logo Sign Up

Privacy Policy

This Privacy Policy explains how Postcode Lottery Casino collects, uses, stores, and protects personal information when you use our website, mobile app, and related services. It describes the types of data we gather, how we process it, the choices available to you, and the controls we provide to manage your information. Our approach is practical and user-focused: clear about what we do and why we do it.

What Personal Information We May Collect

Account registration and identity information

When you create an account we collect information necessary to establish and verify your identity and eligibility. This may include:

  • Full name and date of birth.
  • Contact details: email address and telephone number.
  • Residential address and postcode.
  • Copies or photographs of identity documents and proof of address.

We use this information to verify age and residency, to operate your account safely, and to comply with legal and regulatory requirements.

Device, browser and technical information

We collect technical data about the device and software you use to access our services, including:

  • IP address, device type, operating system and version.
  • Browser type and version, screen resolution, and language settings.
  • App version, device identifiers and mobile device settings.

This data helps us deliver a reliable, responsive service and diagnose technical issues.

Usage analytics and behavioural data

We collect information about how you use our platform to improve functionality and user experience. This includes:

  • Pages viewed, features used, clicks, navigation paths and session duration.
  • Time stamps, error logs and performance metrics.
  • Aggregated and anonymised usage patterns for product development and research.

We may combine usage data with other account information to provide personalized notifications and to troubleshoot issues.

Communications and preferences

We record communications you send to us and your preferences for receiving messages, such as:

  • Email opt-ins and marketing preferences.
  • Push notification settings and in-app notification preferences.
  • Customer service interactions.

You can update most communication choices in account settings.

Cookies and Tracking Technologies

Types of cookies we use

We use cookies and similar technologies to make the service work and to improve your experience:

  • Essential cookies for authentication, session management and security.
  • Performance cookies to measure site and app loading times and features usage.
  • Functional cookies for remembering preferences and enabling one-tap sign-in or biometric login options.
  • Analytical cookies for aggregated usage statistics.

Managing cookies and tracking

Most browsers allow you to control cookie settings. You may also manage tracking preferences from within the app or account settings. Disabling certain cookies may affect functionality such as automatic sign-in, saved preferences, and session continuity.

Communication Preferences and Marketing

Opt-ins and notifications

We send transactional messages as necessary to operate your account. Marketing communications and promotional messages are sent only to users who have given explicit consent. You can change your preferences at any time via your account settings or by contacting .

Types of messages

  • Account and service-related notifications.
  • Optional marketing and promotional emails, push notifications, or messages.
  • Important security or policy notices.

Data Storage, Retention and Deletion

How long we keep data

We retain personal information for as long as it is necessary to provide our services, to comply with legal and regulatory obligations, and to resolve disputes or enforce our terms. This includes the period while your account is active and a reasonable period after account closure to meet record-keeping requirements.

Where specific retention periods are required by law or regulation, we will retain the relevant data for that period.

Account closure and deletion requests

You may request deletion or correction of personal data by contacting . We will honor legitimate requests in line with applicable law, subject to retention requirements for operational, legal or regulatory reasons. Certain information may be retained in anonymised or aggregated form after deletion requests to support analytics and service improvement.

Security and Account Protection

Technical and organisational measures

We apply a range of technical and organisational controls to protect personal information, including:

  • Encryption in transit to secure data as it moves between your device and our systems.
  • Encrypted credential storage and secure session management.
  • Web application firewalls, DDoS mitigation services and API security gateways to protect platform availability and integrity.
  • Regular third-party security assessments, penetration testing and compliance reviews.
  • Information security management aligned with recognised standards and audited by independent assessors.

These measures are designed to reduce risk; however, no technical system is immune to all threats. We continuously monitor and improve our security posture.

Account access and password protection

You are responsible for maintaining the confidentiality of your account credentials. We recommend:

  • Choosing a strong, unique password and updating it periodically.
  • Enabling available protections such as biometric login, device-based authentication, and automatic session timeouts.
  • Signing out of shared devices and reporting suspected unauthorised access immediately.

We store passwords using secure hashing techniques and will never email plain-text passwords.

Session management and login protection

Sessions automatically expire after a period of inactivity to reduce the risk of unauthorised access. Our mobile app supports Face ID, Touch ID and fingerprint authentication for convenient, secure re-access. We log authentication events and can require additional verification for sensitive account changes.

Platform Monitoring, Fraud Prevention and Compliance

We monitor activity on the platform for security threats, suspicious behaviour and misuse. Monitoring activities may include analysing device and usage patterns, examining logs and performing risk-based checks to protect accounts and platform integrity. Information gathered for these purposes is used only to detect and prevent fraud, abuse, and other conduct that could harm users or the service.

Where required by applicable law or regulatory obligations, we retain relevant records and cooperate with lawful requests from regulators and law enforcement.

Use of Aggregated and Anonymised Data

We regularly transform personal data into anonymised or aggregated datasets for internal analysis, reporting, product development and research. Once fully anonymised, data cannot be linked back to an individual and may be used without further consent.

Third-Party Services and Integrations

We use a limited set of trusted third-party service providers to support operations, including:

  • Infrastructure and security providers that help deliver and protect the service.
  • Independent auditors and testing laboratories that review system security and integrity.
  • Analytics and notification providers that help deliver and measure communications.

We require third parties to implement adequate safeguards for personal data and limit their use of data to specified purposes. When data is shared with third parties, we put contractual protections in place.

Your Rights and How to Exercise Them

You have rights regarding your personal data under applicable data protection laws, which may include:

  • Right of access: request a copy of personal information we hold about you.
  • Right of rectification: ask us to correct inaccurate or incomplete data.
  • Right to erasure: request deletion of personal data, subject to retention obligations.
  • Right to restriction: request limited processing in certain circumstances.
  • Right to portability: request a copy of certain personal data in a commonly used electronic format.
  • Right to object: object to certain types of processing, including direct marketing.

To exercise these rights, contact with sufficient information to locate your records. We will respond in accordance with applicable legal timelines. If you are unsatisfied with our response, you may lodge a complaint with the UK Information Commissioner’s Office.

Age Restrictions and Minor Protection

You must be at least 18 years old to use our services. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a person under the minimum age, we will take steps to delete that information without undue delay.

Changes to This Policy

We may update this Privacy Policy to reflect operational, legal or regulatory changes. When material changes are made, we will notify active users by email or an in-app notification and publish the updated policy on our website. The effective date will be clearly indicated.

Contact and Data Requests

For privacy questions, to exercise your rights, or to request information about our data practices, contact us at:

If you prefer to write, you may send correspondence to our data protection team at the address provided in account documentation.