Privacy Policy
This Privacy Policy explains how Bao Casino collects, uses, stores, and protects your personal information when you use our platform. We take data protection seriously and comply with applicable privacy regulations including GDPR where relevant. By using Bao Casino, you agree to the practices described in this policy.
Last updated: November 2024
Information We Collect
We collect several types of information to provide and improve our services:
Personal Information You Provide
When you register an account, we collect basic identification details: full name, email address, date of birth, country of residence, and postal address. During verification (KYC), we collect copies of government-issued ID, proof of address documents, and payment method verification images.
Payment information includes credit card numbers (stored securely through payment processors, not on our servers), e-wallet account details, cryptocurrency wallet addresses, and transaction history. We never store full credit card details - only the first six and last four digits for verification purposes.
Information Collected Automatically
When you use Bao Casino, we automatically collect technical data: IP address, browser type and version, device type (desktop, mobile, tablet), operating system, language preferences, referring website URLs, pages visited, time spent on pages, and clickstream data.
Gaming activity is tracked including games played, bet amounts, win/loss records, bonus claims, deposit and withdrawal history, and session duration. This data helps us detect fraud, ensure responsible gambling compliance, and improve user experience.
Cookies and Tracking Technologies
We use cookies to maintain your login session, remember your preferences, track website performance, and analyze traffic patterns. Essential cookies are required for the site to function - they enable account login and security features. Performance cookies help us understand how visitors interact with the site so we can improve navigation and features.
You can control cookie settings through your browser, but disabling essential cookies will prevent you from using certain features like staying logged in or accessing your account.
How We Use Your Information
Your personal data serves specific purposes, all related to providing gaming services and maintaining platform security:
Account Management
We use your information to create and manage your account, process registrations, verify your identity (KYC compliance), and provide customer support. This includes responding to inquiries, resolving disputes, and handling withdrawal requests.
Payment Processing
Financial data is used to process deposits and withdrawals, verify payment methods, prevent fraud and money laundering, and maintain transaction records as required by financial regulations.
Gaming Services
Your gaming activity data helps us provide game access, track bonus eligibility and wagering progress, manage VIP tier progression, calculate cashback rewards, and enforce betting limits and self-exclusion periods.
Security and Fraud Prevention
We monitor account activity to detect suspicious behavior, prevent multiple account abuse, identify fraudulent transactions, protect against unauthorized access, and comply with anti-money laundering (AML) regulations.
Communication
Your email address is used to send account notifications, withdrawal confirmations, bonus offers (if you opted in), important policy updates, and responses to support tickets. You can unsubscribe from marketing emails anytime through the link in each email or via account settings.
Legal Compliance
We process data to comply with licensing requirements, respond to legal requests from authorities, enforce our terms of service, resolve disputes and legal claims, and maintain records as mandated by gambling regulations.
Who We Share Your Data With
We do not sell your personal information to third parties. However, we share data with specific service providers necessary for platform operations:
Payment Processors
Credit card companies, e-wallet providers, cryptocurrency exchanges, and banking institutions receive payment information necessary to process transactions. These providers operate under their own privacy policies and security standards.
Game Providers
Software providers like Pragmatic Play, NetEnt, and Evolution Gaming receive limited data (typically just a player ID, not personal details) to deliver game sessions and track gameplay for fairness auditing.
Verification Services
Third-party KYC verification services analyze your submitted documents to confirm identity and prevent fraud. They access only the documents you upload for verification purposes.
Customer Support Tools
Live chat platforms and support ticketing systems may access conversation history and account details necessary to resolve your inquiries. Support staff are bound by confidentiality agreements.
Analytics Providers
We use analytics services to understand website traffic patterns, user behavior, and platform performance. These services collect anonymized data and do not have access to personally identifiable information without your explicit consent.
Legal Authorities
We disclose information to law enforcement, regulators, or courts when legally required through valid subpoenas, court orders, or regulatory investigations. This includes compliance with anti-money laundering investigations and gambling license audits.
How We Protect Your Data
Security measures are implemented at multiple levels to protect your personal information:
Encryption
All data transmission between your device and our servers uses SSL/TLS encryption (the same technology banks use). This prevents interception of sensitive information during login, deposits, or withdrawals. Stored data is encrypted at rest using industry-standard encryption algorithms.
Access Controls
Only authorized personnel have access to personal data, and access is granted on a need-to-know basis. Staff undergo background checks and sign confidentiality agreements. Two-factor authentication is required for internal systems accessing player data.
Regular Security Audits
Our systems undergo periodic security assessments to identify vulnerabilities. Penetration testing, code reviews, and infrastructure audits are conducted by independent security firms.
Data Retention Limits
We retain personal data only as long as necessary for operational and legal purposes. Active accounts maintain full data records. Closed accounts have data archived for regulatory periods (typically 5-7 years depending on jurisdiction), then securely deleted.
Breach Notification
In the unlikely event of a data breach affecting your personal information, we will notify you within 72 hours via email and provide details about what data was compromised, steps we're taking to address the breach, and actions you should take to protect yourself.
Your Privacy Rights
You have specific rights regarding your personal data. Here's what you can do:
Right to Access
You can request a copy of all personal data we hold about you. Contact our support team with your request, verify your identity, and we'll provide a comprehensive data export within 30 days.
Right to Correction
If your personal information is inaccurate or outdated, you can request corrections. Most details can be updated directly in account settings. For changes requiring verification (like email addresses or names), contact support.
Right to Deletion
You can request deletion of your personal data, subject to legal retention requirements. We must retain certain records for regulatory compliance (typically 5-7 years for financial transactions), but non-essential data can be deleted upon request.
Right to Restrict Processing
You can ask us to limit how we use your data. For example, if you dispute data accuracy, we'll restrict processing while verifying your claim. Self-exclusion automatically restricts marketing communications.
Right to Data Portability
You can receive your personal data in a structured, machine-readable format (typically JSON or CSV) to transfer it to another service provider if desired.
Right to Object
You can object to certain data processing activities, particularly marketing communications. Opt-out links are included in all promotional emails, or adjust preferences in account settings.
Right to Withdraw Consent
Where we process data based on your consent (like marketing emails), you can withdraw consent anytime without affecting the lawfulness of processing done before withdrawal.
How Long We Keep Your Data
Data retention periods vary by data type and legal requirements:
- Account Information: Retained while your account is active plus 7 years after closure for regulatory compliance.
- Transaction Records: Maintained for 7 years minimum to comply with anti-money laundering regulations and tax laws.
- KYC Documents: Stored for 5 years after account closure as required by licensing authorities.
- Communication Logs: Support chat and email correspondence retained for 3 years for quality assurance and dispute resolution.
- Gaming Activity: Session logs and bet history kept for 5 years for fairness auditing and dispute resolution.
- Marketing Data: Deleted immediately upon unsubscribe request or within 2 years of last account activity if opted out.
After retention periods expire, data is securely deleted through irreversible processes including overwriting storage media and destroying physical records.
International Data Transfers
Bao Casino operates globally and may transfer your data to servers located in different countries. When transferring data internationally, we ensure adequate protection through:
- Standard contractual clauses approved by regulatory authorities
- Ensuring recipient countries have adequate data protection laws
- Implementing additional security measures for sensitive data
- Using data centers certified under international security standards (ISO 27001, SOC 2)
Players in jurisdictions with strict data protection laws (like the EU under GDPR) have the right to object to international transfers if inadequate protections are in place.
Children's Privacy
Bao Casino is strictly for adults 18 years or older. We do not knowingly collect information from minors. Age verification occurs during registration, and KYC documents confirm age before withdrawals are processed.
If we discover that a minor has registered an account, we immediately close the account, void all transactions, and delete the minor's data. Deposits are refunded to the payment source. If you suspect a minor has accessed our services, contact support immediately.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in legal requirements, business practices, or service features. Material changes will be communicated via email to registered users at least 30 days before taking effect.
The "Last Updated" date at the top of this policy indicates the most recent revision. Continued use of Bao Casino after policy changes take effect constitutes acceptance of the updated terms.
Contact Us About Privacy
For questions about this Privacy Policy, to exercise your data rights, or to report privacy concerns, contact us through:
- Email: [email protected]
- Live Chat: Available 24/7 through the website
- Mail: Address available in our Contact page
We respond to privacy requests within 30 days. For urgent matters, use live chat for faster response times.


