Data & Privacy
super9 Privacy Policy – How We Handle Your Personal Data
This Privacy Policy describes how super9 collects, uses, stores, and protects the personal information of Members and visitors. We are committed to handling your data with the same standard of care you expect from a trusted Malaysian financial services provider.
Last updated: June 2026 | Governing language: English
Our Privacy Commitments
What super9 Promises About Your Data
Six principles that govern how super9 treats every piece of personal information entrusted to us by Malaysian Members.
Data Minimisation
super9 collects only the personal data necessary to operate your account, process payments, verify identity, and comply with our regulatory obligations. We do not collect data for its own sake.
Security First
All personal and financial data is encrypted in transit using 256-bit SSL and at rest using industry-standard encryption. Access to Member data is restricted to authorised personnel on a need-to-know basis.
No Unauthorised Sale of Data
super9 does not sell, rent, or trade your personal data to third-party marketers. Data is shared with third parties only where required for platform operation, payment processing, or legal compliance.
Your Rights Respected
Members may request access to, correction of, or deletion of their personal data by contacting super9 support. We will process such requests in accordance with applicable data protection legislation.
Defined Retention Periods
Personal data is retained only for as long as necessary for the purpose for which it was collected, or as required by applicable law, including AML record-keeping obligations.
Breach Notification
In the event of a data breach that poses a risk to Members, super9 will notify affected Members and the relevant supervisory authority within the timeframes required by applicable law.
1. Introduction
This Privacy Policy ("Policy") is issued by super9 ("we", "us", "the Platform") and applies to all personal data processed in connection with the super9 online betting and casino platform accessible at super9.win. This Policy is intended to provide Members, prospective Members, and visitors ("Data Subjects", "you") with transparent information about how we collect, use, store, and protect personal information.
By accessing super9.win, registering an account, or using any feature of the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with the practices described herein, you should not use the Platform. This Policy should be read in conjunction with the super9 Terms & Conditions.
2. Categories of Personal Data We Collect
Depending on the nature of your interaction with super9, we may collect the following categories of personal data:
| Category | Examples |
|---|---|
| Identity Data | Full legal name, date of birth, nationality, government-issued ID number |
| Contact Data | Malaysian mobile number, email address, residential address |
| Financial Data | Bank account details, FPX reference numbers, DuitNow registered number, eWallet account identifiers, transaction history |
| Account Data | Username, account preferences, communication preferences, bonus balances |
| Transaction Data | Deposit amounts, withdrawal requests, wagering history, game play records |
| Technical Data | IP address, device type, operating system, browser type, session duration, referral URL |
| Usage Data | Pages visited, features used, betting patterns, login timestamps |
| KYC Documents | Copies of MyKad, passport, utility bills, or other documents submitted for identity verification |
3. How We Collect Personal Data
super9 collects personal data through the following means:
- Direct submission — data you provide when registering an account, completing KYC, making a deposit or withdrawal, or contacting customer support.
- Automated technologies — data collected automatically when you access the Platform, including through cookies, web beacons, server logs, and similar tracking technologies.
- Payment processors — transaction confirmation data received from FPX, DuitNow, Maybank2u, CIMB Clicks, Public Bank, Touch n Go eWallet, Boost, and other approved payment channels.
- Third-party verification services — identity and age verification data received from licensed KYC service providers used to comply with AML obligations.
4. Purposes of Data Processing
super9 processes personal data for the following purposes:
- To create, maintain, and administer your super9 account.
- To verify your identity and age in compliance with regulatory requirements, including the strict 21+ age restriction.
- To process deposits and withdrawals in MYR through approved payment channels.
- To detect, investigate, and prevent fraud, money laundering, and other unlawful activities.
- To provide customer support services via live chat and email.
- To personalise your experience on the Platform, including relevant game and promotion recommendations.
- To monitor for problem gambling indicators and to administer responsible gaming tools including self-exclusion.
- To comply with applicable legal obligations, including those imposed by our gaming licence and AML/CFT regulations.
- To send you service communications, including notifications about account activity, security alerts, and policy updates.
- To improve the Platform through analysis of aggregate usage patterns (using anonymised or pseudonymised data where possible).
5. Legal Basis for Processing
super9 processes personal data on the following legal bases, as applicable:
- Contractual necessity — processing required to provide the services you have requested, including account operation, payment processing, and wagering.
- Legal obligation — processing required to comply with applicable laws including AML/CFT regulations, gaming licence conditions, and tax obligations.
- Legitimate interests — processing required to detect and prevent fraud, secure the Platform, and improve our services, where such interests are not overridden by your rights.
- Consent — where we rely on your consent for specific processing activities (e.g., optional marketing communications), you may withdraw that consent at any time by contacting support.
6. Sharing Your Personal Data
super9 does not sell, rent, or trade your personal data to third-party marketers. We may share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate data processing agreements:
- Payment processors — FPX, DuitNow network participants, licensed eWallet operators, and banking partners necessary to process MYR transactions.
- KYC and fraud prevention providers — licensed identity verification and AML screening services.
- Game software providers — to the extent required to authenticate your session and record game play results for auditing purposes.
- IT and infrastructure providers — hosting, security, and technical support providers operating under strict confidentiality obligations.
- Regulatory authorities and law enforcement — where required by applicable law, court order, or regulatory request, including our gaming licence supervisory authority.
- Professional advisers — legal, accounting, and audit firms operating under professional confidentiality obligations.
7. Cookies and Tracking Technologies
super9 uses cookies and similar technologies to operate the Platform, remember your preferences, and analyse usage patterns. The categories of cookies we use include:
- Strictly necessary cookies — essential for Platform functionality, including maintaining your logged-in session. These cannot be disabled.
- Functional cookies — used to remember your language preference, display settings, and other personalisation choices.
- Analytics cookies — used to collect anonymised data about how Members use the Platform, enabling us to improve user experience. No personally identifiable data is included in analytics reports.
- Security cookies — used to support authentication, detect fraud, and protect account security.
You may manage cookie preferences through your browser settings. Please note that disabling certain cookies may impair the functionality of the Platform.
8. Data Retention
super9 retains personal data for as long as is necessary for the purpose for which it was collected, or as required by applicable law. In practice:
- Account data and transaction records are retained for a minimum of five (5) years following account closure, in accordance with AML record-keeping requirements.
- KYC documents are retained for the period required by our gaming licence conditions, which may extend beyond account closure.
- Technical and usage data is retained for a maximum of two (2) years in identifiable form, after which it is anonymised or deleted.
- Customer support records are retained for three (3) years following resolution of the relevant matter.
9. Your Data Protection Rights
Subject to applicable law and certain conditions, you have the following rights in respect of your personal data held by super9:
- Right of access — to request a copy of the personal data we hold about you.
- Right to rectification — to request correction of inaccurate or incomplete personal data.
- Right to erasure — to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to overriding legal obligations.
- Right to restriction — to request that we restrict processing of your personal data in certain circumstances.
- Right to object — to object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on your consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact super9 via the 24/7 in-platform live chat or by email at [email protected]. We will respond to all requests within a reasonable timeframe, and in any event within the period required by applicable law.
10. Security Measures
super9 implements technical and organisational security measures appropriate to the risk level of the data we process. These measures include:
- 256-bit SSL/TLS encryption for all data transmitted between your device and our servers — the same standard applied by Maybank2u and CIMB Clicks.
- Encryption of sensitive data fields at rest within our database infrastructure.
- Role-based access controls ensuring staff access to Member data is limited to what is required for their specific function.
- Regular independent penetration testing and security audits conducted by third-party security firms.
- Multi-factor authentication requirements for access to production systems by super9 technical staff.
- Incident response procedures providing for prompt containment, investigation, and notification in the event of a security breach.
11. International Data Transfers
In order to operate the Platform and deliver certain services, personal data may be transferred to and processed in jurisdictions outside Malaysia. Where such transfers occur, super9 ensures that appropriate safeguards are in place, including data processing agreements incorporating standard contractual clauses or equivalent protections recognised by applicable data protection law. super9 will not transfer your personal data to jurisdictions that do not provide an adequate level of data protection without implementing supplementary protective measures.
12. Children's Privacy and Age Restriction
super9 is strictly an adults-only platform. Access is prohibited for any person under the age of 21 years. We do not knowingly collect or process personal data relating to individuals under 21. If we discover that an account has been registered by a person under 21, that account will be immediately closed and any balance therein may be forfeited. If you have reason to believe that a person under 21 has registered on super9, please contact our support team immediately.
13. Changes to This Privacy Policy
super9 reserves the right to amend this Privacy Policy at any time. Material changes will be communicated to Members via the Platform notification system or by email to the registered address on file. The date of the most recent revision is displayed at the top of this Policy. Your continued use of the Platform following publication of a revised Policy constitutes your acceptance of the updated terms. We encourage you to review this Policy periodically.
14. Contact and Complaints
If you have any questions, concerns, or complaints about how super9 processes your personal data, please contact our Data Protection team in the first instance via the 24/7 in-platform live chat, or at: [email protected] (plain text — not a clickable link).
We aim to resolve all data protection enquiries promptly and fairly. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction.
Your Privacy Is Protected
Play with Confidence at super9
Now that you understand how super9 protects your personal data, explore our sportsbook, live casino, and slots — all backed by the same privacy standards Malaysian banking users expect.
Strictly for adults aged 21 and above. Please gamble responsibly.