LEON Casino Privacy Policy
What we collect, why we collect it, who else sees it and what you can ask us to do with it.
How We Approach Your Privacy
LEON Casino Australia handles personal data because gambling is a regulated activity, not because collecting it is convenient. This page sets out what we hold, why we hold it, who else sees it and what you can ask us to do with it. It is written to be read, not filed away.
We follow the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where the law sets a floor, we treat it as a floor rather than a target, and where a practice would be legal but hard to justify to a player, we do not adopt it.
What Personal Data We Collect
Each category below has a matching purpose in the next section. If a purpose disappears, so does the reason to hold the data.
- Identity data: full name, date of birth, country of residence and preferred currency.
- Contact data: email address, phone number including the country prefix, and a postal address where verification calls for one.
- Financial data: the payment methods you use, deposit and withdrawal history, and the balance movements tied to them.
- Verification data: a copy of your identity document, proof of address such as a recent utility bill, and the outcome of the checks run against them.
- Technical data: IP address, device type, operating system, browser and the security events recorded against your sessions.
- Usage data: pages viewed, games opened, bets placed, bonus opt-ins, session length and support conversations.
Why We Collect It and on What Legal Basis
- Contract: opening your account, crediting deposits, settling bets and paying withdrawals. Without this data there is no account to run.
- Legal obligation: anti-money laundering and counter-terrorism financing checks, identity verification, and the record keeping that goes with them.
- Consent: marketing by email and SMS. You opt in, and you can opt out at any time without losing access to your account.
- Legitimate interests: fraud prevention, bonus abuse detection, platform security and responsible gambling monitoring.
Marketing consent and anti-money laundering obligations are separate things. Withdrawing marketing consent stops the messages. It does not delete the verification records we are required by law to keep.
Who We Share Your Data With
We do not sell personal data and we do not pass it to advertising brokers. It goes only to parties with a defined job to do:
- Payment processors and acquiring banks, to move deposits and withdrawals.
- Identity verification agencies, to complete KYC and sanctions screening.
- Game providers, so a session, its stake and its result reconcile with your account.
- Regulators, auditors and law enforcement, where a lawful request or a licence condition requires disclosure.
Every one of them is bound by contract to use the data only for the purpose it was disclosed for, and to return or destroy it when that purpose ends.
Sending Data Outside Australia
Some of those processors operate overseas. When personal data leaves the country, APP 8 applies: we take reasonable steps to satisfy ourselves that the overseas recipient handles it under protections substantially similar to the Australian Privacy Principles, and we keep the transfer to what the purpose actually needs.
If you want to know which categories of your data are processed overseas, ask us through the contact route at the end of this page and we will tell you.
Your Rights Under the Privacy Act 1988
- Access: ask for a copy of the personal data we hold about you. Send the request from the email address on the account.
- Correction: ask us to fix data that is wrong or out of date. Most fields can also be edited in your account settings.
- Deletion: ask us to delete data we no longer have a lawful reason to keep. Records covered by anti-money laundering retention cannot go while that obligation runs, and we will name the parts that stay.
- Opt-out: withdraw marketing consent from the unsubscribe link in any message, or from the communication preferences in your account.
We answer privacy requests in writing. If our answer does not resolve your complaint, you can escalate it to the Office of the Australian Information Commissioner (OAIC), the independent body that handles privacy complaints in Australia. The OAIC is separate from LEON and assesses complaints on its own terms.
How Long We Keep Your Data
Retention follows purpose, not habit.
- Account, transaction and verification records are kept after the account closes for the period anti-money laundering law requires. That is a legal obligation rather than a commercial choice, and it is why closing an account does not erase everything at once.
- Marketing preference records are kept while consent stands, plus the short period needed to show that an opt-out was honoured.
- Technical and security logs are kept for as long as an investigation into fraud or a security incident could need them, then deleted or aggregated.
When a retention period ends, the data is deleted or irreversibly de-identified. We will not tell you that everything disappears the moment you ask, because that would not be true.
Cookies and Similar Technologies
- Essential cookies keep you signed in, protect the session and remember your currency. The site does not work without them.
- Performance cookies count page views and errors so we can find what is broken.
- Marketing cookies record which campaign brought you here and whether it was worth running.
You can refuse performance and marketing cookies on the consent banner, and you can clear or block cookies from your browser settings at any time. Blocking essential cookies signs you out.
How We Protect Your Data
Traffic between your device and the platform is protected by SSL encryption. Stored verification documents and payment records sit behind access controls, so only staff whose role requires them can open them. Two-factor authentication is available on your account and we recommend switching it on.
Part of the protection is yours to hold. Use a password you do not reuse anywhere else, sign out on shared devices, and never send documents or credentials through any channel other than the official site and its support team.
Protecting Minors
Gambling in Australia is for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18, and no part of this site is aimed at children.
If we find an account belongs to someone under 18, the account is closed, play is voided under the terms and conditions, deposits are returned through the original payment method where the law allows, and the personal data collected is deleted apart from the minimum record needed to show why the account was closed. If you believe a minor has registered, tell us through the contact route below.
Contact Our Privacy Team
Access requests, correction requests, deletion requests and privacy complaints reach the data protection contact through the official support channels: live chat, open 24/7, and the support email address published in your account. Put "Privacy request" in the subject line so it is routed to the right team.
Tell us what you want and which account it concerns. We confirm receipt and set out the next steps in writing. If the outcome does not satisfy you, the OAIC route described above stays open.