Account Registration
Data collected at sign-up is limited to what is needed to open and verify your account — no surplus collection.
Your privacy matters to us, and this policy sets out exactly what data gb999 collects when you open an account, how we use it, and how we keep...
This policy applies to all personal data processed through your gb999 account, including identity details you submit at registration, transaction records from JazzCash, Easypaisa, SadaPay and Raast deposits or withdrawals, and device data collected during sessions. We process this data to operate your account, verify transactions, and meet our legal obligations in supported regions where local law permits. We do not sell
your data to third parties. Retention periods vary by data type — transaction records are kept for the period required by applicable financial regulations, while marketing preferences you set are held only as long as your account remains active.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
We apply consistent data governance across every part of the gb999 platform, from the moment you submit your registration details through to the point a withdrawal clears to...
All personal and financial data is stored with encryption at rest. Account credentials use hashed storage so no plain-text passwords...
Only staff with a verified operational need can access your personal data. Access logs are reviewed regularly, and any anomaly...
JazzCash, Easypaisa, SadaPay and Raast transaction data is processed through isolated pipelines. Your payment credentials are never stored on gb999...
Our privacy policy is reviewed on a fixed internal cycle and updated whenever regulations in supported regions change. We notify...
Any processor we engage — analytics, fraud detection, or KYC verification — operates under a data processing agreement that limits...
For accounts registered from Pakistan and other supported regions, we align our data handling with applicable local and international data...
Our privacy commitments carry through consistently across every section of the gb999 platform. The table below shows how the principles in this policy connect to the areas of the site where your...
Data collected at sign-up is limited to what is needed to open and verify your account — no surplus collection.
JazzCash and Easypaisa deposit flows share the same data isolation standards as SadaPay and Raast withdrawals.
Device and session data collected during your visit is used solely for security and performance — never sold or profiled for advertising.
Identity documents submitted for verification are held only for the legally required period and then deleted or anonymised per our retention schedule.
We send promotional messages only where you have actively opted in. Withdrawing consent is a single action inside your account settings.
Our cookie policy, linked at the bottom of every page, mirrors the consent and withdrawal mechanisms described in this privacy policy.
Pages on gb999 may link to external services. This policy does not extend to those sites; we flag where a link leaves our platform.
Privacy at gb999 is not a compliance checkbox — it is built into how we designed account flows, data pipelines, and support processes from the start...
We collect only the data we genuinely need for your account to function. If a field is not operationally necessary, it is not on our forms — reducing the data footprint we hold on your behalf.
Data you provide for one purpose — say, KYC verification — is not repurposed for unrelated activities like profiling or third-party marketing without your explicit consent at the time of collection.
Every category of data we collect is listed in this policy alongside the legal basis we rely on to process it. There are no silent data uses operating outside what is described here.
You can access, correct, or request deletion of your personal data at any time through your account settings or by contacting our privacy team directly, without needing to justify the request.
We maintain a documented response plan for data incidents. If a breach affects your personal data, we notify you and relevant authorities within the timeframe required for supported regions.
Data is not kept indefinitely. Each category has a defined retention period tied to its operational or legal purpose, after which it is deleted or anonymised systematically.