Privacy at a Glance
Fake Casino is a free-to-play entertainment platform that does not process real money, financial data, or payment information of any kind. We collect minimal data necessary to operate the Platform (account info, gameplay data, technical logs). We do not sell your personal data. We do not use your data for targeted advertising. We do not share your data with data brokers. This policy explains exactly what we collect, why, and how you can control it.
1Introduction
Fake Casino ("we," "us," "our") is committed to protecting and respecting your privacy. This Privacy Policy ("Policy") describes how we collect, use, store, share, and protect your personal information when you access or use the Fake Casino website, applications, and services (collectively, the "Platform").
This Policy applies to all Users of the Platform, regardless of how they access it (web browser, mobile device, API, or any other means). By accessing or using the Platform, you consent to the collection, use, and disclosure of your information as described in this Policy. If you do not agree with this Policy, please do not use the Platform.
This Policy should be read in conjunction with our Terms of Service. Capitalized terms not defined in this Policy have the meanings given to them in the Terms of Service.
We may update this Policy from time to time. Please review it periodically. Your continued use of the Platform after any changes to this Policy constitutes your acceptance of such changes.
2Information We Collect
2.1 Information You Provide Directly
When you create an Account or use certain features of the Platform, you may provide us with the following information:
| Data Type | Details | Purpose |
|---|---|---|
| Account credentials | Username, email address, password (hashed) | Account creation and authentication |
| Profile information | Avatar image, banner image, bio text | Profile customization and display |
| Communications | Support requests, feedback, bug reports | Customer support and platform improvement |
We do NOT collect: real names (unless voluntarily provided in bio), physical addresses, phone numbers, government-issued IDs, Social Security numbers, financial information, payment card details, bank account information, or any other financial data. The Platform does not process any real-money transactions and therefore has no need for financial data of any kind.
2.2 Information Collected Automatically
When you access or use the Platform, we automatically collect certain technical and usage information:
| Data Type | Details | Purpose |
|---|---|---|
| IP address | Your Internet Protocol address at time of registration and access | Fraud prevention, abuse detection, multi-account prevention, security |
| Device information | Browser type, operating system, screen resolution, device type | Platform optimization, debugging, responsive design |
| Usage data | Pages visited, features used, time spent, click patterns | Analytics, platform improvement, feature prioritization |
| Game data | Bet history, game outcomes, wager amounts (Virtual Currency), win/loss records | Gameplay functionality, leaderboards, achievements, fraud detection |
| Authentication tokens | JSON Web Tokens (JWT) for session management | Secure session management, authentication |
| Log data | Server logs including request timestamps, endpoints accessed, response codes | Debugging, security monitoring, performance optimization |
2.3 Information from Third Parties
We do not currently purchase or otherwise obtain personal information from third-party data brokers, social media platforms, or other external sources. If this changes in the future, we will update this Policy accordingly.
2.4 Sensitive Personal Information
We do NOT knowingly collect or process any sensitive personal information, including but not limited to: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation data, criminal conviction data, or financial account information.
3How We Use Your Information
We use the information we collect for the following purposes:
3.1 Platform Operations
To create and manage your Account; to authenticate your identity and maintain session security; to process gameplay actions, calculate game outcomes, and maintain Virtual Currency balances; to operate leaderboards, achievement systems, lottery features, and other Platform functionality; to maintain and display your user profile and game statistics.
3.2 Security and Fraud Prevention
To detect, prevent, and address fraud, abuse, and violations of our Terms of Service; to enforce our one-account-per-person policy; to identify and block malicious automated access (bots, scrapers); to monitor for exploitation of bugs or vulnerabilities; to protect the security and integrity of the Platform and its Users.
3.3 Communication
To send you transactional emails, including email verification, password reset confirmations, and Account-related notifications; to respond to your inquiries, support requests, and feedback; to send you important notices about changes to the Platform, Terms, or this Policy. We will NOT send you marketing emails or promotional communications unless you have explicitly opted in to receive them.
3.4 Analytics and Improvement
To analyze usage patterns and trends to improve the Platform; to identify and fix bugs, errors, and performance issues; to develop new features and functionality; to understand how Users interact with the Platform to improve user experience.
3.5 Legal Compliance
To comply with applicable laws, regulations, legal processes, or government requests; to enforce our Terms of Service and other policies; to protect our rights, property, or safety, and the rights, property, or safety of our Users or others; to respond to lawful requests from law enforcement or other government authorities.
3.6 What We Do NOT Use Your Information For
We do NOT use your personal information for: targeted advertising or behavioral advertising; selling or renting your data to third parties; building advertising profiles; credit scoring or financial assessments; employment screening or background checks; automated decision-making that produces legal or similarly significant effects; political profiling or targeting; or any purpose unrelated to the operation and improvement of the Platform.
4Legal Basis for Processing
If you are located in the European Economic Area (EEA), United Kingdom (UK), or another jurisdiction that requires a legal basis for processing personal data, we rely on the following legal bases:
| Legal Basis | Processing Activities |
|---|---|
| Contractual necessity | Account creation, authentication, gameplay operations, Virtual Currency management, profile functionality — all necessary to provide the Services you requested |
| Legitimate interests | Fraud prevention, security monitoring, abuse detection, analytics, platform improvement, bug fixing — our legitimate interest in operating a secure and functional Platform |
| Consent | Email communications beyond transactional notices, cookies (where required by law), optional profile information — you may withdraw consent at any time |
| Legal obligation | Compliance with applicable laws, responding to lawful government requests, preserving data for legal proceedings |
Where we rely on legitimate interests, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms, particularly given that the Platform is a free entertainment service that does not involve real money or sensitive financial data.
7Data Retention
7.1 Retention Periods
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected and to comply with our legal obligations:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data | Duration of Account existence + 30 days after deletion request | Contractual necessity, fraud prevention |
| Game history / bet records | Duration of Account existence | Platform functionality, leaderboards, achievements |
| Server logs | 90 days | Security, debugging, abuse prevention |
| IP addresses (registration) | Duration of Account existence | Fraud/multi-account prevention |
| Email communications | Duration of Account existence or resolution of inquiry | Support, legal compliance |
| Uploaded images (avatars, banners) | Until replaced or Account deleted | Profile functionality |
7.2 Deletion
When your data is no longer needed for the purposes described in this Policy, or when you request deletion of your Account, we will securely delete or anonymize your personal information within a reasonable timeframe (typically within 30 days), except where retention is required by law or for the establishment, exercise, or defense of legal claims.
7.3 Backup Systems
Your data may persist in encrypted backup systems for a limited additional period after deletion from primary systems. We will ensure that data in backups is not actively used and will be permanently deleted when the backup rotation cycle completes.
8Data Security
8.1 Security Measures
We implement and maintain commercially reasonable technical and organizational security measures designed to protect your personal information from unauthorized access, use, disclosure, alteration, or destruction. These measures include but are not limited to:
Encryption of data in transit using TLS/SSL protocols; encryption of data at rest in our databases; secure password hashing using industry-standard algorithms (bcrypt); token-based authentication with expiring JSON Web Tokens; input validation and parameterized queries to prevent injection attacks; regular security assessments and updates; access controls limiting employee and contractor access to personal data on a need-to-know basis; secure cloud infrastructure with managed security services.
8.2 No Absolute Security
While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee the absolute security of your information. You acknowledge and accept this inherent risk when using the Platform. In the event of a security breach, we will take appropriate remedial action and notify affected Users and authorities as required by applicable law.
8.3 Your Security Responsibilities
You are responsible for maintaining the security of your Account credentials (username and password), using a strong, unique password, not sharing your Account credentials with anyone, logging out of shared or public devices, and promptly reporting any suspected unauthorized access to your Account.
9Your Rights and Choices
Depending on your jurisdiction, you may have some or all of the following rights regarding your personal information:
9.1 Access
You have the right to request confirmation of whether we process your personal data and to access a copy of the personal data we hold about you. Much of this data is already available directly through your Account (profile, game history, achievements, statistics).
9.2 Correction
You have the right to request correction of inaccurate or incomplete personal data. You can update your profile information (username, bio, avatar, banner) directly through the Platform. For other data corrections, please contact us.
9.3 Deletion
You have the right to request deletion of your personal data ("right to be forgotten"), subject to certain exceptions (legal obligations, defense of legal claims, etc.). Upon Account deletion, we will delete or anonymize all personal data associated with your Account within 30 days.
9.4 Data Portability
You have the right to request a copy of your personal data in a structured, commonly used, and machine-readable format (such as JSON or CSV).
9.5 Restriction of Processing
You have the right to request restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when the processing is unlawful.
9.6 Objection
Where we process your personal data based on legitimate interests, you have the right to object to such processing. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
9.7 Withdrawal of Consent
Where we process your personal data based on your consent, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
9.8 Exercising Your Rights
To exercise any of these rights, please contact us using the information provided in Section 21. We will respond to your request within 30 days (or such shorter period as required by applicable law). We may need to verify your identity before processing your request. We will not discriminate against you for exercising any of your privacy rights.
10Children's Privacy
10.1 Age Restrictions
The Platform is not intended for children under the age of thirteen (13). We do not knowingly collect, store, or process personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will promptly delete such information from our servers and terminate the associated Account.
10.2 Parental Rights
If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us immediately so we can take appropriate action to remove such information.
10.3 Teen Users (13-17)
Users between 13 and 18 (or the age of majority in their jurisdiction) may use the Platform with parental consent and supervision. Parents or guardians of teen users should review this Policy and supervise their teen's use of the Platform. We encourage parents and guardians to instruct their children to never provide personal information on the Platform without permission.
10.4 COPPA Compliance
We comply with the Children's Online Privacy Protection Act (COPPA) and similar laws in other jurisdictions. We do not knowingly collect personal information from children in violation of these laws.
11International Data Transfers
The Platform may be operated from servers located in various countries. If you access the Platform from outside the country where our servers are located, your information may be transferred to, stored, and processed in a country other than your country of residence. By using the Platform, you consent to the transfer of your information to countries which may have different data protection laws than your country.
Where required by applicable law (such as the GDPR), we ensure that appropriate safeguards are in place for international transfers of personal data, including Standard Contractual Clauses (SCCs), adequacy decisions, or other legally recognized transfer mechanisms. Our cloud infrastructure providers (DigitalOcean, Cloudflare) maintain compliance certifications and data processing agreements that include appropriate transfer safeguards.
12California Privacy Rights (CCPA/CPRA)
12.1 Applicability
If you are a California resident, you may have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA/CPRA"). This section applies only to California residents and supplements the information contained in the rest of this Policy.
12.2 Categories of Personal Information
In the preceding twelve (12) months, we have collected the following categories of personal information: Identifiers (username, email address, IP address); Internet or electronic network activity (browsing history within the Platform, gameplay data, interaction history); and other information that you voluntarily provide (profile information, uploaded images).
12.3 Your California Rights
As a California resident, you have the right to: know what personal information we collect, use, disclose, and sell; request deletion of your personal information; opt out of the "sale" or "sharing" of your personal information (note: we do NOT sell or share personal information as defined under CCPA/CPRA); not be discriminated against for exercising your privacy rights; and correct inaccurate personal information.
12.4 'Do Not Sell or Share My Personal Information'
We do NOT sell your personal information. We do NOT share your personal information for cross-context behavioral advertising. Therefore, there is no need to opt out of the sale or sharing of personal information. However, if California law changes or if our practices change in the future, we will update this Policy and provide an opt-out mechanism as required.
12.5 Sensitive Personal Information
We do NOT collect or process sensitive personal information as defined under CCPA/CPRA, including Social Security numbers, driver's license numbers, financial account information, precise geolocation, racial or ethnic origin, religious beliefs, biometric information, health information, or sex life/sexual orientation information.
12.6 Authorized Agent
You may designate an authorized agent to make a request on your behalf. To verify an authorized agent, we may require a signed authorization letter or power of attorney, and we may directly confirm with you that you authorized the agent to act on your behalf.
12.7 Financial Incentives
We do not offer any financial incentives or price or service differences in exchange for the retention or sale of personal information.
13European Privacy Rights (GDPR)
13.1 Applicability
If you are located in the European Economic Area (EEA), the General Data Protection Regulation (GDPR) provides you with specific rights regarding your personal data. This section supplements the information in the rest of this Policy.
13.2 Data Controller
For the purposes of the GDPR, Fake Casino is the data controller of your personal data processed through the Platform. As data controller, we determine the purposes and means of processing your personal data.
13.3 Your GDPR Rights
In addition to the general rights described in Section 9, EEA residents have the right to: lodge a complaint with a supervisory authority (your local Data Protection Authority) if you believe our processing of your personal data violates the GDPR; request restriction of processing in specific circumstances; object to processing based on legitimate interests; receive your personal data in a portable format; and not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
13.4 Data Protection Officer
Given the nature and scale of our data processing activities (minimal personal data, no sensitive data, no real-money transactions), we have not appointed a formal Data Protection Officer. However, all privacy inquiries can be directed to the contact information in Section 21, and we will respond within the timeframes required by the GDPR (typically 30 days).
13.5 Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) when required by the GDPR, particularly when introducing new processing activities that may result in a high risk to individuals' rights and freedoms.
14UK Privacy Rights (UK GDPR)
If you are located in the United Kingdom, the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 provide you with substantially similar rights to those described in Section 13 (GDPR). References to "supervisory authority" in this Policy shall be understood to include the UK Information Commissioner's Office (ICO). We process personal data of UK residents in accordance with UK GDPR requirements, and applicable transfer mechanisms are in place for any international data transfers from the UK.
15Other Jurisdictional Rights
15.1 Australia
If you are located in Australia, you have rights under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You may request access to and correction of your personal information. If you believe we have breached the APPs, you may file a complaint with the Office of the Australian Information Commissioner (OAIC).
15.2 Canada
If you are located in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws provide you with rights regarding your personal information, including access, correction, and complaint rights. You may file a complaint with the Office of the Privacy Commissioner of Canada.
15.3 Brazil
If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) provides you with rights regarding your personal data, including access, correction, anonymization, deletion, portability, and objection rights. You may file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
15.4 Other Jurisdictions
If you are located in any other jurisdiction with applicable data protection laws, we will comply with such laws to the extent they apply to our processing of your personal data. Please contact us if you have questions about your specific rights under your local laws.
16Do Not Track Signals
Some web browsers have a "Do Not Track" (DNT) feature that sends a signal to websites you visit, requesting that they not track your online activity. Because there is no universally accepted standard for how to respond to DNT signals, the Platform does not currently respond to DNT signals. However, as described in this Policy, we do not engage in cross-site tracking or targeted advertising, so the practical effect is equivalent to honoring a DNT request. If a universal standard for DNT is adopted in the future, we will review and update our practices accordingly.
17Third-Party Links and Services
The Platform may contain links to third-party websites, services, or resources (including community channels on Discord, Reddit, and other platforms). This Privacy Policy applies only to the Platform and does not extend to any third-party websites or services. We have no control over, and assume no responsibility for, the privacy practices of any third-party websites or services. We encourage you to read the privacy policies of every website and service you use. The inclusion of any link does not imply endorsement by Fake Casino of the linked website or service.
18Automated Decision-Making
The Platform uses automated systems for certain operational purposes, including: random number generation for game outcomes (which determines Virtual Currency gains or losses); automated fraud detection algorithms that may flag or restrict suspicious Account activity; automated systems for enforcing rate limits and preventing abuse. These automated processes do not make decisions that produce legal or similarly significant effects concerning you, as the Platform deals exclusively in Virtual Currency with no real-world value. If you believe an automated decision has been made in error (such as an incorrect fraud flag), you may contact us to request human review.
19Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by applicable law (GDPR, UK GDPR, etc.); notify affected Users without undue delay where the breach is likely to result in a high risk to their rights and freedoms; document the breach, its effects, and the remedial actions taken; and take all reasonable steps to mitigate the impact of the breach and prevent recurrence. We maintain an incident response plan and regularly review and update our security practices to minimize the risk of data breaches.
20Changes to This Privacy Policy
We reserve the right to update, modify, or replace this Privacy Policy at any time at our sole discretion. Changes will be effective immediately upon posting the revised Policy on the Platform with a new "Last Updated" date. For material changes that significantly affect how we process your personal data, we will endeavor to provide you with advance notice through a prominent notice on the Platform or via email (if we have your email address). Your continued use of the Platform after any changes to this Policy constitutes your acceptance of and agreement to the revised Policy. We encourage you to review this Policy periodically to stay informed about how we protect your information.
21Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, your personal data, or our privacy practices, please contact us through the official channels listed on the Platform. We take all privacy inquiries seriously and aim to respond within 30 days (or such shorter period as required by applicable law in your jurisdiction).
If you are not satisfied with our response, you have the right to lodge a complaint with the appropriate data protection supervisory authority in your jurisdiction. For EEA residents, a list of supervisory authorities is available at the European Data Protection Board website. For UK residents, complaints may be directed to the Information Commissioner's Office (ICO).
By using the Platform, you acknowledge that you have read, understood, and agree to the collection and use of your information as described in this Privacy Policy. If you do not agree with any part of this Policy, please do not use the Platform.