Privacy Policy

Version: 1.0  |  Last Updated: 10 August 2026

This Privacy Policy ("Policy") explains how FatPirate Casino UK ("FatPirate", "we", "us" or "our"), operating through the website fatpiratecasinouk.co.uk (the "Website"), collects, uses, stores, shares and protects your personal data. It applies to all visitors, registered Players and any other individuals who interact with our Services.

This Policy should be read alongside our Terms & Conditions and our Responsible Gaming Policy. By accessing or using the Website, you acknowledge that you have read and understood this Policy.

1. Introduction

FatPirate is committed to protecting your personal data and respecting your privacy rights. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our obligations under these laws seriously and have implemented appropriate technical and organisational measures to ensure the security and confidentiality of your data.

We act as the data controller in respect of the personal data we collect through the Website and Services. If you have any questions or concerns about how we handle your data, please contact our Data Protection Officer (DPO) using the details set out in Section 13.

2. Data We Collect

We collect personal data from you directly, automatically through your use of the Website, and from third parties where permitted by law.

2.1. Data You Provide Directly

  • Identity data: full name, date of birth, gender;
  • Contact data: email address, residential address, telephone number;
  • Account credentials: username, password (stored in hashed form);
  • Financial data: payment method details, transaction history, source of funds information;
  • Identity verification documents: passport, driving licence, utility bills, bank statements (for KYC purposes);
  • Communications: records of your correspondence with our support team, chat logs and survey responses.

2.2. Data Collected Automatically

  • Technical data: IP address, device type, browser type and version, operating system, device identifiers;
  • Usage data: pages visited, links clicked, games played, session duration, referring URLs;
  • Transaction data: deposit and withdrawal amounts, dates, payment methods, gaming history;
  • Cookies and tracking data: see Section 6 for full details.

2.3. Data from Third Parties

  • Identity verification providers: confirmation of identity and age from third-party KYC services;
  • Fraud prevention agencies: risk scores and fraud signals;
  • Payment processors: transaction confirmations and payment status;
  • Affiliate partners: referral data indicating how you found the Website;
  • Publicly available sources: information from public records or sanctions lists for AML compliance.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Account registration and management: to create and maintain your Account, verify your identity and process your transactions;
  • Service delivery: to provide access to games, process deposits and withdrawals, and deliver customer support;
  • Legal compliance: to fulfil our obligations under AML, KYC, CTF, gambling regulation and tax law;
  • Fraud prevention and security: to detect, investigate and prevent fraudulent transactions, prohibited conduct and security breaches;
  • Responsible gambling: to monitor gaming behaviour, apply player protection tools, identify at-risk players and fulfil safer gambling obligations;
  • Marketing communications: to send you promotional offers, newsletters and personalised recommendations where you have given consent or where we have a legitimate interest and you have not opted out;
  • Website improvement: to analyse usage patterns, conduct A/B testing and improve the functionality and user experience of the Website;
  • Legal claims: to establish, exercise or defend legal claims and comply with court orders or regulatory investigations.

4. Legal Bases for Processing

We rely on the following legal bases under UK GDPR to process your personal data:

Purpose Legal Basis
Account registration and managementPerformance of a contract (Article 6(1)(b))
Processing deposits and withdrawalsPerformance of a contract (Article 6(1)(b))
AML / KYC / CTF complianceLegal obligation (Article 6(1)(c))
Responsible gambling monitoringLegal obligation / Legitimate interests (Article 6(1)(c)(f))
Fraud preventionLegitimate interests (Article 6(1)(f))
Marketing (email / SMS)Consent (Article 6(1)(a))
Website analyticsLegitimate interests (Article 6(1)(f))
Legal claims and regulatory complianceLegal obligation / Legitimate interests (Article 6(1)(c)(f))

Where we rely on legitimate interests, we have conducted a balancing test and concluded that our interests are not overridden by your data protection rights. You may request a copy of this balancing test by contacting our DPO.

Where we rely on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

5. Data Sharing & Third Parties

We do not sell your personal data to third parties. We may share your data with the following categories of recipients:

  • Identity verification and KYC providers: to confirm your identity, age and address;
  • Payment service providers and banks: to process deposits and withdrawals securely;
  • Fraud prevention and AML agencies: to detect and prevent financial crime;
  • Game software providers: who may process limited technical data to deliver games;
  • IT and cloud service providers: hosting, data storage and security infrastructure partners;
  • Customer relationship management (CRM) platforms: to manage communications and support tickets;
  • Marketing technology providers: to deliver and measure marketing campaigns (where consent applies);
  • Analytics providers: to analyse Website performance and player behaviour in aggregated or pseudonymised form;
  • Regulatory and law enforcement authorities: where required by law, court order or regulatory obligation;
  • Professional advisers: including lawyers, auditors and insurers, bound by duties of confidentiality.

All third-party processors are required to process your data in accordance with our instructions, maintain appropriate security measures and comply with applicable data protection law. We enter into data processing agreements with all relevant third parties.

6. Cookies & Tracking Technologies

6.1. What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They allow the website to remember your preferences, improve functionality and provide us with insights into how the site is used.

6.2. Types of Cookies We Use

Cookie Type Purpose Duration
Strictly NecessaryEssential for the Website to function (login sessions, security)Session / up to 1 year
FunctionalRemember your preferences (language, currency, layout)Up to 1 year
AnalyticsUnderstand how visitors use the Website (e.g., Google Analytics)Up to 2 years
MarketingDeliver targeted advertisements and measure ad effectivenessUp to 2 years

6.3. Managing Cookies

You can manage your cookie preferences through our Cookie Consent Manager, accessible via the cookie banner displayed on your first visit and at any time through the footer of the Website. You may also configure your browser to refuse cookies entirely, though this may affect the functionality of the Website. For detailed guidance on managing cookies in your browser, please visit allaboutcookies.org.

7. Data Security

We implement a comprehensive range of technical and organisational security measures to protect your personal data from unauthorised access, loss, misuse, alteration or destruction. These include:

  • SSL/TLS encryption for all data transmitted between your browser and our servers;
  • At-rest encryption for sensitive data stored in our databases;
  • Access controls ensuring only authorised personnel can access personal data on a need-to-know basis;
  • Regular penetration testing and security audits conducted by independent specialists;
  • Intrusion detection and monitoring systems;
  • Staff training on data protection and information security obligations.

While we take all reasonable precautions, no data transmission over the internet can be guaranteed to be completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority in accordance with our obligations under UK GDPR.

8. Data Retention

We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting or reporting requirements.

  • Account and transactional data: retained for a minimum of five (5) years after account closure, in compliance with AML regulations;
  • KYC documentation: retained for a minimum of five (5) years from the end of the business relationship;
  • Marketing data: retained until you withdraw consent or opt out, plus one (1) year;
  • Technical and usage data: retained for up to two (2) years after collection;
  • Support correspondence: retained for three (3) years from the date of resolution.

Upon expiry of the applicable retention period, data is securely deleted or anonymised.

9. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right of access: to obtain a copy of the personal data we hold about you (Subject Access Request);
  • Right to rectification: to request correction of inaccurate or incomplete data;
  • Right to erasure ("right to be forgotten"): to request deletion of your data where there is no compelling reason for us to continue processing it, subject to legal retention obligations;
  • Right to restriction of processing: to request that we limit how we use your data in certain circumstances;
  • Right to data portability: to receive a structured, machine-readable copy of the data you provided to us, and to transmit it to another controller;
  • Right to object: to object to processing based on legitimate interests or for direct marketing purposes;
  • Rights related to automated decision-making: to not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where necessary for a contract or permitted by law;
  • Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time.

To exercise any of these rights, please contact our DPO at [email protected]. We will respond to all valid requests within one (1) calendar month, extendable by a further two months where the request is complex or numerous. We may need to verify your identity before processing your request.

If you are dissatisfied with our response or believe we are processing your data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by telephone on 0303 123 1113.

10. International Data Transfers

Certain third-party service providers we use may be located outside the United Kingdom. Where your personal data is transferred to countries that do not benefit from a UK adequacy decision, we ensure that appropriate safeguards are in place, such as:

  • UK International Data Transfer Agreements (IDTAs) or equivalent approved clauses;
  • Adequacy regulations adopted by the UK Secretary of State;
  • Binding Corporate Rules where applicable.

You may request a copy of the relevant safeguards by contacting our DPO.

11. Minors

Our Services are not intended for persons under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a person under 18, we will take immediate steps to delete that data and close the associated Account. If you believe a minor has registered with us, please contact us immediately at [email protected].

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, technology or our business practices. We will notify you of any significant changes by email and/or by displaying a prominent notice on the Website. The date at the top of this Policy indicates when it was last revised. We encourage you to review this Policy periodically. Your continued use of the Services after any update constitutes your acceptance of the revised Policy.

13. Contact Information

If you have any questions, concerns or requests relating to this Privacy Policy or our data processing practices, please contact us:

We aim to respond to all privacy-related enquiries within five (5) business days.