Nine Casino Privacy Policy: How Account and Payment Data Is Handled

Scope and last update

Last updated: 21 August 2026. This policy explains the processing of registration, identity, payment, device, gameplay, communication and safer-gambling data connected with Nine Casino services.

Data collected

Account fields include name, birth date, address, email, telephone and credentials. KYC may include identity and address documents, payment ownership and source-of-funds evidence. Technical records include IP address, device, browser, cookies, login events and fraud signals.

Why processing occurs

Data supports account performance, legal compliance, payment execution, fraud prevention, security, customer service, responsible gambling, analytics and marketing preferences. Each purpose should rely on contract, legal duty, legitimate interest or consent as applicable.

Recipients and transfers

Payment processors, identity services, game suppliers, hosting providers, professional advisers and authorities may receive limited data where required. Contracts and security controls should govern international processing.

Retention and security

Records are retained for operational, dispute, anti-money-laundering and regulatory periods, then deleted or anonymised. Access controls, encryption in transit, monitoring and staff restrictions reduce exposure but cannot remove every online risk.

Player choices and rights

Depending on jurisdiction, a user may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. Identity verification can be required before a privacy request is fulfilled. Marketing choices are separate from essential account messages.

Lawful purposes and minimisation

Account data is processed to provide the service, meet legal and security duties, execute payments, prevent fraud, resolve disputes and administer player-protection controls. Collection should remain limited to information relevant to those purposes. Marketing consent must be separated from essential account processing where law requires it.

Automated risk signals

Device, payment and gameplay signals may identify duplicate accounts, account takeover, bonus abuse or suspicious transactions. An automated flag can trigger a manual review rather than deciding the final outcome alone. A player may request information about an adverse decision subject to fraud-prevention and legal restrictions.

Breach and incident response

Security incidents are assessed by scope, data type and likely harm. Access credentials may be reset, sessions revoked and affected payment methods restricted. Where notification is legally required, it should describe the incident, likely consequences, mitigation and contact route without exposing security details.