Privacy

InstaSpin Privacy Policy

What data we collect, how we protect it and what your rights are under the UK GDPR.

TLS encryption

All communication between your device and our servers is end-to-end encrypted.

Transparent

We tell you exactly what we collect and why.

GDPR compliant

Processing in accordance with the European data protection law of 2018.

Access rights

Request an overview or correction of your data at any time.

Introduction

InstaSpin respects your privacy and processes personal data solely in accordance with the UK General Data Protection Regulation (UK GDPR). This privacy policy explains in plain language what data we collect, why we do so, how long we retain it and what rights you have as a visitor or player. The policy applies to all interactions with the website instaspin.live, including browsing pages, completing forms and using your account. As data controller within the meaning of Article 4(7) UK GDPR, InstaSpin is committed to transparency about the legal bases for processing: contract performance under Article 6(1)(b), compliance with legal obligations under Article 6(1)(c), and legitimate interests under Article 6(1)(f) for security and fraud-prevention measures. Direct marketing is conducted solely on the basis of your explicit consent under Article 6(1)(a). You may withdraw that consent at any time without suffering any disadvantage.

What data we collect

We distinguish three categories. Identification data includes your name, date of birth, address, email address and telephone number. This data is required to comply with statutory age verification and the KYC requirements applicable to the online gambling market. Financial data includes your payment method, transaction history and balance. This is processed to enable deposits, withdrawals and bonus settlement.

Behavioural data includes technical information such as IP address, browser type and visit statistics, plus playing behaviour such as which games you play, how much time you spend on them and which bonuses you activate. This data is analysed to improve the site, prevent fraud and identify signs of problem gambling at an early stage. This analysis of playing behaviour is carried out solely for the stated purposes and not to build commercial profiles for sale to third parties. The algorithms used are regularly reviewed for bias and fairness to ensure no group of players is treated less favourably. Insights from this analysis feed directly into the development of our Responsible Gambling tools.

Purposes of processing

We process your data for six main purposes: to perform the contract between you and InstaSpin, i.e. making the gaming offering and related administration available; to fulfil legal obligations, including age verification, anti-money-laundering rules and gambling tax; and to protect players against fraud, identity theft and problem gambling.

To improve our services through anonymised analysis of user behaviour; to send direct marketing, only after explicit consent and with a simple opt-out; and to respond to customer queries through our support channels.

With whom we share data

InstaSpin never sells personal data to third parties for commercial purposes. We share data only with parties necessary for our service provision: payment processors such as Trustly, Mifinity and card companies; identity verification services for KYC checks; technical service providers hosting our servers and software; and legally authorised authorities upon a justified request.

All external parties sign a data processing agreement and must comply with the UK GDPR. For transfers outside the UK or European Economic Area we use the Standard Contractual Clauses of the European Commission as the legal basis.

Retention periods

Data is not retained longer than necessary. Account data and transaction history are kept for seven years after account closure, in line with fiscal retention obligations. Marketing preferences are kept until you actively withdraw them. Technical logs are anonymised or deleted after 90 days. Identity verification documents such as copies of ID are deleted once the verification process is complete, unless a statutory retention obligation applies. For anti-money-laundering purposes, transaction and identification data are retained for a minimum of five years. Once all applicable retention periods have expired, data is securely deleted or fully anonymised so that no further link to your identity remains.

Security

Our systems are protected with modern encryption, two-factor authentication for administrative access, and regular penetration tests by external specialists. Passwords are stored hashed using the bcrypt standard. In the event of a data breach posing a high risk to your rights, we will inform you within 72 hours and report it to the relevant supervisory authority. We also train staff regularly in the secure handling of personal data and have implemented internal data protection policies that restrict access to customer data to the minimum required. Access to production databases is secured via role-based access controls, and all database accesses are logged and reviewed monthly. Independent security audits are commissioned regularly to ensure our protective measures remain aligned with the current state of the art.

Your rights under the UK GDPR

You have the right of access, rectification, erasure, restriction and portability of your data, plus the right to object to specific processing activities. Send requests to privacy@instaspin.live with a copy of a valid identity document for verification. We respond within 30 days free of charge. In detail: the right of access allows you to request a complete copy of all data held about you; the right to rectification lets you have inaccurate or incomplete information corrected; the right to erasure applies unless a statutory retention obligation prevents deletion; the right to restriction allows you to limit processing temporarily while an objection is under consideration; the right to portability lets you receive your data in a structured, machine-readable format for transfer to another controller; and the right to object applies especially to processing based on legitimate interests.

If you disagree with our handling, you can lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. For general privacy questions you can also visit our Contact page. Additionally, read our Cookie Policy for specific information about cookies and tracking.

Changes

This policy is updated periodically to reflect changes in legislation or business practices. The current version is dated 8 May 2026. Material changes will be announced via a notification on your account dashboard.

Frequently asked questions