SSocial Casino
Checking session
Return Home

Privacy Policy

Effective Date: January 1, 2025 · Last Revised: January 1, 2025

1. Data Controller & Contact Details

Social Casino("we", "us", "the Operator") is the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and the California Consumer Privacy Act (CCPA) as amended by the CPRA.

Submit a privacy request

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer to oversee our compliance with data protection law. You may contact the DPO on any matter relating to your personal data:

Contact the privacy team

3. Categories of Personal Data We Collect

  • Identity data — full name, date of birth, username, avatar.
  • Contact data — email address, phone number (optional).
  • Account data — operator affiliation, jurisdiction, role, registration date, age verification flag.
  • Financial data — wallet balances, deposit and withdrawal amounts, payment method identifiers (CashApp tag, Lightning invoice, card last-4, on-chain addresses).
  • KYC documents — government-issued ID images, selfie verification, proof-of-address documents.
  • Transaction data — bet stakes, game outcomes, payouts, transaction history, bonus and coupon redemptions.
  • Technical data — IP address, browser & device fingerprint, user-agent, OS, page interactions, cookies.
  • Communications data — chat messages with support, customer-service tickets.
  • Usage data — game sessions, login streak, VIP progress, quest progress, referral activity.

4. Source of the Data

We collect personal data directly from you when you register, make a deposit, request a withdrawal, complete KYC, contact support, or interact with the platform. Where you sign in with Google OAuth, we receive your name and verified email from Google. We do not purchase personal data from data brokers.

5. Purposes of Processing & Lawful Basis

PurposeLawful Basis (GDPR)
Provide the gaming service, account, and walletContract (Art. 6(1)(b))
Verify age (18+) and identity (KYC)Legal obligation (Art. 6(1)(c)) — AML/BSA, age-gaming laws
Detect and prevent fraud, money-laundering, structuringLegal obligation (Art. 6(1)(c)) + Legitimate interest (Art. 6(1)(f))
Process deposits and withdrawalsContract (Art. 6(1)(b))
Send transactional emails (deposit confirmations, withdrawal status)Contract (Art. 6(1)(b))
Send marketing and promotional emailsConsent (Art. 6(1)(a)) — opt-in, withdrawable anytime
Analyze usage to improve the product (analytics cookies)Consent (Art. 6(1)(a)) — opt-in via cookie banner
Personalized advertisingConsent (Art. 6(1)(a)) — opt-in via cookie banner
Comply with law-enforcement requestsLegal obligation (Art. 6(1)(c))

6. Legitimate Interests Relied Upon

Where we rely on legitimate interests (Art. 6(1)(f)) — for example fraud detection and AML monitoring — we have balanced those interests against your privacy rights and concluded that the processing is necessary and proportionate. Our legitimate-interests assessment is available on request from the DPO.

7. Recipients of Your Personal Data

We share personal data only with the following categories of recipients:

  • Payment processors (BoltPayouts, CashApp, card networks).
  • Identity verification providers (KYC vendors).
  • Cloud infrastructure providers (see Section 14 — Data Processors).
  • Law-enforcement and regulatory authorities where legally required.
  • Professional advisors (lawyers, auditors) bound by confidentiality.

We do not sell your personal data to third parties.

8. International Data Transfers

Your data may be processed in the United States, the European Union, and other jurisdictions where our processors operate. Where personal data leaves the EU/EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, the UK IDTA / Addendum, or another recognized transfer mechanism. A copy of the relevant SCCs is available on request from the DPO.

9. Retention Periods

Data CategoryRetention PeriodLegal Basis
Account data (name, email, profile)Until account deletion + 30 daysContract
Transaction data (deposits, withdrawals, ledger)5 years after account closureAML/BSA 31 CFR 1010.430; EU 5AMLD
KYC documents (ID images, selfies)5 years after account closureAML/BSA 31 CFR 1010.230; 5AMLD Art. 40
Audit logs5 yearsAML/BSA; internal security
Chat messages with support2 yearsLegitimate interest (dispute resolution)
Suspicious-activity reports5 yearsAML/BSA
CookiesPer consent choice (max 13 months)Consent
Marketing consent recordUntil consent withdrawn + 3 yearsConsent (proof of consent)

10. Your Data Subject Rights (GDPR Articles 15–22)

Under GDPR you have the right to:

  • Access (Art. 15) — receive a copy of your personal data. Use the Download my data tool or email the DPO.
  • Rectification (Art. 16) — correct inaccurate personal data.
  • Erasure (Art. 17) — request deletion of your personal data, subject to AML retention law. Use the Delete my account tool.
  • Restriction (Art. 18) — limit processing pending verification.
  • Portability (Art. 20) — receive your data in a structured, machine-readable JSON file.
  • Objection (Art. 21) — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent (Art. 7(3)) — withdraw consent for marketing, analytics, or functional cookies at any time via the cookie banner in the footer.
  • Not be subject to automated decision-making (Art. 22) — see Section 13.

To exercise any of these rights, use the in-app tools above. We respond within 30 days.

11. Right to Complain to a Supervisory Authority

You have the right to lodge a complaint with your local data-protection supervisory authority. EU residents may complain to their Member State DPA; UK residents to the ICO; California residents to the California Attorney General. We ask that you contact us first so we can resolve the issue.

12. California Consumer Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know what personal data we collect and who we share it with.
  • Delete your personal data (subject to AML exceptions).
  • Correct inaccurate personal data.
  • Opt out of "sale" or "sharing" of personal data for cross-context behavioral advertising. We do not sell data; you may still opt out at our Privacy Rights page.
  • Limit use of sensitive personal information.
  • Not be discriminated against for exercising any CCPA right.

To exercise any of these rights, visit /privacy-rights. Authorized agents must submit a signed power of attorney.

13. Automated Decision-Making & Profiling

We use automated processing for the following purposes:

  • Fraud / AML monitoring — automated rules flag transactions that match structuring, rapid-movement, or large-transaction patterns. Flagged transactions are held for human review and never auto-rejected.
  • Reality-check prompts — every 60 minutes of play, a reality-check modal is shown. No decision is made about you; this is a player-protection tool.

We do not use automated decision-making that produces legal or similarly significant effects on you without your explicit consent. You may contest any flagged transaction by contacting the DPO.

14. Data Processors

We engage the following categories of third-party processors to operate the service:

CategoryPurposeLocation
Database & Auth ProviderUser authentication, data storage, and file hostingUSA / EU
Application Hosting & CDNWebsite hosting, edge caching, and content deliveryGlobal / USA
Image StorageAvatar and document storage and transformationUSA / EU
Payment ProcessorDeposit and withdrawal payment processingUSA
Font DeliveryWeb font hosting and deliveryGlobal
Identity ProviderOptional social sign-in (OAuth)USA

Each processor is bound by a Data Processing Agreement (DPA) that meets GDPR Art. 28 requirements. A list of sub-processors is maintained and updated; material changes will be announced on this page.

15. Data Security

We implement industry-standard technical and organizational measures to protect your data, including: encryption in transit (TLS) and at rest (AES-256); strict access controls with role-based permissions; audit logging of administrative actions; intrusion detection; regular security assessments; and employee security training. Despite these measures, no system is 100% secure — please practice good password hygiene and enable MFA where offered.

16. Cookies & Withdrawal of Consent

We use four categories of cookies: Strictly Necessary (always on), Functional, Analytics, and Marketing. On your first visit you will see a cookie-consent banner with three actions: Accept All, Reject Non-Essential, and Customize. Your choice is stored inlocalStorage with a timestamp.

You can withdraw consentat any time by clicking the "Withdraw Consent" link in the footer of any page, or by clearing your browser storage.

17. Children's Privacy

The service is strictly for individuals 18 years of age or older. We verify date of birth at registration and require KYC before cumulative deposits exceed $1,000. If you believe we have collected personal data from a minor, please contact the DPO immediately and we will erase it.

18. Changes to This Policy

We may update this policy from time to time. Material changes will be announced by email and on this page at least 30 days before they take effect. Continued use after the effective date constitutes acceptance of the updated policy.

For any privacy-related enquiry, use the privacy request form.

Last updated: January 1, 2025

S
Social Casino

Premium social sweepstakes gaming with instant redemptions and bank-grade security.

Platform

Games LibraryVIP RewardsRefer & EarnLeaderboard

Support

Help CenterResponsible GamingSystem StatusContact

Legal

Terms of ServicePrivacy PolicySweeps RulesKYC Policy

© 2026 Social Casino. All rights reserved.

256-bit AES Encryption
18Adults Only
Do Not Sell My Personal Information·Responsible Gaming·If you have a gambling problem, call 1-800-GAMBLER