel.

Security includes encryption, access control and change records. Users also need to protect the device, email account and recovery credentials connected to their account.

Security incidents

If an account holder suspects that personal information has been exposed, the first steps are to secure the email account, change compromised passwords, review active sessions and check recent transactions. Support should be contacted through a verified route if account activity appears unauthorized.

Access, correction and deletion requests work best when the user states exactly what is being requested. A precise request reduces the need to collect extra details during verification.

Updated 2026-08-20