Privacy Policy
This page is a working map of how IPAY9 handles the file attached to your login. You give a name, a phone, and a payment rail. The platform retains round IDs, cashier lines, and device logs so a dispute has something to match against. That is the job. It is not a license to treat your MyKad photo as marketing fuel.
House rules sit in the terms and conditions. Play caps sit under responsible gaming. If this guide and the live privacy page disagree, the live page wins. Bookmark the official domain you typed yourself.
Who is accountable for the file
The operator named in the registration and in the live About Us block is the controller for the player account. A bank, e-wallet, or game studio may control the slice they process under their own notice. We remain responsible for what we send them under contract. A chat that found you first on WhatsApp is not that controller.
What we actually collect
Details you type
Sign-up asks for full name, date of birth, email, mobile number, and address when required. Those fields support age checks, recovery, and notices. For a first withdrawal or a flagged login, we may ask for your MyKad, passport, or another government ID, plus a selfie, when the risk screen prompts you to. Cropped images that hide the clock waste a round trip.
Money and play records
The cashier stores the methods you approved, the amounts in RM, the deposit and withdrawal IDs, and whether a request is pending. Game studios send round results for a given session. The casino and sports products send settlement lines we need for audits. Bonus opt-ins, limit changes, and support transcripts sit in the same account file.
Device and session data
When you use the site or the app, we log IP address, device type, browser, language, and coarse location for fraud screening. Cookies keep a session open and remember a language choice. A ticket you send, a complaint, or an optional survey is stored to close the case. Promotional replies you send stay with that campaign until you opt out.
Data type | Why it exists | Typical clock |
Identity fields | Age check, name match on payouts | While the account is open, then legal hold |
Cashier lines | Deposits, withdrawals, disputes | Years after the last movement if rules require |
Round and bet IDs | Freeze reviews, bonus contribution | As long as a complaint window can still open |
Device and IP | Login risk, duplicate-account flags | Shorter unless a fraud file is open |
Support chat | A written record of what was asked | Until the ticket and any appeal close |
What we use the file for
Each field should have a job. If a job is missing, do not assume it is for marketing use.
- Open and recover the login.
- Move RM in and out on a rail in your name.
- Send a promotions notice only where you opted in.
- Meet identity and anti-fraud checks the cashier requires.
- Match a frozen round to history when you write in.
- Apply a limit, cool-off, or exclusion you requested.
We do not use a round ID to invent a “due win.” Independent rounds stay independent. A long-run payback figure is not a debt.
Who else may see a field?
We do not sell player lists. Sharing happens when the job cannot finish without it:
- Payment providers, to credit or debit the method you chose.
- Identity partners, to read a document you uploaded.
- A legal or regulatory request we are required to answer.
- A successor if the operator transfers the business, under the same duty.
- Contracted hosts, email, or security vendors who run a slice of the site.
Those parties should not add your file to their mailing list. If a stranger asks for an OTP “from IPAY9,” stop. Open the Contact Us page from the bookmark and start a new ticket.
Your choices
You can ask for a copy of what we hold, a correction to an incorrect field, a restriction on certain uses, or a deletion where the law allows. You can object to certain processing. You can ask for a portable copy of data you supplied. None of that skips a verification step. Staff will not discuss a balance with a relative who only has the password story.
Deletion is not instant if a withdrawal is pending or a dispute is open. Fraud holds, and payment records often outlive a closed login. Ask which clock applies. Take a screenshot of the answer with the ticket ID.
Cookies, without folklore
Session cookies die when you close the browser. Persistent cookies last until they expire or you clear them. They remember login, language, and some cashier states. Analytics cookies help us see which pages fail on a phone. Marketing cookies, if used, should follow the consent control on the live site.
You can block cookies in the browser. The login may then bounce, the cashier may forget a method, and a live table may reload. That is a trade, not a punishment. Do not clear cookies mid-withdrawal and then open a second request “to test.”
How long we keep it, and where it sits
We keep a file while the account is open and then as long as payment, tax, dispute, and fraud rules require. After that, the live policy says whether rows are deleted or stripped of identifiers. Some processors sit outside Malaysia. Transfers should keep a comparable lock on the file. “Overseas” is not a reason to skip a screenshot of the notice you accepted.
We do not knowingly keep a file for anyone under 18. If a minor’s data is entered into the system, the account should be closed and the file removed from the active list. Report that through official contact, not through a social comment.
Security that is actually a habit
Transport should be encrypted. Staff access should be limited to the ticket in front of them. Unusual logins should flag. Independent tests: when the live page names them, check the claim. Your job is still a screen lock, a password you do not paste into chat, and a log-out on a family tablet. Public USB is a bad place to open the cashier.
When this page changes
The operator may update the live privacy page. A notice may sit on login or arrive by email. The version you accepted on the day you uploaded an ID is the one a later dispute will need. Screenshot it. A banner you remember from last year is not that file.
A request you can paste
Write: I need a copy / a correction / a deletion request. Username: [x]. Malaysia time: [date and hour]. Field: [name/address/payment method]. Then attach one full-screen image if the error is on screen. One complete message beats five short ones.
What most people get wrong
They email a cropped MyKad with the clock cut off. They send the password “so you can check.” They open a second deposit while asking about the first. They argue over a marketing email from last year’s banner. The useful habit is one ticket, one field, one screenshot with the clock, and the ticket ID saved.
- Do not post identity photos in a social comment.
- Do not clear cookies mid-withdrawal and fire a twin request.
- Do not assume a closed login deletes cashier history the same night.
- Do not treat a processor outside Malaysia as a reason to skip the notice you accepted.
If a lookalike site collected a login, change the password on the official bookmark first, then tell official chat the time of the fake page. The privacy file cannot undo a password you typed on a clone until you lock the real account.
Marketing mail and silence
If you opted in, you may receive product mail and SMS messages. You can opt out on the live preference screen or through the unsubscribe link in a real message that matches the official domain. Silence after opt-out is the test. If mail appears to be from a lookalike domain, do not click. Open the official contact and send the From address and the time.
We should not use your play history to imply a win is due. A “you are on a streak” push is a notification setting you can mute. Mute it if it pulls you back in after the cap is already hit.
Shared devices and ID photos
A family tablet remembers logins. Log out. Do not leave a MyKad photo in the gallery if a child uses the same phone. Upload through the official portal only. A private chat that asked for the photo first is not that portal. Daylight, uncropped, edges visible. Then wait for the ticket; don’t upload a second time “to be sure.”
If you share a household, keep the password out of group chats. A sibling who “just wants to look” is still a login on your file. Your play history and cashier lines are tied to that same login.
A first-week privacy checklist
- Read the live privacy page on the day you upload an ID. Screenshot it.
- Use a method already in your name. Do not lend the login.
- Turn on a screen lock. Log out on a shared tablet.
- Opt into email only if you want it. Silence is a valid choice.
- Keep the ticket ID if you ask for a copy or a correction.
Type the official address yourself. Ask in a ticket, not in a forwarded chat. If this page and the live privacy notice disagree, the live notice wins. 18+ only.
Copy, correction, restriction, deletion
These are different jobs. A copy is a file of what we hold. A correction is a wrong field: a misspelled name, an outdated phone number, a stale address. A restriction is “stop using this for marketing” or a similar limit the live policy allows. Deletion is a request to remove the file from the active list, where permitted by law. Payment and fraud rows often stay. Ask which clock applies to your case and keep the ticket ID.
Staff must verify you first. A relative with the password story is not you. Do not send the password to speed the check. Send the username, Malaysia time, and the field. One full-screen image if the error is on the screen.
You want | Say this in the first line | What usually happens |
A copy | Please send a copy of my account file | Verification, then a file or a summary |
A correction | Please correct [field] from [old] to [new] | Name match on payouts may be rechecked |
A marketing stop | Please stop promo mail and SMS | Silence after opt-out is the test |
A deletion | Please delete my account file where allowed | Holds if a dispute or payout is open |
International processors, in practice
A game studio, a cloud host, or an identity vendor may sit outside Malaysia. That does not mean your MyKad is public. It means the live notice should state that transfers occur and that a comparable lock remains on the file. Take a screenshot of that notice on the day you upload an ID. A later dispute will need the version you accepted, not a memory of a banner.
“Overseas” is not a reason to skip the official portal and send the photo in a private chat. The portal is the path. A stranger who asked for the photo first is not the path.
OTP, clones, and the privacy file
If a lookalike collected a login, change the password on the official bookmark first. Then tell official chat the time of the fake page. The privacy file cannot undo a password you typed on a clone until you lock the real account. Do not argue with the clone in a social comment that includes identity photos.
If this page and the live privacy notice disagree, the live notice wins. 18+ only.
What a good ID upload looks like
Daylight. Uncropped. All four edges of the card visible. No finger over the number. No filter. A selfie, if asked, in the same sitting, same lighting, no sunglasses. Then wait for the ticket. A second upload, “to be sure,” while the first is in review, duplicates the queue. A crop that hides the clock or the expiry date is rejected.
Do not send the photo in a private chat that found you first. Do not post it under a social comment. The official portal is the path. If the portal fails, tell the official chat the error text and the time. Attach a screenshot of the error, not the ID, until they ask for the portal retry.
- Name on the card matches the registration name.
- Address on the form matches a document if one is requested.
- Payment rail is already in that name.
- Keep the ticket ID from the upload, not only the photo in your gallery.
A closed login does not always delete cashier history the same night. Ask which clock applies if you requested deletion. Screenshot the answer.