Last Updated: 12 June 2026 | This Privacy Policy applies to all users of mbi123 (mbi123.bid), including members based in Malaysia.
1. Who We Are and How to Contact Us
mbi123 ("we", "us", "our") is the operator of the online casino and sportsbook platform accessible at mbi123.bid. mbi123 is licensed by an international gaming regulatory authority. We act as the data controller in respect of the personal data collected through the mbi123 Platform.
If you have any questions about this Privacy Policy or wish to exercise any of your data rights, you may contact our Data Protection team by email at [email protected]. Please note that this email address is displayed as plain text and is not a clickable link. Our support team is also available via live chat on the Platform 24 hours a day, seven days a week.
2. Information We Collect
mbi123 collects personal data in the following categories:
2.1 Registration and Account Data
- Full legal name as it appears on government-issued identification
- Date of birth (used to verify the 21+ age requirement)
- Email address and Malaysian mobile phone number
- Residential address (for KYC and correspondence purposes)
- Username and encrypted password credentials
2.2 Identity Verification (KYC) Data
- Copies of government-issued photo identification (e.g., Malaysian MyKad, passport)
- Proof of residential address (e.g., utility bill, bank statement)
- Payment method ownership documentation
- Source of funds declarations where applicable
2.3 Financial and Transaction Data
- Deposit and withdrawal transaction records including amounts, timestamps, and payment method identifiers
- Wallet balance history
- Bonus and promotion redemption records
- Bank account numbers, Touch n Go eWallet identifiers, Boost wallet identifiers, and FPX reference codes — stored only in tokenised or masked form
2.4 Gaming and Betting Activity Data
- Game session logs, bet amounts, game outcomes, and win/loss records
- Sportsbook wager records including event selections, stake amounts, and settlement results
- Session duration and activity timestamps
- Responsible gaming tool usage (deposit limits set, self-exclusion requests, cool-off activations)
2.5 Technical and Device Data
- IP address at time of registration and login
- Device type, operating system, and browser version
- Geolocation data (country/region level) derived from IP address
- Session tokens and authentication logs
- Cookies and similar tracking technologies (see Section 5)
2.6 Communications Data
- Content of live chat, email, and any other support communications you initiate with mbi123
- Survey responses and feedback submitted voluntarily
- Marketing communication preferences and opt-in/opt-out records
3. How We Use Your Information
mbi123 uses collected personal data for the following purposes:
- Account creation and management: To register your mbi123 account, verify your identity, and maintain your account in good standing.
- Service delivery: To provide access to casino games, sportsbook betting, promotions, and all other mbi123 Platform features.
- Payment processing: To process deposits and withdrawals via Touch n Go eWallet, Boost, FPX, and other supported Malaysian payment methods.
- Regulatory compliance: To fulfil our obligations under our international gaming licence, including anti-money laundering (AML) checks, KYC verification, and reporting obligations.
- Responsible gaming: To monitor gaming patterns for indicators of problem gambling, enforce self-exclusion requests, and operate deposit and loss limit tools.
- Fraud prevention and security: To detect and prevent fraudulent activity, unauthorised account access, bonus abuse, and multi-accounting.
- Customer support: To respond to your enquiries and resolve account issues efficiently.
- Marketing communications: Where you have given consent, to send you promotional offers, new game announcements, and platform updates. You may withdraw consent at any time from your mbi123 account settings.
- Platform improvement: To analyse aggregate usage patterns, identify technical issues, and improve the mbi123 Platform experience for all Malaysian members.
4. Legal Bases for Processing
mbi123 processes personal data on the following legal bases:
- Contractual necessity: Processing required to perform the contract between you and mbi123, including account management, game access, and payment processing.
- Legal obligation: Processing required to comply with applicable law and our gaming licence conditions, including KYC, AML obligations, and regulatory reporting.
- Legitimate interests: Processing necessary for our legitimate interests, including fraud prevention, Platform security, and responsible gaming monitoring, where these interests are not overridden by your data protection rights.
- Consent: Processing for marketing communications, and for certain cookies and analytics, where we have obtained your prior consent. Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
5. Cookies and Tracking Technologies
mbi123 uses cookies and similar technologies on the mbi123 Platform for the following purposes:
- Strictly necessary cookies: Required for the Platform to function. These include session authentication tokens and security cookies. They cannot be disabled without impairing Platform functionality.
- Functional cookies: Used to remember your preferences such as language settings, game lobby view preferences, and responsible gaming tool settings.
- Analytics cookies: Used to collect aggregated data about how members navigate and use the mbi123 Platform. This helps us improve the user experience. Analytics data is anonymised wherever possible.
- Marketing cookies: Used, where consent has been obtained, to serve relevant promotional content and track the effectiveness of mbi123 marketing campaigns. These are not used to track you across unrelated third-party websites.
You may manage your cookie preferences at any time through your browser settings. Note that disabling strictly necessary cookies will prevent you from using the mbi123 Platform.
6. Sharing Your Information
mbi123 does not sell your personal data to third parties. We may share your data with the following categories of recipients, strictly for the purposes described in this Policy:
- Payment service providers: Including Touch n Go eWallet, Boost, FPX network participants (Maybank, CIMB, Public Bank, and others), and card processors, solely to process your financial transactions.
- Identity verification providers: Third-party KYC and AML service providers engaged to assist in satisfying our regulatory verification obligations.
- Game content providers: Game studios and live casino operators whose games are hosted on the mbi123 Platform may receive limited technical session data necessary to deliver the game experience.
- Regulatory and law enforcement authorities: Where required to do so by law, court order, or a valid request from a regulatory or gaming authority.
- IT infrastructure and security providers: Cloud hosting providers and cybersecurity services that process data on our behalf under strict data processing agreements.
All third-party service providers are contractually bound to process your personal data only for the purposes for which it was shared, and to maintain appropriate technical and organisational security measures.
7. International Data Transfers
The mbi123 Platform is operated from outside Malaysia. Your personal data may be transferred to and processed in countries other than Malaysia, including countries in which our gaming licence is held, and countries where our technology infrastructure providers are based. Where such transfers occur, mbi123 implements appropriate safeguards — such as standard contractual clauses or equivalent mechanisms — to ensure that your data receives a level of protection consistent with applicable data protection standards.
8. Data Retention
mbi123 retains personal data for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, regulatory, accounting, and reporting requirements. The following general retention periods apply:
- Active account data: Retained for the duration of the membership and for a period of five (5) years following account closure, to meet AML and gaming regulatory obligations.
- KYC verification documents: Retained for a minimum of five (5) years following the end of the business relationship.
- Financial transaction records: Retained for a minimum of five (5) years in accordance with standard AML retention requirements.
- Support communication records: Retained for two (2) years from the date of the last communication.
- Marketing consent records: Retained until consent is withdrawn, and for a reasonable period thereafter as evidence of the consent.
Where data is retained solely to comply with a legal obligation and is no longer required for any active purpose, it is stored in a restricted archive with strictly limited access.
9. Security Measures
mbi123 implements industry-standard technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, and destruction. Key security measures include:
- TLS 1.3 encryption for all data transmitted between your device and the mbi123 Platform
- Encrypted storage of all personal and financial data at rest
- Access controls limiting mbi123 employee access to personal data on a strict need-to-know basis
- Multi-factor authentication for internal systems containing member data
- Annual independent cybersecurity audits of the mbi123 Platform and data infrastructure
- Automated anomaly detection to identify and respond to potential data security incidents
In the event of a personal data breach that poses a risk to your rights and freedoms, mbi123 will notify you and the relevant supervisory authority in accordance with applicable breach notification obligations.
10. Your Rights
Subject to applicable law, you may hold the following rights in respect of your personal data held by mbi123:
- Right of access: You may request a copy of the personal data mbi123 holds about you.
- Right to rectification: You may request correction of inaccurate or incomplete personal data.
- Right to erasure: You may request deletion of your personal data, subject to our legal retention obligations.
- Right to restriction: You may request that we restrict the processing of your data in certain circumstances.
- Right to data portability: You may request a structured, machine-readable copy of data you have provided to us.
- Right to object: You may object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact our support team via live chat or at [email protected]. We will respond within thirty (30) days. Some rights may be subject to limitations where we are required by law to retain or process the data.
11. Children and Minors
The mbi123 Platform is strictly for individuals aged 21 years and above. mbi123 does not knowingly collect personal data from individuals under this age. If you are a parent or guardian and believe that a minor has registered an account or submitted personal data to mbi123, please contact us immediately at [email protected]. Upon verification, we will promptly delete the relevant account and associated personal data.
12. Changes to This Policy
mbi123 reserves the right to update this Privacy Policy at any time to reflect changes in our data practices, legal obligations, or Platform features. Where material changes are made, we will notify registered members by email or via an on-Platform notification at least seven (7) days before the updated Policy takes effect. The date of the most recent revision is displayed at the top of this page. Continued use of the mbi123 Platform following the effective date of any revision constitutes your acceptance of the updated Policy.
We encourage you to review this Privacy Policy periodically to stay informed about how mbi123 protects your personal data.