RockySpin Casino Privacy Policy
Effective date: May 9, 2026
RockySpin (“we”, “us”, “our”, “RockySpin Casino”) is committed to protecting the privacy and security of the personal data of our customers and visitors. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, how we secure it, your choices and rights, and how to contact us. This Policy applies to all services offered through the RockySpin website and applications, including but not limited to casino, live-casino, sportsbook and cryptocurrency services.
Operator and regulatory details
- Operator: Terdersoft B.V., acting on behalf of RockySpin Entertainment Ltd.
- Registered address: Emancipatie Boulevard Dominico F., “Don” Martina 31, Curaçao. Registration code: 164860.
- License: Curaçao e-Gaming license number 8048/JAZ.
If you have questions about this Privacy Policy or about how we process your data, please contact our support team at support@rockyspin.com.
Scope and acceptance By using RockySpin services (including accessing our website, registering an account via /login/, installing the RockySpin app /app/ or Progressive Web App, or transacting through any payment channel), you accept the practices described in this Policy. If you do not agree, do not access or use our services.
Personal data we collect We collect and process personal data necessary to provide gambling services safely, to comply with legal obligations (including anti-money laundering and age verification), to operate our platform, and to communicate with you. Categories of data we collect include:
a) Account and identity data
- Full name, date of birth, gender
- National identification number, passport or ID scans, driver’s license
- Username, password, security questions
- Account registration data and login history
- Photographs or scans required for KYC and verification
b) Contact data
- Email address, postal address, telephone number
- Correspondence and communications with our support team
c) Financial and payment data
- Card details (as required for transactions; card numbers are tokenized or managed by our payment processors)
- Bank account details for withdrawals
- Cryptocurrency wallet addresses and blockchain transaction data
- Deposit and withdrawal history, transaction values and timestamps
d) Usage, device and technical data
- IP address, device identifiers, device and browser type, operating system and settings
- Geo-location information derived from IP address or device settings (only to the extent necessary for compliance and fraud prevention)
- Game activity (games played, bet sizes, wins/losses), time-stamped session data, game settings
- Cookies and similar tracking technologies
e) Communications and marketing preferences
- Email/SMS consent and opt-out preferences
- Support chat logs and complaint records
f) Special categories and sensitive-like processing
- We do not intentionally collect data revealing health conditions, race, or other special categories. However, when you self-declare gambling addiction or request self-exclusion, records of those requests and related notes will be processed to protect you.
Sources of data We collect data when you provide it directly (registration, KYC submission, correspondence), when you transact (deposits/withdrawals), through automated means (cookies, analytics), and from third parties necessary for compliance and service provision (payment processors, identity verification providers, public databases, responsible gambling and fraud prevention services).
Purposes and legal bases for processing We process personal data for the following primary purposes:
a) Account administration and service delivery
- To create and manage your account, process deposits and withdrawals, enable gameplay (slots, live dealer, sportsbook), deliver winnings, and provide customer support. Legal basis: performance of contract.
b) Compliance, KYC and fraud prevention
- To verify your identity and prevent money laundering, fraud, underage gambling, and other abuses. KYC documentation is required before withdrawals and in certain risk scenarios. Legal basis: compliance with legal obligations and legitimate interests (fraud prevention, financial crime mitigation).
c) Security and system integrity
- To detect and respond to security incidents, protect accounts, and maintain platform integrity. Legal basis: legitimate interests.
d) Responsible gambling and account restrictions
- To apply deposit limits, self-exclusion, cooling-off periods, and other protective measures you request or that our systems determine are necessary. Legal basis: legitimate interests and compliance with license conditions.
e) Marketing and promotions
- To send promotional offers, bonuses and news about our services if you consent or where permitted by law. You can manage preferences or opt out at any time (see Section 9). For details on promotions see /bonuses/. Legal basis: consent and legitimate interests (where permitted).
f) Analytics and service improvement
- To analyze platform usage, improve product features, detect trends, and personalize offers. Legal basis: legitimate interests and/or consent where required.
g) Regulatory reporting and legal claims
- To respond to law enforcement requests, regulatory inquiries, dispute resolution and litigation. Legal basis: legal obligations and legitimate interests.
- Cookies, tracking and analytics We use cookies and similar technologies to operate our site, improve usability, analyze traffic, and provide targeted promotions. Types of cookies we use include:
- Essential cookies: required for site functionality and secure logins.
- Performance and analytics cookies: to measure and improve site performance (e.g., aggregate usage statistics).
- Functional cookies: to remember preferences and personalization settings.
- Marketing cookies: to deliver and measure marketing and advertising content and personalization.
You may manage cookie preferences through the cookie banner at first visit, via your account settings, or by adjusting your browser settings. Blocking essential cookies may prevent you from using certain features. We may use third‑party analytics and advertising partners; these third parties may place cookies and collect information in accordance with their own policies.
- How we share your data We share personal data only as necessary and under safeguards. Categories of recipients include:
a) Service providers and partners
- Game and platform providers, live-dealer studios, payment processors, cryptocurrency custodians and blockchain services, identity verification vendors, fraud detection providers, KYC/AML screening partners, hosting and IT service providers, email/SMS delivery services, and analytics providers. These parties process data on our behalf under contracts that require confidentiality and appropriate security measures.
b) Regulators and law enforcement
- To comply with legal obligations and regulatory requests from gaming authorities, tax authorities, and law enforcement agencies. License and compliance obligations under Curaçao jurisdiction require us to share information where lawfully requested.
c) Affiliated companies and corporate transactions
- Within the RockySpin group or to potential purchasers, investors, or in connection with a corporate re-organization, merger, sale or liquidation. Recipients will be required to respect data protection standards.
d) Third parties where required by law or to protect rights
- To assert or defend legal claims, to respond to subpoenas or court orders, and to protect the safety, rights, property or security of RockySpin, our users, or the public.
We do not sell your personal data to third parties for cross-context behavioral advertising. If you are located in jurisdictions with “Do Not Sell” or similar rights, contact us at support@rockyspin.com to exercise those rights.
International transfers and safeguards Your data may be transferred to and processed in countries outside your jurisdiction, including jurisdictions that do not have the same data protection laws. We implement appropriate safeguards for international transfers, such as encryption, contractual protections, and, where applicable, Standard Contractual Clauses or equivalent measures. Cryptocurrency transactions by nature occur on public blockchains and blockchain transaction information (wallet addresses and transaction hashes) is visible on-chain.
Security of data We apply technical and organizational measures to secure personal data:
- Transport security: industry-standard encryption (256-bit SSL/TLS) for data in transit. We implement TLS 1.2 with ECDHE_RSA key exchange using X25519 and AES_128_GCM cipher suites.
- Storage security: access controls, data encryption at rest where appropriate, regular security audits and vulnerability testing, and secure backups.
- Operational controls: role-based access, staff training on data protection and responsible gambling, and incident response procedures.
No security system is invulnerable. We require you to keep your account credentials confidential, use strong passwords, and immediately notify support of suspected unauthorized access. In the event of a data breach affecting your personal data, we will act without undue delay to investigate, mitigate and notify affected persons and regulators as required by applicable laws.
- Account verification, KYC and withdrawal conditions To comply with our license, anti-money laundering rules and to protect players, we require identity and source-of-funds verification prior to withdrawals and in higher-risk scenarios. Required documents may include government identification, proof of address (utility bill or bank statement dated within the last three months), and payment method verification (photo of card or wallet details). Typical verification processing time is up to 24 hours, but can vary based on complexity.
Failure to provide requested documents may result in suspension, withdrawal restrictions, closure of account and forfeiture of bonuses or funds where permitted by law and our Terms and Conditions. For details on payment options, limits and processing timelines see our Payment Methods page (/payment-methods/).
- Retention of personal data We retain personal data only for as long as necessary to fulfill purposes set out in this Policy and to meet legal, regulatory and contractual obligations. Specific retention periods:
- Account and transactional data: retained for the period required by applicable law and gaming license obligations (minimum five (5) years after account closure), or longer if necessary for dispute resolution or legal claims.
- KYC and AML records: retained at least as required by applicable AML laws and license conditions (minimum five (5) years after account closure).
- Marketing and consent records: retained until consent is withdrawn plus any retention period required by law or business necessity.
- Aggregate, de-identified data: may be retained indefinitely for analytics and product development, provided it cannot be re-identified.
- Your rights and how to exercise them Depending on your jurisdiction, you may have rights regarding your personal data, including:
- Right of access: request a copy of personal data we hold about you.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure: request deletion of personal data where there is no lawful basis to retain it.
- Right to restriction of processing: ask us to limit processing in certain circumstances.
- Right to data portability: receive a copy of your data in a structured, commonly used format.
- Right to object: object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: withdraw consent for processing that relied on consent.
To exercise any of these rights, please contact us at support@rockyspin.com. We will verify your identity before acting on requests. Where permitted by law, we may refuse or limit requests that are manifestly unfounded, excessive or where we are legally required to retain data (for example for AML obligations or to preserve evidence in disputes).
If you are a resident of the European Economic Area and you believe your rights under applicable law (including GDPR, where applicable) have been violated, you also have the right to lodge a complaint with your local data protection authority or the Curaçao regulator in relation to our licensed operations.
- Direct marketing and communication preferences We may contact you with service messages (e.g., account or safety notices) regardless of marketing preferences. For promotional communications (email, SMS, push notifications), we will rely on your consent or legitimate interest where allowed by law. You may opt out of marketing at any time by:
- Clicking the unsubscribe link in marketing emails.
- Changing your preferences in your account settings.
- Contacting support@rockyspin.com with your request.
Please note that even if you opt out of marketing, you will still receive transactional messages related to account management, security, or legal notices.
Third‑party content and links Our website and services may contain links, widgets or content from third-party websites (including game providers, social platforms and advertising partners). This Privacy Policy does not apply to third parties and we are not responsible for their practices. We recommend you review the privacy policies of third parties before providing personal data or using their services.
Children and age restrictions You must be at least 18 years old (or the minimum legal age in your jurisdiction, whichever is higher) to register and play. We do not knowingly collect personal data from minors. If we learn that we have collected personal data from an individual under the legal gambling age, we will delete such data and close the account in accordance with legal obligations.
Cryptocurrency transactions If you use cryptocurrency services via /crypto-casino/, you should be aware that blockchain transactions are public on the applicable ledger and that transaction hashes and wallet addresses may be recorded as part of our records. Cryptocurrency deposits and withdrawals may be subject to blockchain network fees (these fees are not charged by RockySpin). We retain associated transaction records to meet AML and regulatory obligations.
Changes to this Privacy Policy We may update this Policy from time to time to reflect changes in our processing activities, regulatory requirements, or business practices. When changes are material, we will post a prominent notice and a new effective date. Continued use of our services after the effective date constitutes acceptance of the updated Policy.
Contact, complaints and supervisory authority For questions about this Policy, to exercise rights or to make a privacy complaint, contact:
RockySpin Support Email: support@rockyspin.com Postal address: Emancipatie Boulevard Dominico F., “Don” Martina 31, Curaçao
Regulatory / licensing complaints regarding our licensed operations may be directed to the Curaçao Gaming regulator in accordance with applicable procedures. You may also lodge complaints with your local data protection authority if you believe we have not properly handled your personal data.
- Additional resources and internal pages
- To access your account, manage settings or review security recommendations, use /login/ or /app/.
- For information on bonuses, promotional terms and how we use marketing data, visit /bonuses/.
- For details about cryptocurrency services and crypto-specific terms, see /crypto-casino/.
- For live dealer game operations and streaming information, see /live-casino/.
- For payment options, limits, processing times and methods, consult /payment-methods/.
- For sportsbook betting features and related processing, see /sportsbook/.
- Final statement RockySpin is committed to protecting your privacy and processing your personal data lawfully, fairly and transparently. Our practices are designed to support secure gameplay, regulatory compliance, and the responsible provision of gambling services. If you have any questions or need assistance concerning your personal data, please contact support@rockyspin.com.