This policy explains what happens to your personal information when you use Diva-Spinaustralia.com, an independent Australian guide to DivaSpin Casino. It is written in plain English rather than legalese, on the basis that a policy has to be readable before anybody can act on it. Last updated August 2026.
The short version: this is a content site. We publish reviews, bonus breakdowns and payment guides. There is no casino here, no player balances, and no point at which we see your deposits, your identity documents or your gaming password. Everything below is the longer version, covering which data categories we hold, how long each one stays, who else it reaches, and the route to having any of it corrected or deleted.
Scope: Whose Policy This Is and What It Covers
The scope of this document stops at the edge of Diva-Spinaustralia.com. It covers the pages you read here, the contact form, our analytics, our server logs and the cookies this domain sets in your browser. Details on who operates this website sit on our About page, together with the editorial process behind the reviews.
It does not cover DivaSpin Casino itself. DivaSpin is a separate offshore operator with its own privacy policy, its own data controllers and its own regulator. From the moment you leave this site and land on the operator’s platform, that operator’s terms and privacy policy govern registration, deposits, identity checks, gameplay history, marketing preferences and account closure. None of that is visible to us. We cannot look up your account, see your balance, or retrieve, amend or delete anything the operator holds on its systems. If you want to know what the casino collects at sign-up, read its own policy before you complete the form; our guide to the data collected when you sign up walks through what the process asks for in practice.
The Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs) are the standard this site operates to. A small publisher with annual turnover of A$3 million or less currently sits inside the small-business exemption in the Act, and that is the position this site is in. The APPs are applied regardless, as a minimum standard, since the exemption changes what is legally required of us and not what a reader is entitled to know about where their contact details ended up.
What Personal Information We Collect — and What We Never Collect
Personal information, under the Privacy Act, means information or an opinion about an identified individual, or an individual who is reasonably identifiable. The list below is exhaustive for this site as of August 2026.
Information you choose to give us
- Contact form submissions. The name you type, the email address you type and the body of your message. If you mention a casino username or the details of a dispute inside that message, it ends up in our records because you sent it to us rather than because anything on the form asked for it.
- Correction and access requests. The identifying details you supply so the right record can be located and the reply goes to the right person.
- Editorial feedback and corrections. Where you flag an out-of-date bonus figure or a broken payout limit, the correspondence is kept so there is a record of why an article changed and when.
Information collected automatically
- IP address, captured in server logs by the hosting infrastructure.
- Device and browser signals, meaning browser family and version, operating system, screen size and language setting.
- Usage data: which pages you opened and in what order, how long you stayed, which page you arrived from, and whether you reached us through search, social or a direct link.
- Approximate location, derived from IP at country or state level. We use it to confirm the audience is Australian and to keep currency and terminology correct. It is not street-level, and there is no process here that tries to make it more precise.
- Cookie identifiers, which are random strings letting the site remember a consent choice or count a returning visit.
What we never collect, and never will
This is the part most Australian visitors ask about, so it is set out in full:
- No payment details. No card numbers, no BSB or account numbers, no crypto wallet addresses, no e-wallet credentials. There is no cashier on this domain and no payment gateway attached to it. Deposits go directly to the operator.
- No KYC documents. No driver licence scans, no passport photos, no utility bills, no selfies holding identification. Those go to the casino’s verification team through the operator’s own encrypted upload and nowhere else. Our page explaining how KYC documents are used for payouts describes that process; describing it is the full extent of our involvement in it.
- No gaming account passwords. We will never ask for one, and no legitimate support agent from any operator will either. If a page, email or chat window claiming to be us asks for your casino password, close it and report it to us.
- No gameplay, balance or transaction history. We cannot see your spins, your wins, your losses or your withdrawal queue position.
- No sensitive information in the Privacy Act sense: health, biometric, racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record. There is no reason for a review site to hold any of it, and none of it is ever asked for.

How Information Is Collected
Four collection channels exist on this site, and the amount of control you have varies from one to the next, which is why they are worth separating out.
1. Direct submission. You fill in the contact form and press send. Nothing is collected until you do. The form asks for a name and an email because a reply needs somewhere to go. If you would rather stay anonymous, a throwaway address works fine and the answer goes back to it.
2. Server logs. Every web server on the internet writes a line when it serves a page: timestamp, requested URL, IP address, user agent, response code. This is automatic and unavoidable at the protocol level. Those logs exist for security and diagnostics, which in practice means spotting a bot flood, tracing a 500 error, or confirming whether a page was actually delivered to the browser that asked for it.
3. Analytics. A third-party measurement script records the page view and a handful of technical attributes. It runs on aggregated, non-identifying reporting, described in detail two sections below.
4. Cookies and local storage. Small files written by your browser, either by this domain or by a service embedded in a page. Full detail lives in our separate cookie policy, which lists every category, its purpose and its lifespan.
We do not buy mailing lists, we do not scrape contact details, and we do not run fingerprinting scripts designed to identify you across other websites.
Cookies and Similar Technologies
Cookies on this site fall into three groups. Strictly necessary cookies keep the site functioning: remembering that you dismissed the age gate, holding a consent preference, protecting the contact form from spam. Analytics cookies count visits and page paths in aggregate. Referral cookies record which page of this site an outbound click came from, which is how we tell whether the bonus guide or the payments guide is doing more of the work. What they carry is a page identifier rather than anything about you.
None of it is compulsory. Every major browser lets you block or clear cookies, and most offer a per-site control. Blocking analytics and referral cookies costs you nothing here: no feature breaks and no content is withheld. Blocking the strictly necessary group means the age confirmation and the consent prompt reappear on every visit. Step-by-step instructions for Chrome, Safari, Firefox and Edge, on desktop and mobile, are set out on the cookie page linked above.
Visit DivaSpin CasinoAnalytics and Measurement: What the Site Owner Actually Sees
Readers often assume an analytics dashboard is a surveillance console with names attached to it. The reality is duller, so here is what actually appears on our side after you visit.
We see that a visitor from, say, Queensland, on an Android phone running Chrome, arrived from a Google search, read the bonuses page for three minutes, opened the withdrawal page and then left. Who that person is does not appear anywhere. No name, no email, no phone number and no account identifier is attached to the session, and there is nothing in the reporting that would let one be added afterwards.
Reporting is aggregated by default: 4,000 sessions this week, 61% mobile, average two pages per visit, most-read article this month. De-identified data of that kind is what «aggregated statistics» means in practice, meaning information from which the identity of an individual is not apparent and cannot reasonably be ascertained. It is the sort of output that shows the payments guide needs a clearer table. Identifying the particular reader who scrolled past that table is not something the reporting supports.
Where analytics does touch personal information is the IP address, which the Privacy Act may treat as personal information where an individual is reasonably identifiable from it in combination with other data we hold. We minimise that exposure by keeping raw logs short-lived and by not joining log data to contact form submissions. There is no internal process, and no commercial reason, for building a profile of an individual reader.
Why We Collect It: Purposes Under APP 3 and APP 6
APP 3 says an organisation may only collect personal information that is reasonably necessary for its functions or activities. APP 6 says it may only use or disclose that information for the purpose it was collected for, the primary purpose, or for a related secondary purpose you would reasonably expect. Measured against that test, our purposes are:
- Answering you. If you send a message, we use your name and email to reply. That is the entire primary purpose of the contact form.
- Site security and uptime. Logs let us detect scraping, credential-stuffing attempts against the publishing platform, and denial-of-service traffic.
- Improving the content. Knowing that eight in ten readers of the bonus page bounce before the wagering table tells us the table is buried too deep.
- Legal obligations. Retaining records where a law, court order or regulator requires it.
- Updates you asked for. Only where you have opted in, and only until you opt out.
Several things are deliberately absent from that list. Personal information is not sold, traded, rented or handed to data brokers. Email addresses are not used to build advertising audiences, and reader contact details are never uploaded to an ad platform for targeting purposes.
Disclosure: Who Sees Your Information and When
Four categories of recipient, and no others:
- Our hosting provider. Server infrastructure necessarily processes traffic data to deliver pages. The provider acts on our instructions and does not use the data for its own purposes.
- Our analytics provider. Receives the technical and usage signals described above under a processing arrangement.
- Email delivery. If you opt into updates, an email service provider stores your address in order to send the message and record whether it bounced.
- Law enforcement, regulators and courts, but only where disclosure is required or authorised by Australian law, or where it is reasonably necessary to prevent a serious threat to life, health or safety. Requests of this kind are rare, and each one is assessed on its own facts.
One question comes up often enough to answer directly: submitting our contact form does not pass your details to DivaSpin or to any other gambling operator. Casino registration happens on the operator’s site, with the operator, under the operator’s own policy, and nothing typed into a form on this domain is forwarded to a casino. Reading this page alongside the terms this policy sits alongside gives you both halves of the picture: what happens to data here, and what rules govern the accounts we write about.
Overseas Disclosure (APP 8)
Some of the services above operate infrastructure outside Australia, typically in Singapore, the United States, the United Kingdom and the European Union, which is standard for web hosting, content delivery networks and analytics platforms in 2026.
APP 8 governs this. Before an Australian entity discloses personal information to an overseas recipient, it must take reasonable steps to ensure the recipient does not breach the APPs, and section 16C makes the disclosing entity accountable for what the overseas recipient then does with the information. In practical terms, we choose providers that publish binding data-processing terms, we prefer Australian or Singaporean regions where the option exists, and we do not disclose contact form content to any recipient outside the four categories listed in the previous section.
Assume that basic technical data, meaning IP address, browser and requested URL, crosses a border every time you load a page hosted on a global network. That holds for almost every commercial website you visit, which is why APP 8 was drafted as an accountability rule rather than a prohibition.
Data Security, Retention and Data Breaches
How we protect information
The whole site is served over HTTPS with a valid certificate, so traffic between your browser and the server is encrypted in transit. Access to the publishing platform is restricted to named editorial accounts with multi-factor authentication. Software and plugins are patched on a routine schedule, since unpatched components remain the single most common route into a content site. Contact-form data is accessible only to the editorial team member who handles correspondence.
No system is impregnable, and a claim to the contrary would not be worth much. The commitment that can be made is about proportion: a site holding less data has less to lose in an incident, which is the main reason the «what we never collect» list above runs as long as it does.
How long we keep it
| Data category | Why it is collected | Retention period | Who it is shared with |
|---|---|---|---|
| Contact form name, email and message | To answer your question or correction request | 24 months from last contact, then deleted | Editorial team only; email provider in transit |
| Privacy access or correction requests | To action the request and evidence our response | 24 months (record of the request and outcome) | Editorial team only |
| Newsletter or update subscriptions | To send content you opted in to receive | Until you unsubscribe, plus a 30-day suppression record | Email delivery provider |
| Server logs (IP, URL, user agent, timestamp) | Security, abuse detection, error diagnostics | Up to 90 days, then purged | Hosting provider |
| Analytics events (pages, device, referrer, region) | Aggregated audience measurement and content decisions | Up to 14 months at event level; aggregates retained longer | Analytics provider |
| Cookie and consent identifiers | Remember consent choice and age confirmation | Up to 12 months, or until you clear cookies | Nobody — stored in your browser |
| Outbound referral parameters | Identify which page sends readers to the operator | Up to 30 days | Destination platform receives the page identifier |
When a retention period ends, information is deleted or de-identified. Where a backup snapshot still contains a record scheduled for deletion, that snapshot ages out on its own cycle instead of being individually edited. This is standard practice across the industry, and it is the reason deletion is described here as happening within the retention window rather than instantly and everywhere at once.
If something goes wrong: the Notifiable Data Breaches scheme
Australia’s NDB scheme sets a clear sequence. Where there are grounds to suspect an eligible data breach, meaning one likely to result in serious harm to an affected individual, a reasonable and expeditious assessment must be carried out, and the Commissioner expects that assessment to be completed within a maximum of 30 calendar days, and faster wherever possible, because risk grows with delay. If the assessment confirms an eligible breach, affected individuals and the Office of the Australian Information Commissioner must be notified as soon as practicable, with a statement covering what happened, which information was involved and what steps people should take.
Our commitment is to run that process on the statutory timetable and to notify affected readers directly. Given what is held here, the worst-case incident involves email addresses and message content. That is serious enough to warrant notification, and it is also the reason nothing heavier is stored on this domain in the first place.
See the DivaSpin Welcome OfferYour Rights: Access, Correction, Deletion and Complaints
Access (APP 12)
You can ask what personal information we hold about you, and we will tell you. Email the address in the final section with enough detail to locate the record, which is usually the email address you used to contact us. We will respond within a reasonable period, which the OAIC indicates should generally not exceed 30 calendar days. There is no charge for making a request. If we ever refuse access, we must tell you why in writing and explain how to complain about that refusal.
Correction (APP 13)
If something we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to fix it, and we must take reasonable steps to do so. The same 30-day guideline applies. If we disagree with the correction, you can require us to attach a statement noting that you consider the record inaccurate, and that statement then travels with the record.
Deletion and withdrawing consent
Ask us to delete your contact record and we will, unless a law requires us to keep it. Unsubscribing from updates is a one-click action in the footer of any message we send, and it takes effect on the spot. Withdrawing consent does not affect anything lawfully done before you withdrew it.
Complaining — to us first, then to the OAIC
The process is prescribed, and complaints that skip the first step usually take longer to resolve rather than less:
- Complain to us. Put it in writing to our privacy contact. You are entitled to a response, and the standard expectation is a reply proposing a resolution within 30 days.
- Escalate to the OAIC. If we do not respond in that window, or you are not satisfied with the outcome, you may lodge a complaint with the Office of the Australian Information Commissioner. Complaints under the Privacy Act must be made in writing, and the OAIC cannot accept a privacy complaint by phone. Use the form at oaic.gov.au/privacy/privacy-complaints, email it to [email protected], or post it to GPO Box 5288, Sydney NSW 2001. General enquiries: 1300 363 992.
- What happens next. The OAIC acknowledges receipt and aims to respond within 30 calendar days, telling you if it needs longer and why. It may conciliate, investigate, or decide the matter is better resolved directly.
Since 10 June 2025 there is also a statutory tort for serious invasions of privacy under the Privacy Act, giving individuals a direct right of action for intrusion upon seclusion or misuse of information. That is a court remedy rather than a complaint pathway, and it sits well beyond anything a content site would ordinarily be involved in. It appears here because it forms part of the rights an Australian reader now has.
Children and Minors: Strictly 18+
This site is for adults. Gambling content is not appropriate for anyone under 18, and Australian operators, including offshore ones, accept only customers aged 18 and over. Nothing here is designed to appeal to children: no cartoon mascots aimed at under-18s, no school-holiday campaigns, no placements on youth platforms.
We do not knowingly collect personal information from anyone under 18. If we discover that a contact form submission or subscription came from a minor, we delete the record promptly and do not use it for any purpose, including replying beyond a short acknowledgement. Parents or guardians who believe a child has submitted information can email the privacy contact below, and we will locate and remove it without requiring proof of the child’s identity beyond what is needed to find the record.
Parental control software blocks gambling categories at device level, and it is considerably more effective than any policy statement. Family Zone, Qustodio and Net Nanny all do it, as does the filtering built into iOS Screen Time and Android Family Link. A Children’s Online Privacy Code is being developed under the 2024 privacy reforms, and where its obligations touch a site like this one, we will align with them as they take effect.
Third-Party Websites and Gambling Operators
This site links out. Some links go to DivaSpin Casino, others to regulators, support services, game providers and news sources. Once you follow any of them, you are on someone else’s property under someone else’s rules.
That has a few consequences worth spelling out. This policy stops at our domain boundary, so a destination site’s own privacy policy governs what it collects from you. Outbound links to the operator carry a tracking parameter identifying which page you left from, and the destination platform sees that parameter along with the standard technical data any website receives from any visitor. Whatever the destination stores afterwards sits outside our control and outside our access.
Before you register anywhere, read that platform’s privacy policy and its terms, particularly the sections on identity verification, data retention after account closure, and marketing consent, since those are the clauses people most often wish they had read. DivaSpin operates under an offshore Curaçao framework rather than an Australian licence, which means its data handling is supervised under that framework and not by the OAIC.
Play at DivaSpinMarketing Communications and Unsubscribing
Email goes only to people who asked for it. There is no pre-ticked box anywhere on this site, and submitting the contact form does not sign you up to anything; the only thing that comes back is an answer to what you asked.
If you do subscribe, expect content updates: revised bonus terms, changes to payout limits, new guides. Every message carries a working unsubscribe link and a sender address that accepts replies. Under the Spam Act 2003 (Cth), commercial electronic messages must include a functional unsubscribe facility and honour requests promptly, and that is treated here as a hard requirement. We never sell or rent our subscriber list, and we never pass it to a gambling operator.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects for you. No algorithm on this site decides what you are shown based on an individual profile, no scoring model is applied to readers, and no automated process makes a decision about your rights or entitlements.
We flag this deliberately. From 10 December 2026, entities regulated by the Privacy Act must disclose in their privacy policies where computer programs are used to make, or substantially help make, decisions that significantly affect an individual’s rights or interests. Our answer to that requirement is a straightforward «not applicable». If the position ever changes, this section gets rewritten before any such process is switched on.
Visitors from the European Union and the United Kingdom
This site targets an Australian audience, but people read it from elsewhere. If you are in the EU or the UK, the GDPR and UK GDPR give you rights that broadly parallel the APPs: access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interests. Where we rely on consent, which covers analytics and non-essential cookies, you can withdraw it at any time by clearing cookies or declining the consent prompt, with no effect on processing already carried out.
Our lawful bases are consent for optional cookies and marketing, and legitimate interests for security logging and aggregate audience measurement. EU and UK residents also have the right to complain to their national supervisory authority, or the Information Commissioner’s Office in the UK. Requests from EU and UK visitors are handled on the same timetable as Australian requests.
Changes to This Policy and How to Contact Us
Privacy law in Australia is moving. The Privacy and Other Legislation Amendment Act 2024 delivered the first tranche of reforms, the statutory tort commenced in June 2025, automated decision transparency obligations bite in December 2026, and further tranches are expected. This policy will be revised as those obligations land, and the «last updated» date at the top of the page is the authoritative marker of the current version.
Material changes get flagged on the page rather than slipped in quietly. That covers a new category of data, a new recipient, or a materially longer retention period. Continuing to use the site after an update means the current version applies to you, so the page is worth a glance if you have arrived after a long gap.
For any privacy request, correction, deletion or complaint, use the contact form on our About page. Please write «Privacy request» in the subject line so it is routed correctly, and include enough detail for us to find the relevant record. If your question is about a casino account, a stuck withdrawal or a verification document, it must go to the operator’s support team; we have no access to those systems, and forwarding your message to them is not something we can do on your behalf. For broader context on this site and how it is put together, start from the DivaSpinAustralia.com homepage.
FAQ — Privacy at Diva-Spinaustralia.com
What data does this site collect when I visit?
Automatically: your IP address, browser and device type, the pages you view, the referring source and an approximate region. Voluntarily: only what you type into the contact form. No payment data, no identity documents and no gaming credentials, at any point.
Does DivaSpinAustralia.com share my data with third parties?
Only with our hosting provider, our analytics provider, our email delivery provider, and law enforcement or regulators where Australian law requires it. We do not sell, rent or trade personal information, and we do not pass contact form details to any gambling operator.
How long is my information stored?
Contact form records for 24 months from last contact, server logs up to 90 days, analytics events up to 14 months, cookie identifiers up to 12 months, subscriptions until you unsubscribe. The table above sets out every category in one place.
Can I request deletion of my data?
Yes. Email a deletion request from the address you originally used and we will remove the record, unless a law requires us to retain it. You can also request access to what we hold (APP 12) or correction of anything inaccurate (APP 13); both are free and answered within roughly 30 calendar days.
Who do I contact about privacy concerns?
Us first, through the contact form, marked «Privacy request». You are entitled to a response proposing a resolution within 30 days. If that does not resolve it, lodge a written complaint with the OAIC by form, email or post; the OAIC aims to respond within 30 calendar days.
Does this policy cover my DivaSpin Casino account?
No. The operator holds your account, your KYC documents and your transaction history under its own policy and its own offshore regulator. This policy covers this website only, and we cannot access, amend or delete anything held by the casino.
Is my data sent overseas?
Basic technical data may be processed by infrastructure located outside Australia, which is normal for global hosting and analytics. APP 8 requires us to take reasonable steps to ensure overseas recipients handle that information consistently with the APPs, and it keeps us accountable if they do not.
About this review
This policy was drafted and reviewed by the Diva-Spinaustralia.com editorial team in August 2026, checked line by line against the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Notifiable Data Breaches scheme and the OAIC’s published complaint-handling guidance. We tested what the site actually collects rather than describing a template: we inspected the cookies set on a clean browser profile, reviewed the analytics reporting available to the site owner, confirmed the contact form stores nothing beyond the fields shown, and verified that no payment or identity-document upload path exists on this domain. It is reviewed at least annually and whenever Australian privacy obligations change.
18+ only. Gambling can be addictive — play responsibly. Support: Gambling Help Online or the national self-exclusion register BetStop.