Privacy Notice
What This Notice Does Not Cover
Unless a visitor lands on a page that carries its own separate privacy statement, this notice is the only document that governs how Casumo casino treats information gathered on this website. It does not apply to any external platform a visitor reaches by following a link from these pages, nor does it cover data that a visitor shares directly with the casino operator itself rather than with this review site. The notice is written for people who read the reviews, use the comparison tools, or otherwise interact with the editorial content published here.
Information Collected
Two broad categories of information can end up in the website’s hands. The first is data a visitor actively supplies, which happens through a limited set of actions: sending a message through the contact form, subscribing to optional updates, or responding to a direct request for feedback. The second category is generated passively, the moment a browser loads a page, without the visitor typing anything at all.
Technical data of that second kind arrives through server logs, cookies, and analytics scripts. It typically includes the IP address the request came from, the browser type and version, the operating system, screen resolution, the referring page, and a record of which pages were viewed and in what order. None of this is collected to single out a specific reader; it is gathered in bulk to understand how the site performs.
Categories at a Glance
- Identity and contact details, such as a name or email address, provided voluntarily
- Correspondence records, including the content of messages sent to the website
- Device and network data, including IP address and browser identifiers
- Usage statistics, covering page views, navigation paths, and interaction with page elements
- Preference signals, such as cookie consent choices and regional settings
How Collected Information Is Used
Every use of personal data on this website traces back to a practical need. The most basic is keeping the pages functional: server logs help diagnose outages, and cookies remember whether a visitor has already dismissed a pop-up. Beyond that, the data supports responding to messages, so a question sent through the contact form can be answered accurately and without asking the visitor to repeat themselves.
The same information feeds into understanding how the site performs. Aggregate navigation statistics show which reviews are read to the end and where readers tend to drop off, which guides the editorial team in structuring future content. Security is another legitimate use: pattern analysis of traffic can flag suspicious behaviour such as automated scraping or repeated failed attempts to access restricted areas. Finally, the data supports internal administration, including record-keeping and dispute resolution.
Data is never sold, rented, or traded to outside parties for their own marketing purposes. The website does not build advertising profiles of its readers, and it does not combine browsing data with information from third-party data brokers.
Cookies and Similar Technologies
Cookies are small text files stored by the browser, and they are not the only storage mechanism in play. Local storage, session storage, and similar technologies perform comparable functions, and this notice treats them all the same way. They are grouped by what they do rather than by their technical name.
Strictly necessary cookies keep the site working. They remember consent choices, keep a session alive while a visitor moves between pages, and prevent the same overlay from appearing on every page load. Without these, core functions break, so they cannot be switched off through the cookie banner.
Preference cookies remember choices that are not strictly required but improve comfort, such as a previously selected region or a collapsed sidebar state. Analytics cookies, by contrast, do not store anything a visitor chose; they measure how often pages are opened, how long a visit lasts, and which content attracts the most attention. This data is aggregated and does not identify an individual reader.
Browser settings offer a way to block or delete cookies, and the website respects the Global Privacy Control signal where the browser sends it. Disabling cookies comes with a trade-off: the site remains fully readable, but some conveniences, such as remembered settings and personalised layouts, will not persist between visits, and the analytics picture becomes less complete.
Data Shared With Third Parties
Running a website of this kind involves outside service providers, and some data necessarily passes through their systems. Hosting providers store the files that make up the site and the logs that record its traffic. Analytics services process usage statistics so the editorial team can read them in a dashboard. Communication tools handle the delivery of messages sent through the contact form. Cybersecurity partners may receive data as part of threat monitoring and mitigation.
Each of these processors receives only the information needed to perform its specific task. They are not permitted to use the data for their own purposes, to build their own profiles of visitors, or to pass the data on to further parties without instruction. Where a processor operates outside the visitor’s country of residence, the transfer relies on standard contractual safeguards recognised for cross-border data protection.
The website does not sell personal data, and it does not share it with advertisers or data brokers. Aggregate, anonymised statistics may be discussed publicly, but these contain no identifying details.
Protecting Stored Data
Access to stored information is restricted to people who need it for the purposes described in this notice. Internal procedures govern who can view correspondence records and who can run reports on traffic data. Secure connections protect data in transit, and administrative access to the site’s backend requires authentication.
Monitoring systems watch for unusual activity, such as a sudden spike in failed logins or an unexpected pattern of data requests, and alerts are raised when something looks off. Despite these measures, no method of electronic storage or transmission is completely secure. The website therefore cannot guarantee absolute protection against every conceivable breach, and it encourages visitors to use strong, unique passwords wherever they create accounts on external platforms.
Engagement Data in Responsible Gaming Content
Pages related to responsible gambling and player protection occasionally incorporate limited engagement data. The purpose is straightforward: to see which educational resources are actually being read, which sections of a guide are skipped, and whether a visitor who opens a self-exclusion explainer continues to related pages. This informs decisions about where to place warnings and how to phrase them so they reach the people who need them.
The data used for this purpose is aggregated and anonymised. The website does not track individual players, does not build profiles of at-risk behaviour, and does not link browsing patterns to any identity. The goal is to make protection resources more visible and more practically useful, not to monitor how any single visitor interacts with them.
Visitor Rights and Requests
Depending on the privacy framework that applies to the visitor’s location, a range of rights may be available. These include the right to access stored personal data, to receive a copy in a portable format, to request correction of inaccurate details, to ask for deletion where the data is no longer needed, and to withdraw consent from specific processing activities such as optional communications.
Submitting a request is done through the website’s contact channels. Before acting on a request, the website verifies the identity of the person making it, which prevents one visitor from accessing or altering another’s data. The verification step typically involves confirming details that only the requester would know, such as the email address used in a previous message.
Once verified, the request is processed without undue delay. Where a request is refused, the visitor receives an explanation of the reason, which might be a legal obligation to retain the data or a legitimate interest that overrides the deletion request. A refusal does not end the matter: the visitor retains the right to lodge a complaint with the relevant supervisory authority in their region.
How Long Information Is Kept
Retention periods are not fixed across the board; they depend on why the data was collected in the first place. Correspondence records are kept as long as they serve a valid purpose, which could mean until the conversation is resolved, or longer if the topic raises a dispute that needs a paper trail. Server logs accumulate for a limited operational window before they are rotated and overwritten.
Analytics data is retained in a form that allows meaningful trend comparison, then aggregated or stripped of identifying details. Consent records, such as the choice a visitor made in the cookie banner, are kept for as long as they need to be defensible, since the website must be able to demonstrate that it respected the visitor’s preference. In every case, the guiding principle is the same: data stays only while it serves a genuine technical, operational, security, or legal purpose, and it is deleted, anonymised, or locked down in restricted form once that purpose lapses.
External Links and Third-Party Pages
Reviews on this website regularly mention casinos, game providers, and comparison tools, and some of those mentions include links that take a visitor away from this site. Once a visitor clicks through, this privacy notice stops applying. The external site has its own policies, its own data practices, and its own contact channels, and this website has no control over any of them.
Readers are advised to check the privacy statement of any external site before supplying personal information. This website bears no responsibility for how third parties collect, use, or protect data after a visitor has left these pages, and it cannot act as an intermediary in disputes with those parties.
Changes to This Notice
This notice is reviewed periodically and may be updated to reflect changes in how the website operates, new legal interpretations, or shifts in industry practice. When a revision is published, the updated version replaces all earlier versions immediately, and the date of the latest revision is shown at the top of the page.
Material changes, such as a new category of data collection or a new type of third-party sharing, are flagged prominently so returning visitors can spot them without re-reading the entire document. Continued use of the website after a revision takes effect constitutes acceptance of the updated terms. Visitors who disagree with a change are free to stop using the site and to request deletion of their data through the contact channels.
Contacting the Website About Privacy
Questions about this notice, requests to exercise a privacy right, or concerns about how data has been handled can all be directed to the website’s contact channels. The contact form is the preferred route, as it routes messages to the right person and provides a record of the request. Privacy-related messages are treated with priority over general enquiries.
When writing, it helps to be specific about the nature of the request, whether it is a question about retention, a request for a copy of stored data, or a complaint about a specific processing activity. The website aims to acknowledge receipt promptly and to resolve the matter within a reasonable time. If a request cannot be fulfilled, the response explains why and outlines any further steps available to the visitor.