Privacy Policy
Carlospin operates as an online gaming platform committed to protecting user information and maintaining transparent data handling practices. This privacy policy outlines how personal information is collected, processed, stored, and protected when users access the platform. Understanding these practices enables informed decisions about data sharing and account management. The platform adheres to international data protection standards and implements security measures designed to safeguard user privacy throughout the gaming experience.
Information Collection and Usage
The platform collects various categories of information necessary for account creation, service delivery, and regulatory compliance. Personal identification data includes full name, date of birth, residential address, email address, and telephone number. Financial information encompasses payment method details, transaction history, deposit amounts, and withdrawal requests. Technical data collected automatically includes IP addresses, device identifiers, browser types, operating systems, and gameplay patterns. This information serves multiple purposes including identity verification, age confirmation, fraud prevention, payment processing, customer support, and compliance with legal obligations. Location data may be collected to ensure service availability in permitted jurisdictions and to enforce geographic restrictions where applicable. Communication records, including customer support interactions and promotional correspondence, are retained for service improvement and dispute resolution purposes.
Data Processing and Legal Basis
Data processing activities occur under several legal frameworks depending on the nature and purpose of collection. Contractual necessity forms the basis for processing essential account information required to deliver gaming services and process financial transactions. Legitimate interests justify processing for fraud detection, security monitoring, service optimization, and business analytics. Legal compliance mandates data retention for anti-money laundering verification, tax reporting, and regulatory audits. Users provide explicit consent for marketing communications, promotional offers, and optional data sharing arrangements. The platform implements data minimization principles, collecting only information directly relevant to specified purposes. Processing activities undergo regular review to ensure ongoing compliance with applicable privacy regulations. Safe gaming initiatives may require processing behavioral data to identify patterns indicating problematic gambling habits and to implement appropriate player protection measures.
Data Sharing and Third-Party Access
Information sharing occurs exclusively with authorized parties necessary for platform operations and legal compliance. The following table outlines primary data sharing categories:
| Recipient Category | Data Shared | Purpose |
|---|---|---|
| Payment Processors | Financial details, transaction amounts | Process deposits and withdrawals |
| Identity Verification Services | Personal identification data | Age and identity confirmation |
| Regulatory Authorities | Account information, transaction records | Compliance reporting |
| Technical Service Providers | Device data, usage statistics | Platform maintenance and security |
| Customer Support Systems | Communication records, account details | Service delivery and issue resolution |
Third-party processors operate under contractual obligations requiring equivalent data protection standards and limiting use to specified purposes. No information is sold to marketing companies or unrelated commercial entities. Cross-border data transfers comply with appropriate safeguards including adequacy decisions, standard contractual clauses, or binding corporate rules. Users may request information about specific third parties processing their data through designated privacy contact channels. Safe gaming organizations may receive anonymized statistical data for research purposes without individual identification.
Data Security and Retention
The platform implements comprehensive security measures protecting information throughout collection, transmission, storage, and disposal phases. Technical safeguards include SSL/TLS encryption for data transmission, secure socket layers for financial transactions, encrypted database storage, regular security audits, firewall protection, intrusion detection systems, and multi-factor authentication options. Organizational measures encompass access controls limiting employee data access to role requirements, regular staff training on privacy obligations, incident response protocols, and vendor security assessments. Retention periods vary based on data categories and legal requirements. Active account information remains accessible during platform use, transaction records are retained for seven years following account closure to meet financial regulations, identity verification documents are maintained according to anti-money laundering requirements, and marketing consent records are preserved until withdrawal or regulatory limitation periods expire. Upon account closure, users may request data deletion subject to overriding legal retention obligations. Backup systems maintain data integrity while respecting deletion requests through anonymization processes.
User Rights and Controls
Users possess specific rights regarding personal information held by the platform. Access rights enable requests for copies of stored personal data and information about processing activities. Rectification rights allow correction of inaccurate or incomplete information through account settings or support requests. Erasure rights permit deletion requests subject to legal retention requirements and legitimate business needs. Restriction rights enable limitations on processing activities under specified circumstances. Data portability rights facilitate transfer of information to alternative service providers in structured, commonly used formats. Objection rights allow opposition to processing based on legitimate interests, including automated decision-making and profiling activities. Consent withdrawal terminates future processing dependent on voluntary agreement while preserving lawfulness of prior activities. Rights exercise requests are processed within applicable regulatory timeframes, typically 30 days from verified receipt. Identity verification procedures protect against unauthorized access to personal information. Privacy settings within user accounts provide direct control over communication preferences, marketing consent, and optional data sharing. Users may contact the designated privacy officer through specified channels for assistance with rights exercise or privacy concerns. Safe gaming tools include deposit limits, session time controls, self-exclusion options, and reality check features that users may activate independently to manage gambling behavior responsibly.
