Wingo Game • India

Privacy Policy — Data Protection, KYC, UPI, Security & Rights for Indian Players

Welcome to the official Wingo Game Privacy Policy. This document explains what personal data we collect, why we process it, how long we keep it, how we secure it, your rights under applicable laws, and how responsible gaming, age and state eligibility, and KYC/UPI payments interact with privacy safeguards.

This policy is educational and transparency-focused. It is not legal advice. We avoid sensational claims and emphasize control, clarity, and safety for 18+ users in eligible Indian states.

Scope, Audience & Definitions

Scope. This policy covers the Wingo Game website and app experiences provided to users located in India, including registration, login, game participation, results viewing, UPI deposits, bank withdrawals, KYC verification, support interactions, and responsible-gaming tools.

Audience. The service is for adults only (18+). Access and participation are subject to state-level rules; users from restricted states must not participate. We employ self-declarations and geolocation signals to reduce ineligible access.

Definitions. “Personal data” means information that identifies or can reasonably be linked to you (e.g., name, mobile, email, KYC documents). “Processing” means any operation performed on personal data (collection, storage, use, sharing, deletion). “KYC” is “Know Your Customer.” “UPI” is the Unified Payments Interface used for Indian real-time payments. “Responsible gaming” means tools and education that help users keep activity within healthy limits.

Data We Collect: Categories & Examples

Identity & Contact

  • Mobile number (for OTP), email (for passwordless links), display name.
  • KYC data: government ID details, proof of address, date of birth (18+ check).
  • Bank details necessary for withdrawals and reconciliation.

Account & Activity

  • Account settings, device trust signals, session logs.
  • Game participation records, draw IDs, timestamps, result history.
  • Responsible-gaming preferences: spending caps, reminders, time-outs.

Payments & Technical

  • UPI deposit reference IDs, success/pending/error states, status notifications.
  • Withdrawal requests, KYC hold status, bank verification checks.
  • Device model, OS, app version, IP-derived geolocation signals to support eligibility and abuse prevention.

Support & Compliance

  • Support tickets, call/chat transcripts, attached screenshots with redaction practice.
  • Risk & fraud indicators, velocity checks, device change events.

Data We Avoid

We do not intentionally collect content unrelated to the service (e.g., personal photo galleries, contacts). If such data is accidentally submitted, we delete or redact it once identified.

Purposes & Legal Bases (Illustrative)

Provide the Service

  • Registration, login, device trust, session maintenance.
  • Gameplay, results, history archives, responsible-gaming tools.

Legal bases may include contract performance and legitimate interests.

Payments & KYC

  • UPI deposits, reconciliation, duplicate prevention, refunds/reversals.
  • Withdrawals to bank accounts, name-match checks, fraud prevention.
  • KYC verification and re-verification where required.

Legal bases may include legal obligations, contract, and legitimate interests.

Safety, Compliance & Improvement

  • Risk signals, anomaly detection, incident response.
  • Support operations, quality assurance, product analytics (privacy-minded).

Legal bases may include legitimate interests and legal obligations.

Cookies, Local Storage & Similar Technologies

We use cookies and similar storage (including local storage) for session continuity, security hardening, feature toggles, language preferences, and lawful analytics. We avoid invasive fingerprinting; device signals are collected narrowly to protect accounts and deter fraud.

  • Essential: sign-in tokens, CSRF protections, eligibility gates.
  • Functional: remembered preferences, accessibility settings.
  • Analytics (privacy-minded): performance metrics to improve reliability and Core Web Vitals.

You can clear cookies/storage in your browser or OS settings; doing so may sign you out or reset preferences.

Retention: How Long We Keep Data

Guiding Principles

  • Keep data no longer than necessary for the purposes stated.
  • Respect legal/contractual obligations and dispute periods.
  • Apply redaction or deletion schedules to stale records.

Illustrative Windows

  • Account & sessions: active use + short grace period for recovery.
  • KYC records: retained per compliance requirements.
  • Payments & reconciliation: retained per financial rules and audits.
  • Support tickets: retained for quality, fraud investigations, and legal holds.

Exact periods can vary by law and context; in disputes or investigations we may retain relevant data until resolution.

Sharing: Processors, Partners & Disclosures

  • Processors: verified service providers for infra, storage, analytics, customer support, and KYC processing under contractual safeguards.
  • Payments: banks and UPI-related parties for deposits, settlements, and reconciliation.
  • Compliance: competent authorities when legally required (e.g., lawful requests, court orders).
  • Business operations: strictly limited sharing for auditing and incident response with confidentiality commitments.

We do not sell personal data. We pursue minimal, purpose-bound sharing with security and confidentiality obligations.

Security: Defense-in-Depth & Incident Handling

Technical Measures

  • Encryption in transit and at rest; hardened configurations.
  • Rate limiting, bot mitigation, anomaly detection.
  • Access controls, session revocation, device notifications.

Organizational Measures

  • Role-based access, staff training, privacy-by-design reviews.
  • Incident runbooks, red-team style drills, supplier audits.
  • Change logs for material updates to policies or flows.

Incident Response

If we identify a security issue affecting users, we follow documented playbooks: triage, containment, forensic analysis, remediation, and notifications consistent with applicable requirements.

Children, Sensitive Data & High-Risk Contexts

The service is for adults only (18+). We do not knowingly allow underage participation; signals suggesting underage use trigger account restrictions and reporting consistent with policy and law.

We avoid processing sensitive categories unless strictly necessary and lawful (e.g., age verification via KYC). We discourage users from uploading unrelated sensitive information into support channels.

Your Privacy Rights & How to Exercise Them

Core Rights (Illustrative)

  • Access: request a copy of your personal data we hold.
  • Correction: ask us to fix inaccurate or incomplete data.
  • Deletion: request deletion subject to legal/contractual retention.
  • Portability: request data in a portable format when feasible.
  • Restriction/Objection: ask us to pause or limit certain processing where applicable.
  • Withdraw Consent: when processing relies on consent, you can withdraw it.

Exercising Rights

You can initiate requests through in-app support or verified channels tied to your account. For identity protection we may request additional verification. If your request involves third-party systems (e.g., banks), coordination may be needed.

We respond within reasonable timeframes. If we cannot fulfill a request due to legal obligations, we will explain why where permitted.

International Data Transfers

Service providers or infrastructure may be located in or route through multiple jurisdictions. We use contractual protections and technical safeguards to protect data across borders, following applicable requirements and best practices.

Automated Decision-Making & Profiling

We use automated systems to detect risk patterns such as unusual sign-ins, payment anomalies, or suspected fraud. These systems can trigger holds or additional verification. Human review is involved for material decisions to reduce errors and bias. We do not use automated systems to promise outcomes or guarantee results in lottery-style draws.

Changes to This Policy & Versioning

We may update this policy to reflect product changes, legal developments, or security improvements. We publish change notes summarizing material updates and adjust the effective date. Continued use after changes indicates acceptance of the updated policy.

For significant changes, we provide prominent notice within the service.

Legality in India & Responsible Gaming Context

Lottery and lottery-style number games operate under state-level rules. Some states historically permit online formats (e.g., Kerala, Sikkim, Nagaland); others restrict or prohibit. Users must be 18+ and in eligible locations. We implement geolocation checks and self-declarations to reduce ineligible access.

Responsible gaming is a core value: we provide spending caps, reminders, time-outs, and educational prompts about randomness and variance. We discourage myths and “guaranteed prediction” claims.

Glossary: Privacy & Security Terms

Personal Data

Information that identifies you or can be linked to you, such as mobile number, email, KYC info, or payment references.

Processing

Any operation on personal data: collection, storage, use, sharing, deletion.

KYC

Know Your Customer; required for withdrawals and specific risk reviews.

UPI

Unified Payments Interface used by Paytm, PhonePe, Google Pay for real-time transfers in India.

Encryption

Protects data during transmission and at rest to reduce unauthorized access.

Retention

How long data is kept before deletion or anonymization, based on purpose and legal needs.

Incident Response

Structured process for detecting, containing, investigating, and communicating about security issues.

Responsible Gaming

Controls and education that help users keep activity within healthy limits.

Frequently Asked Questions

Do you sell my personal data?

No. We do not sell personal data. Sharing is purpose-bound (e.g., processors, UPI/banks, lawful requests) with safeguards and contracts.

What data is required for KYC and withdrawals?

Identity and address documents, age confirmation (18+), and bank details that match your legal name. Unclear scans or mismatched names may lead to holds until corrected.

How do I exercise my privacy rights?

Submit a request via in-app support or verified channels. We may request additional verification to protect your account. Responses are provided within reasonable timeframes as allowed by law.

Do you track my location?

We use IP-derived signals and self-declarations to help assess state-level eligibility and prevent abuse. We avoid excessive location tracking and collect only what’s necessary for eligibility and safety.

What happens if there is a data incident?

We follow incident-response playbooks (triage, containment, investigation, remediation, notifications as required). We aim for clear, practical guidance to affected users when applicable.

Are predictions or “tips” used to profile me?

No. We do not use predictions to promise returns. We discourage myths and emphasize randomness and responsible play.

How long will you retain my data if I close my account?

We delete or anonymize data according to retention schedules and legal requirements. Some records (e.g., financial or compliance) must be retained for specified periods before deletion.

Back to Home

If you want to revisit our India overview and responsible-gaming guidance before proceeding, return to Wingo Game. Participation is optional; stop immediately if you are under 18, in a restricted state, or feel any financial stress.

Effective Date: This policy takes effect upon publication and remains in force until updated. Material updates will be announced in-product.