Cookies rank near the bottom of anyone’s list of interesting web topics and near the top of the list of things readers write in about. This page sets out which cookies Diva-Spinaustralia.com uses, what each one does, how long it survives in your browser, and how to switch it off in every browser Australians actually run. Last updated August 2026.
The boilerplate has been left out. Four hundred words of «we value your privacy» does nothing for a reader who still cannot say what is being stored on their device or how to stop it. Both questions are answered below, with a table of every cookie, browser-by-browser instructions, and a plain note on what stops working if you block the lot.
What This Cookie Policy Covers
This policy applies to Diva-Spinaustralia.com and to nothing else. It covers the pages you are reading, the consent banner, our traffic measurement, our server logs and every cookie written by this domain. For the wider picture on data handling, covering contact form submissions, server logs, retention periods and your access and correction rights, read the full privacy policy, which sits alongside this document rather than repeating it.
This is a guide to DivaSpin Casino rather than the casino itself. No gaming software runs here, no player balances are held, and nothing you enter at the operator ever passes through this domain. For cookies that distinction has a specific consequence: the moment you follow a link off this site and land on an operator’s platform, that platform sets its own cookies under its own domain, governed by its own policy, and nothing on this page has any bearing on them. There is more about this site, its editorial process and the people who maintain it on our About page.
One more boundary is worth stating. This is an information site with no accounts, no logins and no shopping cart. There is no member area, so no profile is attached to you here, no order history exists and no payment details are stored anywhere. The cookie footprint of a site like this one is far smaller than that of a casino platform or an online retailer, and the table further down reflects it.
What Cookies Actually Are, in Plain English
A cookie is a very small text file, usually a couple of hundred bytes and capped at roughly 4 KB, that a website asks your browser to store. It holds a name and a value, something like consent = analytics_declined. Every time you request another page from that same site, your browser quietly sends the cookie back, which is how a stateless protocol like HTTP manages to remember anything at all between clicks.
Cookies cannot execute code. They are not programs, they cannot scan your hard drive, they cannot read your other files, and they cannot see cookies belonging to a different domain. A cookie set by this site is invisible to your bank, and your bank’s cookies are invisible to us. The browser enforces that separation at the software level, which is why it holds regardless of what any individual site would prefer.
What a cookie can do is act as a marker. Give a browser a unique-looking value and you can recognise it again later, count it once instead of twenty times, remember that it already dismissed a notice, or see which page it arrived from. The same mechanism covers the useful applications and the intrusive ones, which is why the rest of this page is organised around what each cookie is for rather than around the technology.
First-Party vs Third-Party Cookies
A first-party cookie is set by the domain in your address bar. On this site that means Diva-Spinaustralia.com. First-party cookies are the ones doing housekeeping: remembering your consent choice, holding a page state, keeping a security check valid.
A third-party cookie is set by a different domain whose code or content is embedded in the page you are on, such as a content delivery network, an analytics vendor, an embedded video player or a payment widget. Because that third domain appears on thousands of sites, its cookie can in principle recognise the same browser across all of them. This is the mechanism behind cross-site tracking, and it is the category most browsers now restrict by default.
Session vs Persistent Cookies
A session cookie has no expiry date. It lives in memory and vanishes when you close the browser, genuinely gone rather than merely hidden. Session cookies handle the things that only need to survive a single visit.
A persistent cookie carries an expiry timestamp and stays on disk until that date passes or you delete it. A consent record has to be persistent, otherwise the banner would ambush you on every single page. Analytics identifiers are persistent too, which is precisely why they are optional. Australian practice has converged on a maximum of twelve to thirteen months for most persistent cookies, and we do not exceed that.
Similar Technologies Worth Naming
Cookies get all the attention and all the legislation, and they are one of several ways a browser can be made to remember something. The rest of the toolkit is below, along with where this site stands on each item in it.
Local Storage and Session Storage
Modern browsers give every site a small key-value database, around 5 to 10 MB per origin, that is not transmitted with each request the way a cookie is. We use local storage sparingly for interface state: whether you collapsed a long comparison table, which tab of a multi-tab block you had open, whether you have already dismissed the age notice. Clearing site data in your browser wipes it exactly as it wipes cookies.
Tracking Pixels and Web Beacons
A pixel is a one-by-one transparent image, or these days a tiny script request, embedded in a page. Loading it tells the server hosting it that the page was viewed, from what rough location, on what device. We do not run advertising pixels on this site: there are no display ad networks in our pages and no social media pixels. Our traffic measurement uses a script rather than a pixel, and it is covered under Analytics below.
Device Fingerprinting
Fingerprinting skips storage entirely. Instead of writing something to your device, a script reads a combination of signals your browser volunteers anyway, including screen dimensions, time zone, installed fonts, graphics rendering quirks and language settings, then hashes them into an identifier. It is durable precisely because there is nothing for you to delete.
We do not fingerprint visitors. The objection is straightforward: the main selling point of the technique is that it survives privacy controls a user has deliberately switched on. Our security provider does evaluate request characteristics in order to filter automated traffic, which is a narrower use and does not build a cross-site profile of anyone.

The Four Cookie Categories on This Site
Everything this site stores falls into one of four buckets. Two of them run regardless of what you choose, since without them the page either cannot function or cannot record your refusal. The other two are yours to decline.
1. Strictly Necessary
These keep the site working and secure. The group includes the consent record itself, a session identifier that holds page state during a visit, and the security cookies our content delivery and bot-filtering layer sets to tell a human reader from an automated scraper. There is no consent toggle for it, since the cookie storing your refusal has to survive in order for that refusal to mean anything. None of them holds a behavioural profile, and none is used for measurement.
2. Preferences
Small conveniences: a dismissed notice staying dismissed, a comparison table remembering how you sorted it, a dark-mode choice persisting between visits. Preference cookies hold interface settings only. Decline them and the site still works perfectly, it simply forgets your small adjustments and greets you the same way each time.
3. Analytics
These count visits and describe them in aggregate. They tell us that a page had four thousand readers last month rather than four hundred, that most of them arrived on a phone, and that the bonus terms section is where people stop scrolling. That feedback is what tells the editorial team which guides to expand and which to rewrite. Analytics cookies are optional. Decline them and the visit goes uncounted, with no shadow record kept and no collection deferred until later.
4. Third-Party Outbound Tracking
Some links on this site point to external gaming platforms. When you follow one, the destination platform may write its own cookie to attribute the visit to the source it arrived from. That cookie belongs to the destination domain rather than to ours, and it is set on their side once you are on their site. It is standard measurement plumbing across the entire web, from software trials to airline bookings, and it is described in full in its own section below.
Visit DivaSpin CasinoCookie Table: Purpose, Type, Lifespan and Control
The names below reflect our current configuration. Tooling changes over time and a specific name may be replaced; the categories and their purposes do not change without this page being updated.
| Cookie / group | Purpose | Type | Typical lifespan | Can you disable it? |
|---|---|---|---|---|
| Consent record | Stores which cookie categories you accepted or refused on the banner | First-party | 6 months | No — deleting it only makes the banner reappear |
| Session identifier | Holds page state during a single visit; expires the moment you close the browser | First-party | Session | No — the site cannot serve pages reliably without it |
| Security / bot filtering | Confirms the request comes from a real browser and not an automated scraper | Third-party (delivery network) | 30 minutes to 12 months | No — blocking it can lock you out of the site entirely |
| Interface preferences | Remembers dismissed notices, table sort order and display choices | First-party | 12 months | Yes — refuse Preferences on the banner |
| Analytics identifier | Separates one browser from another so visits are counted once, in aggregate | First-party (written by the analytics script) | 13 months | Yes — refuse Analytics on the banner |
| Analytics session state | Groups page views inside one visit so a single reader is not counted six times | First-party | 30 minutes, rolling | Yes — refuse Analytics on the banner |
| Outbound click measurement | Set by an external gaming platform after you follow a link off this site, to attribute the visit to its source | Third-party (destination domain) | 30 to 90 days, set by that platform | Yes — block third-party cookies in your browser |
| Embedded media | Set by a video or map provider if a page embeds one; playback and regional settings | Third-party | Varies by provider | Yes — block third-party cookies |
What Our Analytics Measure, and What They Never See
Here is the actual list, field by field.
Measured: which page was requested and in what order; approximate location at city or state level, derived from a truncated IP address; device type, screen size and browser; operating system; whether the visit came from a search engine, a direct entry or another website, without the individual search term ever being attached to you; time on page and scroll depth; whether an outbound link was clicked, as a count rather than as a personal event.
Not measured: your name, your email address or your phone number, none of which we ask for outside the contact form, where submissions are handled separately under the privacy policy. Also absent: your full untruncated IP address in stored reports; any payment or banking detail; anything about a gaming account, since we have no access to any operator’s systems; your activity on other websites; and any special-category information such as health, ethnicity or political views. We do not build advertising audience segments and we do not sell traffic data to anyone.
Reports arrive as aggregates. A typical line reads «12,480 sessions, 71% mobile, 4:12 average time on page.» No individual reader is identifiable in that output, and we have no mechanism to reverse it back into a person.
Cookies Set by External Gaming Platforms
Several pages link out to DivaSpin’s own platform. What follows is the mechanics of what happens when you click one of those links, set out step by step, because the process tends to be described vaguely elsewhere.
You click. Your browser leaves this domain and requests a URL on the operator’s tracking infrastructure. That infrastructure records a technical event, covering which source the request came from, roughly when, and from what type of device, then writes a cookie under its own domain. Then it forwards you to the casino. The whole exchange takes a fraction of a second and is normally invisible. That cookie now lives on the operator’s side and typically persists for thirty to ninety days, so if you return to the platform directly a week later it still recognises where you first arrived from.
That has several consequences. The cookie is set once you have already left our site, which puts it beyond the reach of our consent banner and inside the reach of the operator’s own notice and your browser settings. We cannot read it, delete it or look anything up with it, because it does not belong to us. And it carries no identity: what it stores is a source marker, and it exists before you have entered a single detail on the operator’s platform.
If you would rather this did not happen, blocking third-party cookies in your browser prevents it, and browsing the operator’s site in a private window or after clearing site data resets it. Neither step affects your ability to read anything here. If you want the context on what the operator asks for once you do register, our guide to the cookies used during account signup walks through the sign-up flow step by step.
Claim the 250% Welcome PackageYour Choices: Banner, Do Not Track and Global Privacy Control
On a first visit you get a banner with three actions: accept all, refuse everything optional, or open the detail view and toggle Preferences and Analytics separately. Refusing takes one click rather than a walk through nested menus, and nothing on this site is withheld from readers who do. There is no paywall, no «accept to continue» and no degraded version for people who declined.
Changing Your Mind Later
Your choice is stored for six months, after which you will be asked again. To revisit it sooner, use the cookie settings link in the site footer, which reopens the same panel with your current selections shown. Alternatively, clearing this site’s data in your browser deletes the consent record along with everything else, and the banner returns on your next visit as though you had never been here.
Do Not Track: Why It No Longer Does Much
Do Not Track was a browser header proposed in 2009 that asked sites to refrain from tracking. It was never binding anywhere, most sites ignored it, and browser vendors gradually gave up on it. Safari dropped the setting years ago, and Mozilla removed it from Firefox in version 135, released in early 2025, on the grounds that a signal nobody honours can make a browser easier to fingerprint rather than harder. If your browser still sends the header, we honour it by treating it as a refusal of analytics, though it is not something to rely on elsewhere, because almost nothing else does.
Global Privacy Control
Global Privacy Control is the successor with some weight behind it. It sends a Sec-GPC header, it is supported natively in Firefox and Brave and through extensions elsewhere, and roughly a dozen United States jurisdictions now treat it as a legally binding opt-out signal rather than a polite request. Australian law does not yet require sites to honour it. This one does: where the header is present, optional cookies are treated as refused before the banner renders, and the banner opens with that already selected.
How to Manage Cookies in Your Browser
Browser settings override anything a website does, including us. These paths are current as of August 2026; menu wording shifts slightly between versions, but the location rarely moves.
Google Chrome (Desktop and Android)
Open the three-dot menu, then Settings → Privacy and security → Third-party cookies. You can allow third-party cookies, block them in Incognito only, or block them everywhere. To clear what is already stored, go to Settings → Privacy and security → Delete browsing data, tick Cookies and other site data, and choose a range from the last fifteen minutes through to all time. For a single site, click the icon to the left of the address bar, open site settings, and clear data for that domain alone, which is the surgical option when you want to reset one site without signing out of everything.
Safari on iPhone and iPad
On recent iOS releases, Safari’s controls live in the Settings app rather than in Safari itself: Settings → Apps → Safari. Under Privacy & Security you will find Prevent Cross-Site Tracking, which is on by default and blocks third-party trackers while leaving normal site cookies alone. For the blunt instrument, tap Advanced → Block All Cookies; be aware this removes existing website data and will break sign-ins on most sites you use. To clear only stored data, tap Clear History and Website Data and pick a timeframe. If that option appears greyed out, Screen Time restrictions are usually the cause.
Safari on macOS
Open Safari → Settings → Privacy. Tick Prevent cross-site tracking to restrict third-party cookies, or click Manage Website Data to see every domain holding something on your Mac and remove them individually or all at once. The Advanced tab adds Block all cookies if you want the strictest setting. Safari’s Intelligent Tracking Prevention also caps script-written first-party cookies at seven days by default, which is why analytics figures in Safari tend to run lower than elsewhere.
Mozilla Firefox
Go to Settings → Privacy & Security. Enhanced Tracking Protection offers Standard, Strict and Custom. Standard already blocks known cross-site trackers; Strict blocks considerably more and occasionally breaks embedded content; Custom lets you decide cookie by cookie. Lower down, under Cookies and Site Data, use Clear Data to wipe everything or Manage Data to remove specific domains. Firefox also isolates cookies per site by default, so a third-party cookie set on one site cannot be read on another.
Microsoft Edge
Open Settings → Cookies and site permissions → Manage and delete cookies and site data. From there you can block third-party cookies globally, add allow or block rules for individual sites, and inspect what each domain has stored. Tracking prevention sits separately under Settings → Privacy, search, and services with Basic, Balanced and Strict levels; Balanced is the default and is a reasonable compromise for most people.
Samsung Internet
Tap the menu, then Settings → Privacy and security. Samsung Internet blocks third-party cookies by default, which is stricter out of the box than Chrome. You can toggle Accept cookies off entirely, or leave first-party cookies working while keeping cross-site ones blocked. To delete what is stored, use Personal browsing data → Delete browsing data and select Cookies and site data. Secret Mode discards everything at the end of the session automatically.
What Actually Breaks If You Block Cookies
The consequences below are the real ones, including the inconvenient parts.
Blocking third-party cookies only. This is the setting most privacy-conscious readers are after. On this site nothing visible changes. Embedded media may ask for an extra click before playing, and outbound click measurement stops. Several browsers already apply it by default, and it is the option that suits almost everyone.
Refusing optional categories on our banner. The site behaves identically. You lose remembered interface preferences and you are not counted in traffic figures, and nothing at all is withheld.
Blocking all cookies, everywhere. This is where the internet starts fraying. Our consent banner reappears on every page load, because the record of your refusal is itself a cookie with nowhere to live, and interface state resets constantly. The larger effect is on everything else you use: online banking will refuse to log you in, email in a browser will not stay signed in, government portals such as myGov will fail authentication, and most retail checkouts will lose the basket between pages. Few people keep the setting on for long, and a narrower option usually achieves what they were after.
Clearing cookies periodically. A sensible middle path. You get signed out of things and have to log back in, and nothing is permanently damaged. Most browsers can be set to clear cookies automatically on exit while keeping exceptions for a handful of sites you trust.
Cookies and Australian Privacy Law
The Privacy Act 1988 and the Australian Privacy Principles
Australia has no standalone cookie statute of the kind the European Union has. Cookies are governed through the general framework of the Privacy Act 1988 (Cth) and its thirteen Australian Privacy Principles. The pivot point is the definition of personal information: an online identifier such as an IP address, a device identifier or a cookie value counts as personal information when it is reasonably capable of being linked back to an identifiable individual. A bare visit counter is not personal information; a persistent identifier that can be joined to other records may well be.
The framework has been moving. Amendments in late 2022 lifted the maximum penalty for serious or repeated interference with privacy to A$50 million, three times the benefit obtained, or thirty per cent of adjusted turnover, whichever is greater. The Privacy and Other Legislation Amendment Act 2024 then took effect in stages: most provisions from 10 December 2024, a statutory tort for serious invasions of privacy from 10 June 2025, and disclosure obligations covering automated decision-making from December 2026. Further tranches of reform remain on the government’s agenda, with consent standards and direct-marketing rules among the topics under review.
Turnover here runs under A$3 million, which places a publisher of this size within the small-business exemption the Act provides, and that has never been disguised on this page or anywhere else on the site. The APPs are applied regardless. What the exemption governs is the floor a regulator could enforce, and it says nothing at all about what a reader is entitled to be told about their own device.
The Role of the OAIC
The OAIC is the federal regulator responsible for privacy in Australia. It publishes guidance on how the APPs apply online, handles complaints from individuals who believe an organisation has mishandled their personal information, conducts own-motion investigations, and can seek civil penalties in the Federal Court. Its published position on online identifiers is the reason a cookie policy in this market has to talk about linkability rather than hiding behind the word «anonymous». If you have a privacy concern about any Australian site, the OAIC is the body to escalate to once you have raised it with the site itself.
If You Are Reading From Europe or the UK
Our audience is Australian, but traffic arrives from everywhere. If you are in the European Economic Area or the United Kingdom, the GDPR and the ePrivacy Directive apply to you, and their standard is stricter than Australia’s in two specific ways. Non-essential cookies require prior opt-in consent, meaning they must not be set before you act on the banner. Refusing also has to be as easy as accepting, which rules out the pattern of a bright «Accept all» button sitting next to a buried settings link. Our banner is built to that stricter standard for every visitor rather than switching behaviour by region, which leaves one consent flow to maintain instead of two.
The 2026 Browser Landscape: Third-Party Cookies Did Not Die
For several years the industry expected Chrome to remove third-party cookies outright. It did not happen. Google abandoned the deprecation timetable, confirmed in April 2025 that no separate phase-out prompt would ship, and left the controls where they already were in Chrome settings. In October 2025 it retired most of the Privacy Sandbox proposals, including Topics, Protected Audience and Attribution Reporting, keeping only a small residue of standards work. The UK competition regulator subsequently released Google from the commitments it had given over the project.
The practical upshot for a reader is that third-party cookies still work in Chrome by default, and getting rid of them means changing the setting yourself. Safari and Firefox already restrict them by default, and Samsung Internet blocks them out of the box. Your choice of browser therefore has more effect on your cookie exposure than any industry roadmap has had, which is why the browser instructions above are the section of this page most worth acting on.
Age Restrictions: This Is an 18+ Site
Diva-Spinaustralia.com covers real-money gambling and is intended only for adults aged 18 and over. We do not knowingly collect information from minors, we run no cookies designed to build profiles of young people, and we serve no advertising targeted by age or interest.
If you share a device with children, browser-level parental controls and network filtering are considerably more reliable than any site-side measure, and both are worth setting up before the issue arises. Parents who want the wider context on tools, limits and support services will find them under our responsible gambling resources. If you believe a person under 18 has submitted information through our contact form, tell us and we will delete it promptly.
Changes to This Policy and How to Reach Us
We revise this page when our own configuration changes, when a browser meaningfully alters how it handles storage, or when Australian law shifts. The revision date at the top always reflects the latest substantive edit. Material changes, such as a new category of cookie, a longer retention period or a new third-party service, are also flagged on the consent banner, which re-prompts so your earlier choice is not silently rolled over onto something you never agreed to. Cosmetic edits do not trigger a re-prompt.
Questions about anything on this page can go to the contact address published on our About page, and we aim to reply within five business days. If a cookie appears in your browser under our domain that is not described in the table above, tell us: that is a configuration error worth fixing, and a specific report with the cookie name attached is far easier to act on than a general one. For the rules governing use of this website more broadly, review the full terms, and for the complete picture of how we handle data, the privacy policy linked earlier is the companion document to this one.
Play at DivaSpinFAQ — Cookies on Diva-Spinaustralia.com
Does this site use cookies?
Yes, in four categories: strictly necessary, preferences, analytics, and third-party outbound tracking set once you leave for an external platform. Only the first group runs without your agreement, and it exists to keep the site functional and to remember what you chose. The full breakdown, including lifespans, is in the table above.
Can I browse without accepting cookies?
Yes. Refuse everything optional on the banner and every page remains fully readable. There is no paywall, no gated content and no degraded experience for readers who decline. A small number of strictly necessary cookies still run, meaning the consent record itself, a session identifier and the security layer, because without them the site cannot serve pages or remember your refusal.
What happens if I disable cookies entirely?
On this site, the banner will reappear on every page load, since the record of your choice has nowhere to be stored, and interface preferences reset each time. Across the rest of the web the impact is much larger: banking logins, webmail, myGov and most checkout flows stop working. Blocking only third-party cookies gives you most of the privacy benefit with almost none of the breakage.
Do outbound links to the casino use cookies?
Yes. When you follow a link to an external gaming platform, that platform’s own infrastructure writes a cookie under its own domain to record which source the visit came from. It is set after you have left this site, it typically lasts thirty to ninety days, and we cannot read or delete it. Blocking third-party cookies in your browser prevents it, and what it holds is a source marker rather than anything identifying you.
How do I clear cookies on my phone?
On an iPhone, open Settings → Apps → Safari and tap Clear History and Website Data. On Android with Chrome, use the three-dot menu, then Settings → Privacy and security → Delete browsing data and tick Cookies and other site data. In Samsung Internet, go to Settings → Personal browsing data → Delete browsing data. Each of these signs you out of sites you are logged into, so expect to re-enter a few passwords afterwards.
Are cookies personal information under Australian law?
They can be. Under the Privacy Act 1988, an identifier is personal information when it is reasonably capable of being linked to an identifiable individual, and the OAIC’s guidance treats IP addresses, device identifiers and persistent cookie values as falling inside that definition in many circumstances. An aggregate visit count is not personal information. A durable identifier that could be joined to other records may be, which is why we cap retention at thirteen months and truncate IP addresses before they reach any stored report.
Do you sell the data your cookies collect?
No. Analytics data is never sold, rented or traded, no advertising audiences are built from it, and none of it reaches a data broker. The measurement described on this page exists so the editorial team can see which guides are being read and which need work. If that ever changes, this page and the consent banner would change with it before any new collection began.
About this review
This cookie policy was written and verified by the DivaSpin AU editorial team in August 2026. Every browser path listed above was checked against current releases of Chrome, Safari on iOS and macOS, Firefox, Edge and Samsung Internet rather than copied from older documentation, and the cookie table was reconciled against the site’s live configuration using each browser’s own storage inspector. The legal section was checked against the current text of the Privacy Act 1988 and the staged commencement dates of the 2024 amendments. If you want the wider context on the operator we cover, start with this DivaSpin Casino guide.
18+ only. Gambling can be addictive — play responsibly. Support: Gambling Help Online or the national self-exclusion register BetStop.