Your privacy matters to us. This Privacy Policy explains exactly what personal data 18aaco collects, why we collect it, how it is stored and protected, and the rights you have over your information as a player on our platform.
These cards outline the core principles of the 18aaco Privacy Policy. The full legal detail for each principle is contained in the numbered sections below.
18aaco collects only the personal data that is strictly necessary to operate your account, process payments, verify your identity, and comply with legal obligations. We do not collect data speculatively or sell it to advertisers.
All personal data stored by 18aaco is protected using 256-bit SSL encryption in transit and AES-256 encryption at rest — the same standards used by major Bangladeshi banks including Dutch-Bangla Bank and BRAC Bank.
You have the right to access, correct, and request deletion of your personal data held by 18aaco. You may also object to certain types of processing and request a portable copy of your data by contacting our support team.
18aaco does not sell, rent, or trade your personal data to third-party marketers, advertisers, or data brokers. Your information is used exclusively for delivering and improving the 18aaco platform and for meeting legal requirements.
Data is shared only with trusted service providers — payment processors like bKash, Nagad, and Rocket; identity verification partners; and game studios like Pragmatic Play and Evolution Gaming — solely to deliver our services to you.
Promotional communications from 18aaco are opt-in by default. You may withdraw consent for marketing emails, SMS, or in-platform notifications at any time via your account settings or by contacting customer support.
1.1 This Privacy Policy ("Policy") describes how 18aaco ("we", "us", "our", "Platform") collects, uses, stores, discloses, and protects personal data relating to individuals ("you", "Player", "User") who access or use the 18aaco online casino and sports betting platform at https://18aaco.app.
1.2 18aaco is committed to handling your personal data responsibly and in accordance with applicable data protection principles. We recognise that the protection of your privacy is fundamental to the trust you place in our platform.
1.3 This Policy applies to all personal data processed in connection with your use of the 18aaco platform, regardless of the device or method of access. It covers data collected via the website, any mobile-optimised interface, and any customer support or promotional communications.
1.4 This Policy should be read alongside the 18aaco Terms and Conditions and Responsible Gaming Policy, both of which form part of the overall framework governing your relationship with 18aaco.
1.5 If you have any questions about this Policy or about how your personal data is handled, please contact us using the details provided in Section 16.
2.1 For the purposes of this Privacy Policy, 18aaco acts as the data controller in respect of personal data collected from players and platform users. As data controller, 18aaco determines the purposes and means by which your personal data is processed.
2.2 Where 18aaco engages third-party service providers to process personal data on its behalf — such as payment processors, identity verification providers, or cloud infrastructure operators — those parties act as data processors and are bound by contractual obligations to process data only on 18aaco's documented instructions and to implement appropriate security measures.
2.3 For all data-related enquiries, you may contact 18aaco at: [email protected] (plain text — not a clickable link).
3.1 18aaco collects the following categories of personal data from players and users of the platform:
4.1 18aaco collects personal data through the following means:
5.1 18aaco processes your personal data for the following purposes:
| Purpose | Data Categories Used | Legal Basis |
|---|---|---|
| Account registration and management | Identity, Contact | Contract performance |
| Identity verification (KYC/AML) | Identity, Financial, Technical | Legal obligation |
| Payment processing (deposits & withdrawals) | Financial, Identity | Contract performance |
| Delivering gaming services | Gaming, Technical | Contract performance |
| Fraud and abuse prevention | Technical, Financial, Gaming | Legitimate interests |
| Responsible gaming monitoring | Gaming, Financial | Legal obligation / Legitimate interests |
| Customer support | Identity, Contact, Communication | Contract performance |
| Platform improvement and analytics | Technical, Gaming, Behavioural | Legitimate interests |
| Marketing communications | Contact, Communication | Consent |
| Legal compliance and regulatory reporting | All categories as required | Legal obligation |
5.2 18aaco will not use your personal data for any purpose that is incompatible with the purposes listed above without first providing you with notice and, where required, obtaining your consent.
6.1 18aaco processes personal data on the following legal grounds:
7.1 18aaco does not sell or rent personal data to any third party. We share personal data only in the following limited circumstances:
To facilitate deposits and withdrawals, 18aaco shares the minimum necessary financial and identity data with approved payment processors including bKash, Nagad, Rocket, Upay, Dutch-Bangla Bank, City Bank, BRAC Bank, Visa, and Mastercard. These processors are contractually bound to use your data only to process the transaction in question.
To fulfil KYC and AML obligations, 18aaco may transmit identity document copies and personal details to third-party identity verification service providers. These partners are authorised to process your data solely for the purpose of verification and are prohibited from using it for any other purpose.
Game studios including Pragmatic Play, Evolution Gaming, PG Soft, JILI, Ezugi, Microgaming, NetEnt, and Spribe may receive a pseudonymised player identifier and session token to load and operate their games within the 18aaco platform. No directly identifiable personal data (such as your name, address, or payment details) is transmitted to game providers.
18aaco uses third-party cloud hosting, content delivery, and cybersecurity services. These providers may have access to personal data stored on 18aaco's infrastructure in the course of providing their services and are bound by data processing agreements requiring them to maintain appropriate security standards.
18aaco may disclose personal data to competent regulatory authorities, law enforcement agencies, or courts where required to do so by law, court order, or other binding legal process. In such cases, 18aaco will disclose only the minimum data required to satisfy the legal obligation and, where permitted by law, will notify the affected player of the disclosure.
8.1 In order to operate the 18aaco platform, certain personal data may be transferred to, stored, or processed in countries outside Bangladesh. This may occur, for example, where 18aaco uses cloud servers or game-provider infrastructure hosted in another jurisdiction.
8.2 Where personal data is transferred internationally, 18aaco ensures that appropriate safeguards are in place to protect the data to a standard equivalent to that required under applicable data protection principles. Such safeguards may include contractual data protection clauses, data processing agreements with the receiving party, or reliance on the recipient country's adequacy status where applicable.
8.3 You may request information about the specific safeguards in place for any international transfer by contacting 18aaco at [email protected].
9.1 18aaco retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, to comply with legal obligations, and to resolve disputes or enforce agreements. The following indicative retention periods apply:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account registration data | Duration of account + 5 years post-closure | Legal and AML compliance |
| KYC identity documents | Duration of account + 5 years post-closure | AML regulatory requirement |
| Financial transaction records | 7 years from transaction date | Financial record-keeping obligations |
| Gaming session logs | 3 years from session date | Dispute resolution and responsible gaming |
| Customer support records | 3 years from last interaction | Quality assurance and dispute resolution |
| Marketing consent records | Until consent is withdrawn + 3 years | Proof of consent |
| Technical and log data | 12 months from collection | Security monitoring and fraud prevention |
9.2 At the end of the applicable retention period, personal data will be securely deleted or anonymised so that it can no longer be attributed to an identifiable individual.
9.3 Where you request deletion of your data under Section 12, 18aaco will assess the request against applicable retention obligations. Data that must be retained to meet a legal obligation cannot be deleted until the legal retention period expires, notwithstanding a deletion request.
10.1 18aaco implements a comprehensive set of technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, loss, or destruction. Key measures include:
10.2 Despite these measures, no online platform can guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, 18aaco will notify affected players promptly and take all reasonable steps to mitigate the impact of the breach.
10.3 You also play an important role in keeping your data secure. You are responsible for maintaining the confidentiality of your account password and for ensuring that you log out of your account after each session, particularly on shared or public devices.
11.1 The 18aaco platform uses cookies and similar tracking technologies to operate core platform functionality, analyse user behaviour, remember your preferences, and detect fraud. The following categories of cookies are used:
11.2 18aaco does not use third-party advertising cookies or retargeting pixels that would track your activity across unrelated websites for advertising purposes.
11.3 Most browsers allow you to manage cookie settings via the browser's privacy preferences menu. Please note that disabling strictly necessary cookies may prevent certain features of the 18aaco platform from functioning correctly.
12.1 Subject to applicable law and the retention obligations described in Section 9, you have the following rights in respect of your personal data held by 18aaco:
12.2 To exercise any of the above rights, please contact the 18aaco support team with your full name, registered account email address, and a clear description of your request. 18aaco will acknowledge your request within 5 business days and aim to provide a substantive response within 30 calendar days.
12.3 18aaco may request additional identity verification before fulfilling a data rights request to ensure that personal data is not disclosed to an unauthorised person.
13.1 The 18aaco platform is strictly intended for adults aged 18 years and above. 18aaco does not knowingly collect personal data from individuals under the age of 18.
13.2 As part of the account registration and KYC process, 18aaco verifies the age of all players. If 18aaco becomes aware that personal data has been collected from a person under the age of 18, that account will be immediately closed, all data associated with the minor will be permanently deleted, and any deposits will be returned to the originating payment method after verification.
13.3 If you have reason to believe that a minor has registered an account on the 18aaco platform, please contact us immediately at [email protected] so that we can investigate and take appropriate action.
14.1 With your consent, 18aaco may send you promotional communications relating to new games, seasonal bonuses, sports betting offers, VIP loyalty programme updates, and platform news. These communications may be delivered via email, SMS to your registered mobile number, or in-platform notification.
14.2 You may opt in to marketing communications during account registration or at any time via the Notifications section of your account settings. Opting in to marketing is entirely voluntary and has no effect on your ability to use the 18aaco platform.
14.3 You may withdraw your consent to receive marketing communications at any time by:
14.4 Withdrawal of marketing consent will be acted upon within 5 business days. Please note that you may continue to receive transactional and service-related communications (such as deposit confirmations, withdrawal notifications, and security alerts) regardless of your marketing consent status, as these are necessary for account operation.
15.1 18aaco reserves the right to update this Privacy Policy at any time to reflect changes in our data practices, applicable law, or the services we offer. The current version of the Policy, together with its effective date, will always be available at https://18aaco.app/privacy-policy.
15.2 Where changes to this Policy are material — meaning they significantly affect your rights or how your data is used — 18aaco will notify registered players via email or in-platform notification at least 14 days before the changes take effect.
15.3 Your continued use of the 18aaco platform following the effective date of any revised Policy constitutes your acknowledgement of the updated terms. If you do not accept the revised Policy, you should cease using the platform and may request account closure under the Terms and Conditions.
16.1 If you have any questions, concerns, or requests relating to this Privacy Policy or the way in which 18aaco handles your personal data, please contact our support team through any of the following channels:
16.2 Where you are not satisfied with 18aaco's response to a privacy-related complaint, you have the right to escalate your complaint to the relevant data protection authority in your jurisdiction.
Now that you know exactly how 18aaco protects your personal information, explore thousands of games, live cricket betting markets, and instant bKash and Nagad transactions — all secured with bank-grade encryption. Still have questions? Our FAQ page has answers to the most common player queries.