Privacy Policy

Version: 1.0  |  Last Updated: 30 May 2025  |  Domain: lightning-link-au.app

This Privacy Policy ("Policy") describes how Lightning Link ("we", "us", "our", or the "Operator"), operating through lightning-link-au.app (the "Website"), collects, processes, stores, and protects the personal data of our users and Players. It also explains your rights in relation to your personal data and how you may exercise those rights.

By using the Website and creating an Account, you acknowledge that you have read and understood this Policy. This Policy should be read alongside our Terms & Conditions and our Responsible Gaming Policy.

If you have any questions or concerns about how we handle your personal data, please contact our Privacy Officer at [email protected].

1. Introduction

1.1. Scope

This Policy applies to all personal data collected by the Operator through:

  • Your use of the Website and associated mobile applications;
  • Your registration and maintenance of an Account;
  • Your interactions with our customer support team;
  • Your participation in promotions, surveys, or other marketing activities;
  • Your use of cookies and tracking technologies on the Website.

1.2. Commitment to Privacy

We are committed to handling your personal data responsibly and in compliance with applicable data protection principles. We collect only the data that is necessary for the purposes described in this Policy, and we do not sell your personal data to third parties for their own marketing purposes.

2. Data We Collect

2.1. Data You Provide Directly

When you register an Account, make a transaction, or contact our support team, we collect:

  • Identity data: Full legal name, date of birth, gender, nationality;
  • Contact data: Email address, telephone number, residential address;
  • Account credentials: Username and encrypted password;
  • Financial data: Payment method details (card numbers are tokenised and not stored in full), transaction history, deposit and withdrawal records;
  • Verification documents: Copies of government-issued ID, proof of address, source of funds documentation submitted as part of KYC;
  • Correspondence: Records of communications with our customer support and compliance teams.

2.2. Data Collected Automatically

When you access or use the Website, we automatically collect certain technical and usage data, including:

  • Device & technical data: IP address, browser type and version, operating system, device identifiers;
  • Usage data: Pages visited, games played, session duration, click patterns, search queries made on the Website;
  • Geolocation data: Approximate location derived from your IP address;
  • Log data: Server logs recording your interactions with the Website, including timestamps and error reports.

2.3. Data from Third Parties

We may receive data about you from third-party sources, including:

  • Identity verification and KYC service providers;
  • Payment processors and financial institutions;
  • Fraud prevention and anti-money laundering screening services;
  • Marketing analytics and affiliate tracking partners;
  • Publicly available sources used for compliance screening.

3. How We Use Your Data

3.1. Purposes of Processing

We use your personal data for the following purposes:

  • Account creation and management: To register, verify, and maintain your Account;
  • Service delivery: To provide access to Games, process deposits and withdrawals, and deliver customer support;
  • Identity verification: To conduct KYC checks and verify your age, identity, and eligibility to use the Website;
  • Fraud prevention & security: To detect, investigate, and prevent fraud, money laundering, cheating, and other prohibited activities;
  • Responsible gaming: To monitor gaming behaviour, apply player protection tools, and fulfil our duty of care obligations as detailed in our Responsible Gaming Policy;
  • Marketing & communications: To send you promotional materials, bonus offers, and other marketing communications (subject to your consent where required);
  • Personalisation: To tailor Website content, game recommendations, and promotional offers to your preferences and gaming history;
  • Legal compliance: To comply with applicable laws, regulatory requirements, and court orders;
  • Analytics & improvement: To analyse usage patterns, monitor Website performance, and improve our products and services.

3.2. Marketing Communications

Where you have provided your consent, we may contact you via email, SMS, or push notifications about promotions, new games, and special offers. You may withdraw your consent and unsubscribe from marketing communications at any time by:

  • Clicking the "unsubscribe" link in any marketing email;
  • Updating your communication preferences in your Account settings;
  • Contacting us at [email protected].

4. Legal Bases for Processing

We process your personal data on the following legal bases:

  • Contractual necessity: Processing is necessary to perform our contract with you (i.e., to provide our services and manage your Account);
  • Legal obligation: Processing is required to comply with applicable legal and regulatory obligations, including AML, KYC, and responsible gaming requirements;
  • Legitimate interests: Processing is necessary for our legitimate interests, including fraud prevention, platform security, business analytics, and improving our services, provided such interests are not overridden by your rights and interests;
  • Consent: Where you have freely given, specific, and informed consent to the processing of your data for a specific purpose (e.g., direct marketing). You may withdraw consent at any time without affecting the lawfulness of prior processing.

5. Data Sharing & Third Parties

5.1. Categories of Recipients

We may share your personal data with the following categories of third parties:

  • Payment service providers: To process deposits and withdrawals;
  • Identity verification providers: To perform KYC and age verification checks;
  • Game software providers: To enable the delivery of Games on the Website;
  • Fraud prevention services: To screen transactions and player activity for suspicious patterns;
  • IT infrastructure and hosting providers: To maintain the technical operation of the Website;
  • Customer support platforms: To facilitate and manage support interactions;
  • Marketing and analytics services: To measure campaign performance and Website usage;
  • Regulatory authorities and law enforcement: Where required by law or in response to a valid legal request.

5.2. No Sale of Personal Data

We do not sell, rent, or trade your personal data to third parties for their independent marketing purposes.

5.3. Third-Party Service Providers

All third-party service providers who process personal data on our behalf are required to do so only on our documented instructions and under appropriate contractual data protection obligations. We conduct due diligence to ensure that our service providers implement appropriate technical and organisational security measures.

6. Cookies & Tracking Technologies

6.1. What Are Cookies?

Cookies are small text files placed on your device by the Website when you visit. They enable the Website to remember your preferences, maintain your session, and collect analytics data. We also use similar tracking technologies such as web beacons, pixel tags, and local storage objects.

6.2. Types of Cookies We Use

Cookie TypePurposeDuration
Essential CookiesRequired for the Website to function properly (e.g., session management, login authentication)Session / Persistent
Functional CookiesRemember your preferences (e.g., language, currency, display settings)Up to 12 months
Analytics CookiesCollect aggregated usage data to help us improve the Website (e.g., Google Analytics)Up to 24 months
Marketing CookiesTrack your activity across our Website and third-party sites to deliver targeted advertisingUp to 12 months
Affiliate Tracking CookiesRecord how you arrived at our Website for commission and attribution purposesUp to 30 days

6.3. Managing Cookies

You can control your cookie preferences through:

  • Our cookie consent banner displayed on your first visit to the Website;
  • Your browser settings, which allow you to accept, reject, or delete cookies;
  • Third-party opt-out tools for advertising cookies.

Please note that disabling essential cookies may impair the functionality of the Website and prevent you from accessing certain features.

7. Data Security

7.1. Security Measures

We implement comprehensive technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, and destruction. These measures include:

  • SSL/TLS encryption: All data transmitted between your device and the Website is encrypted using industry-standard Transport Layer Security (TLS) protocols;
  • Access controls: Strict internal access controls ensure that personal data is accessible only to authorised personnel who require it for legitimate business purposes;
  • Data pseudonymisation & tokenisation: Sensitive financial data such as payment card numbers are tokenised and never stored in plain text;
  • Regular security audits: We conduct regular vulnerability assessments and penetration testing of our systems;
  • Incident response: We maintain a documented data breach response plan and will notify affected individuals and relevant authorities in the event of a significant data breach, in accordance with applicable law.

7.2. Your Responsibility

While we implement robust security measures, no internet transmission is entirely secure. You are responsible for maintaining the confidentiality of your Account credentials and for using secure internet connections when accessing the Website. Please notify us immediately at [email protected] if you believe your Account has been compromised.

8. Data Retention

8.1. Retention Periods

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The following general retention periods apply:

Data CategoryRetention Period
Account registration & identity dataDuration of Account + 7 years after closure
Financial transaction recordsDuration of Account + 7 years after closure
KYC verification documentsDuration of Account + 7 years after closure
Customer support correspondence3 years from last interaction
Marketing preferences & consent recordsUntil withdrawal of consent + 3 years
Website usage & analytics dataUp to 26 months
Cookie dataAs per cookie type (see Section 6)

8.2. Deletion

When your personal data is no longer required, it will be securely deleted or anonymised in accordance with our data retention schedule. In some cases, we may retain anonymised data for statistical and analytical purposes indefinitely.

9. Your Rights

9.1. Rights Available to You

Depending on applicable law, you may have the following rights in relation to your personal data:

  • Right of access: You have the right to request a copy of the personal data we hold about you;
  • Right to rectification: You have the right to request that inaccurate or incomplete personal data be corrected;
  • Right to erasure: You have the right to request the deletion of your personal data, subject to our legal retention obligations;
  • Right to restriction: You have the right to request that we restrict the processing of your personal data in certain circumstances;
  • Right to data portability: You have the right to receive your personal data in a structured, commonly used, machine-readable format;
  • Right to object: You have the right to object to the processing of your personal data for direct marketing or on grounds relating to your particular situation where processing is based on legitimate interests;
  • Right to withdraw consent: Where processing is based on consent, you have the right to withdraw your consent at any time without affecting prior lawful processing.

9.2. Exercising Your Rights

To exercise any of the rights listed above, please submit a written request to [email protected]. We will respond to your request within 30 days. We may need to verify your identity before processing your request. In certain circumstances we may decline a request, for example where complying would conflict with a legal obligation, and in such cases we will explain the reasons for our decision.

10. International Data Transfers

10.1. Cross-Border Transfers

In providing our services, your personal data may be transferred to and processed in countries outside of Australia. Where such transfers occur, we ensure that appropriate safeguards are in place to protect your personal data, including the use of contractual protections and ensuring that recipient countries provide an adequate level of data protection.

10.2. Safeguards

Where we transfer data internationally, we rely on one or more of the following safeguards:

  • Adequate data protection laws in the recipient country;
  • Standard contractual clauses or data transfer agreements with service providers;
  • Binding corporate rules where applicable.

11. Minors

11.1. Age Restriction

The Website is strictly intended for individuals aged 18 years or older. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected personal data from an individual under the age of 18, we will take immediate steps to delete such data and close the associated Account. Please refer to our Responsible Gaming Policy for further information on the protection of minors.

11.2. Parental Controls

We strongly encourage parents and guardians to make use of available parental control software and filtering tools to prevent minors from accessing gambling websites. If you believe a minor has registered an Account on our Website, please contact us immediately at [email protected].

12. Changes to This Policy

We reserve the right to update or modify this Privacy Policy at any time. The revised Policy will be published on this page with the updated version number and effective date. Where we make material changes to this Policy, we will endeavour to notify you via email or a prominent notice on the Website. Your continued use of the Website following the publication of changes constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically.

13. Contact Information

If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us:

We take all data protection enquiries seriously and will respond to your communication as promptly as possible, and in any event within 30 calendar days of receipt.