XSpinZone

PRIVACY POLICY

Your privacy matters. Learn how XSpinZone collects, uses, and protects your personal information on our social casino platform.

PRIVACY COMMITMENT

Last Updated: July 16, 2025 • XSpinZone is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, share, and protect your information when you use our social casino platform. We comply with GDPR, CCPA, and other global privacy regulations to ensure your data rights are respected. You have full control over your personal information and can exercise your privacy rights at any time.

 Effective Date: July 16, 2025 | Version: 2.0

TABLE OF CONTENTS

Information We CollectHow We Use InformationData Sharing & DisclosureData SecurityYour Privacy RightsChildren’s Privacy

 INFORMATION WE COLLECT

We collect information to provide you with the best possible gaming experience while maintaining your privacy. We are transparent about what we collect and why. Here are the categories of information we gather:

 UNIVERSAL RIGHTS

Right to Access

Request a copy of your personal data

Right to Correction

Update or correct inaccurate information

Right to Deletion

Request removal of your personal data

Right to Portability

Receive your data in a portable format

Right to Object

Opt-out of certain data processing

Right to Restriction

Limit how we process your data

 REGIONAL SPECIFIC RIGHTS

 California (CCPA/CPRA)

  • • Right to know categories of data collected
  • • Right to opt-out of data “sale”
  • • Right to non-discrimination
  • • Right to limit use of sensitive data

 European Union (GDPR)

  • • Right to withdraw consent
  • • Right to lodge complaints with DPA
  • • Right to automated decision-making info
  • • Enhanced data portability rights

 HOW TO EXERCISE YOUR RIGHTS

Step 1: Submit Request

Use our privacy dashboard, email privacy@xspinzone.com, or submit through your account settings

Step 2: Identity Verification

We’ll verify your identity to protect your privacy (usually via email confirmation)

Step 3: Processing

We’ll process your request within 30 days (45 days for complex requests with notice)

Step 4: Response

You’ll receive confirmation and any requested data in your preferred format

 DATA RETENTION

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations. Our retention periods are based on business needs and legal requirements.

Data CategoryRetention PeriodReason
Account InformationDuration of account + 90 daysService provision & recovery
Game DataDuration of accountGame continuity & progress
Transaction Records7 yearsLegal & tax requirements
Support Communications3 yearsService improvement & legal
Analytics Data26 monthsPlatform optimization
Security Logs1 yearSecurity & compliance
Marketing PreferencesUntil withdrawn + 30 daysPreference management

DELETION EXCEPTIONS

We may retain certain information beyond stated periods when required by law, for legitimate business purposes, or to protect legal rights. Anonymized data used for analytics may be retained indefinitely.

 INTERNATIONAL DATA TRANSFERS

As a global platform, we may transfer your personal information across international borders. We ensure all transfers comply with applicable data protection laws and implement appropriate safeguards.

TRANSFER MECHANISMS

Standard Contractual Clauses

EU Commission-approved contracts for data transfers

Adequacy Decisions

Transfers to countries with adequate protection levels

Explicit Consent

Your consent for specific transfers when required

DATA LOCATIONS

United States

Primary servers and data processing

European Union

EU user data and backup systems

Global CDN

Content delivery for performance

 CHILDREN’S PRIVACY

XSpinZone is committed to protecting children’s privacy. Our platform is designed for adults and we do not knowingly collect personal information from children under 18 years of age.

AGE RESTRICTION: 18+

You must be at least 18 years old to use XSpinZone. We employ age verification measures and will terminate accounts of users found to be underage.

  • • Age verification required during registration
  • • Immediate account termination if underage
  • • No marketing directed at minors
  • • Parental notification if underage user detected

 FOR PARENTS & GUARDIANS

If You Discover Your Child Has an Account

Contact us immediately at privacy@xspinzone.com. We will:

  • • Verify your identity as parent/guardian
  • • Immediately suspend the account
  • • Delete all personal information
  • • Provide confirmation of deletion

Prevention Measures

We implement multiple safeguards:

  • • Clear age warnings on all pages
  • • Age verification technology
  • • No content appealing to children
  • • Regular audits of user demographics

 THIRD-PARTY SERVICES & LINKS

Our platform may contain links to third-party websites and integrate with external services. We are not responsible for the privacy practices of these third parties, and we encourage you to review their privacy policies.

INTEGRATED SERVICES

Analytics Providers

Google Analytics, Adobe Analytics for usage insights

Customer Support

Zendesk, Intercom for support services

Infrastructure

AWS, Cloudflare for hosting and security

EXTERNAL LINKS

Not Our Responsibility

External sites have their own privacy policies. We are not responsible for their practices or content.

Clear Indicators

We clearly mark external links with icons to indicate you’re leaving our platform.

 HOW WE USE YOUR INFORMATION

We use your information only for legitimate purposes that benefit you and improve our platform. Every use of your data is designed to enhance your experience while respecting your privacy. Here’s how we use the information we collect:

SERVICE PROVISION

  • • Create and manage your account
  • • Provide access to games and features
  • • Save your progress and preferences
  • • Process virtual currency transactions
  • • Deliver customer support

PLATFORM IMPROVEMENT

  • • Analyze usage patterns and trends
  • • Optimize game performance
  • • Develop new features
  • • Fix bugs and technical issues
  • • Enhance user experience

SECURITY & SAFETY

  • • Detect and prevent fraud
  • • Protect against unauthorized access
  • • Monitor for harmful activities
  • • Enforce terms of service
  • • Comply with legal obligations

COMMUNICATION

  • • Send account notifications
  • • Respond to inquiries
  • • Share platform updates
  • • Deliver promotional content (with consent)
  • • Provide game recommendations

 LEGAL BASIS FOR PROCESSING

Under GDPR (European Users)

  • • Contract: To provide our services
  • • Consent: For marketing communications
  • • Legitimate Interest: For analytics and security
  • • Legal Obligation: To comply with laws

Under CCPA (California Users)

  • • Business purposes disclosed at collection
  • • No sale of personal information
  • • Right to opt-out of data sharing
  • • Equal service regardless of privacy choices

 DATA SHARING & DISCLOSURE

We do not sell your personal information. We only share your data in limited circumstances to operate our platform effectively and comply with legal requirements. Here’s when and how we may share information:

 SERVICE PROVIDERS

Infrastructure

  • • Cloud hosting (AWS)
  • • Content delivery (Cloudflare)
  • • Database management

Analytics & Support

  • • Google Analytics
  • • Customer support tools
  • • Email service providers

Security

  • • Fraud prevention services
  • • Security monitoring
  • • Identity verification

 All service providers are contractually bound to protect your data and use it only for specified purposes.

 LEGAL REQUIREMENTS & PROTECTION

Legal Obligations

We may disclose information when required by law, court order, or government request. We will notify you when possible unless prohibited by law.

Protection of Rights

We may share data to protect our rights, property, safety, or that of our users and the public, including fraud prevention and risk reduction.

Business Transfers

In case of merger, acquisition, or sale of assets, your information may be transferred. We’ll notify you before any transfer that results in a change to this policy.

 WITH YOUR CONSENT

Social Features

When you use social features like leaderboards or friend connections, certain information may be visible to other users based on your privacy settings.

Third-Party Integrations

If you connect third-party accounts or services, we’ll share only the information necessary for the integration with your explicit consent.

 DATA SECURITY

We implement industry-standard security measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction. Security is a top priority at XSpinZone.

 TECHNICAL MEASURES

Encryption

SSL/TLS encryption for data in transit, AES-256 for data at rest

Secure Infrastructure

Firewalls, intrusion detection, and regular security updates

Access Controls

Multi-factor authentication and role-based permissions

Regular Backups

Automated encrypted backups with tested recovery procedures

 ORGANIZATIONAL MEASURES

Employee Training

Regular privacy and security training for all staff

Security Audits

Annual third-party security assessments and penetration testing

Vendor Management

Strict vetting and contracts for all third-party processors

Incident Response

24/7 monitoring and rapid response procedures

 COMPLIANCE & CERTIFICATIONS

SOC 2 Type II

Audited annually

ISO 27001

Certified

GDPR

Compliant

PCI DSS

Level 1

 YOUR PRIVACY RIGHTS

You have comprehensive rights regarding your personal information. We respect these rights and provide easy ways to exercise them. Your rights may vary based on your location, but we strive to provide the highest level of protection to all users.

 INFORMATION YOU PROVIDE DIRECTLY

Account Information

  • • Email address
  • • Username
  • • Password (encrypted)
  • • Date of birth (for age verification)
  • • Profile picture (optional)
  • • Display preferences

Communication Data

  • • Support tickets and inquiries
  • • Feedback and suggestions
  • • Survey responses
  • • Chat messages (if applicable)
  • • Email communications
  • • Newsletter preferences

 AUTOMATICALLY COLLECTED INFORMATION

Device & Technical Data

  • • IP address and geolocation
  • • Browser type and version
  • • Operating system
  • • Device type and identifiers
  • • Screen resolution
  • • Time zone settings

Usage & Analytics Data

  • • Pages visited and features used
  • • Game play statistics
  • • Session duration and frequency
  • • Click-through rates
  • • Error logs and performance data
  • • Referral sources

 INFORMATION FROM THIRD PARTIES

Social Media

If you connect social accounts, we may receive your public profile information, friend lists, and email address.

Payment Processors

Transaction confirmations and fraud prevention data (we never store payment card details).

Analytics Partners

Aggregated demographic and interest data to improve our services and user experience.

 UPDATES TO THIS POLICY

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will notify you of any material changes and obtain consent where required.

UPDATE PROCESS

Advance Notice

30 days notice for material changes via email and platform notifications

Version History

All previous versions archived and available upon request

Consent Required

New consent obtained when required by law for significant changes

RECENT CHANGES

Version 2.0 – July 16, 2025

Enhanced data security section, updated retention periods

Version 1.5 – March 1, 2025

Added CPRA compliance, clarified international transfers

Version 1.0 – January 1, 2025

Initial privacy policy publication