Data Protection

Privacy Policy

At Rajatoto, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our online casino and sports betting platform — and the rights you have over that data under applicable regulations.

Last Updated: 1 January 2026

How Rajatoto Protects Your Data

Our core data protection commitments, summarised for Malaysian players who want the key points without reading every clause.

256-Bit SSL Encryption

Every piece of data transmitted between your browser and Rajatoto's servers is protected by 256-bit SSL encryption — the same standard used by Maybank and CIMB for their online banking platforms.

No Data Sales — Ever

Rajatoto will never sell, rent, or trade your personal information to third-party marketers or data brokers. Your data is shared only with service providers necessary to operate your account and process your payments.

Full User Rights

You can access, correct, export, restrict, or delete your personal data at any time by contacting our support team. We respond to valid data rights requests within 30 calendar days.

Secure Payment Data

Full payment card numbers are never stored on Rajatoto's systems. Malaysian e-wallet and bank references (Touch 'n Go, Boost, Maybank, CIMB) are handled by PCI-DSS compliant processors.

Clear Retention Limits

Data is retained only as long as legally required or operationally necessary. KYC documents are held for a minimum of five years post-closure. Analytics logs are purged within 12–24 months.

Opt-Out Marketing

Marketing communications are only sent where you have explicitly consented. You can withdraw consent and unsubscribe at any time — your request will be processed immediately with no effect on your account access.