9KBoss Privacy Policy for Personal Data in India

The 9KBoss privacy policy manages account information. The company gathers personal data for registration, KYC, payments, security, customer support, gaming controls, and compliance. Technical records assist with account management activities. Staff use technical records to safeguard login sessions, identify fraud, maintain site operations, and review errors. Users should read the privacy policy before registering and review it after updates.

Information Collected

Users submit information. Technical systems supply additional details. The service collects personal data across several categories.

Data category Examples
Registration data Name, date of birth, mobile number, email address, country, language, and account ID
Identity records Aadhaar, PAN, passport, driving licence, address proof, selfie, and verification results
Payment data UPI ID, bank details, transaction references, cryptocurrency wallet addresses, deposits, and withdrawals
Account activity Login history, bonuses, limits, casino rounds, sports bets, wins, losses, and balance changes
Device information IP address, device type, operating system, browser, application version, language, and approximate location
Support records Chat messages, contact forms, complaints, attachments, case references, and responsible gaming requests
Preference data Language, notifications, marketing consent, cookie choices, limits, and self-exclusion status

Purposes of Data Processing

Staff process payments. They use data to manage accounts and maintain security. Staff support communication, ensure compliance with legal requirements, and oversee user controls. They process information as described in the Privacy Policy and related notices.

9KBoss collects and manages personal data to meet operational needs, legal obligations, and security requirements. Staff process information from account registration and use, with each purpose based on lawful grounds under applicable data protection regulations.

Marketing messages are sent only with user consent or when permitted by law. Users can opt out at any time by clicking unsubscribe links, adjusting their account settings, or updating their preferences. However, communications about security, payments, legal matters, or updates will still be sent.

Cookies and Third-Party Services

Cookies and similar tools store session details. Staff rely on these tools to protect logins, remember user preferences, and manage language choices. Cookies also help identify errors and guide account navigation. Staff use them to process payment requests, measure traffic, support marketing, and measure performance. When cookies enable sign-in, they increase security.

Allowed cookie types can be managed through browser settings. Blocking required cookies prevents logging in, using Cashier, and accessing account settings. Deleting cookies erases saved preferences and starts a new session when you return.

External organisations access information according to their roles and contracts. This includes payment services, KYC providers, cloud hosting companies, fraud-prevention services, game suppliers, sports data and analytics providers, communication tools, advisers, and authorities, all of whom use or handle these details as required.

The Privacy Policy outlines the types of information that may be shared and the reasons for sharing them. The site may disclose information to comply with legal obligations or in response to a legitimate request. Before submitting any information, users should review the notice related to third-party payment or identity services.

Security, Retention and International Transfers

Staff connect through encrypted channels. Access controls remain in place throughout each session. Authentication occurs every time a session starts. The team records activity periodically. Managers organize and perform backups. If an incident arises, the team follows established response procedures.

Users secure their accounts by locking devices, protecting contact methods, setting passwords, and keeping software updated. Before handing devices to others, they log out. If they find unfamiliar sessions, account changes, or unexpected payments, they report these issues through chat.

Retention periods are determined by factors such as account operation, KYC requirements, anti-fraud checks, payments, tax duties, legal claims, gaming records, and disputes. Once staff no longer require the information and the retention period has expired, they delete or anonymise the data.

Indian data protection law consists of the Digital Personal Data Protection Act, 2023. The Digital Personal Data Protection Rules, 2025, are also relevant. External providers might use or process data in locations outside India. The policy outlines the legal, contractual, and security requirements that govern such data transfers.

User Rights, Updates and Contact

Privacy rights are determined by applicable law, purpose of processing, and identity verification. Users should visit the Contact section to submit a request; if logged in, users may use the support channel to submit a request. Users must provide their account ID, request type, and registered contact details for record location.

Indian data protection law grants users control over their personal data by limiting how organizations collect, use, and store it. After identity verification, users gain specific rights, and organizations must explain data collection purposes and follow retention regulations.

Identity checks prevent unauthorized access to personal records. When a deletion request is submitted, the site continues to comply with Know Your Customer and Anti-Money Laundering regulations. The request does not affect payment retention, tax retention, security retention, self-exclusion retention, or dispute retention.

The service updates its Privacy Policy due to legal, operational, security, or technical changes. Before signing in again, users must review the revised policy and may adjust their consent or marketing preferences during this process.

Frequently Asked Questions

What information does 9KBoss collect?

The data set contains registration and KYC details, payment records, account activity, device data, support messages, user preferences, security records, and gaming control entries.

Does account closure delete every record immediately?

No. People must retain records for a set period to meet legal, payment processing, KYC, security, dispute resolution, tax, and self-exclusion requirements.

How does a user submit a privacy request?

Sign in, go to the Contact section or support channel, enter your account ID, select your request type, and provide your registered contact details.