📅 Last Updated: 1 June 2026
1. Who We Are
This Privacy Policy applies to the online gaming platform operated under the brand name shell99, accessible at shell99.one and all associated subdomains and mobile web interfaces (collectively, the "Platform").
For the purposes of this Privacy Policy, shell99 is the data controller responsible for your personal data. When we refer to "shell99", "we", "us", or "our", we mean the operating entity that owns and runs the shell99 Platform. When we refer to "you", "your", or "Member", we mean any individual who accesses or registers on the Platform.
shell99 serves players primarily in Malaysia, including Kuala Lumpur, Penang, Johor Bahru, Petaling Jaya, Bangsar, and across all Malaysian states. This Policy is written in compliance with internationally recognised data protection principles and applicable privacy obligations.
If you have any questions about this Policy or how we handle your personal data, please contact us using the details set out in Section 14.
2. Data We Collect
shell99 collects personal data from you in a number of ways. The categories of personal data we collect include:
2.1 Registration & Account Data
- Full legal name as it appears on your government-issued identification.
- Date of birth (for age verification — shell99 requires all Members to be 21 years of age or older).
- Email address and chosen username.
- Residential address, including postcode and state.
- Mobile phone number (for SMS OTP and two-factor authentication).
2.2 Identity Verification (KYC) Data
- Copy of a valid government-issued photo identification document (Malaysian IC or passport).
- Proof of residential address (utility bill, bank statement, or equivalent), where required.
- Proof of payment method ownership (screenshot or document linking the payment method to your identity), where required.
- Facial verification data, if required by our KYC process at the time of your account verification.
2.3 Financial Transaction Data
- Deposit and withdrawal amounts, dates, and payment method identifiers (e.g., partial Touch n Go eWallet reference, last four digits of bank account).
- Transaction history associated with your shell99 Account.
2.4 Gaming Activity Data
- Game session logs, including games played, bets placed, outcomes, and timestamps.
- Sportsbook betting history, including markets bet on and amounts wagered.
- Bonus usage and wagering progress data.
- Responsible gaming settings and self-exclusion status.
2.5 Technical & Device Data
- IP address and approximate geolocation derived from IP.
- Device type, operating system, and browser information.
- Login timestamps and session duration data.
- Cookie identifiers and related tracking data (see Section 6).
2.6 Communications Data
- Records of your communications with shell99 support, including live chat transcripts and email correspondence.
- Survey responses and feedback you voluntarily submit to shell99.
3. How We Use Your Personal Data
shell99 uses your personal data for the following purposes:
- Account creation and management: To register your shell99 Account, verify your identity, maintain your account settings, and manage your ongoing relationship with the Platform.
- Age verification and KYC compliance: To verify that you are 21 years of age or older and to comply with Know Your Customer obligations required by our operating licence.
- Payment processing: To process your deposits and withdrawals via Touch n Go eWallet, Boost, GrabPay, Maybank, CIMB, Public Bank, and other supported payment methods.
- Game provision and personalisation: To deliver casino games, live dealer tables, and sportsbook markets, and to personalise your gaming experience based on your activity history and preferences.
- Bonus and promotion management: To award applicable bonuses, track wagering progress, and communicate relevant promotional offers to your Account.
- Security and fraud prevention: To monitor login activity, detect suspicious transactions, and protect your Account and the integrity of the shell99 Platform against fraud, collusion, and money laundering.
- Legal and regulatory compliance: To comply with applicable laws, respond to regulatory inquiries, and fulfil our obligations under our gaming operating licence.
- Responsible gaming: To monitor gaming patterns for signs of problem gambling, enforce self-exclusion requests, and apply deposit limits and session reminders as configured by you.
- Customer support: To respond to your support enquiries, resolve disputes, and improve our service quality based on your feedback.
- Platform improvement: To analyse aggregate usage patterns and technical performance data for the purpose of improving the shell99 Platform.
4. Legal Basis for Processing
shell99 processes your personal data on the following legal bases:
- Performance of contract: Processing necessary to provide you with your shell99 Account and the associated gaming services you have requested.
- Legal obligation: Processing required to comply with applicable laws, regulatory requirements, and our gaming operating licence — including age verification, KYC, anti-money laundering checks, and responsible gaming obligations.
- Legitimate interests: Processing necessary for fraud prevention, platform security, abuse detection, and service improvement, where those interests are not overridden by your privacy rights.
- Consent: Where we rely on your consent for specific processing activities (such as marketing communications), we will obtain that consent explicitly and you may withdraw it at any time by contacting support or adjusting your Account notification settings.
5. Data Sharing & Disclosure
shell99 does not sell your personal data to third parties. We share your data only in the following limited circumstances:
- Game providers: Your session data is shared with licensed game software providers (e.g., live casino studio operators, slot game developers) solely to the extent necessary to deliver the games to your Account. These providers are contractually bound to process your data only for this purpose.
- Payment processors: Your financial transaction data is shared with payment service providers (including Touch n Go eWallet, Boost, GrabPay, and bank FPX systems) to process deposits and withdrawals. Payment processors are required to protect your data in accordance with applicable financial regulations.
- KYC and identity verification partners: Your identity documents and verification data are shared with our authorised KYC verification service provider for the purpose of age and identity verification. This provider processes your data under strict contractual data protection obligations.
- Fraud prevention and security services: Technical and behavioural data may be shared with third-party fraud detection services to protect the Platform and our Members.
- Legal and regulatory authorities: We may disclose your personal data to law enforcement agencies, regulatory bodies, or courts where we are legally required to do so, where we have a good-faith belief that such disclosure is necessary to prevent harm or financial crime, or where required by our gaming operating licence.
- Business transfers: In the event of a merger, acquisition, or sale of shell99's business assets, your personal data may be transferred to the acquiring entity, subject to equivalent data protection obligations.
⚠️ Important: shell99 will never sell, rent, or trade your personal data to third-party advertisers or data brokers.
6. Cookies & Tracking Technologies
shell99 uses cookies and similar tracking technologies on the Platform for the following purposes:
- Essential cookies: Required for the Platform to function correctly, including session management, login state maintenance, and security token validation. These cookies cannot be disabled without impairing Platform functionality.
- Analytics cookies: Used to collect aggregate, anonymised data about how Members use the Platform — including which pages are visited most frequently and how long sessions last. This data is used solely to improve the shell99 experience.
- Preference cookies: Store your Platform preferences such as language settings, responsible gaming configurations, and game lobby layout choices.
- Security cookies: Used to detect and prevent fraud, including CSRF protection tokens and device fingerprinting to identify suspicious login activity.
You may manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using certain features of the shell99 Platform, including the login function. shell99 does not use third-party advertising cookies or behavioural profiling cookies for commercial advertising purposes.
7. Data Retention
shell99 retains your personal data for as long as is necessary to fulfil the purposes for which it was collected, including for the duration of your Account's active status and for a defined period thereafter:
- Account and KYC data: Retained for a minimum of 5 years following Account closure, in compliance with anti-money laundering record-keeping requirements under applicable gaming regulations.
- Financial transaction records: Retained for a minimum of 7 years following each transaction, as required for financial compliance and audit purposes.
- Gaming activity logs: Retained for 12 months from the date of each game session for dispute resolution and responsible gaming monitoring purposes. Aggregate statistical data may be retained for longer in anonymised form.
- Support communications: Retained for 3 years following the closure of each support case.
- Technical and device logs: Retained for up to 12 months for security monitoring and fraud investigation purposes.
When data is no longer required for its original purpose and no legal retention obligation applies, shell99 will securely delete or anonymise that data.
8. Data Security
🔒 shell99 applies industry-standard security measures to protect your personal data at all times.
The technical and organisational security measures applied by shell99 include:
- 256-bit SSL/TLS encryption for all data transmitted between your device and the shell99 Platform.
- Encryption of sensitive personal data and financial records at rest.
- Role-based access controls limiting employee access to personal data to those with a legitimate operational need.
- Two-factor authentication available (and encouraged) for all Member Accounts.
- Automated monitoring for unusual account activity, including failed login attempts, unusual withdrawal patterns, and suspicious IP behaviour.
- Regular security audits and vulnerability assessments of the Platform infrastructure.
- Staff training on data protection and information security obligations.
Despite these measures, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe your shell99 Account has been compromised, please contact shell99 support immediately.
9. Your Privacy Rights
Subject to applicable laws and the legitimate operational requirements of the shell99 Platform, you have the following rights in relation to your personal data:
- Right of Access: You may request a copy of the personal data that shell99 holds about you.
- Right to Rectification: You may request correction of any inaccurate or incomplete personal data in your Account.
- Right to Erasure: In certain circumstances, you may request deletion of your personal data. Note that shell99 may be required to retain certain data for regulatory compliance purposes even after Account closure.
- Right to Restrict Processing: You may request that shell99 limit how your data is used in certain circumstances, such as while a data accuracy dispute is being resolved.
- Right to Data Portability: Where technically feasible and legally applicable, you may request a copy of your personal data in a structured, commonly used, machine-readable format.
- Right to Object: You may object to the processing of your personal data where shell99 relies on legitimate interests as the legal basis for that processing.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of the above rights, please contact shell99 support using the details in Section 14. We will respond to your request within 30 days. In certain cases, we may need to verify your identity before processing your request.
10. Children's Privacy
🔞 Shell99 is strictly for adults aged 21 and above. We do not knowingly collect personal data from any person under the age of 21.
The shell99 Platform is not directed at, and should not be used by, persons under the age of 21. Registration requires age verification, and accounts suspected of being operated by underage individuals are suspended immediately pending investigation.
If you are a parent or guardian and believe that a person under 21 in your care has registered on the shell99 Platform, please contact us immediately at the details in Section 14. We will take prompt action to close the account and securely delete any personal data collected in connection with it.
11. Cross-Border Data Transfers
As an international online gaming platform, shell99 may transfer your personal data to countries outside Malaysia — for example, when your data is processed by game providers or payment processors whose systems are hosted in other jurisdictions.
When such transfers occur, shell99 ensures that appropriate safeguards are in place to protect your personal data, including contractual data protection clauses with all third-party recipients that require them to process your data to a standard at least equivalent to this Policy.
By using the shell99 Platform, you acknowledge that your personal data may be transferred to and processed in jurisdictions outside your country of residence.
12. Third-Party Links
The shell99 Platform may contain references to or integrations with third-party services (such as game providers' systems and payment gateways). These third-party services operate under their own privacy policies, which are independent of this Policy.
shell99 is not responsible for the privacy practices of any third-party service. We encourage you to review the privacy policies of any third-party service you interact with through the Platform.
13. Updates to This Privacy Policy
shell99 may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable laws, or Platform functionality. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify active Members via email or an in-Platform notification.
Your continued use of the shell99 Platform after any such update constitutes your acceptance of the revised Privacy Policy. If you do not agree with any changes, you should stop using the Platform and contact us to request Account closure.
14. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data by shell99, please contact our Data Protection team:
📧 Email: [email protected] (plain text — not a clickable link)
You may also raise a concern via the live chat function available after signing in to your shell99 Account. We will acknowledge your request within 2 business days and respond in full within 30 days.