Home / Privacy Policy

Privacy Policy

Mia Kalani — Casino Reviewer, DivaSpin AU editorial team · Updated August 2026

This policy explains what happens to your personal information when you use Diva-Spinaustralia.com, an independent Australian guide to DivaSpin Casino. It is written in plain English rather than legalese, on the basis that a policy has to be readable before anybody can act on it. Last updated August 2026.

The short version: this is a content site. We publish reviews, bonus breakdowns and payment guides. There is no casino here, no player balances, and no point at which we see your deposits, your identity documents or your gaming password. Everything below is the longer version, covering which data categories we hold, how long each one stays, who else it reaches, and the route to having any of it corrected or deleted.

Scope: Whose Policy This Is and What It Covers

The scope of this document stops at the edge of Diva-Spinaustralia.com. It covers the pages you read here, the contact form, our analytics, our server logs and the cookies this domain sets in your browser. Details on who operates this website sit on our About page, together with the editorial process behind the reviews.

It does not cover DivaSpin Casino itself. DivaSpin is a separate offshore operator with its own privacy policy, its own data controllers and its own regulator. From the moment you leave this site and land on the operator’s platform, that operator’s terms and privacy policy govern registration, deposits, identity checks, gameplay history, marketing preferences and account closure. None of that is visible to us. We cannot look up your account, see your balance, or retrieve, amend or delete anything the operator holds on its systems. If you want to know what the casino collects at sign-up, read its own policy before you complete the form; our guide to the data collected when you sign up walks through what the process asks for in practice.

The Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs) are the standard this site operates to. A small publisher with annual turnover of A$3 million or less currently sits inside the small-business exemption in the Act, and that is the position this site is in. The APPs are applied regardless, as a minimum standard, since the exemption changes what is legally required of us and not what a reader is entitled to know about where their contact details ended up.

What Personal Information We Collect — and What We Never Collect

Personal information, under the Privacy Act, means information or an opinion about an identified individual, or an individual who is reasonably identifiable. The list below is exhaustive for this site as of August 2026.

Information you choose to give us

Information collected automatically

What we never collect, and never will

This is the part most Australian visitors ask about, so it is set out in full:

How Diva-Spinaustralia.com protects visitor personal information under the Australian Privacy Act 1988

How Information Is Collected

Four collection channels exist on this site, and the amount of control you have varies from one to the next, which is why they are worth separating out.

1. Direct submission. You fill in the contact form and press send. Nothing is collected until you do. The form asks for a name and an email because a reply needs somewhere to go. If you would rather stay anonymous, a throwaway address works fine and the answer goes back to it.

2. Server logs. Every web server on the internet writes a line when it serves a page: timestamp, requested URL, IP address, user agent, response code. This is automatic and unavoidable at the protocol level. Those logs exist for security and diagnostics, which in practice means spotting a bot flood, tracing a 500 error, or confirming whether a page was actually delivered to the browser that asked for it.

3. Analytics. A third-party measurement script records the page view and a handful of technical attributes. It runs on aggregated, non-identifying reporting, described in detail two sections below.

4. Cookies and local storage. Small files written by your browser, either by this domain or by a service embedded in a page. Full detail lives in our separate cookie policy, which lists every category, its purpose and its lifespan.

We do not buy mailing lists, we do not scrape contact details, and we do not run fingerprinting scripts designed to identify you across other websites.

Cookies and Similar Technologies

Cookies on this site fall into three groups. Strictly necessary cookies keep the site functioning: remembering that you dismissed the age gate, holding a consent preference, protecting the contact form from spam. Analytics cookies count visits and page paths in aggregate. Referral cookies record which page of this site an outbound click came from, which is how we tell whether the bonus guide or the payments guide is doing more of the work. What they carry is a page identifier rather than anything about you.

None of it is compulsory. Every major browser lets you block or clear cookies, and most offer a per-site control. Blocking analytics and referral cookies costs you nothing here: no feature breaks and no content is withheld. Blocking the strictly necessary group means the age confirmation and the consent prompt reappear on every visit. Step-by-step instructions for Chrome, Safari, Firefox and Edge, on desktop and mobile, are set out on the cookie page linked above.

Visit DivaSpin Casino

Analytics and Measurement: What the Site Owner Actually Sees

Readers often assume an analytics dashboard is a surveillance console with names attached to it. The reality is duller, so here is what actually appears on our side after you visit.

We see that a visitor from, say, Queensland, on an Android phone running Chrome, arrived from a Google search, read the bonuses page for three minutes, opened the withdrawal page and then left. Who that person is does not appear anywhere. No name, no email, no phone number and no account identifier is attached to the session, and there is nothing in the reporting that would let one be added afterwards.

Reporting is aggregated by default: 4,000 sessions this week, 61% mobile, average two pages per visit, most-read article this month. De-identified data of that kind is what «aggregated statistics» means in practice, meaning information from which the identity of an individual is not apparent and cannot reasonably be ascertained. It is the sort of output that shows the payments guide needs a clearer table. Identifying the particular reader who scrolled past that table is not something the reporting supports.

Where analytics does touch personal information is the IP address, which the Privacy Act may treat as personal information where an individual is reasonably identifiable from it in combination with other data we hold. We minimise that exposure by keeping raw logs short-lived and by not joining log data to contact form submissions. There is no internal process, and no commercial reason, for building a profile of an individual reader.

Why We Collect It: Purposes Under APP 3 and APP 6

APP 3 says an organisation may only collect personal information that is reasonably necessary for its functions or activities. APP 6 says it may only use or disclose that information for the purpose it was collected for, the primary purpose, or for a related secondary purpose you would reasonably expect. Measured against that test, our purposes are:

Several things are deliberately absent from that list. Personal information is not sold, traded, rented or handed to data brokers. Email addresses are not used to build advertising audiences, and reader contact details are never uploaded to an ad platform for targeting purposes.

Disclosure: Who Sees Your Information and When

Four categories of recipient, and no others:

One question comes up often enough to answer directly: submitting our contact form does not pass your details to DivaSpin or to any other gambling operator. Casino registration happens on the operator’s site, with the operator, under the operator’s own policy, and nothing typed into a form on this domain is forwarded to a casino. Reading this page alongside the terms this policy sits alongside gives you both halves of the picture: what happens to data here, and what rules govern the accounts we write about.

Overseas Disclosure (APP 8)

Some of the services above operate infrastructure outside Australia, typically in Singapore, the United States, the United Kingdom and the European Union, which is standard for web hosting, content delivery networks and analytics platforms in 2026.

APP 8 governs this. Before an Australian entity discloses personal information to an overseas recipient, it must take reasonable steps to ensure the recipient does not breach the APPs, and section 16C makes the disclosing entity accountable for what the overseas recipient then does with the information. In practical terms, we choose providers that publish binding data-processing terms, we prefer Australian or Singaporean regions where the option exists, and we do not disclose contact form content to any recipient outside the four categories listed in the previous section.

Assume that basic technical data, meaning IP address, browser and requested URL, crosses a border every time you load a page hosted on a global network. That holds for almost every commercial website you visit, which is why APP 8 was drafted as an accountability rule rather than a prohibition.

Data Security, Retention and Data Breaches

How we protect information

The whole site is served over HTTPS with a valid certificate, so traffic between your browser and the server is encrypted in transit. Access to the publishing platform is restricted to named editorial accounts with multi-factor authentication. Software and plugins are patched on a routine schedule, since unpatched components remain the single most common route into a content site. Contact-form data is accessible only to the editorial team member who handles correspondence.

No system is impregnable, and a claim to the contrary would not be worth much. The commitment that can be made is about proportion: a site holding less data has less to lose in an incident, which is the main reason the «what we never collect» list above runs as long as it does.

How long we keep it

Data category Why it is collected Retention period Who it is shared with
Contact form name, email and message To answer your question or correction request 24 months from last contact, then deleted Editorial team only; email provider in transit
Privacy access or correction requests To action the request and evidence our response 24 months (record of the request and outcome) Editorial team only
Newsletter or update subscriptions To send content you opted in to receive Until you unsubscribe, plus a 30-day suppression record Email delivery provider
Server logs (IP, URL, user agent, timestamp) Security, abuse detection, error diagnostics Up to 90 days, then purged Hosting provider
Analytics events (pages, device, referrer, region) Aggregated audience measurement and content decisions Up to 14 months at event level; aggregates retained longer Analytics provider
Cookie and consent identifiers Remember consent choice and age confirmation Up to 12 months, or until you clear cookies Nobody — stored in your browser
Outbound referral parameters Identify which page sends readers to the operator Up to 30 days Destination platform receives the page identifier

When a retention period ends, information is deleted or de-identified. Where a backup snapshot still contains a record scheduled for deletion, that snapshot ages out on its own cycle instead of being individually edited. This is standard practice across the industry, and it is the reason deletion is described here as happening within the retention window rather than instantly and everywhere at once.

If something goes wrong: the Notifiable Data Breaches scheme

Australia’s NDB scheme sets a clear sequence. Where there are grounds to suspect an eligible data breach, meaning one likely to result in serious harm to an affected individual, a reasonable and expeditious assessment must be carried out, and the Commissioner expects that assessment to be completed within a maximum of 30 calendar days, and faster wherever possible, because risk grows with delay. If the assessment confirms an eligible breach, affected individuals and the Office of the Australian Information Commissioner must be notified as soon as practicable, with a statement covering what happened, which information was involved and what steps people should take.

Our commitment is to run that process on the statutory timetable and to notify affected readers directly. Given what is held here, the worst-case incident involves email addresses and message content. That is serious enough to warrant notification, and it is also the reason nothing heavier is stored on this domain in the first place.

See the DivaSpin Welcome Offer

Your Rights: Access, Correction, Deletion and Complaints

Access (APP 12)

You can ask what personal information we hold about you, and we will tell you. Email the address in the final section with enough detail to locate the record, which is usually the email address you used to contact us. We will respond within a reasonable period, which the OAIC indicates should generally not exceed 30 calendar days. There is no charge for making a request. If we ever refuse access, we must tell you why in writing and explain how to complain about that refusal.

Correction (APP 13)

If something we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to fix it, and we must take reasonable steps to do so. The same 30-day guideline applies. If we disagree with the correction, you can require us to attach a statement noting that you consider the record inaccurate, and that statement then travels with the record.

Deletion and withdrawing consent

Ask us to delete your contact record and we will, unless a law requires us to keep it. Unsubscribing from updates is a one-click action in the footer of any message we send, and it takes effect on the spot. Withdrawing consent does not affect anything lawfully done before you withdrew it.

Complaining — to us first, then to the OAIC

The process is prescribed, and complaints that skip the first step usually take longer to resolve rather than less:

  1. Complain to us. Put it in writing to our privacy contact. You are entitled to a response, and the standard expectation is a reply proposing a resolution within 30 days.
  2. Escalate to the OAIC. If we do not respond in that window, or you are not satisfied with the outcome, you may lodge a complaint with the Office of the Australian Information Commissioner. Complaints under the Privacy Act must be made in writing, and the OAIC cannot accept a privacy complaint by phone. Use the form at oaic.gov.au/privacy/privacy-complaints, email it to [email protected], or post it to GPO Box 5288, Sydney NSW 2001. General enquiries: 1300 363 992.
  3. What happens next. The OAIC acknowledges receipt and aims to respond within 30 calendar days, telling you if it needs longer and why. It may conciliate, investigate, or decide the matter is better resolved directly.

Since 10 June 2025 there is also a statutory tort for serious invasions of privacy under the Privacy Act, giving individuals a direct right of action for intrusion upon seclusion or misuse of information. That is a court remedy rather than a complaint pathway, and it sits well beyond anything a content site would ordinarily be involved in. It appears here because it forms part of the rights an Australian reader now has.

Children and Minors: Strictly 18+

This site is for adults. Gambling content is not appropriate for anyone under 18, and Australian operators, including offshore ones, accept only customers aged 18 and over. Nothing here is designed to appeal to children: no cartoon mascots aimed at under-18s, no school-holiday campaigns, no placements on youth platforms.

We do not knowingly collect personal information from anyone under 18. If we discover that a contact form submission or subscription came from a minor, we delete the record promptly and do not use it for any purpose, including replying beyond a short acknowledgement. Parents or guardians who believe a child has submitted information can email the privacy contact below, and we will locate and remove it without requiring proof of the child’s identity beyond what is needed to find the record.

Parental control software blocks gambling categories at device level, and it is considerably more effective than any policy statement. Family Zone, Qustodio and Net Nanny all do it, as does the filtering built into iOS Screen Time and Android Family Link. A Children’s Online Privacy Code is being developed under the 2024 privacy reforms, and where its obligations touch a site like this one, we will align with them as they take effect.

Third-Party Websites and Gambling Operators

This site links out. Some links go to DivaSpin Casino, others to regulators, support services, game providers and news sources. Once you follow any of them, you are on someone else’s property under someone else’s rules.

That has a few consequences worth spelling out. This policy stops at our domain boundary, so a destination site’s own privacy policy governs what it collects from you. Outbound links to the operator carry a tracking parameter identifying which page you left from, and the destination platform sees that parameter along with the standard technical data any website receives from any visitor. Whatever the destination stores afterwards sits outside our control and outside our access.

Before you register anywhere, read that platform’s privacy policy and its terms, particularly the sections on identity verification, data retention after account closure, and marketing consent, since those are the clauses people most often wish they had read. DivaSpin operates under an offshore Curaçao framework rather than an Australian licence, which means its data handling is supervised under that framework and not by the OAIC.

Play at DivaSpin

Marketing Communications and Unsubscribing

Email goes only to people who asked for it. There is no pre-ticked box anywhere on this site, and submitting the contact form does not sign you up to anything; the only thing that comes back is an answer to what you asked.

If you do subscribe, expect content updates: revised bonus terms, changes to payout limits, new guides. Every message carries a working unsubscribe link and a sender address that accepts replies. Under the Spam Act 2003 (Cth), commercial electronic messages must include a functional unsubscribe facility and honour requests promptly, and that is treated here as a hard requirement. We never sell or rent our subscriber list, and we never pass it to a gambling operator.

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects for you. No algorithm on this site decides what you are shown based on an individual profile, no scoring model is applied to readers, and no automated process makes a decision about your rights or entitlements.

We flag this deliberately. From 10 December 2026, entities regulated by the Privacy Act must disclose in their privacy policies where computer programs are used to make, or substantially help make, decisions that significantly affect an individual’s rights or interests. Our answer to that requirement is a straightforward «not applicable». If the position ever changes, this section gets rewritten before any such process is switched on.

Visitors from the European Union and the United Kingdom

This site targets an Australian audience, but people read it from elsewhere. If you are in the EU or the UK, the GDPR and UK GDPR give you rights that broadly parallel the APPs: access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interests. Where we rely on consent, which covers analytics and non-essential cookies, you can withdraw it at any time by clearing cookies or declining the consent prompt, with no effect on processing already carried out.

Our lawful bases are consent for optional cookies and marketing, and legitimate interests for security logging and aggregate audience measurement. EU and UK residents also have the right to complain to their national supervisory authority, or the Information Commissioner’s Office in the UK. Requests from EU and UK visitors are handled on the same timetable as Australian requests.

Changes to This Policy and How to Contact Us

Privacy law in Australia is moving. The Privacy and Other Legislation Amendment Act 2024 delivered the first tranche of reforms, the statutory tort commenced in June 2025, automated decision transparency obligations bite in December 2026, and further tranches are expected. This policy will be revised as those obligations land, and the «last updated» date at the top of the page is the authoritative marker of the current version.

Material changes get flagged on the page rather than slipped in quietly. That covers a new category of data, a new recipient, or a materially longer retention period. Continuing to use the site after an update means the current version applies to you, so the page is worth a glance if you have arrived after a long gap.

For any privacy request, correction, deletion or complaint, use the contact form on our About page. Please write «Privacy request» in the subject line so it is routed correctly, and include enough detail for us to find the relevant record. If your question is about a casino account, a stuck withdrawal or a verification document, it must go to the operator’s support team; we have no access to those systems, and forwarding your message to them is not something we can do on your behalf. For broader context on this site and how it is put together, start from the DivaSpinAustralia.com homepage.

FAQ — Privacy at Diva-Spinaustralia.com

What data does this site collect when I visit?

Automatically: your IP address, browser and device type, the pages you view, the referring source and an approximate region. Voluntarily: only what you type into the contact form. No payment data, no identity documents and no gaming credentials, at any point.

Does DivaSpinAustralia.com share my data with third parties?

Only with our hosting provider, our analytics provider, our email delivery provider, and law enforcement or regulators where Australian law requires it. We do not sell, rent or trade personal information, and we do not pass contact form details to any gambling operator.

How long is my information stored?

Contact form records for 24 months from last contact, server logs up to 90 days, analytics events up to 14 months, cookie identifiers up to 12 months, subscriptions until you unsubscribe. The table above sets out every category in one place.

Can I request deletion of my data?

Yes. Email a deletion request from the address you originally used and we will remove the record, unless a law requires us to retain it. You can also request access to what we hold (APP 12) or correction of anything inaccurate (APP 13); both are free and answered within roughly 30 calendar days.

Who do I contact about privacy concerns?

Us first, through the contact form, marked «Privacy request». You are entitled to a response proposing a resolution within 30 days. If that does not resolve it, lodge a written complaint with the OAIC by form, email or post; the OAIC aims to respond within 30 calendar days.

Does this policy cover my DivaSpin Casino account?

No. The operator holds your account, your KYC documents and your transaction history under its own policy and its own offshore regulator. This policy covers this website only, and we cannot access, amend or delete anything held by the casino.

Is my data sent overseas?

Basic technical data may be processed by infrastructure located outside Australia, which is normal for global hosting and analytics. APP 8 requires us to take reasonable steps to ensure overseas recipients handle that information consistently with the APPs, and it keeps us accountable if they do not.

About this review

This policy was drafted and reviewed by the Diva-Spinaustralia.com editorial team in August 2026, checked line by line against the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Notifiable Data Breaches scheme and the OAIC’s published complaint-handling guidance. We tested what the site actually collects rather than describing a template: we inspected the cookies set on a clean browser profile, reviewed the analytics reporting available to the site owner, confirmed the contact form stores nothing beyond the fields shown, and verified that no payment or identity-document upload path exists on this domain. It is reviewed at least annually and whenever Australian privacy obligations change.

18+ only. Gambling can be addictive — play responsibly. Support: Gambling Help Online or the national self-exclusion register BetStop.