Logo
Last updated: August 14, 2026

Privacy Policy

This privacy policy explains how Smash Casino collects, uses, stores, and protects personal data submitted by users of the platform. It covers data handling practices, user rights, and the legal basis under which information is processed. Reading this document carefully before registering an account is recommended, as it forms part of the broader legal framework governing use of the service.

Smash Casino is operated by Softon Ltd, a company registered in Cyprus under registration number HE 463977. The platform holds a B2C gaming licence issued by the Anjouan Gaming Authority (AOFA), licence reference ALSI-202409012-FI1. All data processing activities are conducted in line with the operator’s obligations under applicable data protection and privacy law.

What Data Is Collected

Several categories of personal information are gathered during account registration and ongoing platform use. The extent of data collection depends on the stage of the account lifecycle and the services accessed.

Data collected at registration includes:

  • Full legal name and date of birth
  • Email address and password
  • Country of residence and selected account currency
  • Acceptance records for the Terms and Conditions and this privacy policy
  • Optional marketing consent for SMS, email, and newsletter communications

Beyond the registration stage, additional data may be collected when identity verification (KYC) is triggered - typically before the first withdrawal. This includes a government-issued photo ID, proof of address, and in some cases a selfie or biometric identity check. Payment data such as card numbers, crypto wallet addresses, and bank transfer details is processed at the cashier level, with transaction records retained for compliance and anti-money laundering (AML) purposes.

Technical and behavioural data collected automatically during site use includes IP address, device type, browser version, session duration, pages visited, and interaction logs. This information supports fraud prevention, platform performance monitoring, and service personalisation.

How Collected Data Is Used

Softon Ltd processes personal data for a number of defined purposes. Account management and customer support rely on identity and contact details to operate effectively. Financial data is used to process deposits and withdrawals, apply bonus eligibility checks, and enforce limits such as the £1,000 daily withdrawal ceiling and the £100,000 daily net win cap.

KYC and AML obligations require the operator to verify identity before releasing funds, regardless of the payment method used. Cryptocurrency transactions - covering assets such as BTC, ETH, USDT, and LTC - are subject to the same verification standards as fiat payment methods including Visa, Mastercard, and bank transfer.

Where marketing consent is given at registration, contact information may be used to send promotional communications. This consent can be withdrawn at any time by contacting the support team or updating account preferences. The platform does not sell personal data to third parties for independent marketing use.

Data Sharing and Third Parties

Personal data may be shared with carefully selected third parties where operationally necessary. These include game software providers, payment processors, identity verification services, and fraud-detection partners. All third-party processors are required to handle data in a manner consistent with the operator’s privacy obligations.

Regulatory bodies, law enforcement agencies, and licensing authorities such as the Anjouan Gaming Authority may receive data where disclosure is required by law or necessary to fulfil compliance obligations. Data is not transferred to unrelated commercial entities.

For players located in jurisdictions where the service is permitted, data transfers may cross international borders depending on the location of processing infrastructure. Appropriate safeguards are applied in such cases, consistent with applicable data protection frameworks.

Data Retention

Personal and financial records are retained for as long as the account remains active and for a defined period after closure. Regulatory requirements - particularly those related to AML and financial record-keeping - typically require retention for a minimum of five years following the last transaction or account closure, whichever is later. Identity verification documents are held for equivalent periods.

Data collected for technical and security purposes, such as session logs and IP records, is retained for shorter periods unless specific compliance or fraud-investigation reasons require extended storage.

User Rights

Registered users hold certain rights in relation to personal data held by the operator. These include the right to request access to stored information, the right to correct inaccurate records, and in certain circumstances the right to request deletion of data. Requests related to data portability or processing restrictions may also be submitted.

To exercise any of these rights, players can contact the support team directly at support@smash.casino or raise a formal complaint via complaints@smash.casino. The Smash online casino has a 24/7 live chat service available for general enquiries, though formal data access requests should be submitted by email to ensure a clear written record.

Where a request cannot be fulfilled - for example, due to ongoing legal or regulatory obligations - the operator will communicate the reason clearly and indicate any available alternatives.

Cookies and Tracking Technologies

The platform uses cookies and similar tracking technologies to support core site functionality, session management, and analytics. Cookies may also be used in connection with affiliate tracking and marketing attribution. Users can manage cookie preferences through browser settings, though disabling certain cookies may affect site functionality.

Third-party analytics and advertising tools may place cookies independently, subject to their own privacy policies. The operator does not control the data practices of these external services beyond what is agreed contractually.

Security Measures

All data transmitted between the user’s device and the platform is protected using SSL/TLS encryption. This applies to account login, cashier activity, and personal data submission. Financial transactions are processed through secured payment channels, and access to sensitive data within the operator’s systems is restricted on a need-to-know basis.

Despite these measures, no digital platform can guarantee absolute security. Users are advised to choose a strong, unique password and to avoid accessing the account from shared or unsecured networks.

Responsible Gambling and Data

Where responsible gambling tools are used - such as deposit limits, session time limits, or self-exclusion - the data associated with those settings is stored and treated with the same confidentiality as other account information. Self-exclusion records are retained even after account closure to prevent re-registration during an active exclusion period. For further detail on available tools, the Smash responsible gambling page provides a full overview of the protections in place.

Softon Ltd does not share responsible gambling data with third parties except where disclosure is required to fulfil a legal or regulatory obligation.

Changes to This Policy

The operator reserves the right to update this privacy policy at any time. Material changes will be communicated to registered users via email or an in-platform notification. Continued use of the service following the effective date of any update constitutes acceptance of the revised terms. The date at the top of this page reflects the most recent revision.