1. Data We Collect
We operate on a minimal data principle. We do not require real names, addresses, or government IDs for standard accounts.
| Category | Data Points | Required? |
|---|---|---|
| Account | Email address, username, hashed password | Required |
| Bitcoin | Deposit address (HD-derived), transaction hashes | Required |
| Gaming | Bet amounts, game outcomes, session timestamps | Automatic |
| Technical | IP address (hashed), browser type, device type | Automatic |
| KYC | Government ID, selfie (withdrawals >1 BTC only) | Conditional |
2. How We Use Your Data
- Account management: Authentication, balance tracking, withdrawal processing
- Game integrity: Provably fair verification, fraud detection, bonus abuse prevention
- Legal compliance: Anti-money laundering checks, regulatory reporting where required
- Platform improvement: Anonymized analytics to improve game performance and UX
- Customer support: Resolving disputes and account issues
We do not use your data for advertising, sell it to third parties, or profile you for non-gaming purposes.
3. Data Sharing
We do not sell your personal data. We may share data only with:
- Infrastructure providers: Supabase (database), Cloudflare (CDN/DDoS) — bound by strict data processing agreements
- Law enforcement: Only when legally required by valid court order
- Bitcoin blockchain: Transaction data is inherently public on-chain; no additional payment data is shared
4. Security
- All data encrypted in transit via TLS 1.3
- Database encrypted at rest using AES-256
- Passwords stored as bcrypt hashes (never plaintext)
- Bitcoin hot wallet limited to <5% of funds; remainder in cold storage
- Regular penetration testing and security audits
- 2FA available for all accounts
5. Cookies & Local Storage
- Session cookie: Keeps you logged in — essential, 24-hour expiry
- Preferences: Game settings stored in localStorage — no tracking
- Analytics: Anonymous, aggregated metrics only — no third-party trackers
We do not use Google Analytics, Facebook Pixel, or any advertising trackers.
6. Blockchain Data
Bitcoin transactions are recorded on a public blockchain. Your deposit and withdrawal addresses are permanently visible on-chain. While pseudonymous, they are not anonymous. We recommend using a fresh Bitcoin address for each transaction for maximum privacy.
7. Your Rights (GDPR & Similar)
- Access: Request a copy of all data we hold about you
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion (subject to legal retention requirements)
- Portability: Receive your data in machine-readable format
- Objection: Object to certain processing activities
To exercise any right, contact privacy@cryptokasino.io. We respond within 30 days.
8. Data Retention
Active account data is retained for the lifetime of the account plus 5 years (AML requirements). Closed account data is deleted after 5 years. Anonymized gaming logs may be retained indefinitely for statistical purposes.
9. Children's Privacy
Our Platform is strictly for adults aged 18+. If we discover a minor has created an account, it will be immediately closed and all data deleted. Please contact us if you believe a minor is using the Platform.
10. Contact & DPO
Data Protection Officer: privacy@cryptokasino.io
General Support: support.html →
Address: CryptoKasino Ltd, Willemstad, Curaçao