
The JB Casino privacy policy covers every stage of personal data handling for Indian players, from registration to permanent deletion of records. JB.COM operates under Curaçao Gaming Authority licence OGL/2024/1519/0809, with AML/CFT compliance aligned with FATF recommendations. India’s Digital Personal Data Protection Act 2023, operationalised through the DPDP Rules 2025 notified in November 2025, sets binding obligations for operators processing the personally identifiable information of Indian users. Players who prefer to manage their account and privacy settings on mobile can use the JB Casino download page for direct access from an Android device.
JB Casino applies a data minimisation principle – only the minimum required information is gathered at each stage, and no sensitive personal data is requested before it is operationally necessary. At registration, only an email address or phone number is required. A crypto wallet address is collected exclusively when a deposit address needs to be generated. The KYC identity verification stage requires:
The 5-year minimum retention standard for KYC documents and transaction records applies under the Curaçao LMOT ordinance, aligned with FATF requirements for licensed online gaming operators.
| Data Category | Retention Period | Regulatory Basis |
| Account credentials | Duration of active account | Contractual obligation |
| KYC documents | Minimum 5 years post-closure | Curaçao LMOT ordinance |
| Transaction records | Minimum 5 years | FATF-aligned AML requirement |
| Crypto wallet addresses | Duration of transaction processing | Operational necessity |
JB Casino processes personal data strictly within the scope for which it was originally collected. Both automated and manual AML/CFT transaction monitoring run in real time across BTC, ETH, TRX, and XRP. Sanctions screening covers the UN consolidated list and regional databases under the Curaçao compliance framework. Source of funds verification through enhanced due diligence applies to high-value transactions and VIP-level activity, consistent with FATF risk-based approach standards.

Indian account holders on JB Casino have the right to access, correct, and erase personal information under India’s DPDPA 2023. You can request a full copy of records, submit corrections, or file a right to erasure request for information no longer required for regulatory purposes. Under DPDPA Rules 2025, data fiduciaries must respond to valid requests within 7 days. All queries are handled through privacy@jb.com, and JB.COM does not transfer personal data to third parties without explicit user consent.
JB Casino applies a layered security model across all data flows. All transmitted personally identifiable information is protected by SSL/TLS encryption, passwords are stored using SHA-256 hashing, and two-factor authentication via Google Authenticator is available in account security settings. Independent security audits verify compliance under the Curaçao Gaming Authority framework, while geo-restrictions and timezone analysis detect VPN-based access from restricted regions without disrupting eligible Indian users.
| Security Layer | Standard / Protocol | What It Protects Against |
| Data in transit | SSL/TLS | Interception during transmission |
| Password storage | SHA-256 hashing | Credential exposure in case of breach |
| Account login protection | 2FA via Google Authenticator | Unauthorised account access |
| Geographic access control | Geoblocking + timezone mapping | Unauthorised access via VPN |
| Infrastructure compliance | Independent third-party audit | Ongoing regulatory compliance |
This security architecture applies equally to desktop and mobile sessions, relevant given the volume of mobile-first UPI and crypto deposits among Indian users on JB.COM.
JB Casino uses cookies for maintaining active sessions, collecting anonymous analytics, and personalising the interface. No cookies track behaviour outside JB.COM or pass personally identifiable information to advertising networks. Third-party providers engaged for blockchain transaction screening and AML compliance checks receive only the minimum information required and operate under confidentiality agreements. The DPDPA 2023 requires explicit records of any third-party data sharing, and JB Casino meets this obligation. For the full breakdown of transaction monitoring, visit jb.com/help/anti-money.
JB.COM notifies users of material changes before they take effect, in line with consent manager obligations under DPDPA Rules 2025. If you disagree, you can submit a right to erasure request to privacy@jb.com before the update applies.
JB.COM does not transfer personal information to third parties without explicit user consent, and all exceptions are limited to compliance-mandated regulatory disclosures. Third-party providers engaged for AML screening operate under confidentiality agreements and receive only the data required for their specific function.
Submitting a data access request to privacy@jb.com results in a structured copy of all personal information associated with your JB Casino account. Under DPDPA Rules 2025, valid access requests must be fulfilled within 7 days regardless of account status.
Contact JB Casino support immediately via 24/7 live chat and send a formal report with details such as suspicious login times or unrecognised device activity. Under DPDPA 2023, confirmed breaches must be reported to India’s Data Protection Board, so documenting the incident promptly supports a faster resolution.