Last updated: January 2026. This policy applies to beetgoat.my and all BetGoat services available through this domain. “We”, “us”, and “BetGoat” refer to the platform operator. This policy is written to explain what we actually do with your data, not to minimise liability.
BetGoat is a privacy-first platform. That means the default data collection stance is minimal: we collect what is necessary to operate a gaming service, process crypto transactions, and provide customer support. We do not collect advertising data. We do not build behavioural profiles for sale to third parties. We do not share your data with anyone except the categories described in section 3 of this policy, and we do not do so for any commercial purpose outside platform operation.

The data we collect falls into distinct categories, each with a specific purpose. Understanding why each category exists helps you assess whether our collection practices are proportionate to the service we provide.
| Category | Data Included | Purpose | Legal Basis |
|---|---|---|---|
| Account Registration | Email address, username, password (hashed), country of residence | Account creation, authentication, jurisdiction eligibility | Contract performance |
| Crypto Wallets | Wallet addresses used for deposits and withdrawals | Transaction processing, withdrawal routing | Contract performance |
| KYC (when triggered) | Government ID photo, proof of address, selfie | High-value withdrawal verification, AML compliance | Legal obligation |
| Gameplay and Sessions | Games played, bet amounts, session duration, login timestamps | Responsible gaming monitoring, fraud detection, RTP verification | Legitimate interests |
| Device and Technical | IP address, device type, browser/app version, geolocation | Jurisdiction verification, fraud detection, security | Legitimate interests |
| Communications | Live chat transcripts, email content, Telegram messages | Support delivery, dispute resolution, compliance records | Legitimate interests |
| Blockchain Data | On-chain transaction hashes, wallet transaction history | Deposit verification, AML screening, withdrawal confirmation | Legal obligation |
Blockchain transactions are public by design. When you deposit to your BetGoat wallet address, that transaction is visible on the relevant blockchain explorer to anyone who has the transaction hash or your wallet address. BetGoat does not control this: it is a property of the blockchain, not a BetGoat data collection practice. What BetGoat sees is the transaction from your address to your BetGoat wallet address, which we link to your account for deposit crediting purposes.
We record your deposit wallet addresses and withdrawal wallet addresses. These are stored in association with your account for transaction routing and, where legally required, for AML screening purposes. We do not share wallet address information with third parties except in the categories described in section 3. The blockchain itself is public; our internal records of which wallet address belongs to which account are not.
The pseudonymous nature of crypto wallets means that registering with a fresh wallet address provides a degree of unlinkability that fiat payment methods do not. BetGoat does not require you to prove that a deposit wallet is linked to an identity document, except in the KYC-triggered circumstances described below. This privacy architecture is consistent with the platform’s privacy-first positioning.
BetGoat does not require KYC to register, deposit, or play. KYC verification is triggered by one of two conditions: cumulative withdrawals exceeding a threshold set in compliance with our Curacao licence AML requirements, or a security or fraud detection flag on the account. When triggered, KYC requires a government-issued ID photograph and a selfie for identity matching. Some accounts may also need proof of address or source of funds for higher-value withdrawals.
KYC documents are stored in an encrypted document system with access restricted to compliance personnel with individually logged authorisation. Documents are never shared with game providers, marketing services, or any third party for commercial purposes. The retention period for KYC documents is five years after account closure, driven by AML regulatory requirements. We cannot delete them earlier than this regardless of any request. If you make a deletion request for KYC data, we will confirm the applicable retention period and the date on which deletion will occur.
The list of parties who receive BetGoat user data is short and purposeful. Sharing beyond this list does not occur.
When you open a game, an anonymous session token is passed to the provider. No email, no wallet address, no personal data is shared with any game provider. Origami games run entirely within BetGoat infrastructure with no external provider data transfer at all.
Withdrawals are broadcast to the relevant blockchain network (Tron, Bitcoin, Ethereum, Solana). Transaction data is inherently public on-chain. BetGoat does not control blockchain visibility; however, we do not add any additional personal data to on-chain transactions beyond the wallet address and amount.
Curacao gaming authority and applicable law enforcement may request account data under valid legal process. We comply with legally valid requests and, where the law permits, notify affected accounts that a request was received and what was provided.
Blockchain analytics tools screen deposit and withdrawal addresses for AML compliance. These services receive wallet addresses and transaction data only – no personal identity information is shared unless KYC has been completed and a specific regulatory disclosure is required.
BetGoat verifies your location at login and periodically during sessions to confirm you are accessing from a jurisdiction where the platform is licensed to operate. This uses your IP address and, in some cases, device geolocation. We record the jurisdictions from which your account is accessed. If you access from a restricted jurisdiction, your account may be suspended pending review. VPNs and location spoofing violate the platform terms of service: accessing from a restricted jurisdiction using VPN is treated as a policy violation regardless of your physical location.
The geolocation data is used only for jurisdiction compliance and fraud detection. We do not use it for advertising targeting, player profiling, or any commercial purpose. Access location records are retained for one year from collection.
Account registration data is retained for five years after account closure. KYC documents are retained for five years after account closure. Blockchain transaction records are retained for seven years from the transaction date. Gameplay and session records are retained for two years. Support communications are retained for two years from the last message. Device and geolocation records are retained for one year. After each applicable retention period, data is securely deleted or irreversibly anonymised.
BetGoat uses cookies for session authentication (keeping you logged in), language and display preferences, analytics (aggregated feature usage), and security monitoring (detecting unusual session patterns). Advertising cookies are not used. Third-party advertising networks do not receive any data through BetGoat’s cookie implementation. Disabling session cookies in your browser will prevent persistent login and will likely interrupt platform functionality.
Material changes to this policy — those affecting what data is collected, who receives it, or what your rights are — are communicated by in-platform notification at least 14 days before taking effect. Non-material clarifications are updated in the policy text with a revised date and do not require separate notification. The most recent update date is shown at the top of this page.
For all privacy queries: open BetGoat live chat and state it is a data privacy request, or use the contact details in the platform help section. For formal data access requests, include your registered email address and account username. We respond within 5 business days for general queries and within 30 calendar days for formal data requests. For regulatory escalation, contact the Curacao Gaming Authority as the governing jurisdiction for our operating licence.