1. Who we are
Casino API Provider ("we", "us") operates the gamingapi.shop platform, a business-to-business casino aggregator and iGaming API used by regulated operators. This policy applies to visitors of the marketing site, applicants for API access and authenticated users of our client and admin panels.
2. Data we collect
- Account data — name, business email, company, Telegram handle you submit through the contact form or signup.
- Authentication data — email, hashed password, and optional TOTP secret for 2FA. Passwords are never stored in plain text.
- Operational data — API keys, wallets, transactions and support tickets you create while using the platform.
- Technical data — IP address, user agent, request timestamps, error logs used to secure and improve the service.
- Cookies — a strictly-necessary session cookie for auth and a preference cookie for currency and theme.
3. How we use data
We use personal data to provide the API and dashboards, respond to sales and support requests, meet legal and regulatory obligations (KYC, AML, jurisdictional rules for iGaming operators) and to detect abuse. We do not sell personal data.
4. Legal bases (GDPR/UK-GDPR)
Contract performance (running your account), legitimate interests (fraud prevention, product analytics), consent (marketing where required) and legal obligation (record-keeping for regulated operators).
5. Subprocessors
We rely on the following categories of processors: cloud hosting and edge delivery (Cloudflare), managed database and auth (Supabase), transactional email, KYC verification vendors chosen by the operator, and analytics tooling. A current list is available on request from privacy@gamingapi.shop.
6. International transfers
Data may be processed outside the EEA/UK. Where that occurs we rely on Standard Contractual Clauses and equivalent safeguards.
7. Retention
Marketing enquiries: up to 24 months. Account and transactional data: while the account is active plus the retention window required by the operator's licensing regulator (typically 5–10 years for iGaming). Audit logs: 12 months rolling.
8. Your rights
Access, rectification, erasure, restriction, portability and objection. Email privacy@gamingapi.shop and we will respond within 30 days.
9. Security
TLS 1.2+ in transit, encryption at rest, RBAC with row-level security, TOTP-based 2FA for admin accounts, audit logging on privileged actions, HMAC-signed provider callbacks. We publish security updates and respond to reports at security@gamingapi.shop.
10. Contact
Casino API Provider · privacy@gamingapi.shop · Telegram @CasinoxApix