oppatoto User Data Privacy and Protection Policy
Your privacy is our priority. This document transparently explains how oppatoto collects, uses, stores, and protects your personal information as a user of our platform in Malaysia.
Effective date: 1 January 2026. This policy applies to all oppatoto platform users.
1 What information do we collect from you?
When you register and use the oppatoto platform, we collect several categories of information to enable us to deliver a safe, accurate, and responsible service:
- Account information: Full name, email address, phone number, date of birth, and encrypted password collected during the registration process.
- Payment information: Details of the payment method you use for deposits or withdrawals in MYR (RM), including e-wallet information and bank account details required for transaction processing.
- Device and browser information: Device type, operating system, browser version, IP address, time zone, and language settings — used to optimise your platform experience.
- Usage data: Pages visited, features used, session duration, bets placed, and transaction history within the platform.
- Cookies and tracking technologies: Data collected via cookies, session tokens, and device identifiers for authentication and security purposes.
We do not collect information beyond what is necessary to operate the platform. Every category of data collected has a clear and legitimate purpose.
2 What is that information used for?
Oppatoto uses the information collected solely for legitimate purposes directly related to providing our services to you:
- Account management: Processing your registration, verifying your identity, and managing your account settings.
- Transaction processing: Enables secure and accurate deposits, withdrawals, and account balance management in MYR.
- Platform security: Detecting and preventing fraud, unauthorised access, and suspicious activity on your account.
- Service improvement: Analysing usage patterns to improve platform performance, user interface, and mobile experience.
- Legal compliance: Complying with applicable Malaysian legal requirements, including anti-money laundering policies and identity verification obligations.
- Service communications: Sending important notifications regarding your account, transactions, and policy updates via email or in-app notifications.
Oppatoto will not use your data for third-party advertising purposes or sell it to any external company without your consent.
3 Cookies and tracking technologies — what you need to know
The oppatoto platform uses cookies and similar tracking technologies to ensure the platform operates correctly and securely. Below are the types of cookies we use:
- Session cookies (required): Required to maintain your login session, remember your language preference, and ensure session security while you use the platform.
- Preference cookies: Saving your personal settings such as preferred language and display layout for a more comfortable experience.
- Analytics cookies: Collecting anonymised usage data to help us understand how users interact with the platform and identify areas for improvement.
You can manage your cookie settings through your browser. Please note, however, that disabling required cookies may affect core platform functionality and the security of your login session.
4 Data storage, security, and third-party sharing
Storage and security: All personal data you share with oppatoto is stored on servers protected with industry-standard SSL encryption. Passwords are stored in a hashed format that cannot be read without the encryption key. We conduct regular security reviews to ensure our infrastructure remains current and secure.
Retention period: Active account data is retained for as long as your account remains active. Following account closure, data will be kept for the minimum period required under Malaysian law before being securely deleted.
Third-party sharing: oppatoto does not sell or rent your personal data to third parties for marketing purposes. However, we may share your data in the following limited circumstances:
- Payment service providers who process your MYR transactions — limited strictly to the information required to complete the transaction.
- Malaysian regulatory authorities or law enforcement agencies when required to do so by law.
- Technical service providers who assist us in operating the platform — subject to strict confidentiality agreements.
5 Your rights as a user over your personal data
As an oppatoto platform user, you have the following rights with respect to your personal data:
- Right to access: You have the right to request a copy of the personal data we hold about you at any time. Such requests will be processed within 14 business days.
- Right to correction: If any information we hold is inaccurate or out of date, you have the right to request a correction. Much of this information can also be updated directly through your account profile settings.
- Right to erasure: You may request the deletion of your account and associated data, subject to minimum retention requirements mandated under Malaysian law.
- Right to object: You have the right to object to the processing of your data for certain purposes that are not fundamental to the service.
To submit any request related to your data rights, please contact our privacy team by email at [email protected] with a clear description of your request. We are committed to handling every request thoroughly and within a reasonable timeframe.
6 Policy changes and how to contact us
Oppatoto reserves the right to update or modify this Privacy Policy at any time to reflect changes in our practices, legal requirements, or platform improvements. When significant changes are made, we will notify users via in-platform notifications or by email to the address registered to your account.
The latest version of this Privacy Policy is always available on this page, with the effective date clearly stated. It is your responsibility to review this page periodically. Continued use of the platform following any changes constitutes your acceptance of the updated policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or the way oppatoto handles your personal data, please reach out to us:
- Email: [email protected]
- Email subject: Please include "Privacy Enquiry" in your email subject line
- Response time: We will endeavour to respond within 5 business days
This Privacy Policy is governed by the laws of Malaysia, including the Personal Data Protection Act 2010 (PDPA), which sets the standard for personal data protection in Malaysia.