What personal data spinsamuraii.net collects, why it is collected, how long it is kept, who it is shared with, and the rights you hold over it. Set out clearly, without boilerplate that obscures more than it explains.
spinsamuraii.net is an independent online casino review platform operated from Sydney, Australia. We are not a casino. No gambling services are operated here, and we accept no deposits, process no withdrawals and hold no player accounts. The scope of data processing here is correspondingly narrow - we're an informational publisher, and our privacy obligations track that.
The casino reviewed here, Spin Samurai casino, is a separate legal entity run by a third party holding a Curaçao Gaming Authority (CGA) licence. Its privacy practices are governed by its own policy, published on the casino site.
When you reach us by email, we receive:
When you visit any page on this site, our hosting infrastructure and analytics tools automatically collect:
We do not collect real names, home addresses, phone numbers, financial details or government identifiers through any automatic means, and we do not knowingly collect data from anyone under 18.
| Purpose | Data used | Legal basis (where GDPR applies) |
|---|---|---|
| Responding to your enquiry | Contact form data, email | Legitimate interest / consent |
| Site analytics (aggregate traffic trends) | Anonymised IP, pages viewed, device type | Legitimate interest |
| Affiliate attribution (tracking referrals) | Click identifier passed to operator | Legitimate interest |
| Security and abuse prevention | IP address, user-agent, request patterns | Legitimate interest |
| Compliance with legal obligations | Server logs | Legal obligation |
We do not use data to build advertising profiles, run no remarketing campaigns and do not sell, rent or trade personal data to third parties for marketing or commercial purposes.
A small number of processors are used to operate the site. Each has its own privacy policy covering the specific processing they perform:
Where processors transfer data internationally, we rely on their published standard contractual clauses and adequacy mechanisms. A full list of sub-processors for each third party is on their respective documentation.
| Category | Retention period |
|---|---|
| Contact-form submissions and email correspondence | 12 months after last interaction, unless longer is needed to resolve an ongoing matter |
| Server access logs (full IP) | 90 days |
| Aggregated analytics (GA4, no PII) | Up to 26 months per GA4 default retention |
| Affiliate click events | Per the affiliate network's policy, typically up to 24 months |
| Editorial records required by correction policy | Retained as long as the corresponding article is live, for audit of the correction log |
When a retention period ends, the data is deleted or anonymised. Backups rotate on a shorter cycle and lapse on their own schedule.
As an Australian resident, you have the right to:
If you are a resident of the EU or UK, you additionally have rights to data portability, restriction of processing, objection to processing and the right to erasure, subject to applicable conditions.
Email [email protected] with "Privacy" in the subject line. Responses are provided within 30 days. Identity will be verified before personal data is disclosed. The process is documented on the contact page.
Exercising your rights costs nothing. Where a request is plainly unfounded or excessive - repeated requests for the same data, for instance - we may charge a reasonable fee or decline to act, as far as the law allows.
Cookies and similar technologies are used for analytics, security and basic site function. A full cookie list, purposes, retention periods and management instructions are on the cookie policy page. You can block or clear non-essential cookies at any time from your browser settings.
Our main processors (Cloudflare, Google Analytics) run global infrastructure, which means personal data may be transferred to, or reached from, jurisdictions outside Australia - usually the United States and Europe. Those transfers are covered by the processors' standard contractual clauses and adequacy mechanisms, as set out in their own privacy policies.
Where you have a legal right to object to international transfer, you can exercise it by emailing the privacy address above. In practice, objecting typically means asking us to delete the data rather than restrict its location.
The site runs over TLS 1.2+ with modern cipher suites, and the admin side of the hosting uses two-factor authentication. Contact-form submissions and email correspondence live in a mailbox protected by provider-side encryption and 2FA. Within the small team, access to personal data is held to whoever needs it for the task at hand.
No online system is perfectly secure. Should a breach affect your personal information, we'll notify those affected and the OAIC under the Notifiable Data Breaches scheme in Australian law, alongside any equivalent GDPR obligations where they apply.
This site, the review, and all casinos discussed on it are for adults aged 18 or over. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has submitted information to this site, please email info and we will delete the submission. Our broader position on minors and gambling is on the responsible gambling page.
We update this policy when our practices change - say, when we add or drop a processor, revise retention periods, or respond to a shift in legal obligations. A material change updates the "last updated" date at the top, and for significant changes we post a short notice at the top of both the homepage and the policy page for at least 30 days after.
Historic versions of this policy are available on request via the contact page.