Privacy Policy
This policy explains what personal information BetKika collects, why we need each piece of it, how long we keep it and what you can ask us to do with it. It applies to this website and to every account held on it.
What we collect and why
We collect your name, date of birth, email address, phone number and country when you register. The date of birth is not optional and is not decoration: it is the check that enforces the minimum age of 21, and an account cannot be created without it.
We collect your mobile money number and the details of each deposit and withdrawal, because that is how money reaches and leaves your account and because we are required to be able to show where it went.
We record every bet you place, its stake, its price and its outcome. That record is what settles the bet and what lets you dispute a settlement afterwards.
We log the IP address, device and browser used to sign in, and the time of each sign-in. This is what lets us notice a stolen account and prove what happened to one.
If identity verification is required before a withdrawal, we collect the identity documents you upload for it.
What we do not collect
We do not ask for or store card numbers. Money moves by mobile money, so there is no card detail on this platform to lose.
We do not buy personal data about you from third parties, and we do not build a profile of you from activity on other websites.
We do not collect information from anyone we know to be under the minimum age. Where we learn that an account belongs to someone underage, we close it and delete the data we are not obliged to keep.
Why we are allowed to hold it
Most of what we hold is needed to perform the contract you enter when you open an account: we cannot run a wallet, accept a bet or pay out a win without it.
Some of it is held because handling money brings legal obligations, including checks against fraud and money laundering and the duty to keep financial records for a period after an account closes.
A small part is held because we have a legitimate interest in keeping the platform secure, such as sign-in logs used to detect account takeover.
Marketing messages are sent only where you have opted in. The box is unticked when you register, and you can withdraw the consent at any time from your notification settings without affecting anything else.
Who your data is shared with
Our payment provider receives the details needed to move a specific payment, and nothing beyond that. It cannot see your betting history.
Our hosting and infrastructure providers process data on our behalf under contract and may not use it for their own purposes.
We disclose data to a public authority where we are legally required to, and only to the extent required.
We do not sell your personal data, we do not trade it, and we do not hand it to other companies so they can market their products to you. There is no exception to this.
How long we keep it
Account and financial records are kept for as long as the account is open and for a period afterwards to satisfy the record-keeping obligations that come with handling money.
Sign-in and device logs are kept for a short period, long enough to be useful in investigating a security incident.
Identity documents uploaded for verification are kept only as long as needed to complete and evidence that check.
When a retention period ends, the data is deleted rather than archived indefinitely.
Your rights
You can ask for a copy of the personal data we hold about you, and we will provide it.
You can ask us to correct anything inaccurate, and you can change most of it yourself from your profile settings.
You can ask us to delete your data. We will delete everything we are not legally obliged to retain, and we will tell you plainly what we must keep and why rather than refusing the request as a whole.
You can withdraw consent for marketing at any time, and you can ask us to close your account at any time. Neither request needs a reason.
Security
Passwords are stored as one-way hashes and cannot be read back by anyone here, including administrators. Sign-in, password reset and payment endpoints are rate limited, and repeated failures lock the account rather than allowing an attacker to keep guessing.
Requests that change data carry cross-site request forgery protection, output is escaped, and administrative functions are behind role checks.
No system is perfectly secure. If a breach affects your personal data we will tell you what happened and what we are doing about it, rather than staying quiet and hoping.
Cookies, and changes to this policy
Cookies and similar technologies are covered separately in the cookie policy, which explains each one this site sets and what it is for.
If this policy changes in a way that affects what we collect or what we do with it, the change will be published on this page. The date at the foot of the page is the date it last changed.
Asking us about your data
Send a data request through the contact form on this site and it becomes a support ticket with a reference you can follow. Tell us what you want: a copy, a correction, or deletion.
We answer data requests from the account holder. If we cannot tell that a request comes from the account holder, we will ask you to confirm it from the account itself before acting on it, because handing someone else your data would be the worse failure.