Entering online gaming can be thrilling, but it also raises questions about what happens to your personal information https://piperspinscasino.es/legal-and-affiliates/. At PiperSpin Casino, we think understanding data protection should resemble a conversation, not a law exam. Whether you are spinning the reels for the first time or joining our affiliate programme, knowing how your data is collected, used, and safeguarded builds the trust every great gaming experience depends on. This guide takes you through the essentials of our data protection policies in plain language, with a clear focus on the rights and responsibilities that matter to players and partners in Spain. We are focused on full transparency, and this is your starting point for feeling secure every time you visit us.
What a Data Protection Policy Really Includes
Many newcomers assume a data protection policy is just another document of small print they can overlook. It truly is a commitment. In essence, this policy details precisely what data we collect, why we need it, and how we safeguard it. For an internet casino such as PiperSpin Casino, that means outlining everything from the email address you use to sign up to the verification documents required by Spanish law. The policy also describes who we share information with, such as payment processors or regulatory bodies, and under what rigorous terms. By reviewing it, you get a clear understanding of your rights and our responsibilities. We see this document not as a shield for the business, but as an instrument that helps you make knowledgeable decisions about your privacy while playing on our platform.
The Main Principles We Uphold
All determinations we arrive at concerning your data relies on a few core principles. Legality means we deal solely with personal information when we have a valid legal reason, such as satisfying a contract with you or following anti-money laundering regulations. Equity and transparency oblige us to tell you upfront what happens to your data, never hiding details in complicated jargon. Restriction of purpose ensures we obtain data for specific, explicit reasons, like processing a withdrawal, and never redirect it for unrelated marketing without your clear consent. Data minimisation keeps us focused on gathering only what is necessary. These principles are not abstract ideals; they are the practical rules that form our daily operations and protect every member of the PiperSpin Casino community.
How Data Safeguarding Works to iGaming
The online gaming industry handles highly confidential categories of information, which makes strong data protection non-negotiable. Beyond basic contact details, we manage payment operations, ID verification files, and at times behavioral information that supports our efforts for responsible gambling. In Spain, operators like PiperSpin Casino must also comply with specific directives from the Dirección General de Ordenación del Juego (DGOJ) on top of the General Data Protection Regulation (GDPR). This dual layer of oversight means our policies are structured to meet rigorous standards that protect both your privacy and the soundness of the gaming environment. Understanding this context helps you see why we require certain documents during account verification. It is not just administrative procedure, but a legal protection for everyone involved.
Security Measures That Protect Your Data
Strict policies are meaningless without solid security underpinning them. At PiperSpin Casino, we use a tiered approach to shield your confidential and financial information from unauthorized access, alteration, or loss. Our platform utilises industry-standard encryption protocols, including TLS (Transport Layer Security), to guard data during transfer between your device and our servers. We also maintain strict access controls within our organisation, guaranteeing that only authorized personnel with a valid business need can access private information. Routine security audits, vulnerability scans, and penetration testing help us detect and address potential weaknesses before they can be abused. While no online system can promise absolute invulnerability, our constant investment in security technology and staff training shows our dedication to ensuring your data safe.
How We Obtain and Employ Your Data
Clarity about data collection involves knowing the various ways data reaches us. We gather data via direct contact, automated technologies, and verified partners, always with a clear purpose attached. When you create an account, we request information like your name, date of birth, and address to verify your identity and make sure you meet the legal age requirement. If you participate in our affiliate programme, we gather business information to manage commissions and uphold our partnership. Every piece of data possesses a clear function, whether it involves handling a deposit, dispatching a withdrawal confirmation, or enhancing our website’s performance. We never sell your personal information to third-party promoters, and we tightly control internal access to staff who require it to assist you.
Information You Supply In Person
The bulk of the data we keep is obtained directly from you by way of forms, chats, and account settings. This covers registration details, payment method information, and any documents you submit for Know Your Customer (KYC) checks, such as a passport or utility bill. When you reach out to our support team, we store a record of that conversation to handle issues promptly and better our service. If you subscribe to marketing communications, we register your preferences to dispatch only relevant offers, and you can adjust these settings at any time. We treat all directly provided information as confidential, using it exclusively to deliver the services you have asked for and to satisfy our legal obligations under Spanish gambling regulations.
Data Gathered Automatically
As with most modern websites, PiperSpin Casino uses automatic systems to gather certain technical data when you browse our pages. This covers your IP address, device type, browser version, and how you interface with our games and features. We use cookies and similar technologies to store your preferences, maintain your session secure, and examine site traffic. This automatic collection helps us spot potential fraud, like unusual login patterns, and enables us to tailor your experience without jeopardizing your privacy. You can manage cookie settings through your browser, though deactivating essential ones may affect site functionality. We constantly seek consent for non-essential tracking in line with Spanish e-privacy rules.
Data Sharing Within Our Affiliate Programme
Our affiliate programme is founded on partnerships that depend on trust, and data protection sits at the heart of that relationship. When you sign up as an affiliate, we share only the information essential to track referrals, calculate commissions, and maintain the integrity of the programme. This generally includes a unique affiliate ID, aggregated performance statistics, and, in some cases, pseudonymised data about referred players. We never expose sensitive player details to affiliates, and we require every partner to adhere to strict data processing terms. Understanding these boundaries is essential for both new and experienced affiliates who want to promote PiperSpin Casino responsibly while staying fully compliant with Spanish and EU privacy regulations.
Essential Details for Affiliates
As an affiliate, you serve as an independent promoter, not as a data controller for player information. You will have access to a dashboard showing clicks, registrations, and commission earnings, but you will not see individual player identities, payment details, or contact information. This separation is deliberate and legally required. If your promotional activities involve collecting any personal data yourself, for example, through a mailing list, you bear full responsibility for complying with the GDPR and LOPDGDD for that data. We recommend every affiliate post their own clear privacy policy and obtain proper consent before gathering any user information. Our team provides guidance to help you align with these expectations from day one.
Data Processing Agreements
Before you start earning commissions, we require all affiliates to enter into a Data Processing Agreement (DPA) where applicable. This contract defines the scope, duration, and purpose of any data handling that touches our systems. It mandates that you implement appropriate technical and organisational measures to protect information, report any data breaches without delay, and assist us in responding to data subject requests if your actions affect our obligations. The DPA also prohibits you from using shared data for any purpose beyond the agreed campaign tracking. We keep these agreements simple and transparent, reflecting our commitment to making compliance accessible even for those new to affiliate marketing in the regulated Spanish market.

Your Rights Under Spanish and EU Law
As a user or affiliate located in Spain, you are safeguarded by some of the world’s most stringent data privacy laws. The GDPR and the Spanish Organic Law on Data Protection and Digital Rights (LOPDGDD) provide you with a set of enforceable rights over your personal information. We have structured our internal processes to make asserting these rights straightforward, not a bureaucratic maze. If you want to see what data we hold, correct an error, or request deletion, our support team is prepared to handle your request quickly and without unnecessary friction. Knowing these rights transforms you from a passive user into an active participant in your own privacy protection, and we urge every newcomer to make themselves familiar with the tools available.
Access, Rectification, and Portability
You have the right to demand a copy of the personal data we process about you at any time. This access right enables you to verify that we are handling your information lawfully. If you spot an inaccuracy, the right to rectification enables you to have incomplete or incorrect data corrected without undue delay. The right to data portability means you can receive certain information in a structured, commonly used format and even transfer it to another service provider where technically feasible. For example, you could request a machine-readable file of your transaction history. To assert any of these rights, simply contact our Data Protection Officer through the channels listed on our website, and we will respond within the legally mandated timeframe.
Removal, Restriction, and Objection
In specific circumstances, you can ask us to delete your personal data, often called the right to be forgotten. This applies, for instance, when the data is no longer necessary for the purpose we collected it, or if you withdraw consent and no other legal ground for processing exists. Please note that legal obligations, such as anti-money laundering record-keeping, may require us to retain certain information for a set period. You also have the right to restrict processing while a dispute over data accuracy or lawfulness is resolved, and the right to object to processing based on legitimate interests, including profiling for direct marketing. We respect all valid objections and never penalise you for exercising these fundamental rights.
Frequently Asked Questions
Is my payment information stored on your servers?
We do not store full credit card numbers or CVV codes on our systems. Payment transactions are handled by PCI-DSS compliant third-party gateways focused on secure financial processing. Our records only retain tokenised references and transaction amounts necessary for your account history and dispute resolution. This method reduces risk and complies with rigorous industry security standards.
May I ask for the complete removal of my account and data?
Certainly, you may request to close your account and erase your data whenever you wish. All personal information we are not legally obliged to keep will be deleted. Note that anti-money laundering regulations in Spain require us to retain specific records, including transaction logs and identity verification documents, for a set period even after account closure. We will transparently outline what records are kept and their retention period.
How long do you retain my personal data?
Retention periods vary depending on the type of data and the purpose for which it was collected. As a rule, we retain your account information for as long as you are a customer, plus five years after your last activity to meet legal requirements. Marketing data is retained until you withdraw your permission. Once the applicable retention period ends, we securely delete or anonymise your data.
