Privacy Policy
This Privacy Policy explains how the Spinfinity online casino brand, operated for the Spinfinity section of spinfinty.com, collects, uses, discloses and protects personal data of players and website visitors. It applies to individuals who visit our websites, create or use a gaming account, take part in verification (KYC) procedures or interact with our services in any other way. By using spinfinty.com you acknowledge that your personal data will be processed in accordance with this Privacy Policy and applicable data protection laws. This Privacy Policy is effective from 20 January 2026.
Who We Are
The online casino services offered under the Spinfinity brand for users of spinfinty.com, including the Spinfinity section, are operated by ESG N.V. (Entertainment Software Group), a company incorporated under the laws of Curaçao.
Registered and legal address of the operator (data controller)
ESG N.V. (Entertainment Software Group)
Heelsumstraat 51, E-Commerce Park
Curaçao
Gaming licences
ESG N.V. operates the Spinfinity brand under licences issued in Curaçao, including a Master License 365/JAZ granted by the Government of Curaçao and a sub-license GLH-OCCHKTW0705302017 associated with that Master License. These licences are offshore licences and are not issued by the UK Gambling Commission. As a result, players in the United Kingdom do not benefit from the protections applicable to UKGC-licensed operators. You can verify licensing information via the Curaçao eGaming validation service at https://verification.curacao-egaming.com/validate/.
Role under data protection law
For the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and where applicable the EU GDPR and other local laws, ESG N.V. acts as the data controller in relation to personal data processed through spinfinty.com for the Spinfinity brand, including Spinfinity.
Data protection contact details
If you have any questions about this Privacy Policy or how we process your personal data, you may contact our data protection team:
- Email: verification@spinfinty.com (including for KYC and other verification-related privacy queries).
- Online forms: the contact and responsible gaming/self-exclusion forms made available on our sites, including the responsible gaming page currently available at https://spinfinity.casino/responsible-gaming/.
- Postal: ESG N.V. (Entertainment Software Group), Attn: Data Protection Officer, Heelsumstraat 51, E-Commerce Park, Curaçao.
What Personal Data We Collect
We collect and process personal data only to the extent necessary for the operation of our online casino services, compliance with our legal obligations and the protection of our legitimate interests. Depending on how you use spinfinty.com, we may collect the following categories of personal data:
Identity and contact data
- Identification details: full name, date of birth, nationality, username, password (stored in encrypted form), and unique account identifiers.
- Contact information: email address (for example, the address you provide for account registration or KYC, such as those handled via verification@spinfinty.com), telephone number, postal address and country of residence.
- Verification data: copies or details of identification documents (passport, ID card, driving licence), proof of address, proof of funds and other documentation requested as part of know-your-customer (KYC) and anti-money laundering (AML) procedures.
Technical and usage data
- Technical identifiers: IP address, device identifiers, browser type and version, operating system and platform, screen resolution, language settings and approximate location derived from IP.
- Usage and log data: access logs, login dates and times, session duration, pages viewed, clicks, referring URLs, error logs and similar diagnostic information.
- Device and connection data: information about the device you use to access our services (e.g. mobile, desktop, tablet), network connection type and performance indicators.
Gaming and behavioural data
- Account and gameplay data: account balance, deposits and withdrawals, bonuses claimed, wagering requirements, game selections, betting patterns, wins and losses, and other in-game actions (such as session length and bet size).
- Behavioural analytics: interaction with promotions, response to marketing campaigns, click-through on banners, and participation in tournaments or loyalty programmes.
- Responsible gaming indicators: self-exclusion requests, time-out settings, deposit and loss limits, reality checks and internal markers of potential risky behaviour where applicable.
Financial and transactional data
- Payment details: limited payment information associated with deposits and withdrawals (such as masked card numbers, card issuer country, payment method type, e-wallet identifiers or bank account details). Full financial data may be processed by our third-party payment providers on our behalf.
- Transaction history: records of deposits, withdrawals, chargebacks, refunds, bonus credits and loyalty point accruals and redemptions.
- Fraud and risk data: information generated internally or by third parties for fraud monitoring, AML risk assessment and sanctions screening.
Communication and support data
- Support interactions: records of your communications with our customer support, verification and compliance teams, including emails, live chat logs, call notes and submitted forms.
- Complaint and dispute records: information related to any complaints, disputes, or escalations, including those handled via external dispute resolution bodies such as http://centraldisputesystem.com/.
- Feedback and surveys: responses to surveys, feedback forms, ratings and other voluntary information you choose to provide.
Cookies and similar technologies
- Cookies: small text files stored on your device to enable site functionality, remember preferences, perform analytics and tailor advertising.
- Tracking technologies: pixels, tags, scripts, SDKs and similar technologies used to recognise your browser or device, measure the effectiveness of our communications and understand how users interact with spinfinty.com.
- Third-party identifiers: identifiers provided by analytics, advertising or social media partners when their technologies are embedded on our sites.
For more detail on how we use cookies and how you can control them, see the "Cookies & Tracking Technologies" section below.
Legal Basis for Processing
We process your personal data only where we have a lawful basis under applicable data protection laws, including the UK GDPR, the Data Protection Act 2018, and, where relevant, the EU GDPR and Mexican data protection rules for affected individuals. Depending on the specific processing activity, we may rely on one or more of the following legal bases:
- Performance of a contract
We process personal data that is necessary to enter into and perform our contract with you. This includes:- creating and managing your gaming account, including the Spinfinity section;
- allowing you to access games, place bets, receive winnings and use bonuses;
- processing deposits, withdrawals and other payments via our payment partners; and
- providing customer support and resolving account-related issues.
- Compliance with legal obligations
We process your data where necessary to comply with legal and regulatory requirements, particularly those relating to:- know-your-customer (KYC) and anti-money laundering (AML) checks;
- fraud, terrorist financing and sanctions screening;
- responsible gambling and player protection obligations where applicable;
- accounting, taxation and corporate record-keeping duties; and
- responding to lawful requests from supervisory authorities, courts and law enforcement in Curaçao, the UK or other relevant jurisdictions.
- Legitimate interests
We may process personal data where it is necessary for our legitimate interests and these interests are not overridden by your rights and freedoms. This includes:- protecting the integrity and security of our platforms and preventing abuse;
- detecting and preventing fraud, bonus abuse, money laundering and other prohibited activities;
- performing statistical analysis and service improvements, including optimisation of our games, website and user experience;
- personalising content, offers and recommendations in a proportionate manner; and
- defending or establishing legal claims and managing business risks.
- Consent
We will collect and use certain personal data only with your explicit consent, for example:- sending electronic marketing communications (such as newsletters, promotional emails and SMS) that are not strictly necessary for providing the services;
- using non-essential cookies and similar technologies for analytics or targeted advertising purposes; and
- sharing limited data with selected partners for personalised advertising where this is not otherwise justified by another lawful basis.
- Vital interests and legal claims
In rare circumstances, we may process personal data to protect your vital interests or those of another person (for example, when we reasonably believe a player is at serious and immediate risk of harm) or where necessary to establish, exercise or defend legal claims.
Purpose of Processing
We use the personal data we collect for clearly defined purposes. Depending on your relationship with us and how you use spinfinty.com, we may process your data for the following purposes:
- Providing and managing casino services
To register and operate your player account, verify your identity, allow you to access games, process your deposits and withdrawals, credit winnings and bonuses, and deliver customer support. - Compliance, KYC and AML
To perform identity verification, assess financial risk, carry out AML/CTF checks, comply with sanctions regimes, monitor transactions for suspicious activity and meet other legal and regulatory obligations in Curaçao, the UK and other applicable jurisdictions. - Service improvement and analytics
To understand how players use our games and website, identify technical issues, improve site performance, develop new features, refine our game offerings, and conduct statistical and aggregate analysis, using pseudonymisation where reasonable. - Marketing and personalisation
To send you updates about promotions, bonuses, tournaments and new features (where permitted by law and your preferences), and to tailor content and offers to your interests based on your account status, activity and preferences. - Fraud prevention and security
To protect our systems, players and business from fraud, abuse, unauthorised access, bonus misuse, collusion, money laundering, cyber-attacks and other unlawful activities, including through automated monitoring and manual review. - Responsible gambling and player protection
To support safer gambling by enabling self-exclusion, deposit limits, time-outs and reality checks, monitoring markers of harm where appropriate, and applying interventions or restrictions when necessary. - Customer support and dispute resolution
To respond to your questions, investigate complaints, handle disputes (including via external dispute resolution bodies such as centraldisputesystem.com) and provide you with up-to-date information about your account and transactions. - Legal, regulatory and business purposes
To meet our legal obligations, cooperate with competent authorities, maintain business records, manage risk, conduct audits, and in connection with business restructuring, mergers or acquisitions.
Disclosure & Sharing
We treat your personal data as confidential and share it only with third parties where this is necessary for the purposes described in this Privacy Policy, where required by law or where you have provided consent. Categories of recipients may include:
- Group entities and internal teams
Staff and departments within ESG N.V. (and any associated group entities where applicable) who require access to your data to operate the services, such as customer support, verification/KYC, payments, risk and compliance, IT, marketing and management. - Payment service providers and financial institutions
Banks, card schemes, e-wallet providers, payment gateways and other payment service providers that process deposits, withdrawals and refunds on our behalf. These providers receive only the information necessary to process your transactions safely and in compliance with AML and other regulations. - Verification, AML and risk management partners
Third-party service providers assisting with identity verification, document authentication, AML checks, fraud detection, sanctions screening and risk analysis. This may involve cross-checking your data against publicly available databases and reliable third-party sources. - Technology and infrastructure providers
Companies providing hosting, data storage, content delivery networks, security tools, technical support, email and SMS delivery services, analytics, and other IT solutions necessary to operate spinfinty.com. - Marketing and advertising partners
Subject to your consent and applicable laws, we may share limited data (such as hashed identifiers or device data) with marketing, analytics and advertising partners to measure campaign effectiveness and deliver relevant offers. Non-essential cookies and similar technologies will only be used where you have given consent. - Regulators, authorities and dispute bodies
Competent supervisory, tax, law enforcement and regulatory authorities in Curaçao, the United Kingdom, EU Member States, Mexico or other relevant jurisdictions, to the extent required by law or reasonably necessary to protect our rights or the rights of others. For gambling and transactional disputes, we may also share relevant information with recognised alternative dispute resolution bodies such as centraldisputesystem.com. - Professional advisers
Lawyers, auditors, accountants, consultants and other professional advisers who provide services to us and are bound by confidentiality obligations. - Corporate transactions
In the context of a potential or actual sale, merger, restructuring, acquisition or other corporate transaction involving ESG N.V. or the Spinfinity brand, we may disclose your data to prospective or actual buyers and their advisers, subject to appropriate confidentiality protections.
We do not sell your personal data in the sense of directly transferring it for monetary consideration. Any sharing with third parties is done under contractual agreements that impose data protection obligations and limit the use of your data to specified purposes.
International Transfers
Because ESG N.V. is established in Curaçao and works with partners located in various countries, your personal data may be transferred and stored outside the United Kingdom and the European Economic Area (EEA), including in Curaçao and other jurisdictions whose data protection laws may offer a different level of protection than those in your home country.
- Transfers within our operational structure
Data may be transferred from the UK/EEA to Curaçao and other locations where our teams, servers or key service providers are based, in order to operate spinfinty.com and provide the Spinfinity services. - Transfers to service providers and partners
We may share data with third-party processors and partners located outside the UK/EEA, such as payment processors, verification providers, hosting services and analytics partners, when necessary for the purposes described in this Privacy Policy. - Legal safeguards
Where we transfer personal data outside the UK/EEA to a country that is not subject to an adequacy decision, we implement appropriate safeguards in accordance with the UK GDPR and, where applicable, the EU GDPR. These safeguards may include:- standard contractual clauses approved by the European Commission or the UK Information Commissioner's Office (ICO);
- other legally recognised transfer mechanisms or derogations where appropriate; and
- technical and organisational measures such as encryption, strict access controls and minimisation of transferred data.
- Your responsibilities
By using our services, you understand that your data may be processed in countries with different data protection regimes. However, we will always handle your personal data in accordance with this Privacy Policy and apply appropriate safeguards regardless of where the processing takes place.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to comply with legal, regulatory, accounting or reporting requirements. Retention periods may differ depending on the category of data, the type of relationship we have with you and the requirements of applicable laws in Curaçao, the UK and other jurisdictions.
- Player account and transactional data
Core account information (such as identity details, contact data, KYC documents and transaction history) is generally retained for the duration of your active account and for a period of up to five (5) years after your account is closed, unless a longer period is required by AML, tax, gaming or other legal obligations or is necessary for the establishment, exercise or defence of legal claims. - KYC, AML and compliance records
Copies of identity documents, verification records and AML-related analyses are typically retained for a minimum of five (5) years from the end of the business relationship or the date of the last transaction, subject to longer statutory requirements where applicable. - Marketing data
Data used for marketing and profiling purposes is kept for as long as you remain subscribed to marketing communications. If you withdraw consent or opt out, we may retain minimal information (such as your email address on a suppression list) to ensure we respect your choice. Inactive marketing profiles are normally reviewed and either anonymised or deleted after a period of approximately 24 months of inactivity, unless required otherwise by law. - Technical and log data
Server logs, security logs and technical diagnostics are retained for periods that are necessary for security, troubleshooting and analytical purposes, typically ranging from a few weeks up to 24 months, depending on the type of log and any extended retention required for investigations. - Cookies and similar technologies
Retention periods for cookies vary by type and purpose. Session cookies expire when you close your browser. Persistent cookies used for preferences, analytics or advertising may remain on your device for a period from a few days up to 24 months, unless you delete them earlier via your browser or device settings. - Aggregated and anonymised data
We may retain aggregated or anonymised data (which no longer identifies you) for longer periods for statistical, research or business planning purposes. Such data is not considered personal data under applicable law.
When personal data is no longer needed for its original purpose and no legal requirement or legitimate interest justifies further retention, we will securely delete, anonymise or otherwise irreversibly de-identify it.
Your Rights
Under the UK GDPR and, where applicable, the EU GDPR and Mexican privacy legislation, you have a number of rights regarding your personal data. The exact scope of these rights may vary depending on your country of residence and the circumstances of processing, but generally includes the following:
- Right of access
You have the right to obtain confirmation as to whether we process your personal data and, if so, to receive a copy of that data together with information about how we use it. - Right to rectification
You may request correction of inaccurate or incomplete personal data that we hold about you. In many cases you can update key account information directly in your profile on spinfinty.com. - Right to erasure ("right to be forgotten")
You may request deletion of your personal data where, for example, it is no longer necessary for the purposes for which it was collected, you have withdrawn consent (where consent was the sole basis) or you believe it has been processed unlawfully. This right is subject to important exceptions; for instance, we may need to retain certain data to comply with AML and other legal obligations. - Right to restriction of processing
You may request that we restrict the processing of your data in certain situations, such as while we verify the accuracy of data you contest, or when processing is unlawful but you oppose deletion. - Right to object
You may object to processing based on our legitimate interests, including profiling, where you consider that your fundamental rights and freedoms outweigh our interests. You also have an absolute right to object at any time to the use of your personal data for direct marketing, including profiling related to direct marketing. - Right to data portability
Where processing is based on your consent or on a contract and is carried out by automated means, you may request to receive your personal data in a structured, commonly used and machine-readable format and have it transmitted to another controller where technically feasible. - Right to withdraw consent
Where we rely on your consent (for example, for certain marketing communications or non-essential cookies), you may withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before withdrawal but may affect our ability to provide certain services. - Rights related to automated decision-making
If we carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, you have the right to obtain human intervention, express your point of view and contest the decision, unless an exception under applicable law applies. - ARCO rights under Mexican law
If you are protected by Mexican privacy law, you may have specific ARCO rights (Access, Rectification, Cancellation and Opposition) under the Mexican Federal Law on Protection of Personal Data Held by Private Parties. We will handle such requests in line with that law where it applies, while also complying with other relevant legal obligations (for example, AML rules that may require continued retention of certain data).
How to exercise your rights
- Submit your request by email to verification@spinfinty.com with sufficient information to identify your account and the right you wish to exercise.
- Alternatively, you may contact us via available web forms on our sites or by postal mail to our registered address, clearly marking your correspondence "Data Protection Request".
- We may need to request additional information from you to verify your identity before acting on your request, especially where sensitive data or high-risk actions (such as account closure or data deletion) are involved.
- We aim to respond to all legitimate requests within 30 days of receipt. This period may be extended by a further two months where necessary due to complexity or number of requests, in which case we will inform you of the extension and the reasons for it.
- We generally do not charge a fee for handling your request. However, where a request is manifestly unfounded or excessive (for example, repetitive requests), we may charge a reasonable fee or refuse to act, as permitted by applicable law.
If you consider that we have not respected your rights or have otherwise processed your personal data unlawfully, you also have the right to lodge a complaint with a supervisory authority, as described in the "Complaints & Contacts" section.
Cookies & Tracking Technologies
We use cookies and similar technologies on spinfinty.com to ensure the proper functioning of our services, improve user experience, perform analytics and, where permitted, deliver personalised content and advertising.
Types of cookies we use
- Strictly necessary (session) cookies
These cookies are essential for the operation of the website and cannot be disabled through our systems. They are usually set only in response to actions you take, such as logging in, setting privacy preferences, managing your account or filling in forms. They typically expire when you close your browser session. - Functional (persistent) cookies
These cookies enable the website to provide enhanced functionality and personalisation, such as remembering your username, preferred language, or region. They may be set by us or by third-party providers whose services we use. - Analytics and performance cookies
These cookies help us understand how visitors interact with the website by collecting and reporting information anonymously, such as which pages are visited most frequently, how long sessions last and whether any errors are encountered. The information collected is used to improve site performance and user experience. - Advertising and targeting cookies
These cookies may be set by us or our advertising partners to build a profile of your interests and show you relevant advertisements on our site or on other sites. They work by uniquely identifying your browser or device. In many jurisdictions, including the UK, these cookies are only used with your consent. - Third-party cookies
Some cookies are placed by third parties when their content or technologies are integrated into our site (for example, analytics providers or embedded services). These cookies are subject to the privacy policies of the respective third parties.
Cookie consent and management
- Consent for non-essential cookies
In line with UK privacy and electronic communications rules, we will seek your consent before setting non-essential cookies (such as analytics and advertising cookies). You can provide or withdraw this consent through our cookie banner or preference centre, where implemented. - Browser and device settings
Most web browsers allow you to manage cookies through their settings, including blocking or deleting cookies. Please note that disabling certain cookies may affect the functionality of the site or your ability to access some features, such as staying logged in or saving preferences. - Other tracking technologies
Where we use similar technologies (such as pixels or SDKs), we treat them in the same way as cookies for legal purposes and apply the same consent and control mechanisms where required.
For detailed information about the specific cookies used on spinfinty.com, their providers and retention periods, we may provide a dedicated cookie table or cookie management tool accessible from the website footer or settings area.
Data Security
We take the security of your personal data very seriously and implement technical and organisational measures designed to protect it against unauthorised access, accidental loss, destruction or damage. While no system can guarantee absolute security, we strive to maintain a level of protection appropriate to the risks associated with online gambling services.
- Encryption and secure transmission
Data transmitted between your browser and our servers is protected using modern transport layer security protocols (such as TLS 1.2 or higher) to reduce the risk of interception and tampering. Sensitive information is encrypted in transit, and we use industry-standard methods to protect data at rest wherever appropriate. - Access controls and authentication
Access to personal data is restricted to authorised personnel who need it to perform their job functions. We apply role-based access controls, strong authentication mechanisms and secure password policies, and we encourage or implement multi-factor authentication for internal systems where feasible. - Network and system security
Our infrastructure is protected by firewalls, intrusion detection and prevention systems, malware protection and regular security monitoring. We apply security patches, updates and hardening measures in a timely manner and segregate environments where appropriate. - Monitoring, testing and audits
We perform regular monitoring of systems and logs to detect unusual activities, and we periodically review our security controls. Where appropriate, we may conduct vulnerability assessments, penetration testing or independent audits to evaluate the effectiveness of our security measures. Our security framework is informed by recognised standards such as ISO 27001 and SOC 2, although this does not necessarily imply formal certification. - Staff training and policies
Employees and contractors with access to personal data are required to follow confidentiality obligations and receive training on data protection, information security and responsible handling of customer information. Internal policies and procedures govern data access, classification, incident management and acceptable use. - Incident response
We maintain procedures for identifying, reporting, assessing and responding to information security incidents. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required by law, affected individuals without undue delay and in line with applicable legal timeframes.
Complaints & Contacts
We are committed to addressing any concerns you may have about our handling of your personal data. If you believe your privacy rights have been infringed or you are dissatisfied with our response to a request, you have several avenues for complaint and escalation.
Contacting us first
- Step 1 - Customer support
In the first instance, please contact our customer support team using the channels provided on spinfinty.com or related Spinfinity pages. Many issues can be resolved quickly at this level. - Step 2 - Data protection team
If your concern specifically relates to privacy or data protection, or if you are not satisfied with the initial response, you may escalate the matter to our data protection team:- Email: verification@spinfinty.com
- Postal: ESG N.V. (Entertainment Software Group), Attn: Data Protection Officer, Heelsumstraat 51, E-Commerce Park, Curaçao
Escalation to supervisory authorities
If you remain unsatisfied with our response, or you prefer to do so, you have the right to lodge a complaint with an appropriate data protection authority. The competent authority will usually depend on your place of residence.
- United Kingdom
If you are located in the UK or the issue relates to processing under the UK GDPR, you may contact the UK Information Commissioner's Office (ICO). Up-to-date contact details are available at https://ico.org.uk. The ICO's postal address at the time of drafting this policy is:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. - European Union / EEA
If you are in the EU/EEA, you may lodge a complaint with your local data protection authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. Contact details for EU data protection authorities can be found via official EU resources (for example, through links provided on the European Commission's or European Data Protection Board's websites). - Mexico
If you are protected by Mexican privacy law, you may have the right to lodge a complaint with the Mexican data protection authority, the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI). Current contact details and complaint procedures are available at https://www.inai.org.mx.
Lodging a complaint with a supervisory authority does not affect any other administrative or judicial remedies you may have.
Other dispute resolution mechanisms
For certain gambling-related disputes (for example, those concerning the outcome of a game or the settlement of a bet), you may also have access to alternative dispute resolution services, such as those provided via http://centraldisputesystem.com/. These mechanisms are separate from data protection authorities and are primarily intended for gaming disputes rather than privacy complaints.
Updates
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, industry practices or technological developments. When we make changes, we will revise the "Last updated" date and, where appropriate, provide additional notice.
- Notification of changes
For minor or clarifying updates, we may simply post the revised Privacy Policy on spinfinty.com. For material changes that significantly affect how we process your personal data, we will endeavour to notify you in advance through appropriate channels, which may include:- email notifications to the address associated with your account;
- prominent notices or banners on the website;
- alerts or messages within your account dashboard.
- Your review and continued use
We encourage you to review this Privacy Policy periodically to stay informed about how we process your data. Your continued use of spinfinty.com after an updated Privacy Policy takes effect will be considered acceptance of the changes. - Your options
If you do not agree with a material change to this Privacy Policy, you may choose to close your account and stop using our services. You may also exercise your rights as described in the "Your Rights" section, including withdrawal of consent for specific processing activities such as marketing.
Last updated: January 2026