Updated May 2026. This policy covers rezeki-44.my and all Rezeki44 services accessible through this domain. “Rezeki44”, “we”, and “us” refer to the Rezeki44 platform operator within the RM Group network. This policy is written to explain what data is collected, why each category exists, who outside Rezeki44 sees any of it, how long each category is kept, and what you can do about any of it.
E-wallet-native platforms occupy a privacy category that is distinct from both traditional online bank-transfer platforms and fully anonymous crypto platforms. When you use TnG or GrabPay to deposit at Rezeki44, your e-wallet credentials authenticate you to the payment network, and a transaction record is created in both the e-wallet’s system and Rezeki44’s system simultaneously. The e-wallet holds your name, phone number, bank linkage, and transaction history under their own privacy regime. Rezeki44 holds a different subset: the transaction amount, the timestamp, the wallet identifier (your linked phone number), and the resulting balance change in your Rezeki44 account. Both records exist simultaneously in separate systems with separate privacy obligations. This page covers only Rezeki44’s data. Your TnG and GrabPay transaction records are governed by those providers’ own privacy policies.

| Category | Specific Data Points | Why Collected | Retention |
|---|---|---|---|
| Registration | Mobile phone number, password (stored as one-way hash, never as plaintext), age confirmation flag | Account creation, authentication, regulatory compliance on minimum age | 5 years post-closure |
| E-Wallet Linkage | Phone number associated with TnG/GrabPay/Boost account; wallet transaction reference IDs | Deposit credit, withdrawal routing, withdrawal name matching | Duration of account + 5 years |
| KYC Documents | Government-issued ID photograph (IC/MyKad or passport), selfie for identity matching, optional proof of address | First-withdrawal verification, fraud prevention, AML compliance | 5 years post-closure |
| Transaction Records | Deposit amounts in MYR, withdrawal amounts in MYR, timestamps, payment channel type, platform reference IDs | Balance management, dispute resolution, regulatory financial records | 7 years from date of transaction |
| Game Activity | Game titles opened, bet amounts, round outcomes, session start/end times, bonus activations and wagering progress | Responsible gaming monitoring, bonus integrity verification, fraud detection | 2 years from session date |
| Referral Activity | Referral link usage events, referred user registrations, qualifying deposits by referred users, share reward credits issued | Share reward calculation, fraud detection on referral manipulation | 2 years from referral event |
| Device and Technical | IP address, device type, operating system version, browser/app version, approximate geolocation from IP | Jurisdiction verification, fraud detection, session security monitoring | 1 year from collection date |
| Support Communications | Live chat transcripts in English and Bahasa Malaysia | Support quality, dispute resolution, regulatory compliance record | 2 years from last message |
Your Rezeki44 password is never stored in any form that can be read. When you create a password, the platform applies a cryptographic hash function to it and stores only the resulting hash value. A hash is a one-way transformation: given the hash, there is no computation that produces the original password from it. When you log in, the entered password is hashed and the result is compared against the stored hash. If they match, access is granted. If Rezeki44’s database were compromised, the attacker would have a list of hash values, not a list of passwords.
This is why Rezeki44 cannot tell you your current password if you forget it. No one at the platform has access to it. The forgotten password flow generates a new OTP to your registered mobile, which allows you to set a new password — the old one is not recovered because it no longer exists in recoverable form anywhere. The only person who ever knows your Rezeki44 password is you.
KYC identity verification at Rezeki44 is triggered when you request your first withdrawal. It is not required to register, to receive the RM50 free credit, or to make deposits. The KYC process requires a clear photograph of a Malaysian government-issued ID (MyKad for Malaysian citizens, passport for non-citizens) and a selfie that matches the document photo. At higher withdrawal amounts, proof of address may be requested in addition.
Your IC or MyKad contains your full name exactly as it appears in the national identity database. This name is matched against the name associated with your registered mobile number’s TnG or GrabPay account. If the names differ — for example, if your IC shows “Ahmad bin Zulkifli” but your TnG account shows “Ahmad Zulkifli” or a nickname — the withdrawal will be rejected at the name-matching stage. The solution is ensuring your TnG and GrabPay accounts use the exact name from your IC before making your first Rezeki44 withdrawal. Correcting the name after a failed withdrawal verification takes time; correcting it before is a five-minute check.
KYC documents are stored in an encrypted document management system. Access is restricted to compliance team members with individually logged authorisation records for each document they access. Your IC photograph and selfie are never transmitted to game providers, marketing platforms, or other RM Group platforms. When you open a game at Rezeki44, the game provider’s servers receive an anonymous session token — a string that identifies the session for RTP audit purposes but contains no personal information and cannot be used to identify you.
Retention period for KYC documents is five years after account closure. This is a regulatory requirement under anti-money laundering record-keeping obligations. We cannot delete KYC documents before this period ends regardless of any request, including explicit data deletion requests. If you make a deletion request for KYC documents, we confirm this retention obligation clearly and specify the date on which deletion will occur after the regulatory period ends.
This distinction matters specifically for Malaysian players who use TnG or GrabPay as their primary financial app and want to understand which institution holds which record.
Your linked phone number as a wallet identifier. Transaction amounts, timestamps, and reference IDs in MYR. Balance change records per transaction. KYC documents after your first withdrawal. Session and game activity records. Support communication transcripts.
Rezeki44 does NOT hold: your TnG PIN or GrabPay PIN, your e-wallet’s internal account balance, your bank account details linked to TnG/GrabPay, your transaction history with any other TnG or GrabPay merchant.
The transaction records showing transfers to and from Rezeki44 in your e-wallet transaction history. Your full identity information (name, IC, bank linkage) under their own KYC processes. Your e-wallet balance including funds held after a Rezeki44 withdrawal.
TnG and GrabPay transaction records are governed by their own privacy policies, not by this policy. Rezeki44 has no control over what appears in your e-wallet transaction history, which is why those transactions may appear on your TnG or GrabPay statement.
Data sharing at Rezeki44 is narrow and purposeful. Four external parties receive data under specific conditions, each with defined restrictions on what they can do with it.
E-Wallet and Banking Providers receive transaction-specific data to process each deposit and withdrawal: the amount, the timestamp, and the transaction reference. Your game activity, KYC documents, and account history are not included. Payment providers are contractually prohibited from using transaction data shared by Rezeki44 for any purpose other than completing the specific transaction it relates to.
Game Providers (JILI, Pragmatic Play, Mega888, Red Tiger, Pussy888, Joker Gaming) receive anonymous session tokens when you open a game. The token contains no name, phone number, wallet identifier, or personal data. It enables the game session and provides a reference for RTP audit records. No personal identifying information about Rezeki44 players is transmitted to game studios.
Regulatory Authorities may receive account data under valid legal process. Rezeki44 complies with legally valid requests from Malaysian and applicable international authorities. Where the law permits notification to the affected account holder, we provide it along with a description of what was disclosed.
RM Group Shared Infrastructure processes payment transactions and wallet login authentication on behalf of Rezeki44 as part of the network’s shared backend. Data processed for these purposes is used only for the operational function being performed and is not used for cross-platform profiling or marketing without your separate consent.
| Data Category | Retention Period | Regulatory Basis |
|---|---|---|
| Registration data (phone, hashed password) | 5 years after account closure | AML record-keeping requirement |
| KYC identity documents | 5 years after account closure | AML legal obligation – cannot be shortened |
| Transaction records | 7 years from date of each transaction | Financial records regulatory requirement |
| Game activity and session records | 2 years from session date | Legitimate interest (RG, fraud, audit) |
| Referral activity records | 2 years from referral event | Legitimate interest (bonus integrity, fraud) |
| Support communications | 2 years from last message | Legitimate interest (dispute resolution) |
| Device and geolocation data | 1 year from collection | Legitimate interest (security monitoring) |
All data in transit between your device and Rezeki44 servers is encrypted using 256-bit SSL regardless of the type of interaction: login, deposit initiation, game launch, live chat, and all API calls. Sensitive stored data — KYC documents, wallet identifiers, hashed passwords — is encrypted at rest using current encryption standards. Role-based access controls restrict each Rezeki44 staff function to the data categories necessary for their specific role, and all access events are individually logged with the accessing staff member’s identity, the record accessed, and the timestamp.
In the event of a security incident that results in unauthorised access to personal data, affected account holders are notified within 72 hours of Rezeki44 becoming aware of the breach. The notification describes what data was accessed, what action was taken to contain the incident, and what steps you should take to protect your account. If you suspect your Rezeki44 account has been accessed by someone other than you, contact live chat immediately to request an account freeze pending investigation.
Rezeki44 uses cookies for session authentication (keeping you logged in between page loads), language and display preference storage, usage analytics to understand which features and game categories are used most, and security monitoring for unusual session activity patterns. Advertising cookies are not used. Third-party advertising networks do not receive data through Rezeki44’s cookie implementation. Cookie preferences can be managed through your browser settings; disabling session cookies will prevent persistent login and will interfere with normal platform use.
Changes that affect what data is collected, who receives it, or what rights you have are communicated by in-platform notification at least 14 days before they take effect. Clarifications to existing practices update the policy text with a revised date. The current version date is at the top of this page. For all privacy queries: open Rezeki44 live chat, identify your request as a data privacy matter, and include your registered mobile number. We respond within 5 business days for general queries and within 30 calendar days for formal data access requests.