Privacy Policy
This page sets out what personal information Mega Casino collects from visitors, why, where it is stored, who it is shared with, and how you can exercise your rights under UK privacy law. The technical companion — cookies, analytics and browser storage — sits on the Cookie Policy page; this page is the plain-language version of the same arrangement.
Mega Casino is run as an independent editorial platform; broader context is on the About page. This privacy policy covers the Mega Casino website only. Once a reader clicks through to an operator site, that operator's own privacy policy takes over; Mega Casino does not share data with operators except in the limited form described below.
1. What Mega Casino is
The output of Mega Casino consists of reviews and guides covering online casinos open to UK players. Our flagship operator review is hosted on the Mega Casino homepage itself. The site itself runs no games, operates no player accounts, takes no deposits, holds no funds and processes no withdrawals. No signup process exists. No login screen exists. A standard visit involves zero data exchange beyond ordinary, baseline web traffic. In the narrower situations where Mega Casino does collect personal information — for example when you write in via the contact channels — this page describes exactly what subsequently happens to that information.
2. UK privacy law context
Personal information processed by Mega Casino is handled under the UK GDPR and Data Protection Act 2018, alongside the thirteen UK GDPR principles supervised by the Information Commissioner's Office (ICO). Visitors arriving from the EU receive equivalent treatment under EU GDPR rights. Californian visitors receive CCPA rights to the extent those rights are applicable. Across all three frameworks, where any one rule is stricter than another, the stricter rule prevails for that interaction.
3. What data Mega Casino collects
Three separate data categories are involved here: routine technical traffic data, contact data that you voluntarily submit through the site, and high-level aggregated analytics.
| Category | What is collected | Why | Legal basis |
|---|---|---|---|
| Technical traffic data | IP address (anonymised after 24h), browser type, device type, page URL requested, timestamp, referrer. | Serve pages, prevent abuse, debug performance issues. | Legitimate interest under UK GDPR Article 6 legitimate interest. |
| Voluntary contact data | Name, email address, message content, supporting documents you choose to attach. Submitted only if you write to us. | Reply to your enquiry. | Consent under UK GDPR consent basis (you provide the data; we use it for the stated purpose). |
| Aggregated analytics | Pseudonymous traffic statistics generated by Google Analytics 4 with IP anonymisation enabled. | Understand which pages are useful and which are not. | Consent (you can decline analytics cookies on first visit). |
The list of data categories Mega Casino does not collect is just as important: no financial information (since the domain processes no payments), no gambling-account credentials (because no player accounts are operated here), no biometric data, no precise geolocation beyond country-level (derived solely from anonymised IP), and no special-category data such as race, religion, health status, sexual orientation or political views. Neither targeted advertising nor remarketing is deployed on the site; the funding mechanism that keeps Mega Casino running is documented on the Affiliate Disclosure page.
4. Cookies and similar technologies
A comprehensive breakdown of the cookies in use on Mega Casino, the external services responsible for setting each one and the controls you can exercise is laid out on the dedicated Cookie Policy page. As a quick summary: strictly necessary cookies (those covering page rendering, the consent-banner state and abuse-prevention) are always set as a baseline; analytics and affiliate-tracking cookies are placed only after you grant consent through the banner; your choice can be revised at any later time using the dedicated link sitting in the page footer.
5. Affiliate links and operator-side tracking
Three discrete things take place whenever you click an outbound operator link from Mega Casino. To begin, the click passes through an internal redirect at /go which records the event for our internal analytics — whether or not you ultimately complete the journey. Next, the browser is forwarded onward to the operator site itself. Finally, the receiving operator may then set its own cookies and treat the incoming visit as a referral for attribution purposes. At no stage does Mega Casino transmit your name, email address or any other identifying personal data to the operator. All the operator effectively learns is that "a visitor arrived from Mega Casino". If you proceed to register an account on the operator's platform, that registration sits under the operator's own privacy policy and not this one.
6. How long data is retained
- IP addresses: a raw IP is retained for no more than 24 hours, purely for abuse-prevention purposes, after which it is anonymised through truncation of the final octet (IPv4 case) or the last 80 bits (IPv6 case). The resulting anonymised IPs are then retained for up to 14 months in order to support aggregated traffic statistics.
- Contact correspondence: emails and any attachments are kept for 24 months for follow-up and audit purposes, then deleted unless still under active discussion.
- Analytics events: Google Analytics 4 data is kept for 14 months under our configuration, then automatically deleted.
- Cookie consent record: the consent record itself is stored locally in your browser for 12 months, after which the consent banner reappears.
Where statutory retention obligations require a longer hold — a typical example being tax records covered by HMRC record-keeping rules around affiliate-related accounting — the affected data is retained strictly for the legally mandated period and is not repurposed for any other use during that period.
7. Who Mega Casino shares data with
Sharing is restricted to three tightly controlled categories. Service providers running parts of the Mega Casino infrastructure on our behalf — web hosting, content delivery, email — each operate under a written data-processing agreement strictly limiting their use of the data to delivery of the contracted service. Analytics providers such as Google Analytics 4 receive IP-anonymised traffic data only, never personally identifying information. Law-enforcement bodies and regulators receive data only in response to a valid legal demand, and only the slice of data covered by that demand. Selling, renting or trading personal data to anyone, full stop, is something Mega Casino simply does not do.
8. Where data is stored
Hosting for the Mega Casino infrastructure runs on cloud providers physically located inside the UK and the wider European Economic Area. A smaller number of supplementary service providers — Google Analytics 4 being the obvious example — handle their portion of the data inside the United States. Where any data crosses the UK border, the receiving party must be bound either by Standard Contractual Clauses or by an equivalent protection regime that the ICO has already assessed as delivering protection at least as strong as UK law.
9. Your rights
The UK GDPR — and equivalent international privacy regimes — give you a defined set of rights in respect of any personal data that Mega Casino happens to hold about you, set out below.
- Access: ask what we hold and receive a copy.
- Correction: ask for inaccurate data to be corrected.
- Deletion: ask for your data to be deleted, subject to legal retention requirements.
- Withdrawal of consent: if processing is based on consent, you can withdraw it at any time without affecting prior lawful processing.
- Complaint: if the view you take is that Mega Casino has handled your personal data improperly, a complaint can be filed with the ICO via ico.org.uk. UK readers are normally expected to contact us directly first, so that we have the opportunity to investigate and resolve the underlying issue ourselves.
To put any of the above rights into action, send a written request to the dedicated privacy address that is published on the Contact Us page. A response from Mega Casino will follow inside the statutory 30-day reply window mandated by the UK GDPR.
10. Children's privacy
The Mega Casino editorial output is produced for an adult British audience. None of the content here is aimed at or intended for anyone under the age of 18. No personal data is knowingly collected from minors at any stage. If at any point we are made aware that data has been submitted by an under-18, the data in question is deleted immediately and — where appropriate — a notification is sent to the parent or guardian.
11. Security
A standard set of industry security controls is operated at Mega Casino: TLS 1.2+ on every byte of data in transit; layered access controls plus least-privilege rules across all internal systems; routine review of who currently has access to what; administrative-action logging; and periodic third-party penetration testing of the public-facing site. No technical system is unbreakable; in the unlikely event of a personal-data breach likely to cause serious harm, the affected individuals will be notified directly and the ICO will be informed in line with the breach-notification regime established under the UK GDPR.
12. Changes to this policy
Where this policy is amended, the "Last updated" timestamp shown at the top of the page is revised accordingly. Any material amendments — adding new data categories, onboarding new third-party processors, changing how long data is retained — are flagged on the homepage banner for a minimum of 30 days. Minor housekeeping work (wording cleanup, link refresh) does not trigger a banner.
13. Contact
Privacy-related questions are best routed through the privacy contact listed on the Contact Us page. Editorial questions about Mega Casino content go through the editorial channel; correction requests follow the procedure documented on the Editorial Policy page. Player-safety guidance applicable to anyone reading this site sits on the Responsible Gambling page.
