Effective Date: January 1, 2025 · Last Revised: January 1, 2025
Social Casino("we", "us", "the Operator") is the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and the California Consumer Privacy Act (CCPA) as amended by the CPRA.
We have appointed a Data Protection Officer to oversee our compliance with data protection law. You may contact the DPO on any matter relating to your personal data:
We collect personal data directly from you when you register, make a deposit, request a withdrawal, complete KYC, contact support, or interact with the platform. Where you sign in with Google OAuth, we receive your name and verified email from Google. We do not purchase personal data from data brokers.
| Purpose | Lawful Basis (GDPR) |
|---|---|
| Provide the gaming service, account, and wallet | Contract (Art. 6(1)(b)) |
| Verify age (18+) and identity (KYC) | Legal obligation (Art. 6(1)(c)) — AML/BSA, age-gaming laws |
| Detect and prevent fraud, money-laundering, structuring | Legal obligation (Art. 6(1)(c)) + Legitimate interest (Art. 6(1)(f)) |
| Process deposits and withdrawals | Contract (Art. 6(1)(b)) |
| Send transactional emails (deposit confirmations, withdrawal status) | Contract (Art. 6(1)(b)) |
| Send marketing and promotional emails | Consent (Art. 6(1)(a)) — opt-in, withdrawable anytime |
| Analyze usage to improve the product (analytics cookies) | Consent (Art. 6(1)(a)) — opt-in via cookie banner |
| Personalized advertising | Consent (Art. 6(1)(a)) — opt-in via cookie banner |
| Comply with law-enforcement requests | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests (Art. 6(1)(f)) — for example fraud detection and AML monitoring — we have balanced those interests against your privacy rights and concluded that the processing is necessary and proportionate. Our legitimate-interests assessment is available on request from the DPO.
We share personal data only with the following categories of recipients:
We do not sell your personal data to third parties.
Your data may be processed in the United States, the European Union, and other jurisdictions where our processors operate. Where personal data leaves the EU/EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, the UK IDTA / Addendum, or another recognized transfer mechanism. A copy of the relevant SCCs is available on request from the DPO.
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account data (name, email, profile) | Until account deletion + 30 days | Contract |
| Transaction data (deposits, withdrawals, ledger) | 5 years after account closure | AML/BSA 31 CFR 1010.430; EU 5AMLD |
| KYC documents (ID images, selfies) | 5 years after account closure | AML/BSA 31 CFR 1010.230; 5AMLD Art. 40 |
| Audit logs | 5 years | AML/BSA; internal security |
| Chat messages with support | 2 years | Legitimate interest (dispute resolution) |
| Suspicious-activity reports | 5 years | AML/BSA |
| Cookies | Per consent choice (max 13 months) | Consent |
| Marketing consent record | Until consent withdrawn + 3 years | Consent (proof of consent) |
Under GDPR you have the right to:
To exercise any of these rights, use the in-app tools above. We respond within 30 days.
You have the right to lodge a complaint with your local data-protection supervisory authority. EU residents may complain to their Member State DPA; UK residents to the ICO; California residents to the California Attorney General. We ask that you contact us first so we can resolve the issue.
If you are a California resident, you have the right to:
To exercise any of these rights, visit /privacy-rights. Authorized agents must submit a signed power of attorney.
We use automated processing for the following purposes:
We do not use automated decision-making that produces legal or similarly significant effects on you without your explicit consent. You may contest any flagged transaction by contacting the DPO.
We engage the following categories of third-party processors to operate the service:
| Category | Purpose | Location |
|---|---|---|
| Database & Auth Provider | User authentication, data storage, and file hosting | USA / EU |
| Application Hosting & CDN | Website hosting, edge caching, and content delivery | Global / USA |
| Image Storage | Avatar and document storage and transformation | USA / EU |
| Payment Processor | Deposit and withdrawal payment processing | USA |
| Font Delivery | Web font hosting and delivery | Global |
| Identity Provider | Optional social sign-in (OAuth) | USA |
Each processor is bound by a Data Processing Agreement (DPA) that meets GDPR Art. 28 requirements. A list of sub-processors is maintained and updated; material changes will be announced on this page.
We implement industry-standard technical and organizational measures to protect your data, including: encryption in transit (TLS) and at rest (AES-256); strict access controls with role-based permissions; audit logging of administrative actions; intrusion detection; regular security assessments; and employee security training. Despite these measures, no system is 100% secure — please practice good password hygiene and enable MFA where offered.
We use four categories of cookies: Strictly Necessary (always on), Functional, Analytics, and Marketing. On your first visit you will see a cookie-consent banner with three actions: Accept All, Reject Non-Essential, and Customize. Your choice is stored inlocalStorage with a timestamp.
You can withdraw consentat any time by clicking the "Withdraw Consent" link in the footer of any page, or by clearing your browser storage.
The service is strictly for individuals 18 years of age or older. We verify date of birth at registration and require KYC before cumulative deposits exceed $1,000. If you believe we have collected personal data from a minor, please contact the DPO immediately and we will erase it.
We may update this policy from time to time. Material changes will be announced by email and on this page at least 30 days before they take effect. Continued use after the effective date constitutes acceptance of the updated policy.
For any privacy-related enquiry, use the privacy request form.
Last updated: January 1, 2025