SP Gaming World Limited ("FanBet247", "we") is the controller of your personal data when you use the FanBet247 platform. This policy explains what we collect, why, how we use it, and what control you have. Read this together with our Cookie Policy and Terms of Service.
1. Information We Collect
1.1 Information you give us directly
- Account: username, email address, password (stored only as a salted hash), full name, date of birth, phone number, country, preferred currency, favourite team, and an optional avatar.
- KYC documents: photo of a government-issued ID (front and back), a selfie holding the ID, and proof of address (e.g. a utility bill or bank statement).
- Payment details: the payment-method label and identifier you used for a deposit (bank account label, mobile-money number, etc.). We do not store full card numbers or CVVs — those are handled by your payment provider.
- Communication: messages you send in 1:1 chat, league chat, support emails, and bet-share notes.
1.2 Information collected automatically
- Activity: bets placed and accepted, balance changes, transactions, league participation, points, settlement outcomes, and audit logs.
- Device & network: IP address, user-agent string, browser locale, device type (mobile/desktop detection), referrer.
- Authentication: login timestamps, success/failure events, password-reset attempts, OTP / 2FA usage. See the admin and user activity log tables in our database for the technical record.
- Cookies and local storage: session cookie (
PHPSESSID), theme preference, force-desktop session flag. See the Cookie Policy.
1.3 Information from third parties
- Google Sign-In (if you enable it): your Google sub-id, email, name, and profile picture URL only.
- Payment providers and mobile-money operators: confirmation of payment status for deposits and withdrawals.
2. How We Use Your Data
- Create and operate your account, including FC balance, betting, leagues, and settlement.
- Verify your identity (KYC), screen for fraud and money laundering, and apply withdrawal limits.
- Process deposits and withdrawals, including manual review where required.
- Send transactional emails (verification, password reset, withdrawal status, KYC outcome) via our SMTP provider.
- Communicate platform updates, security notices, and (with your consent) marketing.
- Maintain security: rate-limit suspicious login attempts, detect bot traffic, audit admin actions.
- Comply with legal obligations, court orders, and regulatory requests.
3. Legal Bases
Where applicable data-protection law requires a legal basis, we rely on:
- Performance of contract — for account creation, betting, deposits, and withdrawals.
- Legal obligation — for KYC, anti-money-laundering checks, and tax-reporting where applicable.
- Legitimate interest — for fraud prevention, platform security, and product improvement.
- Consent — for optional marketing emails, optional Google sign-in, and any non-essential cookies.
4. Who We Share Data With
- Hosting: our servers and backups run on Hostinger International Ltd. infrastructure.
- Email delivery: Hostinger SMTP (smtp.hostinger.com) for transactional and marketing email.
- Payment providers: when you deposit or withdraw, the relevant bank or mobile-money operator receives the information needed to process the transaction.
- KYC support staff: employees of SP Gaming World Limited with role-restricted access (super_admin, moderator, support) review KYC documents for verification.
- Law enforcement and regulators: when required by a lawful order or to protect users and the platform from imminent harm.
We do not sell your personal data, and we do not share it with advertising networks.
5. International Transfers
Our primary hosting region is determined by Hostinger and may be located outside Nigeria. Where transfers occur, they are protected by Hostinger's standard data-protection terms and any safeguards required under applicable law (such as Standard Contractual Clauses).
6. Retention
- Account & activity records: kept while your account is open and for up to 7 years after closure to satisfy anti-money-laundering and tax record-keeping rules.
- KYC documents: retained for the same 7-year period, then securely deleted.
- Session cookies and short-lived logs: typically kept for 30–90 days.
- Email opt-out lists: retained indefinitely to honour your opt-out.
7. Your Rights
- Access the personal data we hold about you.
- Correct inaccurate information directly via your profile, or by request.
- Delete your account (subject to the legal retention period above).
- Object to or restrict processing in some cases.
- Withdraw consent (e.g. unsubscribe from marketing) at any time.
- Receive a copy of your data in a portable format.
- Complain to your local data-protection authority (in Nigeria, the Nigeria Data Protection Commission).
To exercise any of these rights, email support@fanbet247.com from the email address registered on your account. We will respond within 30 days.
8. Security
We protect data using salted password hashing, HTTPS in transit, encryption at rest for KYC files, SHA-256 integrity verification on uploads, role-based access controls for admin tools, rate-limited authentication endpoints, optional OTP and 2FA for admins, and audit logging of sensitive actions. No system is perfectly secure; please use a strong unique password and enable 2FA where available.
9. Children
FanBet247 is strictly 18+. We do not knowingly collect data from anyone under 18. If you believe a minor has registered, contact us and we will close the account and delete the data.
10. Changes to This Policy
We will publish updates here and, for material changes, notify you by email or an in-app banner at least 14 days before they take effect.
11. Contact
SP Gaming World Limited
Email: support@fanbet247.com
Phone: +234 123 456 7890
Lagos, Nigeria