<a href="/">Nova88</a> <a href="/privacy-policy/">privacy policy</a> Malaysia | Data Protection & GDPR
🔒 Last Updated: May 2026 · GDPR-Aligned

Nova88 Privacy Policy — Your Data, Your Rights

This Privacy Policy explains how Nova88 Malaysia collects, uses, stores and protects your personal information. We follow GDPR-aligned principles and Malaysian data protection standards. We never sell your data to third parties. Read your rights in full below.

SSL 1.3 Encrypted GDPR-Aligned Never Sold to Third Parties Curacao Compliant

1. Who We Are

Nova88 (operating as the official rebrand of IBCBET and Maxbet) is an online betting platform licensed by the Government of Curacao under master licence 8048/JAZ. Our parent group has operated since 2004 across Asia, serving Malaysian, Thai, Indonesian, Vietnamese, Indian and Bangladeshi players. Learn more about Nova88.

This Privacy Policy applies to your use of nova88.me and all official mirror domains listed on our login page.

2. Data We Collect

The categories of personal data we collect, and why.

  • 📝
    Account information: username, password (hashed and salted), email, phone number, currency preference, language preference.
  • 🆔
    Identity verification (KYC): Malaysian IC or passport, date of birth, residential address, proof of address documents, selfie. Required by our AML & KYC policy before /withdrawal/.
  • 💳
    Financial data: /deposit/ and withdrawal records, payment method details, bank account number, e-wallet ID, crypto wallet addresses, transaction history.
  • 🎮
    Gaming activity: bets placed, games played, win/loss history, session duration, bonus claims and wagering progress.
  • 📱
    Technical data: IP address, device type, browser fingerprint, operating system, login timestamps, geolocation (approximate, for compliance only).
  • 📞
    Communication data: live chat transcripts, email correspondence, support ticket history, Telegram and WhatsApp interactions.
  • 🍪
    Cookies and analytics: anonymised usage patterns, conversion tracking, A/B test segmentation. See Section 8 below.

3. How We Use Your Data

Strictly limited to legitimate operational purposes.

🔐

Account Security

Authentication, fraud prevention, account recovery, biometric login token verification, suspicious activity detection.

💸

Transaction Processing

Crediting deposits, processing withdrawals, calculating rebates and bonus rollover, settling bets and game wins.

Regulatory Compliance

KYC checks, AML monitoring, sanctions screening, suspicious activity reporting, age verification, source-of-funds checks.

📞

Customer Service

Live chat support, email replies, Telegram and WhatsApp assistance, dispute resolution, VIP account management.

🎁

Personalised Offers

Bonus targeting based on gameplay (e.g. /slots/ bonus to slot players), VIP tier upgrades, birthday gifts. Always opt-out available.

🛡

Responsible Gaming

Deposit limit monitoring, session limit reminders, self-exclusion enforcement, problem gambling intervention. Read our framework.

📊

Platform Improvement

Aggregated analytics (anonymised) to fix bugs, improve UX, prioritise new features. Never used to identify individuals.

🚫

Fraud Investigation

Pattern analysis to detect bonus abuse, multi-account fraud, payment fraud and chargeback attempts. Protects all members.

4. Data Sharing & Third Parties

Who we share data with — and crucially, who we do not.

🛑 We never sell your personal data. Not to advertisers, not to data brokers, not to affiliates, not to anyone. Period.
  • Payment processors: Maybank, CIMB, Public Bank, DuitNow operator, e-wallet providers and blockchain custodians — limited to the minimum data needed to settle transactions (name, amount, reference).
  • Game providers: Evolution Gaming, Pragmatic Play, PG Soft, Jili, Saba Sports and other partners receive your anonymised player ID for game session tracking. They never see your real name, IC or banking info.
  • KYC verification partners: Identity verification tech (Onfido-class providers) verify your IC or passport authenticity. Documents encrypted in transit, deleted after verification.
  • Regulators & law enforcement: Disclosed when legally compelled — Curacao Gaming Control Board, Bank Negara Malaysia (when required), court orders, tax authorities investigating money laundering.
  • Infrastructure providers: AWS / Cloudflare for hosting and security, with strict data processing agreements. Data stored in Asian regions where legally possible.
  • Advertisers, data brokers, social media tracking: We never share your data with these. We don't sell email lists. We don't use Facebook Pixel to retarget you on your gaming activity.

5. Data Security Measures

The technical and organisational controls protecting your information.

🔐 SSL 1.3 Encryption

Every page (including this one) protected by bank-grade 256-bit encryption. Same standard used by Maybank, CIMB and Public Bank.

🗄 Encrypted at Rest

Database fields containing sensitive data (passwords, IC numbers, banking) are encrypted with AES-256 even when stored on disk.

🤖 AI Fraud Monitoring

Every login, deposit, bet and withdrawal analysed by AI for anomalies. Unusual activity triggers automatic holds and SMS alerts.

👁 Minimal Staff Access

Only KYC and finance team members can see identity documents, and only when actively reviewing a case. All access logged.

🔄 Regular Audits

Penetration testing twice yearly. Vulnerability disclosure programme. ISO 27001-aligned procedures.

🚨 Breach Notification

In the unlikely event of a data breach, affected members are notified within 72 hours alongside regulatory authorities.

6. Your Rights

Under GDPR-aligned principles and Malaysian PDPA, you have the following rights over your data.

  • 📋
    Right to access: request a copy of all personal data we hold /about-us/ you.
  • Right to rectify: correct inaccurate or incomplete data (e.g. address change, email update).
  • 🗑
    Right to erasure: request deletion of your data (subject to 5-year AML retention requirements after account closure).
  • 📤
    Right to portability: receive your data in a machine-readable format (CSV or JSON) for transfer to another service.
  • 🚫
    Right to object: opt out of marketing communications, personalised offers, or analytics cookies anytime.
  • Right to restrict: temporarily halt certain processing activities while a dispute or correction is being resolved.

7. Data Retention

Data CategoryRetention PeriodAfter This
Account & transactionActive life 5 yearsAnonymised or deleted
KYC documentsActive life 5 yearsSecurely destroyed
Live chat & support2 years from last contactDeleted
Marketing preferencesUntil you opt outDeleted within 30 days
Self-exclusion recordsIndefiniteRetained to enforce
Analytics (anonymised)26 monthsAuto-deleted

The 5-year retention is required by AML regulations and Curacao gaming licence conditions. We cannot delete account data earlier even on request.

8. Cookies & Tracking

What we track, what we don't, and how to control it.

  • Essential cookies (always on): login session, security tokens, language preference, mirror redirect. Cannot be disabled — site won't work without them.
  • 📊
    Analytics cookies (opt-out): anonymised traffic measurement, page view counts, bounce rate. We use first-party analytics only — no Google Analytics tracking of individual users.
  • 🎯
    Marketing cookies (opt-in only): personalised bonus offers based on your gameplay. Disabled by default; enable via the cookie banner.
  • 🚫
    What we don't use: Facebook Pixel, TikTok Pixel, Google Ads remarketing, cross-site tracking. Your gambling activity stays private.
  • How to control: reject all non-essential cookies via the banner, or block cookies entirely via your browser settings (Settings → Privacy → Cookies).

9. Children's Privacy

Nova88 is strictly for adults aged 18 and over. We do not knowingly collect personal data from minors. Age is verified during KYC verification before withdrawal — anyone found to be under 18 has their account closed immediately, deposits refunded, and winnings forfeited.

Parents who suspect their child has registered should contact us immediately via customer support. We will close the account, refund deposits and delete the data within 72 hours.

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in law, technology or our practices. Material changes (new data uses, new third-party sharing) will be communicated via email and an in-app banner at least 30 days before taking effect.

Last updated: 1 May 2026. The current version is always available at nova88.me/privacy-policy/.

Privacy FAQ

The most common data protection questions Malaysian members ask.

Does Nova88 sell my personal data to third parties?
No. Nova88 never sells personal data. Data is shared only with regulators, payment processors and service providers strictly necessary for operating the platform, always under contractual data protection agreements.
How long does Nova88 keep my data?
Account data is retained for the active life of your account plus 5 years (AML requirement). After this period, personal data is anonymised or deleted. Read more on data usage.
Can I request a copy of my Nova88 data?
Yes. Contact our Data Protection Officer via contact our support team. We deliver a machine-readable export (CSV or JSON) within 30 days of your request.
Can I delete my Nova88 account and data?
Yes, but personal data linked to active transactions must be retained for 5 years per AML rules. After that period, all personal data is permanently deleted. Account closure guide.
What cookies does Nova88 use?
Essential cookies (always on for security and login), analytics cookies (anonymised, opt-out), and marketing cookies (opt-in only). No third-party tracking like Facebook Pixel or Google Ads remarketing.
Is my Nova88 data stored in Malaysia?
Where legally possible, data is stored in Asian data centres (Singapore, Hong Kong). Some processing (payment gateways) may temporarily transit through other jurisdictions under strict contractual safeguards.

Privacy Questions?

Contact our Data Protection Officer through any support channel — 24/7 live chat, Telegram, WhatsApp or email. Privacy enquiries receive priority handling.

Participation in gambling can be addictive. Please play responsibly. 18 only. Verified licence: Curacao eGaming.

Official Asian Betting Partner
Aston Villa
2024-2026Sevilla FC
2023-2024Inter Milan
2023-2024
Aston Villa
2024-2026
Aston Villa
2024-2026
Sevilla FC
2023-2024
Sevilla FC
2023-2024
Inter Milan
2023-2024
Inter Milan
2023-2024
Gaming Licensevaild gaming license
GambleAware
GambleAware
Awards
awards-egr2025-logo

SHORTLISTED
CRM Campaign

awards-egr2025-op-logo

SHORTLISTED
Best Operator