// legal/privacy.md

Privacy Policy

Last updated: May 20, 2026. Gigabite Games is the data controller. Reach our DPO at [email protected].

What we collect

  • Account identifiers: email, hashed password, display name.
  • Session metadata: IP, user-agent, timezone (retained 30 days).
  • Gameplay logs: spin outcomes, bets, balances (retained 7 years for audit).
  • Support correspondence (retained 24 months).

What we don't collect

No advertising trackers, no fingerprinting, no third-party analytics that resell behavioural data. We do not sell or rent personal data to anyone.

Storage and transfer

Data is encrypted at rest with AES-256 and in transit with TLS 1.3. Primary storage in the EU (Frankfurt and Helsinki). Replicated copies stay inside the EEA.

Rights under GDPR

You can request export, correction, restriction, or deletion of personal data at any time. Email [email protected] and we'll respond within 30 days.