Privacy Policy
SlotAff is a research site about licensed gambling operators. You can read all of it without an account, and we would rather hold nothing about you than hold something we cannot justify. This page lists what we actually store, table by table, and what we do not.
Who is responsible
The data controller is Slotaff LTD, Anton P. Chehov St 2, 1113 Sofia, Bulgaria. For anything in this policy, including a request to see or delete your data, write to info@slotaff.com.
Slotaff LTD is established in Bulgaria, so our lead supervisory authority is the Commission for Personal Data Protection (CPDP, Sofia). You can complain to it, or to the authority in your own country, whichever is easier for you.
If you only read the site
Nothing identifies you. We set no advertising or tracking cookies, we embed no third-party analytics, and we do not build a profile of what you look at. We count some page and filter events to know which parts of the site are used; those counts are written to a server log line with no cookie, no device identifier and no session identifier attached, are never stored in a database, and are never sent to anyone else.
Our web server keeps ordinary request logs, including IP addresses, for a short period so we can find faults and abuse. Those are deleted on a rolling basis.
If you create an account
- Email address, used to sign in, to verify the account and to reply to what you submit. It is never shown publicly and never sold or shared for marketing.
- Password, stored only as a scrypt hash. We cannot read it, and nobody here can tell you what it is.
- Display name, this is public. It appears on every review you publish. Choose one you are comfortable being seen.
- Market, the country whose operators you care about, if you tell us.
- Sessions, when you sign in we store a hash of the session token, the IP address and the browser user-agent, so you can see and end your own sessions and so we can detect a stolen one. The token itself is never stored.
- Login safety counters, failed attempts and lockout time, to stop someone guessing at your account.
If you submit a review or a withdrawal report
What you write is published under your display name once a moderator approves it, along with the details you chose to give: amounts, dates, payment method, KYC and support answers. Edits create a new revision, and the previous ones are kept so moderation can be audited, an approved review that later changes is not silently rewritten.
A moderator’s decision on your submission is recorded with their identity and the time. That record exists so decisions about you can be reviewed rather than taken on trust.
If you attach evidence
- Files are never published. There is no public address for an uploaded file, not a hidden one, not a hard-to-guess one. The only way to open one is a moderator, signed in, through an authenticated request.
- We remove metadata from images automatically before storing them, including the GPS coordinates phones write into photographs. We cannot do this for PDFs, so a PDF is stored as you sent it, including any author or software details inside it.
- We cannot black out what is visible in the picture. Cover card numbers, addresses, dates of birth and identity documents before you attach anything. If you send something you should not have, tell us and we will delete it.
- Files are not virus-scanned. No scanner is installed on our server today. We say so rather than let a status imply a check we do not perform.
- The public review shows only that evidence was provided and what a moderator concluded about it. Readers never see the document.
Email we send you
Account email, verification, password reset, and confirmation of something you submitted, is sent because you asked for it. We keep a delivery record of the recipient, subject, purpose and whether it arrived. We deliberately do not store the message body or the link token, so a leak of that record cannot be used to take over an account.
Mail is sent from our own server in Finland. We are moving delivery to Amazon Web Services (SES, Frankfurt), which will then process the message on our behalf.
Contact records from the previous operation
This platform was operated by someone else before us, and roughly 227,000 contact records were recovered when it changed hands. They are held separately from accounts and are not treated as permission to email anyone. Nobody in that set receives anything from us unless they are asked once, plainly, and say yes. If you would rather we simply deleted your record, write to us and we will.
How long we keep things
- Account and profile, until you delete the account.
- Sessions, until they expire or you end them.
- Published reviews and reports, while the account exists. Delete your account and the published text is removed with it.
- Evidence files, kept while the submission they support is live, then deleted. The record that a file existed and what was decided about it outlives the file itself, so a published verification can still be explained.
- Delivery records, kept for a limited period for troubleshooting.
- Moderation decisions, kept, because an audit trail that can be erased is not one.
Email, consent and unsubscribing
Account email (verification, password reset, replies about your own reports) is sent because you asked for the thing it confirms, it needs no separate consent and stops when your account does.
Research updates are different: you get them only if you tick the optional box (never pre-ticked) and then confirm from the email we send, double opt-in. Silence means we never mail you again about it.
Every such email carries a one-click unsubscribe that works without logging in, plus the standard mail-client unsubscribe header. Unsubscribing takes effect immediately. If a message to you hard-bounces or you mark one as spam, we stop sending to that address on our own, permanently, without waiting for a request.
Your rights
If you are in the UK or the EU you can ask us for a copy of what we hold, ask us to correct it, ask us to delete it, object to how we use it, or ask us to restrict it. Write to info@slotaff.com and we will answer within one month. You can also complain to your national data protection authority.
We rely on your consent for the briefing email, on the necessity of performing what you asked for when you submit a review or report, and on our legitimate interest in keeping the site working and free of abuse for security logging.
Who else sees it
Our hosting provider (Hetzner, Finland) and, for email delivery, Amazon Web Services. We do not sell personal data, we do not share it with the operators we write about, and we do not pass it to advertisers.
Changes
If this policy changes in a way that affects what we do with what we already hold, we will say so on this page and date it.
See also our Terms of Use and Community Guidelines.
