This document describes how the StawkiBet platform collects, uses, stores and protects players' personal data. The operator follows the standards of the EU General Data Protection Regulation (GDPR) and Curaçao law on personal-data processing. By using the service, the player agrees with all provisions of this Policy and allows the processing of the stated data categories to the extent needed for the platform to work. The operator does not pass personal data to third parties for marketing without the player's separate consent.
Scope of data that may be collected
StawkiBet collects data of three main categories: identification, device technical characteristics and financial transaction details. The scope is limited to the minimum needed to run the online casino and bookmaker, pass verification and meet anti-money-laundering requirements. A player may decline certain categories, but this may limit access to some features — for example, deposits or withdrawing winnings.
Identification data
At registration on StawkiBet the following are collected: first and last name as in documents, date of birth to confirm adulthood, gender (optional), email as the main communication channel and a mobile number in international format for SMS verification. During KYC the document number (passport, ID card), the address of permanent or temporary residence, citizenship and country of tax residence are additionally recorded. Document copies are kept encrypted on secure servers with access only for security and compliance staff.
Device technical data
On each visit the following are collected automatically: IP address — to determine location and block access from prohibited jurisdictions, the type and version of the browser (Chrome, Firefox, Safari) for correct content display, the operating system (Windows, macOS, iOS, Android), screen resolution for interface adaptation, and the browser's language settings. Cookies and local storage keep authorisation sessions, settings and the history of viewed games. A device fingerprint is formed from hardware characteristics to detect multi-accounting and fraud.
Financial and transaction data
For deposits, the following are recorded: payment method (Visa, Mastercard, Bitcoin), the last 4 card digits or the crypto-wallet address, the amount and currency, the date and time of the operation, and the provider's unique payment identifier. Full card details are not stored on the casino's servers — processing goes through PCI DSS-certified gateways with tokenisation. Bet history includes the game name, bet size, round outcome, win or loss and the session RTP, so the player can analyse their own activity.
Account activity data
The platform keeps a log of actions in the personal account: login and logout times, profile-setting changes, activated bonuses and promo codes, participation in tournaments and promotions. Game-session history is kept for 5 years under the licence requirements — for resolving disputed situations. Correspondence with support in chat, by email or in Telegram is archived for quality control and conflict resolution. These records may serve as evidence when reviewing complaints via the licensing body or arbitration.
Purpose of collecting personal information
Data is processed only to the extent needed to run the online casino and bookmaker, comply with the law and protect the interests of both the platform and players. The operator does not use data for purposes outside running the service without separate consent. Personalisation of content and recommendations is based on analysing gaming preferences — with the option to opt out in the privacy settings of the personal account.
Identity confirmation and security
The KYC procedure (Know Your Customer) is a mandatory Curacao eGaming licence requirement against money laundering, terrorism financing and fraud. Document checks confirm that the account belongs to a real person aged 18+ who has the right to play under the laws of their country of residence. Matching data from different sources (documents, details, IP addresses) reveals attempts to create multi-accounts to abuse bonuses. Document photos are kept encrypted with access only for authorised security and compliance staff.
Payment processing
Financial data is needed to top up the account and withdraw winnings through integrated payment systems. It is passed to third-party providers (Visa, Mastercard, crypto exchanges) via secure APIs with TLS 1.3 encryption to authorise operations. Transaction history is kept for 7 years under Curaçao tax law and international AML (Anti-Money Laundering) standards. Automatic monitoring analyses deposit and withdrawal patterns to detect structuring of operations (splitting large amounts to bypass verification).
Personalising the service
Analysing preferences helps recommend slots and table games based on previously launched positions and time spent in different catalogue categories. Promotions and bonuses may be targeted by activity level, average bet size and chosen providers. Interface settings (language, currency, favourite games) sync across devices via cloud profile storage. The player may turn off personal recommendations in the privacy settings without losing access to the main functionality.
Meeting legal requirements
The Curacao eGaming regulator requires keeping detailed records of all rounds, financial operations and communications for at least 5 years — for audits and complaint reviews. Curaçao tax authorities may request reports on the volumes of paid winnings to check the operator's tax compliance. Law enforcement gets access to data only under an official court order or a request within international legal assistance. The platform must report suspicious transactions to the Financial Intelligence Unit (FIU) of Curaçao as required by anti-money-laundering rules.
Order of storing and protecting information
Personal data is stored on secure servers in Tier III data centres with multi-layer security, backup power and round-the-clock guarding. Access to the databases is limited to authorised staff using multi-factor authentication and logging of all actions for audit. Backups are made daily, copies are encrypted with AES-256 and kept on geographically distributed servers to protect against data loss due to disasters or cyberattacks.
Encryption methods and secure protocols
Data exchange between the player's browser and StawkiBet servers is protected by HTTPS with an SSL certificate of TLS 1.3 and a 256-bit key. Passwords are stored hashed using the bcrypt algorithm with an individual salt — even administrators have no access to the original passwords. Financial data is tokenised when passed to providers: instead of card details, unique identifiers are transmitted with no way to decode them back. Two-factor authentication via Google Authenticator or SMS codes adds another layer of protection even if the password is compromised.
Data retention period
Identification data and KYC documents are kept for 7 years from the last activity — under the Curacao eGaming licence and tax law. The history of rounds and financial operations is archived for 5 years to resolve disputed situations and for regulator audits. Cookies and session data are deleted automatically after 30 days of inactivity or when the player manually clears the browser cache. After account closure at the player's initiative, personal data is deleted within 90 days, except data that must be kept by law (KYC documents, transaction history).
Physical and digital security measures
Data centres are equipped with biometric access control, 24/7 video surveillance and metal detectors at entrances to protect against physical intrusion. Servers stand in secure racks with separate locks and unauthorised-opening alarms. Network security is provided by multi-layer firewalls, intrusion detection and prevention systems (IDS/IPS) and DDoS protection with malicious-traffic filtering. External cybersecurity companies regularly run pentests and vulnerability audits to find and close weak spots in time.
Data transfer to third parties
The operator does not sell, rent out or pass personal data to third parties for marketing without separate written consent. Transfer is possible only in the cases provided by this Policy and needed for the platform to work: to payment providers — for processing transactions, to game-software providers — for launching slots and live casino, to regulators — for meeting licence requirements. All data recipients must follow confidentiality standards no lower than this Policy and use the information only to provide the specific services.
Payment providers
Deposits and withdrawals are processed through PCI DSS-certified gateways Visa, Mastercard, Skrill, Neteller, Coinbase, which receive the minimum data to authorise operations. Full card details are not stored on the casino's servers — instead, tokenisation is used with a unique identifier for each payment method. Cryptocurrency transactions go through the blockchain without passing personal data to third parties thanks to address pseudonymity. Providers may request additional documents for their own KYC procedures under their regulatory requirements.
Licensing bodies and regulators
Gaming Services Provider N.V. as the Curaçao regulator has the right to request full access to personal data, bet history and financial operations for licence-compliance audits. Curaçao tax authorities receive aggregated reports on the volumes of paid winnings without detail at the individual-player level, except in cases of official tax-evasion investigations. The Financial Intelligence Unit (FIU) receives notifications of suspicious transactions with the player's data if the automation detects signs of payment structuring or other illegal schemes.
Partners providing technical infrastructure
Hosting providers (AWS, Google Cloud) provide server infrastructure with limited access to encrypted databases and no ability to read the content. CDN services (Cloudflare) cache static content to speed up loading and filter DDoS attacks without access to personal data. Email providers (SendGrid, Amazon SES) handle transactional emails with confirmations of registration, deposits and withdrawals, encrypting the transmission channels. Analytics platforms (Google Analytics) collect anonymised data on traffic, traffic sources and behaviour without linking it to personal identifiers.
Cookies and analytics tools
StawkiBet uses cookies for authorisation sessions, interface settings, the history of viewed games and analytics of behaviour on the site. Files are divided into those necessary for operation, functional for convenience and analytical for attendance statistics. The player manages permissions through browser settings or the consent banner on the first visit. Blocking necessary cookies may limit functionality — for example, make authorisation or saving settings between sessions impossible.
Functional cookies
Session files hold the authorisation token for automatic login without re-entering the username and password for the "Remember me" period. Interface settings (language, currency, theme) are kept in the browser's local storage and synced between visits. The list of favourite games and recently launched slots is cached for quick access. These cookies are critical for comfortable operation and cannot be disabled without losing basic functionality.
Analytics cookies
Google Analytics tracks anonymised data on page attendance, session duration and traffic sources (organic, ads, referrals) to optimise marketing and grow conversion. Heatmap tools (Hotjar) record cursor movements, clicks and scrolls to analyse UX/UI and find problem elements. A/B testing distributes players between page versions to find the most effective solutions. All analytics data is aggregated without linking to a person and kept for 26 months under the Google Analytics policy.
Managing cookie permissions
The consent banner on the first visit lets you choose categories: only necessary, functional, analytical or all at once. Settings can be changed at any time via the "Cookies" section in the footer or the browser menu. Fully blocking cookies in the browser will make authorisation impossible, reset interface settings and limit account functionality. We recommend keeping at least the necessary and functional files, optionally disabling only analytics.
Users' rights regarding data
Under GDPR, players have the right to access their data, correct it, delete it or restrict processing. Requests are handled within 30 days of a written request to [email protected] with identity confirmation via KYC documents. The operator may refuse to delete data that must be kept by law (verification documents, transaction history for 7 years). The right to data portability lets you get a copy of your information in a structured machine-readable format (CSV, JSON) to pass to another service.
Access to personal information
A player may request a full report on the collected data by writing to [email protected] with the account email and name. Within 30 days the operator sends an archive with copies of KYC documents, transaction history, session records and correspondence with support in PDF or CSV format. The report includes the categories of collected data, the purposes of their use, the list of third parties and retention periods. One request per year is handled free — additional ones may be charged based on processing costs (up to 50 EUR).
Correcting and updating information
Basic data (email, phone, address) can be changed independently in the "Profile" section with confirmation via SMS code or an email link. First name, last name and date of birth cannot be edited after KYC — a change is possible only via support with documents confirming the reason (surname change after marriage, correcting an error). Payment methods are updated by adding a new card or wallet; old details are deactivated automatically after 90 days of inactivity.
Deletion and restriction of processing
A request to delete the account and data is submitted to [email protected] with identity confirmation via KYC documents. The account is deactivated within 72 hours — login is blocked, data processing stops. Full deletion happens 90 days after the request, except data that must be kept by law (transaction history, verification documents — 7 years). Restriction of processing can be requested to temporarily freeze data use without deleting the account — via support, stating the reason and period.
Limitation of liability regarding data processing
The operator makes maximum efforts to protect data through encryption, multi-factor authentication and regular audits, but cannot guarantee absolute protection against external cyberattacks or hacking via third-party vulnerabilities. The platform is not liable for the compromise of credentials through phishing, keyloggers on the player's device or the player disclosing the password themselves. We recommend using unique complex passwords, enabling two-factor authentication and not following links from suspicious emails posing as official casino messages.
Terms of updating the Privacy Policy
The operator may change this Policy — to meet new regulator requirements, strengthen data protection or connect new services. Players are notified of material changes at least 14 days before they take effect, with a brief description of the updates. The updated version is published on the official site with the date of the last edit at the top of the document. Continued use of the platform after that means automatic acceptance of the new data-processing terms. If you disagree, you may close the account and request data deletion within 30 days.
Contact information for requests
Questions about personal-data processing, access requests and complaints about privacy breaches are sent to [email protected] — a reply usually within 30 days. For urgent account-security matters (suspected hacking, unauthorised access) write to the 24/7 support chat or to [email protected] — handled within 24 hours. Official requests from regulators or law-enforcement bodies are sent to [email protected] with mandatory details of the organisation and the legal grounds for access to the data.