This Privacy Policy ("Policy") is issued by slowin ("we", "us", "our", "the Company"), the operator of the online gaming platform accessible at https://slowin.cam. It applies to all registered players, visitors, and prospective users — including players located in Jakarta, Surabaya, Medan, Bandung, Bali, and across Indonesia. By accessing or using the slowin platform, you acknowledge that you have read this Policy and consent to the data practices described herein. If you do not agree to this Policy, you must cease using the platform immediately.

1

Definitions

Throughout this Policy, the following terms carry the meanings set out below:

  • "Personal Data" — any information relating to an identified or identifiable natural person, including name, identification number, location data, IP address, or any other identifier.
  • "Processing" — any operation performed on Personal Data, including collection, recording, storage, use, disclosure, erasure, or destruction, whether automated or manual.
  • "Data Controller" — slowin, which determines the purposes and means of processing your Personal Data.
  • "Data Processor" — any third party that processes Personal Data on behalf of slowin, including payment service providers, KYC verification partners, and cloud infrastructure providers.
  • "Consent" — a freely given, specific, informed, and unambiguous indication of your agreement to the processing of your Personal Data.
  • "KYC" (Know Your Customer) — the identity and age verification process conducted by slowin and its appointed verification partners to confirm account holder identity before processing withdrawals or as otherwise required.
  • "Cookies" — small text files placed on your device by the slowin platform that enable session management, preference storage, and analytics tracking.
  • "Platform" — the entirety of slowin's online casino and sports betting services, website, and mobile-optimized interface at https://slowin.cam.
2

Information We Collect

2.1 Identity and Registration Data

When you create a slowin account, we collect your full legal name, date of birth, gender, and nationality. This data is essential for age verification (21+ requirement) and fulfilling our KYC obligations.

2.2 Contact Data

We collect your email address and Indonesian mobile phone number at registration. These are used for account communications, security notifications, and optional promotional messages you have opted into.

2.3 Financial Data

To process deposits and withdrawals, we collect payment method details including bank account numbers registered with BCA, BRI, BNI, Mandiri, CIMB Niaga, OCBC NISP, BSI, Bank Permata, or Bank Danamon, and e-wallet identifiers for OVO, DANA, GoPay, ShopeePay, and LinkAja. We do not store full card numbers. All financial data is transmitted via encrypted channels.

2.4 Identity Verification Documents

As part of KYC compliance, we may collect copies of government-issued identification (Indonesian KTP, passport, or SIM), proof of address documents (utility bills or bank statements), and selfie photographs for biometric identity confirmation.

2.5 Technical and Device Data

We automatically collect IP address, device type and operating system, browser type and version, screen resolution, time zone setting (WIB/WITA/WIT), session start and end timestamps, and pages visited within the platform.

2.6 Transaction and Gaming Data

We maintain records of all deposits, withdrawals, wagers, game sessions, bonus activations, and their outcomes. This data is used for account integrity, dispute resolution, frau d detection, and regulatory compliance purposes.

2.7 Communications Data

We retain records of your interactions with our customer support team via live chat and email, including the content of those communications, timestamps, and resolution outcomes. This allows us to maintain service quality and resolve recurring issues effectively.

Minimization Principle: slowin collects only the Personal Data that is strictly necessary for the specific purposes described in this Policy. We do not collect sensitive categories of data (such as race, religion, or health information) unless expressly required for responsible gaming assessments with your consent.

3

How We Collect Data

slowin collects your Personal Data through the following channels and mechanisms:

  • Direct submission — information you provide when registering an account, completing KYC forms, making deposits or withdrawals, contacting support, or responding to surveys.
  • Automated collection — technical and device data gathered automatically as you browse and interact with the platform, including via cookies, web beacons, pixel tags, and server logs.
  • Third-party verification partners — identity and age verification data obtained from licensed KYC service providers who cross-reference your submitted documents against authoritative data sources.
  • Payment processors — transaction status and confirmation data relayed from local Indonesian banks and e-wallet providers upon processing deposits and withdrawals.
  • Fraud prevention services — risk signals and device fingerprinting data from security partners used to detect suspicious activity and protect account integrity.
  • Analytics providers — aggregated behavioral data from platform analytics tools that help us understand usage patterns and improve the user experience.
4

How We Use Your Data

slowin uses your Personal Data for the following purposes. Each purpose is tied to a specific legal basis described in Section 5.

Purpose Data Used Legal Basis
Account creation and management Identity, contact, registration data Contract performance
Age and identity verification (KYC) Identity documents, date of birth Legal obligation
Processing deposits and withdrawals Financial data, transaction records Contract performance
Fraud prevention and security Technical, device, transaction data Legitimate interest
Responsible gaming monitoring Gaming history, self-exclusion requests Legal obligation / consent
Customer support delivery Communications, account data Contract performance
Promotional communications Contact data, gaming preferences Consent
Platform analytics and improvement Technical, behavioral data Legitimate interest
Regulatory reporting and compliance Identity, financial, transaction data Legal obligation

Marketing Opt-Out: If you have consented to receive promotional communications and wish to withdraw that consent, you may do so at any time via your Account Settings or by contacting our support team. Withdrawal of marketing consent does not affect service-related communications such as deposit confirmations or security alerts.

6

Data Sharing

6.1 We Do Not Sell Your Data

slowin does not sell, rent, or trade your Personal Data to any third party for their own marketing or commercial purposes. Any sharing of your data is limited to the categories and purposes described in this section.

6.2 Service Providers (Data Processors)

We share your data with carefully vetted third-party service providers who process data strictly on our behalf and under our instructions, including:

  • Payment processors — Indonesian banks (BCA, BRI, BNI, Mandiri, and others) and e-wallet operators (OVO, DANA, GoPay, ShopeePay, LinkAja) for transaction processing.
  • KYC and identity verification providers — licensed third-party services that cross-reference identity documents to confirm age (21+) and prevent identity fraud.
  • Cloud infrastructure and hosting providers — secure cloud platforms that host the slowin platform and its databases, operating under contractual data security obligations.
  • Fraud prevention and cybersecurity partners — risk intelligence providers that analyze device and behavioral signals to detect and block fraudulent activity.
  • Customer support platform providers — live chat and ticketing system vendors that facilitate communication between players and the slowin support team.
  • Analytics providers — platform performance and usage analytics tools operating on anonymized or pseudonymized data sets.

6.3 Game Content Providers

Third-party game studios whose titles are available on the slowin platform — including Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, and Pocket Games Soft — may receive limited technical data (such as player session identifiers) necessary to deliver their games. These providers operate under their own data protection frameworks and are contractually prohibited from using your data for purposes beyond game delivery.

6.4 Regulatory and Law Enforcement Disclosure

We may disclose your Personal Data to competent authorities, regulators, law enforcement agencies, or courts where we are required to do so by applicable law, court order, or regulatory mandate. We will notify you of such disclosures where legally permissible.

6.5 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of slowin's business, your Personal Data may be transferred to the acquiring entity. You will be notified of any such transfer and the privacy practices of the successor entity before your data is subject to a materially different privacy policy.

Data Processing Agreements: All third-party Data Processors engaged by slowin are bound by contractual Data Processing Agreements (DPAs) that require them to maintain appropriate technical and organizational security measures and process your data only for the specific purposes we authorize.

7

Cookies & Tracking Technologies

7.1 What We Use

The slowin platform uses the following categories of cookies and tracking technologies:

Cookie Type Purpose Duration
Strictly Necessary Session management, login authentication, security tokens Session
Functional Language preferences, display settings, game lobby layout Up to 12 months
Analytics Page view counts, navigation paths, feature usage metrics Up to 24 months
Security / Fraud Detection Device fingerprinting, bot detection, anomaly scoring Up to 12 months

7.2 Managing Cookies

Strictly necessary cookies cannot be disabled as they are essential for the platform to function. You may manage functional and analytics cookies via your browser settings. Most modern browsers allow you to block, delete, or receive notifications about cookies. Please note that disabling certain cookies may limit your access to some platform features or require you to re-authenticate more frequently.

7.3 Do Not Track

Some browsers transmit a "Do Not Track" (DNT) signal. The slowin platform does not currently alter its data collection practices in response to DNT signals, as there is no universally accepted standard for interpreting these signals. We will review this position as industry standards evolve.

8

Data Retention

slowin retains your Personal Data only for as long as necessary to fulfill the purposes outlined in this Policy and to comply with applicable legal and regulatory obligations. The following general retention periods apply:

  • Active account data — retained for the full duration of your account's active status plus a minimum of five (5) years following account closure, to satisfy AML and financial record-keeping requirements.
  • KYC documents — retained for a minimum of five (5) years from the date of submission, or longer if required by applicable regulations.
  • Transaction records — retained for a minimum of five (5) years following the transaction date.
  • Customer support communications — retained for two (2) years from the date of last interaction, unless the matter relates to an unresolved dispute.
  • Marketing preference records — retained for three (3) years from the date of last consent or opt-out, to demonstrate compliance.
  • Cookie and analytics data — retained in accordance with the durations specified in Section 7, subject to periodic review.

Upon expiry of the applicable retention period, Personal Data is securely deleted or irreversibly anonymized so that it can no longer be associated with you.

9

Data Security

slowin implements a comprehensive set of technical and organizational security measures to protect your Personal Data against unauthorized access, disclosure, alteration, and destruction:

  • SSL/TLS Encryption: All data transmitted between your device and slowin's servers is encrypted using industry-standard Transport Layer Security (TLS 1.2 or higher).
  • Data Encryption at Rest: Sensitive data fields — including identity document copies and financial account details — are encrypted at rest using AES-256 encryption.
  • Access Controls: Internal access to Personal Data is restricted on a strict need-to-know basis. All staff with data access undergo background checks and are bound by confidentiality obligations.
  • Multi-Factor Authentication (MFA): Administrative systems handling Personal Data are protected by multi-factor authentication to prevent unauthorized internal access.
  • Regular Security Audits: slowin's platform and data infrastructure undergo periodic independent security audits and penetration testing.
  • Incident Response Plan: We maintain a documented data breach response plan. In the event of a breach that poses a risk to your rights, we will notify affected users within 72 hours of becoming aware of the incident, where practicable.

Your Responsibility: While slowin takes extensive measures to protect your data on our end, you are responsible for maintaining the security of your account credentials. Use a strong, unique password, enable any available two-factor authentication, and never share your login details with others. Report any suspected unauthorized access to [email protected] immediately.

10

Your Rights

Subject to applicable law and certain exemptions, you hold the following rights with respect to your Personal Data held by slowin. To exercise any of these rights, please contact our Data Protection team at the details provided in Section 14.

Right of Access

Request a copy of the Personal Data we hold about you and information on how we process it.

Right to Rectification

Request correction of inaccurate or incomplete Personal Data held in your account.

Right to Erasure

Request deletion of your Personal Data where it is no longer necessary, subject to our legal retention obligations.

Right to Restriction

Request that we temporarily restrict processing of your data while a dispute or correction request is being resolved.

Right to Portability

Receive a structured, machine-readable copy of data you provided to us, where technically feasible.

Right to Object

Object to processing based on legitimate interests, including direct marketing communications at any time.

slowin will respond to all valid rights requests within thirty (30) calendar days of receipt. We may request proof of identity before processing your request to prevent unauthorized access to another person's data.

11

International Data Transfers

slowin operates internationally, and your Personal Data may be transferred to, stored in, or processed in countries outside Indonesia. Some of our third-party service providers — including cloud infrastructure, analytics, and game studio partners — may operate data centers in jurisdictions that do not have data protection laws equivalent to those applied in Indonesia.

Where such transfers occur, slowin ensures that appropriate safeguards are in place to protect your data, including execution of standard contractual clauses, binding corporate rules, or reliance on adequacy decisions where applicable. By using the slowin platform, you acknowledge and consent to the transfer of your data under these safeguards.

12

Minors

The slowin platform is strictly intended for adults aged 21 years or older. We do not knowingly collect Personal Data from individuals under the age of 21. If we become aware that a user under 21 has registered an account or provided Personal Data, we will immediately suspend the account, delete the associated data, and take appropriate remedial action.

Parental Guidance: If you are a parent or guardian and believe your child under the age of 21 has created a slowin account, please contact us immediately at [email protected] (plain text — not a clickable link). We will investigate and remove the account and all associated data promptly.

13

Policy Amendments

slowin reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data practices, legal obligations, or platform features. When material changes are made, we will notify registered users via email to the address associated with their account and display a prominent notice on the platform for a minimum of fourteen (14) calendar days before the amended Policy takes effect.

The "Effective Date" displayed at the top of this page reflects when the current version of the Policy came into force. We encourage you to review this Policy periodically to remain informed of how we protect your data. Your continued use of the platform following the effective date of any amendment constitutes acceptance of the revised Policy.

14

Contact & Complaints

If you have any questions about this Privacy Policy, wish to exercise your data rights, or wish to raise a complaint about how slowin has handled your Personal Data, please contact our Data Protection team through the following channels:

  • Email: [email protected] (plain text — not a clickable link)
  • Live Chat: Available 24/7 via the chat widget on the slowin platform
  • Response Language: English and Indonesian (Bahasa Indonesia)
  • Response Time: Within 30 calendar days for rights requests; within 3 business days for general privacy inquiries
  • Hours: 24 hours a day, 7 days a week (WIB, UTC+7)

slowin is committed to resolving all privacy complaints fairly and transparently. If you are not satisfied with our response, you retain the right to escalate your complaint to the competent data protection authority or regulatory body applicable in your jurisdiction.

Related Policies: This Privacy Policy should be read alongside our Terms & Conditions and Responsible Gaming policy, which together govern your use of the slowin platform in full.