Privacy Policy
1. The short version
Our service needs almost nothing about you: a WhatsApp number and the conversation we have there. We collect no documents, run no trackers for advertisers, and never sell or rent your information. What follows is the detail behind that sentence.
2. What we collect
- Your WhatsApp number — because the service is a WhatsApp conversation.
- Chat contents — ID requests, payment confirmations, support messages. This history doubles as your written record of every commitment made to you.
- Payment references — the UPI/bank references of deposits and payouts, retained for reconciliation and dispute resolution.
3. What we never collect
- No Aadhaar, PAN, passports or document uploads.
- No email marketing lists — email exists only if you write to us first.
- No third-party advertising trackers on this website.
4. How your data is used
Solely to run the service: creating and servicing your ID, processing deposits and withdrawals, resolving disputes against chat and payment records, and meeting our responsible gambling commitments (such as honouring an ID freeze). Nothing else.
5. Sharing
Your details are shared only with the exchange panel to the minimal extent required to operate your ID, and with no one else. We do not sell, rent or trade personal information — full stop.
6. This website
cricbet99winid.in serves static pages. It sets no advertising cookies. If analytics are enabled they run in consent-respecting mode and measure page performance only — never identity.
7. Your rights
Ask in the chat at any time to: know what we hold about you, correct it, or delete it (subject to retaining payment reconciliation records where legally required). Deletion requests are honoured within 30 days.
8. Contact
Privacy questions: [email protected] or the official WhatsApp channel.
9. Why this policy can be this short — the architecture answer
Most privacy policies are long because the businesses behind them collect broadly and reserve widely. This one is short because the service is architecturally minimal: a WhatsApp conversation and a payments ledger, nothing else. There is no account database with profile fields waiting to be filled, no analytics identity graph, no advertising pixel farm — not out of virtue alone, but because the WhatsApp-first model never needed them. The honest summary of our practice is that we know your number, your chat, and your transactions with us — and we forget everything else because we never learned it.
It is worth understanding what this protects you from concretely. Data breaches harm people in proportion to what was stored: a leaked KYC database exposes identity documents; a leaked marketing database exposes profiles and habits. The maximum conceivable exposure here is a phone number and a chat history — serious enough that we protect it, small enough that the worst case is categorically different from document-upload platforms. Choosing services by their breach surface is an underrated privacy habit, and this section exists so you can apply it with accurate information.
10. Your practical privacy checklist as a player
Our side of privacy is architecture; your side is habit. The complete checklist, none of it burdensome: enable WhatsApp two-step verification (Settings → Account → Two-step verification), since your chat is your service identity. Keep the betting chat and browser bookmark off shared devices, and log out of the panel on any phone that is not yours. Use your own UPI identity rather than routing through family accounts — cleaner for privacy and mandatory for smooth payouts anyway. And treat your chat history as the private financial record it is: export or screenshot what matters, delete what you wish, and know that whatever you keep is under your control, not ours.
What you never need to do here: create website passwords (this site has no accounts), share documents (never requested), or click through cookie consent theatre (there is nothing to consent to). Absence of friction is absence of collection — a pattern worth checking on every service you use, not just this one.
11. Retention timelines, specifically
Chat history is retained while your service relationship is active, because it is the working record of terms and confirmations both sides rely on. Payment references are retained for reconciliation and dispute resolution for as long as those purposes genuinely require. After a deletion request, personal data is removed within 30 days, with the narrow exception of payment reconciliation records where a legitimate dispute-resolution basis remains — an exception applied honestly, not as a loophole. A closed ID with settled balances and no open matters clears fully.
12. Changes to this policy
If practice ever changes materially — new data categories, new sharing, new tools — this page changes first and the effective date at the top moves with it. We do not operate a "we may update at any time without notice" clause in spirit: material changes to a privacy relationship deserve visibility, and a service whose entire model is written records can hardly argue otherwise. The version you read is the practice you get.
13. Security practices on our side
A short data list still deserves real protection, and these are the practices behind ours. Service devices and accounts run under access controls with the chat channels limited to the team that needs them — the same team accountable for everything else in this document. Payment reconciliation records live separately from chat operations, so a person answering service questions touches transaction data only when a transaction question requires it. WhatsApp's own end-to-end encryption covers every conversation in transit by platform default. And the deliberate absence of a customer database is itself the largest security practice: what does not exist cannot leak, cannot be exfiltrated, and cannot be subpoenaed beyond its actual contents.
On the website side, cricbet99winid.in serves static content over HTTPS with security headers configured, holds no user accounts and therefore no credentials, and runs no third-party scripts that could carry tracking or compromise. The attack surface of a site with nothing to steal is the quiet privacy feature nobody advertises.
14. The complete third-party inventory
Every external party that could ever touch your data, exhaustively: WhatsApp/Meta carries the conversation under its own terms and encryption — choosing the service means accepting WhatsApp as transport, which for most players is an account they already hold. Your UPI provider and banks process payments under banking regulations, seeing what payment processors always see. The exchange panel receives the minimum needed to operate your ID, as section 5 states. That is the whole list. No analytics vendors with your identity, no advertising networks, no data brokers, no "trusted partners" — and if that list ever grows, section 12's change commitment puts it on this page before it happens.
15. Children and age protection
This service is strictly 18+, and the privacy design participates in enforcing that rather than undermining it. Age is confirmed in the chat before any ID is created; IDs discovered in use by minors are frozen immediately under the terms; and we knowingly hold no data about anyone under 18 — a minor's interaction with the service ends at the age check, leaving nothing behind but the refusal itself. Parents and guardians who believe a minor has accessed betting services through any provider should also know the device-level tools: UPI apps support transaction locks, phones support app restrictions, and WhatsApp chats are visible to whoever manages the device. If such a concern involves us, one message to the chat freezes the relevant ID while the facts are established — treated as an urgent harm matter, not an administrative one.
16. How to read any privacy policy — a transferable skill
Since you are the rare person actually reading one, take the transferable method with you. Four questions expose any policy's reality faster than reading it linearly. What do they collect? — look for the nouns: documents, contacts, location, behavioural data; the length of that list is the risk. Who do they share with? — "partners" and "affiliates" doing heavy lifting is the tell; named categories with purposes is the honest version. How long do they keep it? — indefinite retention "as permitted by law" means forever; real timelines mean someone thought about it. What can you make them do? — access, correction and deletion rights with a concrete process, or a compliance paragraph with no door handle.
Run those four questions on this policy and the answers are: a number, a chat and transactions; the panel minimally and no one else; active-relationship retention with a 30-day deletion clock; and a one-message deletion process. Run them on the next betting site you evaluate — especially the ones demanding document uploads — and you will learn more in two minutes than their marketing pages will tell you in an hour. Privacy literacy is a player skill exactly like odds literacy; both replace trust with verification.