The privacy policy governs how user information is collected, processed, and safeguarded across the Cybet Online Casino and sports betting platform. This document applies to every visitor and registered player accessing the services from any available region. This page covers the types of information gathered, the legal grounds for processing it, player rights, and the technical measures protecting every crypto transaction and account interaction. Reviewing this document helps users understand how the platform handles personal data and what control mechanisms are available to every registered player.

Personal Data Collection by Cybet
Two categories of information are gathered through the platform: data provided directly by users and technical data captured automatically during browsing sessions. The privacy framework treats each category with specific handling protocols tied to operational, security, and legal requirements.
Registration requires only an email address. The platform operates on a No-KYC-friendly basis, so most players begin without submitting identity documents. Additional verification may be requested for fraud prevention, anti-money laundering compliance, or when local regulations demand it.
| Category | Data Type | When Collected |
| Personal Information | Email address | Registration |
| Personal Information | Full name | Verification (if triggered) |
| Personal Information | Date of birth | Age verification |
| Personal Information | Crypto wallet address | Deposits and withdrawals |
| Personal Information | Contact details | If voluntarily provided |
| Technical Data | IP address | Automatic |
| Technical Data | Browser type and version | Automatic |
| Technical Data | Device and OS information | Automatic |
| Technical Data | Pages visited, session duration | Automatic |
| Technical Data | Access times, referral sources | Automatic |
Wallet addresses are stored to process deposits and withdrawals across 12 supported cryptocurrencies, including Bitcoin, Ethereum, USDT, and Solana. All collected data serves specific purposes — no information is gathered beyond what platform functionality demands.
Legal Basis for Data Processing
Every action involving user data — from account creation to transaction monitoring — requires justification under applicable regulations. The privacy framework defines four lawful grounds for handling personal information on the platform.
The following grounds apply to all processing activities:
- Contractual necessity: when a player registers and uses the services, the platform processes data required to fulfill its agreement with the user, covering account management and transaction execution.
- Legitimate interest: fraud detection, risk monitoring, and platform security fall under this category. Unusual login activity or device changes may trigger additional security checks.
- Legal obligation: anti-money laundering requirements and gambling regulations may compel the operator to collect and retain certain records, including identity documentation when requested.
- User consent: marketing communications and non-essential cookies require explicit agreement before activation.
Transaction security relies on on-chain processing, TLS/HTTPS encryption, and two-factor authentication through Google Authenticator. Withdrawal requests may need email confirmation or 2FA verification, and large or higher-risk payouts can undergo manual review.
After analyzing the platform’s operational model under the Anjouan license, these processing grounds cover the vast majority of data interactions between players and the service.
Cookies and Tracking Technologies
Small data files and scripts are deployed across the platform to monitor site performance and manage the browsing experience. These tools play a direct role in how the privacy framework handles non-personal data collection.
The following types are in use:
- Essential cookies: required for core functions such as login sessions, language preferences, and security tokens. Disabling these may prevent access to key features.
- Analytics cookies: track page visits, session duration, and referral sources, helping identify performance issues and optimize the interface.
- Functional cookies: store player settings and preferences between visits, reducing the need to reconfigure options on each return.
- Third-party cookies: used by external service providers for analytics and performance measurement. These partners operate under their own data handling policies.
Browser settings allow managing cookie preferences at any time. Most browsers support blocking or deleting specific cookies, though doing so may limit certain features.
The platform does not use cookies for advertising or to build external marketing profiles. All tracking data follows retention standards — kept only as long as needed for operational and compliance requirements.
Third-Party Data Sharing Protocols
Strict conditions govern when user information may be transferred to external entities. The privacy framework prohibits the sale of personal data under any circumstances.
Transfer to external entities occurs only in these situations:
- Service providers: trusted partners supporting platform operations — hosting infrastructure, analytics tools, and customer support systems. These providers are bound by confidentiality agreements and may only use data for specified purposes.
- Legal and regulatory requests: government authorities or law enforcement may request user data through lawful processes. The operator complies when legally obligated.
- Business restructuring: if the company undergoes a merger, acquisition, or asset sale, user data may transfer as part of that transaction. Affected users would receive notification of any ownership change.
- Security incidents: when suspected fraud, abuse, or unauthorized account activity is detected, relevant data may be shared with security partners or authorities to investigate the issue.
Wallet addresses, transaction history, and account balances are never shared with marketing companies or data brokers. All third-party recipients must meet internal data protection standards before receiving access to user information. Cryptocurrency transaction records remain protected under the same sharing restrictions applied to all other personal data on the platform.

User Privacy Rights and Data Control
Several mechanisms allow players to manage and control how their personal information is processed. Available rights may vary depending on location and applicable laws.
| Right | Description |
| Access | Request a copy of all personal data held by the platform |
| Correction | Ask to fix inaccurate or incomplete records |
| Deletion | Request removal of personal data from the systems |
| Restriction | Limit specific types of data processing |
| Objection | Object to certain processing activities |
Response time for data requests typically falls within 30 calendar days. Some requests may take longer if they involve large data volumes or require legal review.
Transaction records and certain account data cannot be deleted while an account remains active — regulatory compliance demands retention. After account closure, only the minimum data required by law is kept, then removed once retention periods expire.
The 24/7 live chat and email support at [email protected] handle all privacy-related inquiries and data rights requests.
Policy Updates and Breaches
Changes to the privacy framework and responses to data security incidents follow established procedures.When the policy is revised:
- A new version is published on the website with an updated effective date.
- Registered users receive notification of material changes through email or platform announcements.
- Continued use of services after an update constitutes acceptance of revised terms.
If a data breach occurs, the following response protocol is activated:
- Containment: the security team isolates affected systems to stop further unauthorized access.
- Impact assessment: the scope of compromised data, affected accounts, and potential risk level are determined.
- User notification: affected individuals receive details as soon as reasonably possible, including recommended protective steps.
- Regulatory reporting: where required by law, relevant authorities are notified within mandated timeframes.
- Remediation: corrective measures are implemented to prevent recurrence. Account credentials may be reset or re-verification required.
Account security features — email verification, 2FA via Google Authenticator, and continuous activity monitoring — serve as frontline defenses against unauthorized access and potential breaches.