Privacy Policy
Last updated 15 July 2026This Privacy Notice explains how Moon International Ltd (“Moon”, “we”, “us” or “our”) collects, uses, shares, and protects your personal data when you access or use Moon.com, including any associated websites, applications, and services operated under the Moon brand (collectively, the “Services”).
We are committed to handling your personal data in a transparent, secure, and lawful manner, in accordance with applicable data protection laws, including the Comoros Law N°14-029/AU on the protection of Personal Data (the “DPA”), and, where applicable, the EU General Data Protection Regulation 2016/679 (the “GDPR”) and Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”).
This Notice is addressed to individuals who interact with our Services, including registered users (“Customers”) and visitors.
1. Website Use
By accessing or using the Website, You acknowledge this Privacy Notice. We may review and update this Privacy Notice from time to time by posting the updated version on the Website. Any changes will become effective upon publication, unless otherwise required by applicable law. This Privacy Notice does not apply to third-party websites that may be linked from the Website and over which We have no control.
2. Personal Information
For the purposes of this Privacy Notice, “Personal Data” or “Personal Information” means any information relating directly or indirectly to an identified or identifiable natural person (“data subject”), as defined under the DPA and, where applicable, the GDPR and PIPEDA.
The kinds of personal information that We may process about You include, but are not limited to:
- Name.
- Email Address.
- Personally Submitted Preferences.
- Date of Birth.
- Country of citizenship or residence.
- Physical Address.
- Identification Number.
- Government Issued Identification.
- Location Data.
- Device Information.
- IP Address.
Moon may also process:
- Data related to the use of our services and products, such as deposits, withdrawals, wagers, VIP status, affiliate identification, and similar account-related data; and
- Data related to the enforcement of our Terms of Service and other policies.
For further details, please refer to the relevant documents available on the Website.
We collect, or may collect, such information through methods including:
- Data provided during account registration processes.
- Communications with customers.
- Data generated when You use our services and products (including the Website);
- Information obtained from third-party data providers, including identity verification, fraud prevention, and analytics providers, in accordance with applicable law.
Special Categories of Personal Data. Certain categories of personal information are subject to heightened protection under applicable law. These include data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, health data, and data concerning a person’s sex life or sexual orientation ("Special Categories").
We will only process Special Categories of Personal Data where:
- We have obtained Your explicit consent,
- or where processing is otherwise permitted under the DPA and, for European Economic Area residents, under Article 9 of the GDPR.
We do not seek to collect Special Categories of Personal Data in the ordinary course of our services. You should refrain from submitting such information unless expressly requested by Us.
3. Data Processing Purposes
We process Your personal information by lawful and fair means, and in a manner that is not unreasonably intrusive, in order to operate our business as a licensed online wagering operator. The purposes for which We process Your personal information include:
- For Know-Your-Customer (KYC) identity verification.
- If You wish to subscribe to Our marketing communications.
- To process Your application to become a Customer of the Website or any managed subdomains.
- To provide and improve services to You as a Customer.
- To identify You as a Customer and authenticate Your identity for security purposes and to comply with Our legal obligations.
- To maintain Your Customer account.
- To upgrade and enhance Your experience within the Website or over the telephone, or to tailor or develop information, services or products to suit Your needs which may include market research and conducting promotions.
- To tell You about our products or services that We think may be of interest to You by communicating with You via email, SMS or telephone.
- To create aggregate data about Customers through demographic profiling, statistical analysis of the database to provide to potential and existing stakeholders, and to allow for more efficient operation of Our business.
- Automated Decision-Making and Profiling. Where We use automated processing (including profiling) to make decisions that produce legal or similarly significant effects concerning You, We will inform You of this practice, including meaningful information about the logic involved, as well as the significance and potential consequences of such processing. You may exercise these rights by contacting Us at [email protected]. This applies in particular to residents of the European Economic Area, pursuant to Article 22 of the GDPR, and to residents of Canada under PIPEDA Principle 4.3.
- To respond to Your questions, comments, or requests.
- To determine Customers' liability to pay goods and services tax and other taxes where applicable.
- To comply with Our contractual, legal, and statutory obligations.
- For taking appropriate action if We have reason to suspect that unlawful activity or misconduct of a serious nature has been, is being or may be engaged in that relates to Our functions and activities.
- To establish, exercise or defend any legal claims.
- To enforce of Our Terms of Service and Policies.
- To provide You with benefits related to our VIP program, as well as other campaigns and benefits offered by Us or any managed subdomains.
- To manage job applications.
If You do not provide the personal information required, We may be unable to process Your application, provide our Services, or respond to Your requests.
By using the Website or otherwise providing Us with Personal Information, You acknowledge that We may collect, use, process, and disclose Your personal information for the purposes described in this Privacy Notice and in accordance with applicable legal bases.
4. Direct Marketing and Opting Out
From time to time We may use Your personal information to inform You about Our products or services or about promotional activities which We believe may be of interest or of benefit to You. We may do this via email, SMS, telephone or mail. If You no longer wish to receive marketing or promotional material from Moon.com at all or in any particular form, You may contact Us at any time by email to [email protected] with Your request with which We will comply as soon as is practical.
From time to time We may contact You in relation to the management and administration of Your Moon.com account. These communications can be via any of the modes of contact recorded when registering as a Customer. Such communication does not affect Your opt-in or opt-out status for direct marketing communications.
Right to Withdraw Consent. Where Our processing of Your personal information is based on Your consent, You have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw Your consent, please contact Us at [email protected] or use the opt-out mechanisms provided within Our platform or communications. Please note that withdrawal of consent may affect Our ability to provide certain services to You. For residents of Canada, this right is governed by PIPEDA Principle 4.3.8.
5. Legal Basis for Processing
Our processing of Your personal information is supported by the following lawful bases, which apply across all applicable frameworks:
- Performance of a Contract: We need to process Your personal information to perform our contract with You.
- Legitimate Interest: We process Your personal information to further our legitimate interests but only where our interests are not overridden by Your interests or fundamental rights and freedoms.
- Consent: In some cases, We also rely on Your consent to process Your personal information.
- Compliance with Legal Obligations: We may process Your personal information to comply with our legal obligations.
6. Management and Sharing of Your Personal Information
We will take all reasonable steps to ensure that the personal information We collect, use, or disclose is accurate, up to date, and stored in a secure environment accessible only by authorised persons. We store the personal information We receive as described in this Privacy Notice for as long as You use Our services or as necessary to fulfill the purpose(s) for which it was collected, provide Our services, resolve disputes, establish legal defences, conduct audits, pursue legitimate business purposes, enforce Our agreements, and comply with applicable laws.
We can share or disclose personal information in order to provide our services, enforce our Terms of Service and policies, protect or defend our rights and interests, particularly in the following cases:
- Within our Group:Any reference to the "Group" in this Privacy Notice includes STK Services Ltd and its subsidiaries, and any other entities that are directly or indirectly controlled by, or under common control with STK Services Ltd and any pages or websites under the "Moon" brand, including any mobile phone or tablet applications owned and/or operated by Us or whenever We otherwise interact with You.
- To our service providers and third-party partners: In some cases, We may use third party service providers to provide You with Our services or products. In this case, We may need to share or disclose personal information. In each case, We will take reasonable steps to ensure that Your Personal Information is protected and processed as set out in this Notice. Where third parties process personal information on Our behalf, they will do so as data processors subject to appropriate contractual safeguards, pursuant to Article 28 of the GDPR and equivalent requirements under the DPA. Such agreements require processors to implement adequate technical and organisational security measures and to process personal data only on Our documented instructions.
- For legal or regulatory reasons: In certain circumstances, We may be required to disclose Your personal information in response to lawful requests by public authorities.
- In the event of a business sale or restructuring: If the ownership of all or part of Our business changes or if We undergo a reorganization event (or similar), We may transfer Your personal information to the new owner or successor company so that the services can continue to be provided.
Whenever We share Personal Information, We do so in accordance with applicable law and with appropriate safeguards to protect your privacy.
We will securely delete, anonymise, or permanently de-identify personal information when it is no longer required for the purposes for which it was collected, unless retention is required or permitted under applicable law.
7. Security of Personal Information
You acknowledge that no data transmission over the internet is totally secure. Accordingly, We do not guarantee or warrant the security of any information which You transmit to Us. Any information which You transmit to Us is transmitted at Your own risk. However, once We receive Your transmission, We will take reasonable steps to protect Your personal information from misuse, loss and unauthorized access, modification and disclosure including by using password protected systems and databases and Secure Socket Layer (SSL) technology. By using our services or providing personal information to Us, You must be aware that We may communicate with You electronically regarding security, privacy, and administrative issues relating to Your use of the services.
Our employees, agents and contractors are required to maintain the confidentiality of Customers' personal information and Customer account behavior. Information posted on bulletin boards or communicated within a social media environment by You (for example, Facebook, Twitter, Chat Rooms) is considered public information. We cannot guarantee the security of this type of disclosed information.
We take the responsibility to exclude children from access to our services seriously. We will not accept their information for the purposes of opening a Customer account. It is however, ultimately the responsibility of parents or guardians to monitor their children’s internet activities including where appropriate by using internet screening software.
Remember to always log out of Your account when You have completed Your time on the Website. This is particularly important if You share a computer with another person. You are responsible for the security of and access to Your own computer, mobile device or any other handset used to access the Website.
You are responsible for maintaining the confidentiality of your account credentials, including your username and password. You should take appropriate steps to protect access to your devices and accounts, including logging out after using shared devices.
Data Breach Notification In the event of a personal data breach that is likely to result in a risk to Your rights and freedoms, We will assess the breach and may decide to notify the relevant supervisory authority and, where feasible, within 72 hours of becoming aware of the breach for EEA residents, in accordance with Article 33 of the GDPR.
Where a breach is likely to result in a high risk to your rights and freedoms, We will also notify you without undue delay, providing information about the nature of the breach, its likely consequences, and the measures taken or proposed to address it.
For individuals located in Canada, breach notifications will be made in accordance with the requirements of PIPEDA.
8. Access to Personal Information
You may access the personal information collected by Us by following the “Settings” link on the Website or by contacting Us on [email protected].
We will provide access to Your personal information in accordance with applicable laws and, where possible, in the format requested by You.
We will respond to Your request within the timeframes required by applicable law. In certain circumstances, We may need to verify Your identity before processing Your request.
If We are unable to provide access to some or all of Your personal information, We will inform You of the reasons for the refusal, subject to any legal or regulatory restrictions, and of any rights You may have to challenge such decision. In some cases, access may be restricted where it would adversely affect the rights and freedoms of others or where exemptions apply under applicable law.
9. Deletion of Personal Data
You can request to have Your personal data deleted if We no longer have a legal reason to continue to process or store it.
Please note that this right is not absolute, We may retain certain personal data where processing is necessary to:
- Comply with legal or regulatory obligations
- Establish, exercise, or defend legal claims
- Prevent fraud or misuse of Our Services
- Fulfil other legitimate and lawful business purposes.
You can request the deletion of Your personal data by sending an email to [email protected].
10. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, accounting, and reporting requirements. The criteria We use to determine appropriate retention periods include:
- the nature of the personal data and the purposes for which it is processed;
- any statutory or regulatory obligations to retain data for a minimum period;
- the period during which a dispute or claim might arise in relation to the data;
- guidance issued by relevant data protection authorities.
In particular, as a licensed online wagering operator, We are required to retain certain records (including identity verification, KYC documentation, transaction records, and AML-related records) for a minimum period prescribed by applicable gaming and anti-money laundering legislation.
DPA – Retention Principle: Consistent with the Retention Principle under section 10 of the DPA, We will not retain personal data for longer than is necessary for the fulfilment of the purpose for which it was collected or further processed, unless retention is required or authorised by law.
For Customers located in the European Economic Area (“EEA”): GDPR Storage Limitation (Article 5(1)(e)): For Customers located in the EEA, personal data will be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Where We process personal data beyond the period strictly required for the original purpose, We will rely on an appropriate legal basis (such as archiving in the public interest or scientific research) and implement appropriate technical and organisational safeguards.
Canadian Residents – PIPEDA Retention Limitation: For Customers located in Canada, personal information used to make a decision that directly affects a Customer will be retained for a sufficient period to allow the Customer to exhaust any recourse available to them. Personal information that is no longer required to fulfil identified purposes will be destroyed, erased, or made anonymous in accordance with Our records management procedures and applicable Canadian law.
When personal data is no longer required, We will securely destroy or permanently anonymise it in accordance with Our internal data retention and disposal policy. For further information about specific retention periods applicable to Your personal data, please contact Us using the details in Section 16 below.
11. International Data Transfers
All information processed by Us may be transferred, processed, and stored anywhere in the world, including but not limited to other countries, which may have data protection laws that are different from the laws where You live. We will endeavor to safeguard Your information consistent with the requirements of applicable laws, including the DPA, and in particular:
Where We transfer personal data outside the EEA, We will ensure that appropriate safeguards are in place in accordance with the GDPR, such as Standard Contractual Clauses (SCCs) approved by the European Commission, binding corporate rules, or transfers to countries recognised as providing an adequate level of protection by the European Commission.
For Customers located in Canada: Where We transfer personal data outside Canada, We will use contractual or other means to provide a comparable level of protection to that required under PIPEDA while the information is being processed by any third party.
12. Data Subject Rights under the DPA
Under the DPA, data subjects have the following rights in respect of their personal data processed by Us:
- Right to be informed: You have the right to be informed of the purposes for which We collect and process Your personal data.
- Right to access: You may request access to Your personal data that We hold, subject to payment of a prescribed fee and the exceptions set out in the DPA.
- Right to rectification or erasure: You have the right to request correction, completion, or deletion of data that is factually incorrect, incomplete/irrelevant to the purpose, or otherwise processed unlawfully. You may request deletion of Your personal data where We no longer have a lawful basis to retain it, as further described in Section 9.
- Right to object: You have the right to object to the processing of Your personal data, including for direct marketing purposes. Please see Section 4 above for how to opt out of direct marketing.
- Right Not to Be Subject to Automated Decision-Making.
13. Additional Rights for Customers in the European Economic Area (GDPR)
If You are located in the EEA, in addition to the rights described in Section 12 above, You have the following additional rights under the GDPR:
- Right to data portability (Article 20 GDPR): You have the right to receive Your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller, where the processing is based on consent or contract and is carried out by automated means.
- Right to restriction of processing (Article 18 GDPR): You may request that We restrict processing of Your personal data in certain circumstances, for example where You contest the accuracy of the data or where You have objected to processing.
- Right not to be subject to automated decision-making (Article 22 GDPR): You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning You or similarly significantly affects You, except in limited circumstances.
To exercise any of the above GDPR rights, please contact Us at [email protected].
We will respond to Your request within one (1) month of receipt, which may be extended by a further two (2) months where necessary, taking into account the complexity and number of requests.
14. Additional Rights and Obligations for Customers in Canada (PIPEDA)
If You are located in Canada, PIPEDA and applicable provincial privacy laws govern Our collection, use and disclosure of Your personal information. The following additional provisions apply:
- Accountability: We are responsible for the personal information under Our control and have designated a privacy officer who is accountable for Our compliance with PIPEDA. You may contact our privacy officer at [email protected].
- Identifying purposes: We identify the purposes for which personal information is collected at or before the time the information is collected, as set out in Section 3 of this Notice.
- Limiting collection: We collect only the personal information necessary for the purposes identified. We collect information by fair and lawful means.
- Right to access and correction: Canadian residents may request access to their personal information held by Us and request correction of any inaccuracies. We will respond within 30 days of receiving a written request, subject to applicable exceptions.
- Breach notification: In the event of a security breach involving Your personal information that creates a real risk of significant harm, We will notify You and the Office of the Privacy Commissioner of Canada as required by PIPEDA.
15. Cookies and Tracking Technologies
We use cookies and similar tracking technologies (such as web beacons, pixels, and local storage) to enhance Your experience on Our Website and to support the operation of Our services. Cookies are small data files placed on Your device when You visit Our Website. Some cookies are strictly necessary for the Website to function; others are used for performance, analytics, or marketing purposes.
The types of cookies We use include: (i) Strictly Necessary Cookies — required for the Website to operate and cannot be switched off; (ii) Performance and Analytics Cookies — help Us understand how visitors interact with Our Website; (iii) Functional Cookies — enable enhanced functionality and personalisation; and (iv) Targeting and Advertising Cookies — used to deliver relevant advertisements and track campaign effectiveness.
Where required by applicable law (including the GDPR for EEA residents and the DPA), We will obtain Your consent before placing non-essential cookies on Your device. You may withdraw consent or manage Your cookie preferences at any time through Our cookie consent tool or through Your browser settings. Please note that disabling certain cookies may affect the functionality of Our Website. For further details, please refer to Our Cookie Policy.
16. Contact Details
If You have any queries, requests for access or correction or complaints relating to the handling of Your personal information, please contact Us by email at [email protected] or by the site customer support chat function.
Data Protection Officer.In accordance with Article 37 of the GDPR, where required We have appointed a Data Protection Officer ("DPO"). The DPO is responsible for overseeing Our data protection strategy and Our compliance with applicable data protection law. You may contact Our DPO directly at: [email protected]. For residents of Canada under PIPEDA, Our designated accountability officer can also be contacted at this address.
Internal Complaints Procedure. If You have a concern about how We handle Your personal information, We encourage You to contact Us first at [email protected] so that We can attempt to resolve the matter internally. We will acknowledge receipt of Your complaint within five (5) business days and aim to provide a substantive response within thirty (30) days. If You are not satisfied with Our response, You have the right to lodge a complaint with the supervisory authority in Your country of residence (for EEA residents, this is Your national data protection authority; for Canadian residents, this is the Office of the Privacy Commissioner of Canada).
Right to Withdraw Consent. Where processing of Your personal data is based on Your consent, You may withdraw that consent at any time by contacting Us at [email protected]. Please see the Your Rights section of this Privacy Notice for further details on how to exercise this and other data protection rights.
17. Supervisory Authority
Regardless of Your location, You have the right to lodge a complaint with the relevant supervisory authority if You believe Our processing of Your personal information violates applicable law.
Customers in the EEA: If You are located in the European Economic Area, You also have the right to lodge a complaint with the data protection supervisory authority in Your country of residence, place of work, or place of the alleged infringement under Article 77 of the GDPR.
Customers in Canada: If You are located in Canada, You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca regarding Our compliance with PIPEDA.
18. Updates to this Privacy Notice
As noted, We may review, change and update this Privacy Notice from time to time reflect our current practices and obligations. We will publish our current Privacy Notice on our Website at https://moon.com and the changes will take effect at the time of publishing. You should review this privacy notice regularly and remain familiar with its terms.