1. Who We Are
RockySpin Entertainment Ltd. is the data controller responsible for your personal data. We are a licensed online casino operator registered under the laws of Curaçao and operating under e-Gaming license number 8048/JAZ issued by the Curaçao Gaming Authority.
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, you can contact us at any time through our customer support team via live chat on our website or by email at [email protected].
2. Information We Collect
We collect personal data that you provide to us directly, data we generate as you use our Service, and in certain cases data we receive from third parties. The categories of personal data we collect include the following.
Identity and contact data: When you register an account, we collect your full name, date of birth, country of residence, email address, and username. This information is necessary to create and manage your account and to verify your identity in accordance with our legal obligations.
Financial data: When you make deposits or withdrawals, we collect payment method details including card numbers (stored in masked format), e-wallet identifiers, and cryptocurrency wallet addresses where applicable. We do not store full card details on our systems — these are handled by certified payment processors.
Verification documents: As part of our KYC (Know Your Customer) process, we may collect copies of government-issued identity documents, proof of address, and other documentation required to verify your identity and comply with anti-money laundering regulations.
Usage and technical data: We automatically collect information about how you interact with our Service, including your IP address, browser type and version, device type and identifiers, operating system, pages visited, session duration, game activity, betting history, and referring URLs.
Communication data: We retain records of communications between you and our support team, including live chat transcripts and email correspondence, for quality assurance and dispute resolution purposes.
3. How We Use Your Information
We use your personal data for the following purposes, each based on a legitimate legal ground.
To provide and manage the Service: We use your identity, contact, and financial data to create and maintain your account, process deposits and withdrawals, deliver the games and features you access, and administer your participation in promotions and bonuses. This processing is necessary to perform the contract we have with you.
To comply with legal obligations: We are required by law to verify the identity of our players, monitor transactions for signs of money laundering or fraud, maintain records of account activity, and report suspicious activity to relevant authorities where required. KYC document processing and transaction monitoring are performed on this legal basis.
To protect legitimate interests: We use usage and technical data to maintain the security of our platform, detect and prevent fraudulent activity, enforce our Terms of Service, manage risk, and protect the interests of our business and other users.
To communicate with you: We use your contact data to send you transactional communications such as account confirmations, deposit receipts, withdrawal notifications, and security alerts. With your consent, we may also send you marketing communications about promotions, new games, and special offers. You can withdraw consent for marketing communications at any time.
To improve our Service: We analyse aggregated and anonymised usage data to understand how players interact with our platform, identify technical issues, improve game performance, and develop new features. This processing is based on our legitimate interest in improving our business.
4. Legal Basis for Processing
We process your personal data on the following legal bases under applicable data protection law.
Contractual necessity: Processing required to fulfil our obligations under the account agreement, including account creation, payment processing, and service delivery.
Legal obligation: Processing required to comply with applicable laws including anti-money laundering regulations, gambling laws, tax reporting requirements, and regulatory obligations under our gaming license.
Legitimate interests: Processing necessary for our legitimate business interests, including fraud prevention, platform security, and service improvement, where these interests are not overridden by your rights.
Consent: Processing of personal data for marketing communications and optional features, where you have given explicit consent. You have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
5. How We Share Your Information
We do not sell your personal data to third parties. We share personal data only in the following circumstances and only to the extent necessary.
Service providers: We share data with trusted third-party service providers who assist us in operating the platform, including payment processors, identity verification providers, fraud detection services, cloud hosting providers, and customer support tools. These providers are contractually obligated to process your data only on our instructions and to maintain appropriate security standards.
Game providers: Game software providers integrated into our platform may receive limited technical data such as your player identifier and session information to enable gameplay and maintain game integrity. They do not receive your full identity or financial data.
Regulatory and legal authorities: We may disclose personal data to regulators, law enforcement agencies, or other authorities where required by law, where necessary to comply with a legal obligation, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of our business, our users, or others.
Business transfers: In the event of a merger, acquisition, restructuring, or sale of all or part of our business, personal data held by us may be transferred to the acquiring entity as part of that transaction. We will notify you if your data is subject to such a transfer and provide information about your rights in that context.
6. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Active account data: We retain your account information, transaction history, and game activity records for the duration of your account and for a period of at least five years after account closure, as required by anti-money laundering and gaming regulations.
KYC documents: Identity verification documents are retained for a minimum of five years after the end of the business relationship, in accordance with regulatory requirements.
Communication records: Support communications are retained for up to three years after the conversation ends, for quality assurance and dispute resolution purposes.
Marketing data: If you have consented to marketing communications, we retain your contact details for marketing purposes until you withdraw consent or we determine the data is no longer relevant.
When personal data is no longer required, we securely delete or anonymise it in accordance with our data retention policy.
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website to improve your experience, analyse usage, and deliver relevant content. Cookies are small text files stored on your device when you visit our website.
Essential cookies: These cookies are strictly necessary for the website to function and cannot be disabled. They enable features such as session management, security, and account authentication.
Analytical cookies: We use analytical cookies to understand how visitors interact with our website, measure performance, and identify areas for improvement. The data collected is aggregated and does not directly identify individual users.
Functional cookies: These cookies remember your preferences such as language settings and allow us to provide a more personalised experience.
Marketing cookies: With your consent, we may use cookies to track your browsing activity and display relevant promotional content. You can manage your cookie preferences at any time through the cookie settings panel on our website.
You can also control cookies through your browser settings. Disabling certain cookies may affect the functionality of some parts of our website.
8. International Data Transfers
RockySpin operates internationally and your personal data may be transferred to and processed in countries outside your country of residence. Some of these countries may not provide the same level of data protection as your home country.
When we transfer personal data outside regions with strong data protection frameworks, we take appropriate safeguards to ensure your data remains protected. These safeguards may include the use of standard contractual clauses approved by relevant data protection authorities, adequacy decisions, or other legally recognised transfer mechanisms.
If you would like more information about the safeguards we apply to international data transfers, please contact us using the details provided in this policy.
9. Your Rights
Depending on your country of residence and applicable data protection law, you may have the following rights regarding your personal data.
Right of access: You have the right to request a copy of the personal data we hold about you and information about how we use it.
Right to rectification: You have the right to request correction of inaccurate or incomplete personal data we hold about you.
Right to erasure: You have the right to request deletion of your personal data in certain circumstances, for example when it is no longer necessary for the purposes it was collected or when you withdraw consent.
Right to restriction: You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while we investigate a complaint about the accuracy of your data.
Right to data portability: Where processing is based on your consent or on a contract, you have the right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to object: You have the right to object to processing of your personal data based on legitimate interests, including for direct marketing purposes.
Right to withdraw consent: Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please contact our support team. We will respond to your request within 30 days. We may need to verify your identity before processing your request.
10. Security of Your Data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. Our security measures include 256-bit SSL encryption for all data transmitted between your device and our servers, secure storage of personal and financial data, access controls limiting who can view sensitive data within our organisation, regular security assessments and audits, and incident response procedures to address potential data breaches.
While we take every reasonable precaution to protect your data, no method of transmission over the internet or method of electronic storage is completely secure. If you believe your account has been compromised, please contact us immediately so we can take appropriate action.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required by law, we will also notify you directly without undue delay.
11. Children's Privacy
Our Service is strictly intended for individuals who are 18 years of age or older. We do not knowingly collect or process personal data from anyone under the age of 18. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us immediately. Upon confirmation, we will take steps to delete the information and close any associated account as quickly as possible.
We also take reasonable steps to verify the age of our users during the registration process as part of our commitment to responsible gaming.
12. Third-Party Links
Our website may contain links to third-party websites, applications, or services that are not operated by us. We have no control over and accept no responsibility for the content, privacy policies, or practices of any third-party sites. We encourage you to review the privacy policy of every site you visit before providing any personal data.
The inclusion of any link on our website does not imply endorsement of the linked site by RockySpin.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes, we will update the "Last updated" date at the top of this policy.
If we make material changes that significantly affect how we use your personal data, we will notify you by posting a notice on our website or by sending you an email to the address associated with your account before the changes take effect. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the revised policy.
14. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have a complaint about how we handle your personal data, please contact us.
You can reach our Data Protection team via email at [email protected] or through the live chat support available on our website at playrockyspin.com. We will acknowledge your request promptly and aim to resolve all enquiries within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection supervisory authority in your country of residence.