Privacy Policy

Last updated: August 2026

This page is shorter than most privacy policies, for a simple reason: there is no account system here, no registration form and nothing you could submit for us to keep. Everything that is processed is listed below in full rather than compressed into unreadable legal paragraphs.

1. What is recorded

Aggregate navigation statistics only: which pages are opened, how long they are read, device and browser type, and an approximate region derived from IP data in aggregate form. Names, ID numbers, email addresses and phone numbers are not requested, not stored, and there is no place in our systems designed to hold them.

2. Google Analytics 4

This is the only analytics tool running on the site. Cookies and anonymous identifiers produce aggregate reports — readers per page, not profiles per person. You can block it at any time through browser settings or an ad blocker, and the site keeps working in full with nothing removed. The data serves one purpose: identifying which pages need rewriting.

3. The affiliate marker

Links to the Isototo platform carry a referral marker so the operator knows a registration came from this site. That marker contains no personal data. From the moment you register on the platform, the operator's privacy policy applies rather than this one — and reading it before filling in the form is considerably more useful than reading it afterwards. The commercial arrangement is described under affiliate disclosure.

4. Where the data goes

Two directions only: aggregate statistics to Google, and a click marker to the operator. Beyond that, brief technical logs exist in the hosting infrastructure for security purposes; they are deleted automatically on the provider's cycle and are never assembled into profiles. There is no visitor database on our side, which means there is nothing here to leak, sell or hand over to a third party.

5. Your rights

Rights of access, correction and deletion remain yours. In practice they are exercised against Google and against the operator, because those are the parties holding anything. Where a question concerns this site itself, send it to the contact address on this domain and it will be answered directly, with no layered forms and no ticket number.

6. Data retention

Aggregate statistics follow the GA4 retention window and are deleted automatically at the end of it. Nothing is kept indefinitely, and nothing is kept that would let a returning visitor be recognised as an individual.

7. Readers under 18

This site is not directed at readers under 18 and collects no personal data from anyone, so the zero-collection position applies identically across every age group. Verification of age is enforced by the operator at registration, not here.

8. If the tooling changes

If an analytics tool is ever added or replaced, this page is updated first and dated, before the new tool goes live. Consent requested after something is already running is not consent, and that order will not be reversed.

9. Outbound links

The only functional external links on this site point to the Isototo platform and to a small number of responsible gambling organisations. There are no social media widgets, no advertising pixels, no embedded maps and no other third-party trackers — the three things that most often carry reader data somewhere unannounced.

10. Questions and revisions

Privacy questions are answered at the same priority as content corrections, through the contact address on this domain. Any change to this policy is published here with a date, and material changes are flagged at the top of the page so nobody has to hunt for them.

Privacy policy and cookies: how your data is handled

The two documents are often conflated although they cover different ground. A privacy policy answers the question of what personal data a site collects and why — email address, device details, payment traces. The cookie policy answers a narrower one: which small files are stored in your browser and what each is for. Some cookies hold a login session together so you are not signed out on every page change; others measure which pages are genuinely read so the writing can be improved.

Responsible data handling reduces to two sentences: collect only what is actually needed, and delete it once it is not. On Isototo cookie consent is managed from the banner or straight from browser settings, and refusing cookies closes access to nothing — if a site forces you to accept tracking merely to read a page, that in itself tells you something about the site.

Personal data: what the operator collects and how it is protected

Everything typed into the cashier — card details, a document scan, a home address — travels to Isototo over a channel protected by encryption, so anyone listening on the same public network sees only a meaningless string of characters. Encryption of the connection is the baseline expected of a licensed site, and the padlock next to the address bar is the quickest way to confirm it is switched on before a single field is filled in. What the operator actually keeps is narrower than people assume: identity and contact details for verification, transaction history because financial regulation demands it, and technical records of logins and devices so that someone else getting into the account becomes visible. The operator's own privacy policy sets out that list in full, and it is worth opening once rather than never. As for the blunt question — is it safe to play at Isototo? — the honest answer rests on exactly these basics: an encrypted connection, a licence you can look up, and careful account habits.

Data leaves the operator in a few predictable directions: the payment provider that moves the money, the service that checks documents, and the regulator or the bank when they ask formally. All of that processing happens on the operator's side rather than on this site, so a deletion request or a copy of your own file goes to its support desk and not to our contact address. On the player's side the useful habits are dull and effective: a password reused nowhere else, two-factor authentication switched on in the account settings, and no logging in from a friend's laptop or a machine in an internet cafe. If a session was left open on a device you no longer have, changing the password closes it faster than hoping nobody looks. A copy of your data or its deletion is not a favour but a right under GDPR, and licensed operators mirror the same procedures in their privacy policies even for players outside the EU. A secure casino keeps every connection behind SSL encryption and spells out its data protection rules in the privacy policy rather than in a buried help article — that combination is what makes a session safe and secure.

Play Now