Privacy policy
This policy explains what personal information is collected when an account is opened and used, why it is held, how long it is kept and who else sees it. It applies to this site and to the account systems behind it. Much of what is described here is not optional for us: an operator holding a gambling licence is legally required to identify its players and to keep records of their transactions.
Information collected
Four groups of information are collected, and only the first is supplied deliberately by you.
- Account details. First name, surname, date of birth, email address, mobile number, residential address, chosen currency and language.
- Verification documents. Photo identity document, proof of address, evidence of ownership of a payment instrument and, above A$10,000 in cumulative payouts, a source-of-funds document.
- Transaction and play records. Deposits, withdrawals, stakes, results, bonus activations and wagering progress, each with a timestamp.
- Technical data. IP address, approximate location derived from it, device type, operating system, browser, session duration and the pages visited.
Card numbers are not stored on our systems. Payment details are entered on the processor's page and we retain only a masked reference, the amount and the status. Live chat conversations are recorded so that a later query can be traced to what was actually said.
Why it is held
| Purpose | Data used | Basis |
|---|---|---|
| Operating the account | Account details, play records | Performance of the contract with you |
| Age and identity verification | Documents, date of birth | Legal obligation under gambling and anti-money-laundering law |
| Processing payments | Transaction records, masked payment reference | Performance of the contract |
| Fraud and multi-account detection | Technical data, payment references | Legitimate interest in protecting the service |
| Responsible-gaming monitoring | Play patterns, limit settings | Legal obligation and legitimate interest |
| Marketing messages | Email address, mobile number | Consent, withdrawable at any time |
| Analytics and site improvement | Aggregated technical data | Consent through the cookie banner |
Withdrawing marketing consent is done in the account settings or through the unsubscribe link in any message, and takes effect within 48 hours. It does not stop service messages such as a payout confirmation or a security alert, which are part of operating the account rather than marketing.
Retention periods
| Category | Kept for | Reason |
|---|---|---|
| Account details | 7 years after closure | Anti-money-laundering record keeping |
| Verification documents | 5 years after closure | Statutory identification requirement |
| Transaction records | 7 years | Financial and tax obligations |
| Play history | 5 years | Dispute resolution and regulatory audit |
| Support correspondence | 3 years | Complaint handling |
| Technical logs | 12 months | Security and fraud investigation |
| Marketing preferences | Until consent is withdrawn | Consent record |
| Self-exclusion records | Indefinitely | Preventing re-registration during exclusion |
When a period expires, records are deleted or irreversibly anonymised so that they can no longer be linked to an individual. Aggregated statistics derived from anonymised data may be retained indefinitely, since they identify no one.
Sharing with third parties
Personal information is not sold. It is disclosed only to the categories of recipient below, and only to the extent each of them needs.
- Payment processors and banks — to execute deposits and withdrawals and to meet their own compliance obligations.
- Identity verification providers — to check documents against official databases.
- Game suppliers — receive a pseudonymous session identifier and the stake, not your name or contact details.
- Regulators and law enforcement — where disclosure is required by law or by the licensing authority.
- IT and hosting providers — under contracts restricting use to the provision of the service.
- Analytics and communication tools — with technical and contact data, subject to your consent.
Some of these recipients operate outside Australia. Where information is transferred abroad, it is sent under contractual protections requiring a standard of care equivalent to the one applied here, and the transfer is limited to the purpose for which the recipient was engaged.
Your rights
- Access. Request a copy of the personal information held about you. Provided within 30 days.
- Correction. Ask for inaccurate or outdated details to be amended. Name and date of birth can be changed only against a supporting document.
- Erasure. Request deletion of information that is no longer needed. Records held under a legal retention period cannot be deleted early.
- Portability. Receive the details you supplied in a structured, machine-readable format.
- Objection. Object to processing based on legitimate interest, including profiling for marketing.
- Withdrawal of consent. Withdraw consent for marketing or analytics at any time, without affecting processing already carried out.
- Complaint. Complain to the relevant data protection authority. In Australia that is the Office of the Australian Information Commissioner.
Requests are free of charge. Identity is confirmed before a request is actioned, using the documents already on file rather than new ones, because responding to an unverified request would itself be a data breach.
Security
Traffic between your browser and our servers is encrypted with TLS 1.3. Verification documents are held in encrypted storage separated from the account database, and access is limited to the compliance team on a need-to-know basis with each view logged. Passwords are stored as salted hashes and are never visible to staff, which is why support can reset a password but can never tell you what it is.
Payment processing runs through PCI DSS compliant providers, so full card numbers never reach our infrastructure. Two-factor authentication is available on every account and is the single most effective control you can apply yourself. No system is completely secure; if a breach affecting your information occurs, you will be notified without undue delay together with the steps being taken.
Requests and complaints
Data requests are submitted from the Privacy section of the account, which authenticates you automatically, or by writing to support from the registered email address with the subject line marked as a privacy request. A confirmation of receipt is issued within 5 business days and a substantive response within 30 days; where a request is complex, an extension is notified with reasons before the deadline passes.
If a response is unsatisfactory, the matter can be escalated to the licensing authority named in the operator's licence statement or to the data protection authority in your country of residence. Contact details for the operator's data protection function are published in the account and in the terms accepted at registration; this satellite page does not reproduce a postal address, so that no outdated detail is presented as current.