SpinEmpire processes personal data in accordance with the EU General Data Protection Regulation (GDPR), which applies in full to players in Ireland. This policy explains what is collected, why, who it is shared with, how long it is kept and the rights you can exercise at any time.
Three categories of data are processed. Account data: the email address, name, date of birth and password hash you provide at registration, plus your chosen currency. Transaction data: deposits, withdrawals, payment method details and gameplay records. Technical data: IP address, device and browser information, and cookie identifiers generated as you use the site.
Verification adds a fourth category once: the identity documents submitted during KYC.
Each purpose rests on a legal basis under GDPR. Operating your account and paying out winnings is performance of a contract. Age verification, KYC and anti-fraud checks are legal obligations attached to the operator's licence from the Gaming Commission of Ireland. Security monitoring and service improvement rely on legitimate interest. Any marketing communications rest on consent, which can be withdrawn as easily as it was given.
Data is not processed for purposes beyond these.
Cookies keep you logged in, remember preferences and help the operator understand how the site is used. Essential cookies are required for the platform to function — sessions and security depend on them. Analytics cookies are optional and can be managed through your browser settings. Blocking essential cookies will prevent login from working.
Data is shared only where the service requires it. Payment providers receive the details needed to process your deposits and withdrawals. KYC verification partners receive identity documents for the one-time verification check. Regulatory authorities may receive data where the operator is legally obliged to provide it.
Personal data is not sold. Third parties processing data on the operator's behalf are bound by data processing agreements consistent with GDPR.
Data is kept for as long as your account is active, and afterwards for the periods required by licensing, anti-money-laundering and accounting obligations. Once no legal basis for retention remains, data is deleted or anonymised.
Under GDPR you can request: access to the data held about you; rectification of inaccurate data; erasure where no legal obligation requires retention; portability of the data you provided, in a machine-readable format; and objection to processing based on legitimate interest, including any marketing.
Requests are handled free of charge within the statutory timeframe. If you believe your data has been mishandled, you also have the right to lodge a complaint with the Data Protection Commission.
All traffic between your device and the platform is protected with SSL encryption. Access to personal data inside the organisation is restricted to staff who need it, passwords are stored hashed, and payment flows run through the providers' own secured infrastructure.
To exercise any right described above, contact the team by email at [email protected] or through live chat, available 24/7. Include the email address linked to your account so the request can be matched and verified.