Legal

Privacy Policy

Last updated: July 21, 2026. This page is maintained by Casino API Provider to explain how personal data is handled on gamingapi.shop and the connected admin and client dashboards.

1. Who we are

Casino API Provider ("we", "us") operates the gamingapi.shop platform, a business-to-business casino aggregator and iGaming API used by regulated operators. This policy applies to visitors of the marketing site, applicants for API access and authenticated users of our client and admin panels.

2. Data we collect

  • Account data — name, business email, company, Telegram handle you submit through the contact form or signup.
  • Authentication data — email, hashed password, and optional TOTP secret for 2FA. Passwords are never stored in plain text.
  • Operational data — API keys, wallets, transactions and support tickets you create while using the platform.
  • Technical data — IP address, user agent, request timestamps, error logs used to secure and improve the service.
  • Cookies — a strictly-necessary session cookie for auth and a preference cookie for currency and theme.

3. How we use data

We use personal data to provide the API and dashboards, respond to sales and support requests, meet legal and regulatory obligations (KYC, AML, jurisdictional rules for iGaming operators) and to detect abuse. We do not sell personal data.

4. Legal bases (GDPR/UK-GDPR)

Contract performance (running your account), legitimate interests (fraud prevention, product analytics), consent (marketing where required) and legal obligation (record-keeping for regulated operators).

5. Subprocessors

We rely on the following categories of processors: cloud hosting and edge delivery (Cloudflare), managed database and auth (Supabase), transactional email, KYC verification vendors chosen by the operator, and analytics tooling. A current list is available on request from privacy@gamingapi.shop.

6. International transfers

Data may be processed outside the EEA/UK. Where that occurs we rely on Standard Contractual Clauses and equivalent safeguards.

7. Retention

Marketing enquiries: up to 24 months. Account and transactional data: while the account is active plus the retention window required by the operator's licensing regulator (typically 5–10 years for iGaming). Audit logs: 12 months rolling.

8. Your rights

Access, rectification, erasure, restriction, portability and objection. Email privacy@gamingapi.shop and we will respond within 30 days.

9. Security

TLS 1.2+ in transit, encryption at rest, RBAC with row-level security, TOTP-based 2FA for admin accounts, audit logging on privileged actions, HMAC-signed provider callbacks. We publish security updates and respond to reports at security@gamingapi.shop.

10. Contact

Casino API Provider · privacy@gamingapi.shop · Telegram @CasinoxApix