1. Who we are
Stakebet (“we”, “us”) operates the website and services accessible via this domain. We are the data controller for personal information collected through your account. Inquiries: privacy@neonspin.stakebet.gg.
2. What we collect
2.1 At registration:
- Email address (required for account recovery and material notifications)
- Username (public, visible in leaderboards and chat)
- Password (hashed with Argon2id; we never store the plain value)
- Country of residence (self-declared)
- Date of birth (self-declared, used to enforce minimum age of 18)
- Preferred language and timezone
2.2 Automatically:
- IP address (logged for every request; retained 90 days for fraud and abuse detection)
- Device characteristics (browser, operating system, screen size — for responsive rendering and fraud detection)
- Session cookies and the auth cookie
sb-auth
2.3 When you transact:
- Cryptocurrency deposit addresses (your sending address from the on-chain transaction)
- Cryptocurrency withdrawal addresses (the address you provide)
- Transaction hashes and amounts
2.4 If you trigger KYC (above $2k/day cumulative withdrawal, jurisdictional risk flags, or AML pattern hits):
- Identity document image (passport, national ID, or driver licence)
- Selfie matching the document
- Document number and expiry date (extracted)
3. Why we collect it
- Account operation — login, balance management, transactions, support correspondence.
- Legal compliance — AML monitoring, KYC verification when triggered, suspicious-activity reporting.
- Fraud detection — IP, device, payment-method dedup to prevent multi-account abuse and bonus fraud.
- Service improvement — aggregated, anonymized analytics on which games are popular, where bugs occur.
- Communications — service notifications (deposit confirmed, withdrawal processed, password reset). Marketing only with explicit opt-in.
4. Who we share with
We do not sell personal information. We share with third parties only as necessary to operate the service:
- Payment providers — NowPayments (when you choose a non-Tron rail) receives the transaction amount, your deposit/withdrawal address, and a callback URL.
- Game providers — Slotegrator and sub-providers receive a session token and your username for game-state tracking. They do not receive email, country, or KYC data.
- KYC service provider — when KYC is triggered, your document image and selfie are processed by our identity-verification vendor. We retain the verification result; the vendor retains documents for the period mandated by local AML law.
- Hosting infrastructure — DigitalOcean (Frankfurt). Data does not leave the EU economic area unless required by legal process.
- Legal authorities — when compelled by valid legal process from a competent jurisdiction.
5. Cookies
We use three categories of cookie:
- Essential —
sb-auth(session presence flag), the access-token cookie set by Keycloak. Required for the service to function; cannot be opted out of. - Functional — language preference, deposit-currency preference, sound settings. Persistent for convenience.
- Analytics — anonymized usage analytics. Opt-in only.
6. Retention
- Account profile data — retained while the account is active, and for 5 years after closure for AML compliance.
- Transaction history — retained 5 years from the date of the transaction (AML).
- KYC documents — retained 5 years from last interaction, in line with our KYC vendor’s policy.
- IP and device logs — 90 days, then aggregated to anonymous statistics.
- Support correspondence — 2 years.
7. Your rights
Subject to applicable law, you may request:
- Access — a copy of the personal information we hold about you.
- Correction — fixing any inaccurate fields.
- Deletion — removal of your data, subject to AML retention obligations on transaction history.
- Portability — export of your account profile in machine-readable JSON.
- Withdrawal of consent — for marketing communications, immediately upon request.
To exercise any of these rights, email privacy@neonspin.stakebet.gg from the address on file. We respond within 30 days.
8. Security
Passwords are hashed with Argon2id. Authentication uses OAuth2 PKCE via Keycloak. Sessions expire after inactivity. All traffic is encrypted in transit (TLS 1.3). Internal databases are encrypted at rest. We do not store payment-card data — all crypto custody is either self-hosted (Tron HD wallet, mnemonic file-mounted from a SealedSecret) or routed through licenced payment-provider partners.
9. Children
Stakebet is strictly 18+. We do not knowingly collect data from minors. If we become aware that we have collected data from a minor, we delete it.
10. Changes
Material changes to this policy are notified by email at least 30 days before they take effect. Non-material changes (typographic, contact-detail updates) take effect immediately upon posting.