This Privacy Policy explains how Vegastars Casino handles personal data of Australian players across the account lifecycle. Specifically, the document covers data collection, processing purposes, legal bases, cookies, sharing model, international transfers, retention windows and player rights. Furthermore, Neptune Projects S.R.L. acts as the data controller under the published policy. As a result, AU punters gain a clear view of their data rights and the operator’s obligations.
Data Controller
Neptune Projects S.R.L. is the data controller for every processing activity involving Vegastars personal data. The company holds registration number 3-102-900308 in Costa Rica, with a registered address in Curridabat, San Jose. Privacy questions go to [email protected] under that controller relationship. AU players therefore send data-access, deletion and consent updates to this one privacy address.
Neptune Projects S.R.L. holds controller status in every region the brand serves. AU, EU, NZ and CA player data all sit under the same controller. The operator does not pass controller responsibility to local affiliates or regional partners. Every privacy obligation therefore runs directly through the Costa Rica entity, whatever the player's location.
Categories of personal data collected
The operator collects several separate categories of personal data from AU players across the account lifecycle. These cover identity, financial activity, technical signals, communications and responsible-gaming indicators. The data supports account operations, regulatory compliance, fraud prevention and product improvement. The platform therefore works with a structured data set rather than an open-ended collection.
Identity and contact data
Identity and contact data form the foundation of the player record on the platform. Specifically, the operator collects name, date of birth, residential address, email and phone number. Furthermore, nationality and verification-document copies support KYC processes. In addition, identity proof and address proof documents persist as part of the AML records under retention rules.
Account and transaction data
Account and transaction data records every financial and gameplay event on the account. Specifically, the data includes account credentials, deposits, withdrawals, wager history and gameplay history. Furthermore, payment-method details, bonus activations, chargebacks and dispute records sit in the same data category. Therefore, the financial-data set persists beyond an active session for regulatory and audit purposes.
KYC, AML and compliance data
KYC, AML and compliance data covers the identity-verification trail across the account lifecycle. Specifically, the operator stores verification results, due-diligence records and sanctions screening outcomes. Furthermore, PEP (politically exposed persons) screening results and source-of-funds information sit in the same category. As a result, this data category drives the regulatory compliance layer rather than the player-facing service.
Technical and usage data
Technical and usage data captures the device and session signals from every account session. Specifically, the operator logs device identifiers, IP addresses, approximate location (city/country-level), browser and operating system. Furthermore, cookies, session and activity logs, security logs and crash diagnostics also enter the data flow. Therefore, the platform works with country-and-city-level location signals rather than precise GPS-based location.
Communications Data
Communications data covers every interaction between the player and the operator’s support team. Specifically, the record includes emails, live-chat transcripts, webform submissions and support tickets. Furthermore, the operator retains the data for service improvement, dispute resolution and quality control. As a result, AU players can request transcript copies through the [email protected] privacy contact.
Responsible gambling signals
Responsible-gambling signals record session and spend patterns flagged by the operator’s RG framework. Specifically, the data includes session duration, spend patterns and the player’s use of RG tools such as limits and time-outs. Furthermore, the operator analyses the data to identify at-risk play and trigger interventions. Therefore, RG signals can result in account-level interventions in line with the Responsible Gambling Policy.
Preferences and survey data
Preferences and survey data covers the choices and feedback a player gives voluntarily. It includes marketing opt-in status, cookie preferences, and language and UI preferences. Voluntary survey answers and feedback responses fall into the same category when a player chooses to supply them. This data supports marketing personalisation and product-improvement decisions under the consent framework.
How we use personal data
The operator uses personal data for a defined set of purposes set out in the published privacy policy. These purposes cover account operation, gameplay, payments, bonuses and customer support. Identity verification, legal compliance, AML and sanctions screening also belong to the set. Fraud prevention and platform-security work draw on the wider data set as well.
Marketing communications run only where the player has opted in via account preferences. Specifically, promotional emails about welcome-stack updates, new releases and tournaments require active consent. Furthermore, the operator does not send unsolicited marketing to AU players who opt out at sign-up or later. Therefore, consent management runs through the account preferences panel inside the dashboard.
Analytics, reporting, forecasting and finance work also use processed account data on an aggregate basis. Commercial analytics run on aggregated rather than individual data wherever possible. Audit and compliance oversight can access detailed records where regulation requires it. The data therefore serves operational and regulatory functions in parallel across the account lifecycle.
Legal bases for processing
Four main legal bases, set out in the published policy, cover the operator's processing of personal data. Contract necessity covers account operation, payments and service delivery. Legal obligation covers AML, CTF, sanctions screening and regulatory compliance. Legitimate interests cover security, fraud prevention and platform improvement.
Consent applies to specific processing categories where the law requires it. Marketing communications and non-essential analytics cookies both need explicit consent. A player can withdraw consent at any time through the account preferences panel or by emailing [email protected]. The consent layer therefore works independently of the contract-necessity and legal-obligation layers.
Cookies and similar technologies
The platform uses cookies, SDKs and similar tools throughout the website experience. Cookies fall into essential, functional, analytics and advertising buckets. Blocking some categories can affect site functionality and account access. AU players manage cookie preferences through the cookie banner on their first visit and the settings panel after that.
Essential cookies support login persistence, cashier flow and basic site operation. Specifically, removing essential cookies blocks the player from staying signed in across page navigations. Furthermore, these cookies do not require explicit consent under the published policy. Therefore, essential cookies run by default for any active session on the platform.
Functional, analytics and advertising cookies make the site easier to use and guide operational decisions. The cookie banner offers per-category controls during the first session. A player can return to cookie preferences through the account settings panel at any time. AU punters therefore keep granular control over the non-essential cookie categories.
Data sharing with third parties
The operator neither sells nor shares personal data outside a defined disclosure framework. Limited data goes to service providers and processors strictly for operational purposes. Group companies, regulators and public authorities receive data on specific legal grounds. Business-transfer parties may also receive data during M&A activity, with appropriate safeguards in place.
| Recipient Type | Purpose | Legal Basis |
|---|---|---|
| Hosting and security vendors | Platform operation and security | Legitimate interest |
| KYC / AML verification providers | Identity and compliance checks | Legal obligation |
| Payment processors and banks | Cashier processing | Contract |
| Game Studios | Game content operation | Contract |
| Fraud prevention providers | Anomaly detection | Legitimate interest |
| CRM and communications vendors | Customer service | Contract |
| Group Companies | Operations and compliance | Legitimate interest |
| Regulators and authorities | AML, CTF, regulatory reporting | Legal obligation |
| Business transfer counterparts | Merger / acquisition / restructuring | Legitimate interest |
| Player-directed public display | Leaderboard nicknames | Consent |
Service providers work under written processing agreements that limit how they use data. KYC processors receive document data for verification purposes only, within contractual limits. Third-party providers cannot reuse that data for unrelated commercial purposes. The data flow therefore stays under operator control even when approved vendors process it externally.
International Transfers
Operational requirements mean the operator may process and store personal data in countries other than Australia. Processing may take place in Costa Rica (headquarters), Cyprus (card payments), or third-country service-provider locations. The operator puts contractual and other safeguards in place for cross-border transfers. AU player data may therefore move across several jurisdictions under data-protection-equivalent guarantees.
Processor countries are chosen for operational and regulatory fit rather than convenience. Card-payment processing runs through Sultucia Limited in Cyprus under the merchant-of-record arrangement. KYC and AML verification may run through specialist processors in other EU or EEA jurisdictions. The international-transfer footprint therefore mirrors the operational supply chain rather than data minimisation alone.
Security Measures
The operator applies layered technical and organisational security measures across the platform. The framework combines encryption, access controls, logging and monitoring as complementary controls. These controls aim to protect the confidentiality, integrity and availability of data. The platform therefore meets industry-standard security baselines for online casino operators.
The published security controls cover the following measures across the platform:
- Encryption in Transit. SSL/TLS protects all browser-to-server traffic across the site.
- Access Controls. Need-to-know access restrictions cover authorised personnel only.
- Logging and Monitoring. Continuous activity logging runs alongside anomaly detection.
- Vulnerability Management. Regular scans and patches address known software vulnerabilities.
- Incident Response. A defined response process covers breach scenarios end-to-end.
- Independent Testing. RNG outcomes claim independent testing for fairness per the FAQ.
Data Retention
The operator keeps personal data only as long as necessary under the published privacy policy. AML and KYC records carry a minimum 5-year retention from account closure under regulatory rules. Financial records may be kept longer where tax or audit law requires it. Retention windows therefore follow the regulatory environment rather than commercial preference.
Active accounts hold data continuously to support gameplay, payments and compliance. Transaction history remains for the account's active life under regulatory rules. Closing an account does not erase regulatory data that is subject to retention rules. AU players who close an account should therefore expect AML records to remain for at least five years afterwards.
Underage data protection
The operator does not knowingly collect data from anyone under the minimum gambling age. Its minimum age is 18 globally, and any higher jurisdictional age applies instead. If a verification check uncovers an underage player, the platform deletes the data and closes the account. AU underage protection therefore reflects both the operator's 18-year floor and AU domestic gambling-age rules.
Reports of suspected underage account activity go to [email protected] for priority review. The operator investigates each report as a priority and locks confirmed accounts immediately. Confirmed underage accounts close with full data deletion. AU parents and guardians can flag suspected accounts through the same support channel.
Player Rights
AU players hold defined rights over their personal data under the published policy. These rights cover access, correction, deletion and portability requests across the data categories. Players can also object to certain processing or withdraw marketing consent at any time. AU players therefore keep meaningful control over the lifecycle of their personal data.
Rights requests go through [email protected] under the data-controller relationship. A data-access request returns a structured copy of the held data within the statutory window. The operator answers rights requests inside the statutory time windows that apply in the player's jurisdiction. Identity verification accompanies every rights request to prevent fraud or impersonation.
Updates to this privacy policy
The operator may update this privacy policy, giving players reasonable notice. Material changes - new processing purposes, new recipient categories, or new retention periods - trigger explicit notification. The updated policy appears on the website with an effective date. AU players therefore see a clear timestamp on the current version of the policy.
If you keep using the platform after an updated policy takes effect, you accept it. Specifically, the operator does not quietly apply material changes to existing players. Furthermore, AU players who object to a material change can ask for their account to be closed and their full balance refunded, subject to the standard rules. Therefore, the update mechanism keeps operator flexibility while remaining transparent about player consent.
Privacy Contact
Privacy queries for Vegastars go to [email protected], under the data-controller relationship with Neptune Projects S.R.L. Specifically, that address deals with requests for data access, correction, deletion and portability. Furthermore, complaints about data handling go to the same address. As a result, AU players direct every privacy matter to one dedicated channel, which keeps handling consistent.