Privacy Policy
Last updated: September 2026 · Pixi Casino
1. Introduction
Pixi Entertainment Ltd. ('Pixi Casino', 'we', 'us', 'our') is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Pixi Casino platform ('the Service').
This policy complies with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the laws of Malta. By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for your personal data is Pixi Casino.
For privacy concerns, contact us at privacy@pixi.casino.
3. Data We Collect
Registration data: email address, chosen username, date of birth confirmation (18+ verification), and password (stored as a cryptographic hash — we never store plaintext passwords).
Identity verification (KYC): government-issued photo ID, proof of address, and selfie when required by anti-money laundering (AML) regulations. KYC is triggered for withdrawals above defined thresholds.
Financial data: cryptocurrency wallet addresses used for deposits and withdrawals, transaction amounts, and payment processor reference IDs. We do not store private keys or full wallet credentials.
Gameplay data: bet history, game outcomes, session duration, wagering volumes, and bonus usage. This data is required for regulatory compliance and provably fair verification.
Device and technical data: IP address, browser user agent, device type, operating system, and session timestamps. Used for security, fraud detection, and responsible gambling monitoring.
Platform integrity telemetry: allowlisted Pixi page routes, selected account and product actions, timestamps, a first-party session identifier, broad device category, external referring domain when present, and your Pixi account identifier when signed in. This record excludes form contents, URL query strings, wallet addresses, network IP addresses, and raw browser identifiers.
Communications: any support tickets, chat messages, or correspondence you send to us.
4. How We Use Your Data
Providing the Service: processing bets, calculating payouts, managing balances, and facilitating deposits and withdrawals.
Regulatory compliance: maintaining AML/KYC checks, responsible gambling monitoring, and audit log maintenance.
Security and fraud prevention: detecting suspicious activity, preventing multiple accounts, and protecting the integrity of our platform.
Responsible gambling: monitoring play patterns that may indicate problem gambling, and triggering responsible gambling interventions where appropriate.
Communications: sending transactional emails (account confirmation, withdrawal updates), and — with your explicit consent — marketing communications about promotions.
Platform integrity: using limited first-party journey and event signals to detect bots, multi-accounting, coordinated activity, bonus abuse, payment misuse, software exploitation, and unauthorised account access. These signals support staff investigations and are not used for advertising or cross-site tracking.
5. Legal Bases for Processing
Contract performance (Art. 6(1)(b) GDPR): processing necessary to provide the Service you have signed up for, including account management, game operation, and payment processing.
Legal obligation (Art. 6(1)(c) GDPR): AML/KYC verification, regulatory reporting to the Malta Gaming Authority, and audit log retention required by law.
Legitimate interests (Art. 6(1)(f) GDPR): fraud prevention, platform and account security, promotion integrity, and responsible gambling monitoring. We limit journey telemetry to data reasonably needed for those purposes and assess adverse account action against confirmed account records rather than relying only on an automated signal.
Consent (Art. 6(1)(a) GDPR): marketing communications and non-essential analytics cookies. You may withdraw consent at any time via your account settings.
6. Data Sharing & Third Parties
We do not sell your personal data to third parties.
Payment processors: we share transaction data with NowPayments for cryptocurrency payment processing. NowPayments processes data in accordance with their own privacy policy.
Regulatory authorities: we may share data with law enforcement agencies where legally required.
KYC/AML providers: identity verification data may be shared with licensed identity verification services for AML compliance.
Platform integrity telemetry is stored in Pixi's restricted first-party systems and viewed only by authorised staff for security, fraud, promotion-abuse, account-protection, and support investigations. It is not shared for advertising and does not contain your email address, form contents, URL query strings, wallet addresses, network IP address, or raw browser identifier.
Advertising measurement: when you arrive through a Snapchat advertisement and explicitly allow marketing cookies, Snap Inc. receives limited device and browsing event data through the Snap Pixel so we can measure campaign performance. Automated matching is not used, and we do not send your email address, phone number, or Pixi account details to Snap through this integration.
All third-party processors are bound by data processing agreements compliant with GDPR requirements.
7. Data Retention
Account data and transaction records are retained for a minimum of 5 years after account closure, as required by applicable AML regulations.
Chat messages are retained for 90 days for moderation purposes, then permanently deleted.
KYC documents are retained for the duration of the account plus 5 years, or as required by applicable law.
Platform integrity journey events are kept only for as long as reasonably needed to investigate security, fraud, promotion abuse, disputes, and related account activity, then deleted or de-identified under our retention schedule.
You may request deletion of your account and associated data, subject to our legal retention obligations. Some data (transaction records, audit logs) cannot be deleted early due to regulatory requirements.
8. Your Rights Under GDPR
Right of access (Art. 15): you may request a copy of all personal data we hold about you.
Right to rectification (Art. 16): you may request correction of inaccurate data.
Right to erasure (Art. 17): you may request deletion of your data, subject to our legal retention obligations.
Right to restriction (Art. 18): you may request that we limit processing of your data in certain circumstances.
Right to data portability (Art. 20): you may request your data in a machine-readable format.
Right to object (Art. 21): you may object to processing based on legitimate interests.
To exercise any of these rights, contact us at privacy@pixi.casino. We will respond within 30 days.
9. Cookies
We use essential cookies for session management and authentication. These are strictly necessary and cannot be disabled.
Pixi uses a first-party session identifier for limited platform-integrity telemetry that is necessary to secure the requested casino service and prevent or detect fraud and bonus abuse. It is not used for advertising, cross-site tracking, or general marketing profiles.
For visitors arriving through a Snapchat advertisement, we offer an optional Snap Pixel marketing cookie. The Pixel remains unloaded unless you select Allow. Your choice is stored on your device and can be changed at any time through Cookie choices in the site footer.
10. Security
We implement industry-standard security measures including TLS encryption for all data in transit, AES-256 encryption for sensitive data at rest, and access controls limiting staff access to personal data on a need-to-know basis.
Passwords are stored using bcrypt with appropriate work factors. We never store plaintext passwords.
In the event of a data breach affecting your rights, we will notify you and the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR.
11. International Transfers
Your data is primarily stored and processed within the European Economic Area (EEA). Where data is transferred outside the EEA (e.g., to NowPayments infrastructure), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or prominent in-platform notice. The date at the top of this page reflects the most recent revision.
Pixi Casino is operated for entertainment purposes. Data is handled in accordance with applicable privacy laws.
For privacy inquiries, contact: privacy@pixi.casino