Privacy Policy
Last updated: 4 May 2026. This policy covers two distinct data flows: (1) what the editorial site ozwinplayzone.com collects from you when you visit, and (2) what Ozwin Casino — the operator — retains about your real-money account under Curaçao AML rules. The two are different. Read both sections.
Part 1: editorial site data (ozwinplayzone.com)
This site is an editorial property run by Ethan Roberts and the Ozwinplayzone team. We publish onboarding and banking research about Ozwin Casino. We're not the operator, and we don't handle real-money accounts.
What we collect when you visit
- Server logs: IP address, user-agent string, referring URL, request timestamp, page URL. Retained 90 days for security and abuse-prevention.
- Cookies: a session cookie for the cookie-consent banner, plus optional analytics cookies (only if you opt in).
- Email submissions: if you email [email protected], we retain the message until the request is resolved plus 12 months.
What we don't collect
- No account creation, no passwords, no financial data on this domain.
- No third-party advertising trackers.
- No social-login integrations.
Part 2: Ozwin Casino operator data
When you create a real-money account with Ozwin Casino (a separate operator), the operator collects significantly more — required by Curaçao AML and KYC regulations. Below is what our team observed during April 2026 testing and from reader reports; this section reflects the operator's policy, not ours.
What players provide directly
- Identity: full legal name, date of birth, gender, nationality.
- Contact: email, AU mobile number, residential address.
- Account credentials: username, password (hashed), security question answer.
- Financial: payment-card details (tokenised at PCI processor), bank account details for PayID/BPAY/wire, crypto wallet addresses, transaction history.
- KYC documents: photo ID (passport, driver's licence), proof of address (utility bill, bank statement), payment-method proof, source-of-funds evidence above A$2,000.
- Communication records: chat transcripts, emails, support tickets.
What the operator collects automatically
- Device fingerprint, IP address, browser type, OS.
- Gaming activity: bets, wins, losses, session length.
- Cookies and tracking pixels for fraud detection.
- Approximate geolocation for compliance (AU residency check).
Legal basis for processing
The operator processes your data on four grounds: (a) contract performance — fulfilling the gaming-services agreement; (b) legal obligation — Curaçao AML, KYC and tax-reporting rules; (c) legitimate interests — fraud prevention, account security, abuse-prevention; (d) consent — for marketing emails only, and only if you tick the opt-in box on registration page 3.
How long is data retained?
| Data type | Retention | Reason |
|---|---|---|
| Account record | Account life + 5 years | Dispute resolution |
| Transaction records | 7 years minimum | Financial regulation, tax |
| KYC documents | 5 years post-closure | AML compliance |
| Gaming history | 5 years post-activity | Regulator audit |
| Support communications | 3 years | Service quality, dispute records |
| Marketing preferences | Until withdrawn | Consent-based |
Who is your data shared with?
The operator shares your data only with parties required for service delivery or legal compliance. From the operator's documented practice:
- Payment processors for deposit and withdrawal handling (PCI DSS compliant).
- Game providers for game delivery and play tracking (Betsoft, Saucify, Arrows Edge in Ozwin's case).
- Cloud hosting for server infrastructure.
- Identity verification services for document validation.
- Fraud-prevention partners for risk scoring.
- Regulatory authorities when legally compelled (court orders, Curaçao licensing-body requests, tax authorities).
Your data is not sold to data brokers, marketing companies, or social platforms. Ozwin's own policy reaffirms this; we've found no evidence to contradict it.
Security measures
- 256-bit SSL/TLS encryption on all transmissions.
- PCI DSS compliant payment processing — card details never reach Ozwin's own servers.
- Database encryption at rest with rotated keys.
- Multi-layer firewalls plus DDoS protection.
- Quarterly third-party security audits.
- Staff access controls limiting personal-data exposure to job-function need.
What privacy rights do players have?
Under the Curaçao framework and AU privacy expectations, players have:
- Right of access — request a copy of all data held about you. One free request per year; response within 30 days.
- Right to correction — update inaccurate details via account settings or by emailing support.
- Right to deletion — request erasure, subject to the legal retention periods above.
- Right to data portability — receive your data in a machine-readable format.
- Right to restrict processing — pause use of data while a dispute is open.
- Right to object — to legitimate-interests processing.
- Right to withdraw consent — for marketing emails, instantly via the unsubscribe link.
Exercise any of these by emailing the operator's privacy contact (visible in your account dashboard) or, for editorial-site data only, [email protected].
Cookies on this site
Three categories. Essential cookies (session, consent banner) can't be disabled if you want the site to function. Performance cookies (page-load timing) are anonymous and opt-in. Functionality cookies (language, layout preference) are opt-in. We don't run targeting or advertising cookies. Manage all categories from the cookie-consent banner shown on first visit, or in your browser settings (Chrome: Settings → Privacy & Security → Cookies).
International data transfers
Operator infrastructure includes servers in the Netherlands, Canada and Curaçao. AU resident data crosses borders to these jurisdictions under the operator's standard contractual clauses with each provider. Curaçao is the licensing jurisdiction; data transfer there is required for regulator audit.
Under-18 prohibition
Both this site and Ozwin Casino prohibit access to anyone under 18. Date-of-birth checks fire at registration (year dropdown caps at 2008), and again at document review where the passport DOB must match the form DOB. If you believe a minor has accessed an account, email [email protected] immediately. Parental control software (Net Nanny, Qustodio, iOS Screen Time, Google Family Link) is the right defence at home. 18+ | BeGambleAware.org | Gambling Help Online: 1800 858 858.
Changes to this policy
We update this policy when practices, technology or law change. The "Last updated" date at the top reflects the current version. Material changes trigger an email notification to registered users (operator-side) and a banner on this site for 30 days (editorial-side).
Privacy contact
Editorial-site privacy enquiries: [email protected] — response within 48 hours, Mon–Fri 09:00–18:00 AEST. Operator-account privacy enquiries: use the privacy contact shown in your Ozwin account dashboard.