Privacy Policy

Privacy Policy

Version: 1.0  |  Last Updated: 30 July 2025

This Privacy Policy describes how Crownplay ("we", "us", "our"), operating through crownplay-review.com (the "Website"), collects, uses, stores, and protects the personal data of its users ("you", "your"). This policy also explains your rights with respect to your personal data.

This Privacy Policy should be read in conjunction with our Terms & Conditions and our Responsible Gaming Policy. By using the Website, you acknowledge that you have read and understood this Privacy Policy.

We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all applicable data protection legislation.

1. Introduction

1.1. Our Role as Data Controller

For the purposes of applicable data protection law, Crownplay acts as the Data Controller of the personal data collected through the Website. This means we determine the purposes and means of processing your personal data.

1.2. Scope of This Policy

This Privacy Policy applies to all personal data collected through:

  • Your registration and use of the Website;
  • Deposits, withdrawals, and financial transactions;
  • Communications with our Customer Support team;
  • Your participation in promotions, tournaments, or surveys;
  • Cookies and tracking technologies used on the Website.

1.3. Contact Details

If you have any questions about this Privacy Policy or about how we handle your personal data, please contact us at:

2. Data We Collect

2.1. Data You Provide Directly

When you register an Account, transact, or communicate with us, we collect the following categories of personal data:

  • Identity Data: Full legal name, date of birth, gender, nationality;
  • Contact Data: Email address, postal address, telephone number;
  • Account Credentials: Username, encrypted password;
  • Financial Data: Payment method details, deposit and withdrawal history, transaction records;
  • Verification Documents: Copies of identity documents, proof of address, source of funds documentation;
  • Communications Data: Records of correspondence with our support team, including live chat transcripts and emails;
  • Responsible Gaming Data: Self-exclusion requests, deposit limits, session restrictions, and other responsible gaming preferences.

2.2. Data We Collect Automatically

When you use the Website, we automatically collect:

  • Technical Data: IP address, device type, operating system, browser type and version;
  • Usage Data: Pages visited, games played, bet amounts, session duration, click-through data;
  • Geolocation Data: Approximate location derived from IP address (country/region level);
  • Cookie Data: Data collected through cookies and similar tracking technologies (see Section 6).

2.3. Data Received from Third Parties

We may receive personal data about you from third parties, including:

  • Identity verification and KYC service providers;
  • Payment processors and financial institutions;
  • Fraud prevention and anti-money laundering screening services;
  • Marketing partners and analytics providers (where permitted).

3. How We Use Your Data

3.1. Purposes of Processing

We use your personal data for the following purposes:

  • Account Management: To create, maintain, and administer your Account, verify your identity, and manage your preferences;
  • Service Delivery: To provide access to Games, process transactions, and deliver our services in accordance with the Terms & Conditions;
  • KYC & Compliance: To verify your age and identity, comply with anti-money laundering (AML) obligations, and screen against sanctions lists;
  • Customer Support: To respond to your enquiries, resolve disputes, and provide technical assistance;
  • Financial Processing: To process deposits, withdrawals, and any other financial transactions;
  • Security & Fraud Prevention: To detect, investigate, and prevent fraudulent activity, cheating, collusion, and other prohibited conduct;
  • Responsible Gaming: To implement and monitor responsible gaming tools such as self-exclusion, deposit limits, and session controls;
  • Personalisation: To tailor content, promotions, and recommendations to your preferences (where lawful);
  • Marketing: To send you promotional communications where you have opted in or where we have a legitimate interest to do so (subject to opt-out rights);
  • Analytics & Improvement: To understand how users interact with the Website and to improve our services;
  • Legal Obligations: To comply with applicable laws, regulations, court orders, and requests from regulatory authorities.

4. Legal Bases for Processing

4.1. Bases Under GDPR

We rely on the following legal bases to process your personal data:

Purpose of Processing Legal Basis
Account registration and service deliveryPerformance of a Contract (Art. 6(1)(b) GDPR)
KYC, AML, and age verificationLegal Obligation (Art. 6(1)(c) GDPR)
Fraud prevention and securityLegitimate Interests (Art. 6(1)(f) GDPR)
Direct marketing (opted-in)Consent (Art. 6(1)(a) GDPR)
Responsible gaming monitoringLegal Obligation / Legitimate Interests
Analytics and service improvementLegitimate Interests (Art. 6(1)(f) GDPR)
Compliance with court orders / authoritiesLegal Obligation (Art. 6(1)(c) GDPR)

4.2. Withdrawal of Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at [email protected].

5. Data Sharing & Third Parties

5.1. Categories of Third-Party Recipients

We may share your personal data with the following categories of third parties:

  • Payment Processors: To facilitate deposits, withdrawals, and transaction verification;
  • Identity Verification Providers: To fulfil KYC and AML obligations;
  • IT and Cloud Service Providers: Who host and maintain our Website and systems under data processing agreements;
  • Analytics Providers: To analyse Website usage patterns and improve services;
  • Fraud Prevention Services: To detect and prevent fraudulent activity;
  • Game Software Providers: Who supply and operate individual games on the Website and may collect certain technical or gameplay data;
  • Regulatory Authorities: Where required by law, court order, or regulatory obligation;
  • Business Successors: In the event of a merger, acquisition, or transfer of assets, personal data may be transferred as part of that transaction.

5.2. No Sale of Personal Data

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

5.3. Third-Party Data Processors

All third-party service providers acting as data processors on our behalf are required to comply with applicable data protection legislation and are bound by written Data Processing Agreements (DPAs) ensuring appropriate technical and organisational security measures.

6. Cookies & Tracking Technologies

6.1. What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They enable the website to recognise your device and store certain information about your preferences or past actions.

6.2. Types of Cookies We Use

Cookie Type Purpose Duration
Strictly NecessaryEssential for the operation of the Website, including login sessions and security functionsSession / Persistent
PerformanceCollect anonymous data about how visitors use the Website to help us improve performanceUp to 2 years
FunctionalityRemember your preferences such as language and display settingsUp to 1 year
Targeting / MarketingUsed to deliver relevant advertising and track campaign effectivenessUp to 90 days

6.3. Managing Cookies

You can control and manage cookies through your browser settings or through the cookie consent banner displayed upon your first visit to the Website. Please note that disabling certain cookies may affect the functionality of the Website. For more information on managing cookies, visit www.allaboutcookies.org.

6.4. Other Tracking Technologies

In addition to cookies, we may use web beacons, pixel tags, and local storage technologies for similar purposes. These technologies are subject to the same consent and opt-out mechanisms as cookies.

7. Data Security

7.1. Security Measures

Crownplay implements appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:

  • SSL/TLS Encryption: All data transmitted between your device and the Website is encrypted using industry-standard SSL/TLS protocols;
  • Data Encryption at Rest: Sensitive personal data is encrypted when stored on our systems;
  • Access Controls: Strict role-based access controls limit who within our organisation can access your personal data;
  • Regular Security Audits: We conduct periodic internal and external security assessments;
  • Employee Training: All personnel handling personal data receive data protection training.

7.2. Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with applicable data protection law. We will also notify the relevant supervisory authority as required by GDPR.

8. Data Retention

8.1. Retention Periods

We retain your personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law. Typical retention periods are as follows:

Data Category Retention Period
Account and identity dataDuration of Account + 5 years after closure
Financial transaction recordsDuration of Account + 7 years after closure
KYC / verification documentsDuration of Account + 5 years after closure
Customer support communications3 years from last interaction
Marketing preferences / consent records3 years from withdrawal of consent
Cookie and analytics dataUp to 2 years

Longer retention periods may apply where required by law, regulation, or court order.

9. Your Rights

9.1. Rights Under GDPR

Subject to applicable data protection law, you have the following rights in relation to your personal data:

  • Right of Access: To request a copy of the personal data we hold about you;
  • Right to Rectification: To request correction of inaccurate or incomplete personal data;
  • Right to Erasure ("Right to be Forgotten"): To request deletion of your personal data where there is no longer a lawful basis for processing;
  • Right to Restriction of Processing: To request that we limit the processing of your data in certain circumstances;
  • Right to Data Portability: To receive your personal data in a structured, machine-readable format and to transmit it to another controller;
  • Right to Object: To object to processing based on legitimate interests or for direct marketing purposes;
  • Rights Related to Automated Decision-Making: To request human review of any decision made solely by automated means that significantly affects you.

9.2. How to Exercise Your Rights

To exercise any of the above rights, please submit a written request to [email protected]. We will respond within 30 days of receipt of your request. In complex cases, this period may be extended by a further two months, in which case we will notify you accordingly.

9.3. Right to Lodge a Complaint

If you are not satisfied with our handling of your personal data, you have the right to lodge a complaint with the relevant supervisory authority in your country of residence. In Greece, this is the Hellenic Data Protection Authority (HDPA), accessible at www.dpa.gr.

10. International Data Transfers

10.1. Transfers Outside the EEA

Some of our third-party service providers may be located outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Transfers to countries with an adequacy decision from the European Commission;
  • Other lawful transfer mechanisms recognised under applicable data protection law.

10.2. Information on Request

You may request further information about the safeguards applied to international data transfers by contacting us at [email protected].

11. Minors

11.1. Age Restriction

The Website is strictly intended for persons aged 21 years and over. We do not knowingly collect personal data from individuals under the age of 21. If we become aware that personal data has been collected from a minor, we will take immediate steps to delete such data and close the associated Account.

11.2. Parental Controls

We encourage parents and guardians to make use of available parental control software to prevent underage individuals from accessing gambling websites. For further guidance, please refer to our Responsible Gaming page.

12. Changes to This Policy

12.1. Policy Updates

Crownplay reserves the right to update this Privacy Policy at any time to reflect changes in our practices, applicable law, or the services we offer. The updated version will be published on the Website with a revised "Last Updated" date. Where changes are material, we will notify you by email or by a prominent notice on the Website prior to the change taking effect.

12.2. Continued Use

Your continued use of the Website following the publication of any updated Privacy Policy constitutes your acknowledgement of the changes.

13. Contact Information

For all data protection enquiries, requests to exercise your rights, or questions about this Privacy Policy, please contact us:

We are committed to addressing your data protection concerns promptly and transparently.