Privacy policy
1. INTRODUCTION
This page explores how CasinoAlpha (which will also be referred to throughout our content as “we”, “us” or “our”) gathers, uses, shares and protects visitors’ personal information when they navigate our platform (also referred as the “Website” throughout this page)/
CasinoAlpha is an independent casino review and rating service. We operate based on our strict in-house 47-factor methodology for assessing online casinos. We engage to protect gamblers’ data in accordance with applicable laws, including the General Data Protection Regulation (GDPR) and other regional privacy frameworks.
To learn more about who we are and our mission, we recommend visiting our About Us page.
2. INFORMATION WE COLLECT
2.1. Information You Provide Directly
If you make the choice to offer information that is sensitive, such as email, country, name, address, and other such details, we will gather and sort your data. In most situations, the details we collect shall appear in your contact form updates, together with the message you have sent and your specific inquiry.
If you decide to leave a player review, we will also gather and sort the same batch of your personal information. This includes your username, but also your real name, email, the content in your review, and the rating you have given to the online casino.
2.2. Information Collected Automatically
When you visit our platform, we will automatically collect cookie data from your navigation sessions. We will collect your IP address, details on your device and browser, as well as the operating system you are using. We will also collect details on the resolution of your screen, the pages you’ve clicked on and then exited, as well as the time and date stamps from your navigation history.
When you visit and use casinoalpha.ca, we will collect cookie data from your browsing sessions.
The other information and data we collect when visitors use our platform fall into the following categories:
- The period of time you’ve spent on each individual page you’ve visited
- The click and navigation patterns and paths
- Every search query you’ve undergone on our platform
- The depth of your scrolls
- Any interactions you’ve completed with the published content on CasinoAlpha
Note: We do NOT collect specific geolocation information.
2.3. Information From Third Parties
To operate responsibly, we occasionally receive limited information from other sources. Casino operators we review may provide verification details, such as confirmation of licence validity or game providers, used solely for accuracy checks.
Analytics providers may supply aggregated, anonymised performance metrics, and advertising partners may share ad performance information that does not identify you (non-PII). We do not purchase or obtain personal data from data brokers.
3. HOW WE USE YOUR INFORMATION
3.1. Purpose Table
| Purpose | Data Used | Legal Basis (GDPR / Global) | |
|---|---|---|---|
| Sending you newsletters | Your email address, name, and preferences | Your consent | |
| Answering your questions |
|
Fulfilling our agreement with you or our legitimate interest | |
| Making our website work better | Usage data, technical data | Our legitimate interest | |
| Understanding site performance | Cookies, usage data, IP address | Our legitimate interest | |
| Keeping your data safe | IP address, technical data, access logs | Our legitimate interest | |
| Meeting legal requirements | Relevant data as required | Legal requirement | |
| Tracking affiliate referrals | Click data, referral information | Our legitimate interest |
The data we gather helps us improve our 47-factor methodology for reviewing casinos, and ensures that the content we constantly deliver meets user needs and expectations.
3.2. Detailed Purposes
It is possible that we shall send you data from our Newsletter about casino analyses, bonus suggestions, industry insights, and updates about our platform. Our team can also reach out to you in order to answer your questions or address any requests you’ve made. The data and information we gather and sort for Analytics has the purpose for us to understand the visitors of our service, their traffic models and user behaviour, to identify trending content, test new option and be able to diagnose potential technical errors.
If we complete a Website Operation, we may do so because our team of experts maintains how the platform works. Also, we might decide to do so in order for our team to offer you an improved personalised experience to you, or so we can update your sessions to your cookie setting choices. Another possible scenario is for us to need to run a security update in order to keep our platform secure.
Other reasons for collecting data may include:
- Being able to detect and prevent fraudulent activity
- Checking whether or not the website is safe from security threats
- Protecting the service and users from spam content
- Enforcing the rules we’ve set in our Terms and Conditions
We may also collect users’ data for Affiliate marketing purposes, as explained extensively on our Advertiser Disclosure page.
We do this in order to track the referrals each casino platform garners, to be able to calculate our commission properly, and to be able to evaluate if our recommendations match users’ preferences.
Note: If you want to have a professional partnership with us, you can see more details on our Advertise with us page.
3.3. Legitimate Interests
CasinoAlpha reserves the right to collect data from you in the legitimate interest. Such instances include, but are not limited to:
- Enhancing our business model
- Offering free helpful content to our readers
- Keeping our security standards and preventing fraudulent occurrences
- Understanding the preferences of users in order to deliver relevant content
- Sustaining CasinoAlpha’s business model
- Constantly analysing performance metrics in order to improve users’ experience
4. LEGAL BASIS FOR PROCESSING UNDER GDPR (EEA/UK)
We process personal data of visitors from EU, EEA and the UK according to the GDRP ammendments.
4.1. Consent
We are counting on your consent when you constantly acree to certain operations, such as the access to newsletter subscriptions, the use of marketing cookies, and optional data collection cases such as surveys.
It is relevant to know that you are able to withdraw consent at ay given moment. In order to cancel the subscription to our newsletter, simple use the Unsubscribe link present in any newsletter or simply modify your options in the Coockie Settings for your cookies.
4.2. Legitimate Interests
CasinoAlpha processes data according to website analytics’ interests, as well as to the interest of fraud prevention and the well functioning of the platform. We also process data in the interest of affiliate tracking and to be able to respond to enquires. Our team has personally analysed these interests and deemed they do not cross your fundamental rights and feedoms.
4.3. Legal Obligation
Some processing is necessary to comply with legal requirements. This includes complying with court orders or legal processes, tax and financial record-keeping, regulatory compliance, and responding to lawful government requests.
4.4. Contract
CasinoAlpha also processes data in order to perfrom the right steps at your requests before entering into one. This operation actually covers provinding the services you request, as well as processing enquires and support requests. It is a relevant process we need to fulfill our obligations specified in our T&Cs.
For the area where GDPR does not apply, we process data under the legal ammendments of every jurisdiction.
5. COOKIES AND TRACKING TECHNOLOGIES
5.1. What Are Cookies?
Cookies are small text files stored on your device. They help us remember preferences and understand how you use the Website.
5.2. Types of Cookies We Use
A. Strictly Necessary Cookies
These are essential for the Website to function and cannot be disabled.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
| CookieCarousel | CasinoAlpha | Manages cookie consent banner display | 12 months |
| CookieConsent | CasinoAlpha | Stores your cookie consent preferences | 12 months |
| g_state | CasinoAlpha | Maintains application state and user session | Until you close your session |
| Secure-wp-show-GLOBAL ES | CasinoAlpha | WordPress security token for CSRF protection | Until you close your session |
Legal Basis: Necessary for site operation / Legitimate interests (GDPR Art. 6(1)(f)); no consent required for strictly necessary cookies.
B. Analytics and Performance Cookies
Help us understand how visitors interact with the Website.
1) Matomo Analytics (Self-Hosted, Privacy-Focused)
| Cookie Name | Purpose | Duration | Data Collected |
|---|---|---|---|
| _pk_id.* | Recognises returning visitors | 13 months | Anonymised visitor ID |
| _pk_ses.* | Tracks pages in current session | 30 minutes | Page views, time on site |
| _pk_ref.* | Stores referral information | 6 months | Traffic source |
What is Matomo? An open-source, privacy-focused analytics platform hosted on our EU servers.
Privacy features: EU hosting; no third-party sharing; auto-deletion after 24 months; honours Do Not Track (DNT); GDPR-aligned by design.
Not collected: PII, cross-site tracking, ad profiles.
Purpose: Behaviour insights, content/navigation improvements, issue diagnosis, performance measurement.
Legal Basis: Legitimate interests (Art. 6(1)(f)), supported by an LIA.
Opt-out: Update Cookie Settings or enable DNT (Matomo honours DNT).
More info: https://matomo.org/privacy/
2) Google Analytics 4 (GA4)
| Cookie Name | Purpose | Duration | Data Collected |
|---|---|---|---|
| _ga | Distinguishes unique users | 2 years | Anonymised user ID |
| ga* | Maintains session state | 2 years | Page views, events, session data |
| _gid | Distinguishes users | 24 hours | Short-term user ID |
| _gat | Throttles request rate | 1 minute | Rate limiting |
Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Configuration: IP anonymisation; data sharing with Google disabled (no advertising features); User-ID off; no remarketing; Google Signals off; data retention 14 months; cookie timeout up to 24 months.
Purpose: Comprehensive analytics; behaviour and content analysis; traffic sources; conversion tracking (e.g., newsletter signups, affiliate clicks); benchmarking and performance monitoring.
Legal Basis:
For EEA/UK: Consent (Art. 6(1)(a)), explicit opt-in before activation.
For Non-EEA/UK regions: Legitimate interests or consent per local law.
International transfer: Data may be processed in the USA.
Safeguards: EU-US Data Privacy Framework (DPF); SCCs; encryption; access controls; security audits.
DPA: In place with Google (GDPR Art. 28).
Policies & opt-out:
- Privacy: https://policies.google.com/privacy
- Terms: https://marketingplatform.google.com/about/analytics/terms/
- Partner sites: https://policies.google.com/technologies/partner-sites
- Opt-out add-on: https://tools.google.com/dlpage/gaoptout, or use Cookie Settings.
C. Marketing and Advertising Cookies
Track activity for campaign measurement and relevant advertising.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
| utm_* | CasinoAlpha | Tracks marketing campaigns | Session |
Legal Basis: Consent where required (GDPR Art. 6(1)(a)).
D. Notification Cookies
| Cookie Name | Purpose | Duration |
|---|---|---|
| _webpushEndPoint | Stores web push notification endpoint | 12 months |
| _webpushLastVisit | Tracks last visit for notification timing | 12 months |
Purpose: Optional web push notifications for promotions and updates.
Legal Basis: Consent (Art. 6(1)(a)).
5.3. Cookie Consent Management
On first visit, a cookie banner (CookieCarousel) appears with options to Accept All (all categories) or Reject All non-essential cookies. Consent must be freely given and is revocable at any time. Your choices are stored in CookieConsent for 12 months, after which we will ask again.
5.4. Managing and Controlling Cookies
You are able to block all cookies, if one requests, but that might pose problems with how our platform will function. Based on your browser, you have the following options:
- Chrome – https://support.google.com/chrome/answer/95647
- Firefox – https://support.mozilla.org/kb/enhanced-tracking-protection-firefox-desktop
- Safari – https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac
- Edge – https://support.microsoft.com/microsoft-edge/delete-cookies-in-microsoft-edge-63947406
You are able to opt out of Google Analytics using the link above or the Matomo variants. Matomo respects your DNT request, while the Google option does that by default. Marketing cookies follow one’s consent regardless of DNR.
In order to gain access to more routes, our team of experts recommends you follow one of these links:
- https://www.youronlinechoices.com/
- https://optout.networkadvertising.org/
- https://optout.aboutads.info/
5.5. Withdrawing Consent
Use Cookie Settings (footer) to choose “Necessary Only” or customise, then Save Preferences. Effects are immediate and do not affect earlier lawful processing. Some features may be limited.
5.6. Consequences of Disabling Cookies
| Category | Impact |
|---|---|
| Strictly Necessary | Banner may reappear, and some security features may fail |
| Analytics | No functionality loss, but our ability to improve UX is reduced |
| Marketing | You get fewer relevant ads, and the usual affiliate attribution may be affected |
| Preference | Language/region/currency must be re-selected on each visit |
| Notifications | Web push is disabled, and you may miss updates |
5.7. Third-Party Cookies
When you enter our platform, you will come across several links from sites that are not us or our service. These platforms may add their own set of cookies on your device. This tends to happen frequently for social media or video content platforms, since they rely on tracking cookies to adapt their algorithm to your needs.
When you browse casinoalpha.ca, you will encounter links from sites that are not us or our service. These sites might place their own cookies on your device. Such services include Facebook, X, and YouTube.
When you click on an affiliate link to visit a casino paty, the third-party sites can place their own tracking cookies to attribute your visit and activity. Such cookies are governed by the respective third party’s privacy policy, not ours.
5.8. Cookie Lifespan and Deletion
There are two different types of cookies that can be stored on visitors’ devices based on how long they last. Session cookies are only available for a short time which will be deleted as soon as the browser is closed. Persistent cookies remain on our platform for a set period of time, but this period never exceeds 24 months.
Two types of cookies can be stored on your device based on how long they last. Session cookies are only there for a short time and are deleted when you close your browser. Persistent cookies stay on our site for a set amount of time, but never more than 24 months.
5.9. The Technical Implementation of Cookie Trackers
Our platform runs on WordPress, a platform that has its own innate cookies that apply.
5.10. Cookie Audit and Monitoring
CasinoAlpha audits cookies in order to keep our policy accurate.
6. THIRD-PARTY SERVICES AND DATA SHARING
We share data with trusted third parties only where necessary.
6.1. Analytics Services
A) Matomo Analytics (Self-Hosted)
- Provider: Self-hosted on our EU servers (no external processor)
- Location: Germany
- Relationship: We are Data Controller; Matomo is our tool (not a separate processor)
- Data Collected: IP addresses; pages visited/time spent; referral source; device type/browser (anonymised); geographic location (country/city from IP); click events/interactions.
- Not Collected: PII; cross-site tracking; data shared with advertisers.
- Privacy Features: EU-hosted; no third-party sharing; honours DNT; GDPR-aligned.
- Purpose: Behaviour insights, UX improvements, performance monitoring
- Legal Basis: Legitimate interests (Art. 6(1)(f)) — LIA conducted
- Retention: 24 months • Opt-Out: Cookie Settings or enable DNT
- More Info: https://matomo.org/privacy/
B) Google Analytics 4 (GA4)
- Provider: Google LLC
- Address: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- Relationship: Processor (GDPR Art. 28, DPA in place)
- Data Collected: IP addresses; pages viewed/user journeys; session duration/bounce rate; traffic sources/referrals; device info (type, OS, browser); approximate location (city level); custom events/interactions; conversion tracking.
- Disabled: Advertising features; Google Signals; enhanced ad measurement.
- Privacy Configuration: Data sharing with Google disabled; data retention 14 months; cookie timeout ≤24 months.
- Purpose: Analytics, behaviour insights, traffic sources, conversions, benchmarking, performance monitoring.
- Legal Basis: EEA/UK: Consent (explicit opt-in).
- Non-EEA/UK: legitimate interests or consent per local law.
- Transfers to USA with DPF certification/SCCs and additional safeguards (encryption, access controls, audits).
Policies:
- Privacy: https://policies.google.com/privacy
- Terms: https://marketingplatform.google.com/about/analytics/terms/
- DPA: https://privacy.google.com/businesses/processorterms/
- Partner sites: https://policies.google.com/technologies/partner-sites
- Opt-Out: Add-on: https://tools.google.com/dlpage/gaoptout
6.2. Comparison: Matomo vs. Google Analytics
| Feature | Matomo | Google Analytics |
|---|---|---|
| Hosting | Self-hosted EU | Google USA |
| Data Ownership | 100% ours | Shared with Google |
| Privacy Focus | Very high | Moderate (configured) |
| GDPR Built-in | Yes | Requires config + consent |
| International Transfer | None (EU only) | Yes (EU → USA) |
| Third-Party Access | None | Google (no ad use) |
| IP Anonymisation | 2 bytes | 1 byte |
| DNT Respect | Yes | No |
| Data Retention | 24 months | 14 months |
| Legal Basis | Legitimate interests | Consent (EEA) |
Why both: Matomo for privacy-first analytics; GA4 for benchmarking/advanced features.
Your choice: Consent to both, Matomo only, or neither via Cookie Settings.
6.3. Casino Operators (Affiliate Relationships)
Important affiliate disclosure: CasinoAlpha earns commissions when you register/play at casinos through our links.
For complete transparency about how we maintain editorial independence despite these financial relationships, please review our detailed Advertiser Disclosure and Editorial Policy.
How affiliate tracking works: You click a tracked link → the operator places a cookie (typically 30–90 days) → you register and/or deposit → the operator attributes the referral to CasinoAlpha → we receive commission (e.g., €20–€150 CPA or 20%–40% revenue share).
- Data shared with the casino: referral source (casinoalpha.com), click timestamp, our affiliate ID, click ID (session).
- Data shared back to us: aggregate conversion info and commission due.
- We do not receive: your name, email, address, deposit amounts, balances, payment details, or gameplay data.
Once you visit a casino, you are subject to their Terms and Privacy Policy. Review those before registering.
Editorial independence: See our Editorial Policy
Legal Basis: Legitimate interests for affiliate tracking (Art. 6(1)(f)); consent (Art. 6(1)(a)) if required by the operator.
Opt-Out: Reject Marketing Cookies in Cookie Settings (may affect referral attribution).
6.4. Email Service Provider
- Provider: Aweber
- Purpose: Newsletter delivery and email marketing
- Data shared: email address, name (if provided), preferences, engagement (opens/clicks)
- Legal Basis: Consent (Art. 6(1)(a))
- Privacy: https://www.aweber.com/privacy.htm
6.5. Hosting and Infrastructure
- Provider: Google Cloud
- Location: EU/EEA
- Services: Website hosting, CDN, DDoS protection, SSL/TLS, database management, backups
- DPA: GDPR-compliant DPA in place
- Data transferred: Operational website data as necessary
- Legal Basis: Legitimate interests (Art. 6(1)(f))
6.6. When We Must Disclose Data
- Legal obligations: court orders, subpoenas, legal processes; compliance with laws/regulations; lawful requests from authorities; tax/financial reporting.
- Protection of rights: enforce Terms and Conditions; detect/prevent fraud and security issues; protect our rights, property, safety; protect users and the public.
- Business transfers: merger, acquisition, bankruptcy, sale of assets. We will notify via email and Website notice. Any acquirer must honour this Policy or seek fresh consent.
- With your consent: any other disclosure with explicit consent.
- Data minimisation: we disclose only the minimum necessary.
6.7. We Do Not Sell Your Personal Data
CasinoAlpha does not sell, rent, or trade personal data. Affiliate commissions are not a “sale” under GDPR/CCPA/CPRA because we do not transfer PII to operators.
Newsletter subscribers receive casino reviews, bonus offers, and industry insights from our expert team. You can unsubscribe at any time via the link in any email.
6.8. Third-Party Links
The Website contains links to casino/third-party sites. Once you click, their terms and privacy policies apply. We do not control their practices and are not responsible for their content, security, or data handling. Please review third-party privacy policies before sharing personal information.
6.9. List of Third-Party Data Recipients
| Recipient | Purpose | Location | Data Shared | Legal Basis |
|---|---|---|---|---|
| Matomo | Analytics (self-hosted) | EU (our servers) | IP/usage | Legitimate interests |
| Google Analytics | Analytics | USA | IP/usage | Consent (EEA); Legitimate interests (non-EEA) |
| Casino Operators | Affiliate tracking | Various | Referral info (non-PII) | Legitimate interests |
| Aweber (Email Provider) | Newsletter | US/EU | Email, name, preferences | Consent |
| Google Cloud (Hosting) | Website hosting | EU | Operational data | Legitimate interests |
| [CDN Provider] | Content delivery | Global | IP, pages requested | Legitimate interests |
Full details: see subsections above.
Questions about data sharing or privacy practices? Contact our data protection team or review our company information for more details about CasinoAlpha’s operations.
7. INTERNATIONAL DATA TRANSFERS
7.1. Where Your Data Is Processed
- Primary location: EU/EEA
- Website servers: Germany, United Kingdom
- Matomo analytics: EU (self-hosted)
- Hosting provider: EU data centres
Most data remains within the EU/EEA.
7.2. Transfers Outside EU/EEA
- United States (USA) – Google Analytics
- Recipient: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- Why transfer occurs: GA processes data on US servers to deliver analytics.
Legal basis for transfer:
- EU-US Data Privacy Framework (DPF): Google LLC certified (see: https://www.dataprivacyframework.gov/s/)
- Standard Contractual Clauses (SCCs): EU Commission-approved (2021, Module 2)
- Supplementary measures: TLS 1.3 in transit; encryption at rest; strict access controls; audits; transparency reports; legal redress mechanisms
- Your consent (EEA/UK): we request explicit consent before GA is activated (withdraw in Cookie Settings)
Your rights:
- Opt-out add-on: https://tools.google.com/dlpage/gaoptout
- Withdraw consent via Cookie Settings to stop transfer
Alternative: Choose Matomo-only (EU-hosted) to avoid international transfers.
Other potential transfers:
- Casino operators: various jurisdictions (Malta, Curaçao, Gibraltar, UK, etc.). You enter a direct relationship; their policies apply.
- Social media platforms: Facebook, Twitter/X, LinkedIn (EU/USA as applicable) under SCCs/DPF.
7.3. Adequacy Decisions
The EU Commission recognises certain countries as providing “adequate” protection (e.g., Andorra, Argentina, Canada (commercial), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, UK, Uruguay; USA for entities certified under the DPF). Full list: European Commission website.
7.4. Your Rights Regarding International Transfers
You may: be informed (as set out here); object by withdrawing consent; request details about SCCs/DPF certification; and opt out via Cookie Settings (e.g., reject GA).
7.5. No Transfer to High-Risk Jurisdictions
We do not transfer data to countries/organisations subject to EU sanctions, known for mass surveillance without safeguards, or lacking adequate protection.
7.6. Monitoring Legal Changes
We monitor developments (e.g., Schrems II, DPF updates) and adjust our approach. Material changes will be reflected in this Privacy Policy.
8. DATA RETENTION
We retain personal data only as long as necessary.
8.1. Retention Periods
| Data Type | Retention Period | Reason |
|---|---|---|
| Newsletter subscribers | Until unsubscribe + 30 days | Processing unsubscribe requests |
| Contact form inquiries | 2 years from last contact | Support history/legal requirements |
| Analytics data (Matomo) | 24 months | Performance analysis |
| Analytics data (Google) | 14 months | Performance analysis |
| Cookies | As specified in Section 5 | Session to 24 months |
| User accounts (if applicable) | Until deletion + legal requirements | Account management |
| Aggregate/anonymised data | Indefinitely | Not personal data |
8.2. Retention Criteria
We set retention based on purpose fulfilment, legal obligations, legitimate business needs (e.g., defending legal claims), and consent period.
8.3. Secure Deletion
After expiry: personal data is securely deleted or anonymised; backups are purged per schedule (max 90 days); third parties are instructed to delete data.
Deletion methods: secure overwrite; anonymisation.
8.4. Exceptions
We may retain data longer where required by law, needed for legal claims, you request retention, or data is fully anonymised.
9. YOUR RIGHTS UNDER GDPR (EEA/UK)
For EU/EEA and UK residents, the following rights apply.
9.1. Right to Access (Art. 15)
Request a copy of your personal data and related information.
How: use the Contact page form with your full name, email, and scope.
Response: within 30 days (may extend to 60 days for complex requests).
Fee: free unless requests are excessive/unfounded.
9.2. Right to Rectification (Art. 16)
Ask us to correct inaccurate or incomplete personal data. Response: 30 days.
9.3. Right to Erasure / “Right to be Forgotten” (Art. 17)
Request deletion where applicable (e.g., data no longer needed, consent withdrawn, unlawful processing, or legal obligation to erase).
Exceptions: legal retention or legal claims/public interest.
How: Contact page form. Response: 30 days.
9.4. Right to Restrict Processing (Art. 18)
Request that we limit processing (e.g., accuracy contested, legal claims). We store but limit processing. Response: 30 days.
9.5. Right to Data Portability (Art. 20)
Receive your data in CSV/JSON/XML where processing is based on consent or contract and automated. How: Contact page form. Response: 30 days.
9.6. Right to Object (Art. 21)
Object to processing based on legitimate interests or to direct marketing.
- Legitimate interests: we stop unless we demonstrate compelling grounds.
- Direct marketing: we stop immediately.
9.7. Rights Related to Automated Decision-Making (Art. 22)
You have the right not to be subject to solely automated decisions with legal or similarly significant effects. Our practice: we do not use such profiling. If this changes, we will notify you and explain safeguards.
9.8. Right to Withdraw Consent
Withdraw consent at any time:
- Newsletter: click Unsubscribe
- Cookies: update Cookie Settings
Withdrawal is immediate and does not affect prior lawful processing.
9.9. How to Exercise Your Rights
Contact:
- Email: legal@casinoalpha.com
- Mail: [Company Name], [Full Address]
Or the Contact page form (preferred)
Include: full name, email, specific request, and proof of identity if needed.
Response time: 30 days (extendable to 60 days; we’ll inform you).
Fee: none unless requests are manifestly unfounded or excessive. If we refuse, we’ll explain why and inform you of your right to complain to a supervisory authority.
9.10. Right to Lodge a Complaint
Your Local Data Protection Authority (EU/EEA): https://edpb.europa.eu/about-edpb/board/members_en
UK Residents – ICO: https://ico.org.uk • Phone: 0303 123 1113 • Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
You may contact us first at legal@casinoalpha.com. Judicial remedies remain available.
10. DATA SECURITY
We implement appropriate technical and organisational measures.
10.1. Technical Measures
TLS 1.3 encryption; secure hosting (ISO 27001 where applicable); WAF and network firewalls; intrusion monitoring; timely security patches; bcrypt password hashing; RBAC; 2FA for admins; encrypted backups.
10.2. Organisational Measures
Internal policies; employee training; least-privilege access; NDAs; vendor due diligence; incident response plan; periodic security audits; DPO (if applicable).
10.3. No Absolute Security
No internet transmission or storage system is 100% secure. Your responsibility: use strong, unique passwords; keep devices secure; log out on shared devices; report suspicious activity promptly.
10.4. Data Breach Notification
If a personal data breach occurs:
- Supervisory authority: notify within 72 hours if risk to rights/freedoms
- Individuals: notify without undue delay if high risk
We will share: nature of breach, likely consequences, measures taken/proposed, contact point, and protective advice.
10.5. Phishing and Security Warnings
We will never request passwords or payment details by email or send urgent “account problem” links. Legitimate messages come from @casinoalpha.com (e.g., newsletter@, support@, privacy@).
If you receive a suspicious message: don’t click links/downloads; verify by typing casinoalpha.com directly; Common scams include fake bonus emails, “update payment details urgently,” and spoofed casino messages.
11. CHILDREN’S PRIVACY
Age Restriction: 18+ Only. The Website is intended for adults (18+) or the legal gambling age in your jurisdiction, whichever is higher. We do not knowingly collect data from minors and will delete such data if discovered. We are not liable for unauthorised use by minors.
Parental Controls:
- Net Nanny (https://www.netnanny.com),
- Qustodio (https://www.qustodio.com),
- Norton Family (https://family.norton.com),
- Kaspersky Safe Kids (https://www.kaspersky.com/safe-kids), and built-in OS controls (Windows Family Safety, macOS/iOS Screen Time, Android Family Link). Enable Safe Search and consider site-blocking extensions.
Organisations:
- GamCare: https://www.gamcare.org.uk
- BeGambleAware:mhttps://www.begambleaware.org
- NCPG (US): https://www.ncpgambling.org
Report concerns: use the Contact page form (subject “Minor Data Concern”).
12. AFFILIATE MARKETING DISCLOSURE
12.1. Transparency Notice
CasinoAlpha is an affiliate marketing website. We may earn commissions when you register or play at casinos via our links. This does not change your costs or bonus terms. Our reviews remain objective and based on rigorous testing.
12.2. How Affiliate Marketing Works
Steps: You visit CasinoAlpha and click a tracked link → the operator sets a cookie (usually 30–90 days) → you register and/or deposit → the operator attributes the referral → we earn commission.
Commission types: CPA (€20–€150 per qualifying player); Revenue Share (20%–40% of net gaming revenue); Hybrid.
What we receive: registration/deposit confirmation (yes/no), commission owed, aggregated data (e.g., “a player from CasinoAlpha deposited”).
What we don’t receive: your name, email, address, deposit amounts, wins/losses/balances, payment details, or gameplay data.
12.3. Impact on Your Experience
Affiliate tracking does not affect signup, bonuses, wagering requirements, odds, withdrawals, customer support, or your legal rights.
12.4. Editorial Independence
Commissions do not influence ratings. We apply a documented methodology, list only licensed casinos, and adjust ratings based on player feedback and testing. No pay-for-play.
Example: If Casino B offers better security/games/UX than Casino A, Casino B rates higher—even if Casino A pays a higher commission.
Methodology: see our Editorial Policy.
12.5. Sponsored and Featured Content
We label placements clearly: Featured Partner, Exclusive Offer, Sponsored, Ad/Advertisement. Non-labelled content follows standard editorial processes (it may still contain affiliate links).
12.6. Your Privacy in Affiliate Tracking
Operators may place tracking cookies. You can reject Marketing Cookies via Cookie Settings (note this may impact our attribution). We do not receive your PII from operators.
12.7. Regulatory Compliance
We follow: FTC Endorsement Guidelines (US) – 16 CFR Part 255 • ASA CAP Code (UK) • Consumer Rights Act 2015 (UK) • GDPR transparency (EU) • UKGC Social Responsibility Code.
12.8. Why Affiliate Marketing
It allows us to offer free, comprehensive reviews, remain independent of operators, and invest in testing and research, without charging subscription fees.
12.9. Your Choice
To avoid affiliate links: type the casino URL directly; search for the casino independently; reject Marketing Cookies in Cookie Settings. We respect your decision.
12.10. Questions About Affiliate Relationships
Contact us through the Contact page form; expect a response within 5 business days.
12.11. Summary Checklist
- We earn commissions from referrals
- Your costs don’t increase
- We don’t receive your personal information from casinos
- Editorial independence maintained
- Ratings are methodology-based
- Sponsored content is clearly labelled
- You control tracking via Cookie Settings
- We comply with FTC, ASA, GDPR
- Your trust is our priority
13. CONTACT INFORMATION & DATA PROTECTION OFFICER
13.1. General Contact
For privacy-related questions, requests, or complaints:
Form: use the Contact page form
Response time: within 30 days
13.2. Company Information
Legal Name: Extremoo Marketing SRL
Registration Number: J23/6289/2017
Registered Address: Romania, Dobroesti, Ilfov, Mesteacanului 4
VAT Number: RO38630895
Website: https://casinoalpha.com
14. CHANGES TO THIS PRIVACY POLICY
14.1. Right to Modify
We may update this Privacy Policy periodically to reflect changes in our practices, legal or regulatory updates, new features or services, and user feedback.
14.2. How We Notify You
Material changes: email to subscribers, prominent Website notice/banner, and, where feasible, a 30-day notice period before the effective date.
Minor changes: update the Last Updated date; effective upon posting.
14.3. Your Options
If you disagree with changes, stop using the Website, delete any accounts, and request deletion of personal data (subject to legal retention). Continued use after changes means you accept the updated Policy.
14.4. Review Regularly
Please review this Privacy Policy periodically and note the Last Updated date.
15. YOUR PRIVACY RIGHTS SUMMARY
| Right | What It Means | How to Exercise |
|---|---|---|
| Access | Get a copy of your data | Contact page form / legal@casinoalpha.com |
| Rectification | Correct inaccurate data | Contact page form |
| Erasure | Request deletion | Contact page form |
| Restrict | Limit processing | Contact page form |
| Portability | Export your data | Contact page form |
| Object | Object to legitimate-interest processing | Contact page form |
| Withdraw Consent | Revoke consent | Cookie Settings or Unsubscribe |
| Complain | Contact your DPA/ICO | Links in Section 9.10 |
Response time: 30 days (extendable to 60 days for complex cases).
ACKNOWLEDGMENT
BY USING THIS WEBSITE, YOU ACKNOWLEDGE THAT:
- You have read and understood this Privacy Policy
- You agree to the collection, use, and disclosure of your personal information as described
- You consent to cookies according to your Cookie Settings
If you do not agree, please do not use the Website.
Understanding your privacy rights is important. We encourage you to:
- Learn about our company: About CasinoAlpha
- See how we use data to improve reviews: Our review methodology
- Meet our team: Casino expert authors
- Contact us with privacy questions: Contact form
- Join our privacy-conscious team: Career opportunities
- Understand our revenue model: Advertiser Disclosure
- Review our legal terms: Terms and Conditions
Why You Should Trust Us
Integrity
Objective reviews. Unbiased ratings. Transparent expert information
Player Control
Empowering gamblers in the fight against addiction: prevention & education resources
Safety
Safety-first online gambling. Casino sites with the latest encryption & security protocols
Independency
Original online casino database. Independent research. Authentic data analysis
Budgeting
Gamble risk-free: Secure fund management guidance for online casino transactions
Progress
Evolving for players: adapting our practices to meet your needs