Privacy policy

What LEON Casino collects from Australian players, why it is held, who it reaches, and how to exercise your rights under the Privacy Act 1988.

Last updated: 31 August 2026

Data Protection and Privacy at LEON Casino Australia

LEON Casino handles identity documents, payment records and gameplay history for Australian players. This policy explains what is collected, the legal basis for holding it, who receives it and what you can require us to do with it. It is written to be used, not filed.

Our position on your data

Two obligations pull in opposite directions here. Anti-money-laundering law requires an operator to identify players and keep those records; privacy law requires that nothing beyond that is collected, kept or shared. We treat the second as the default and the first as the narrow exception, rather than the other way round.

This policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) made under it.

What personal information is collected

  • Identity data: full name, date of birth and residential address, taken at registration and checked against your documents.
  • Contact data: email address and mobile number, used for confirmation, security alerts and, if you opt in, promotions.
  • Verification (KYC) data: a photo ID such as a driver's licence or passport, plus proof of address such as a utility bill or bank statement. Requested before a first withdrawal, not at registration.
  • Financial data: the payment method used, deposit and withdrawal history, and the masked identifiers your provider returns. Full card numbers are handled by the payment provider, not stored by the casino.
  • Technical data: IP address, device and browser type, operating system and session timestamps.
  • Usage data: which games and markets you open, session length, bet and wagering history, and any responsible gambling limits you set.

Why it is collected, and on what basis

Each category has a reason attached to it, and the reason determines whether you can decline.

  • Contract: running the account — registration, deposits, payouts, bonus tracking and support. Without this data there is no account to run.
  • Legal obligation: age verification, KYC and anti-money-laundering monitoring, and record-keeping required by the licence. This cannot be declined while the account exists.
  • Legitimate interest: fraud and multi-account detection, platform security, and improving how the site performs.
  • Consent: marketing email and SMS, and advertising cookies. This is the only category you can switch off without closing the account, and doing so has no effect on your ability to play, deposit or withdraw.

Marketing consent is kept separate from the data required by law. Unsubscribing from promotions does not delete your KYC file, and refusing KYC does not unsubscribe you from anything — they are different records with different rules.

Who your data is shared with

Your personal information is not sold. It is disclosed only where a specific function requires it, and only to the extent that function needs:

  • payment providers and banks, to move a deposit or a withdrawal;
  • identity verification agencies, to confirm a document is genuine;
  • game studios, where a title needs an anonymous session identifier to run;
  • regulators, auditors and law enforcement, where a licence condition or a lawful request requires it.

Each of these operates within a verified partner network under contract. We do not pass your details to unrelated third parties for their own marketing.

Data that leaves Australia

Some of these providers — verification agencies, payment processors and hosting — operate outside Australia. Where your information is disclosed overseas, APP 8 applies: the recipient is bound by contract to protect it to a standard comparable with the Australian Privacy Principles, and the disclosure is limited to the purpose that required it.

Your rights under the Privacy Act

  1. Access. Ask for a copy of the personal information held about you. Send the request from the email address registered on the account; expect a response within 30 days.
  2. Correction. If a detail is wrong, ask for it to be corrected. Where the field was used for verification, a supporting document may be needed before it is changed.
  3. Deletion. Ask for your data to be erased. Anything not covered by a retention obligation is deleted; the rest is explained below.
  4. Opt-out. Withdraw marketing consent at any time, from the account settings or the unsubscribe link in any promotional message.

If a privacy complaint is not resolved to your satisfaction, you can escalate it to the Office of the Australian Information Commissioner (OAIC), which is independent of this platform and of the operator.

How long data is kept

Deletion is not instant and total, and it would be dishonest to say otherwise. Anti-money-laundering rules require identity records, verification documents and transaction history to be retained for a set minimum period after the account relationship ends — typically several years, as specified by the applicable AML obligations.

In practice this means that when you ask for deletion, marketing data, preferences, analytics identifiers and support correspondence are removed, while the KYC and transaction file is locked down: it is retained, access is restricted to compliance staff, and it is not used for any other purpose. Once the retention period expires it is deleted.

Cookies and tracking

Essential cookies keep your session alive, performance cookies measure how pages behave, and marketing cookies measure campaigns. Only the essential group is set without your agreement. Full detail, including the browser-level controls, is on the cookie policy page.

How your data is protected

  • 256-bit SSL encryption on every transaction and every page that carries account data;
  • two-step verification (2FA) available on the account, plus fingerprint and face unlock on supported devices;
  • restricted internal access, so that verification documents are visible only to staff performing verification;
  • a unique password used nowhere else, which is the one control that is yours rather than ours.

Support staff will never ask for your password, an SMS code or an email reset link. Any message that does is not from LEON Casino.

Protection of minors

The platform is for adults aged 18 and over. We do not knowingly collect or hold personal information about anyone under 18. Where an account is found to belong to a minor it is suspended immediately, winnings are void, net deposits are returned, and the associated data is removed except where a record of the incident must be kept for the regulator.

Contacting the privacy team

Privacy requests — access, correction, deletion, or a complaint — can be sent to the Data Protection Officer through the support channels on the official LEON Casino website, marking the message for the attention of the privacy team. Live chat and email are staffed 24 hours a day, and written requests are acknowledged when received rather than left open-ended.

Play at LEON