Fortunica privacy policy: what data the casino collects and what happens to it

Signing up at any casino means handing over more than an email address — and Fortunica is no exception, because withdrawals there are gated behind full identity checks. This independent review breaks down what personal data the operator collects, why it collects it, and what you can realistically ask it to delete.

One thing to settle first: Fortunica launched in 2025 under Winstar N.V. (Curacao registration 168709) and holds a reported Anjouan Offshore Financial Authority licence, ALSI-202501022-F11, plus a reported Curacao Gaming Authority secondary licence OGL/2024/611/0233. It is not a UK Gambling Commission licensee, and the operator’s own terms restrict United Kingdom customers. That changes which privacy regulator you can escalate to, so read this page with that in mind.

What personal information does Fortunica collect?

Fortunica collects three broad categories of data: the identity details you type in when you open an account, technical information your device produces while you play, and the financial records created every time money moves. Verification documents sit on top of that once you request a payout.

What do you hand over when you register?

Account creation is the first collection point. The operator needs enough to create a unique account, contact you, and later match you against your payment instrument.

  • Full name and date of birth (age gating — under-18s cannot legally hold an account)
  • Email address and, in most cases, a mobile number
  • Country of residence and address details
  • Chosen currency, username and password credentials
  • Any communication preferences you tick during sign-up

The step-by-step of opening the account itself is covered elsewhere: Fortunica registration process.

What documents does verification require?

Fortunica will not release a withdrawal until KYC is complete, and KYC means uploading actual identity documents. According to the operator, three items are required:

  • A government-issued photo ID — passport, driving licence or national ID card
  • A selfie holding the same ID, so the face on the document can be matched to a live person
  • A bank statement or utility bill dated within the last three months as proof of address

These are the most sensitive files you will ever send a casino. Send them only through the account’s own upload area, never by ordinary email, and blank out any transaction lines on a bank statement that are not needed to prove your name and address.

What usage data is logged automatically?

You do not type this data in — it is generated as you browse and play. Typical automatic collection includes your IP address, approximate location derived from it, device type and operating system, browser version, session timestamps, pages viewed, and the games you open. Bet history, stake sizes and session length are logged on the gaming side, partly because those records are what a regulator or a payment provider would ask to see in a dispute.

What payment and transaction information is stored?

Every deposit and withdrawal leaves a permanent record. The cashier is advertised as a 14-method setup: Visa and Mastercard cards, with mirror pages aimed at GBP players also listing Skrill, Neteller, ecoPayz and bank transfer, alongside nine listed cryptocurrencies as a secondary route. The minimum deposit is EUR 10.

What that means for your data: card payments create a stored token and masked card number; Skrill, Neteller and ecoPayz create a linked wallet identifier tied to your email; bank transfers expose your account name, IBAN and bank. Crypto transfers still create a wallet address permanently written to a public ledger. Timings, fees and limits belong on their own page: Fortunica payment methods.

How does Fortunica use your information?

Your data is used for four practical purposes: running the account and paying you out, personalising and promoting offers, meeting anti-money-laundering and licensing obligations, and catching fraud or duplicate accounts. Game sessions are also shared with software suppliers so results can be generated and audited.

How is your data used to run the account?

Basic service delivery covers logins, balance tracking, bet settlement, support tickets and payout processing. Game rounds are passed to the studios powering the lobby — Novomatic, Playson, Evoplay, Booongo (BNG), Gamzix, Ela Games, Hacksaw Gaming, Slotopia, Swintt and Pragmatic Play — because the game server, not the casino, calculates the outcome. Those suppliers see a session identifier and bet data, not your passport scan.

How is your data used for marketing?

Deposit history, favourite game types and inactivity gaps feed promotional targeting. That is how a casino decides who gets a reload email and who gets a free spins nudge. The advertised welcome package is 290% up to EUR 6,000 + 200 free spins, with 40x wagering on the bonus portion of cash bonuses and 30x on free spin winnings, a max bet of EUR 5 while wagering, bonus and free spin balances expiring 5 days after credit, max conversion of 5x the reward value, free spin winnings capped at EUR 100, a EUR 10 minimum deposit and no bonus code required. Full offer detail lives here: Fortunica welcome bonus.

Marketing consent is separable from account data. Refusing emails does not close your account; it only stops the promotional stream.

How is your data used for compliance and fraud prevention?

Identity documents exist for one reason: to prove you are who you say you are before money leaves the platform. The operator ties KYC to payouts directly, and also applies a wagering condition — the deposit must be turned over at least 1x, or an 8% withdrawal fee applies. Device fingerprints and IP data are used to spot duplicate accounts, shared devices and bonus abuse.

Because the licence is offshore rather than domestic, the compliance framework Fortunica answers to is the Anjouan Offshore Financial Authority one, not a UK regime. Casino Guru rates the site 5.1/10 (“Below average”) and lists 26 complaints generating 576 black points, with denial of payouts the dominant theme — worth weighing before you upload a passport scan.

How is your data protected and stored?

Data protection at an online casino rests on three pillars: encrypted transmission between your browser and the servers, restricted internal access to verification files, and defined retention periods driven by anti-money-laundering rules rather than by your preference. Third parties handle payments and analytics under contract.

What security measures apply?

Traffic between your device and the casino travels over TLS/SSL encryption — check for the padlock and an https address before you type a password. Payment card details are handled by the payment processors themselves, which is why the casino stores a token rather than your full card number.

The part you control matters more than most people admit:

  • Use a password unique to this account, not one recycled from your email
  • Never play through public Wi-Fi when uploading verification documents
  • Log out on shared devices instead of leaving a session open
  • Keep the confirmation emails for every deposit and withdrawal — they are your evidence in a dispute

How long is your data kept?

Gambling operators are generally required to retain identity and transaction records for years after an account closes, because anti-money-laundering law demands an auditable trail. Deleting your account therefore does not wipe your KYC file — the practical outcome is that marketing stops and the account is frozen, while the compliance records survive for the statutory retention window. Ask the operator to confirm its exact period in writing before you assume a shorter one.

Who else sees your data?

Data is shared with a defined set of processors rather than sold as a list. In practice that means:

  • Payment providers — Visa, Mastercard, Skrill, Neteller, ecoPayz and the banks behind transfers, which need your name and transaction data to settle
  • Game studios supplying the lobby, which receive session and bet data
  • Identity verification partners, which check your document against public and commercial records
  • Analytics and advertising platforms, which receive cookie and device-level data
  • Regulators and financial authorities, where a licence condition or legal request requires disclosure

Cross-border transfer is the honest caveat here. With a Curacao-registered operator and an Anjouan licence, your data may be processed outside the UK and EEA, under legal protections that differ from the ones you are used to.

What privacy rights do you have?

You can generally ask for a copy of the data held about you, ask for errors to be corrected, ask for deletion where no legal duty prevents it, and withdraw marketing consent at any time. Enforcement is the weak point: an offshore licensee is not answerable to a UK data regulator.

How do you request access to your data?

Send a written request to the operator’s support channel from the email address registered on the account, and state exactly what you want: account details, bet history, transaction records, communication logs. Ask for a response deadline in the same message and keep a dated copy. A vague request is easy to stall; a specific one is not.

Can you correct or delete your data?

Correction is straightforward — a misspelt surname or an outdated address should be fixed on request, and you want it fixed before verification, because a mismatch between your account name and your ID is the single most common reason a payout stalls.

Deletion is more limited. You can ask for the account to be closed and for marketing data to be erased, but records tied to anti-money-laundering obligations stay. Anyone closing an account for gambling-harm reasons should also look at the self-exclusion route: Responsible Gambling.

How do you opt out of marketing?

Three routes usually work, and it is sensible to use more than one:

  • Unsubscribe link at the foot of any promotional email
  • Communication preferences inside the account settings
  • A direct written request to support asking for removal from email, SMS and push lists

Opting out of marketing does not stop service messages such as withdrawal confirmations or verification requests, and it should not affect a bonus already credited to the balance.

How does Fortunica use cookies and tracking?

Cookies keep you logged in, remember your currency and language, measure which pages and games get used, and let affiliate and advertising partners attribute a sign-up to the site that referred you. Most can be refused through the browser; the strictly necessary ones cannot, because the session would break.

What types of cookies are used?

  • Strictly necessary — session, login state, security tokens and fraud checks
  • Functional — language, currency, sound settings and layout preferences
  • Analytics — page views, navigation paths, drop-off points, device breakdown
  • Advertising and affiliate — referral attribution, retargeting, campaign measurement

How do you manage cookie preferences?

Use the consent banner on first visit to reject anything beyond the necessary category, then use the browser itself as a second layer: block third-party cookies, clear stored data on exit, or run the casino in a private window. Rejecting analytics and advertising cookies does not restrict gameplay — it only reduces how precisely your behaviour is tracked.

What about third-party analytics and advertising?

Affiliate tracking is the part players rarely notice. When you arrive at Fortunica through a review site, a tracking parameter records the referral so commission can be attributed — that identifier travels with your session and is visible to the tracking platform. Ad platforms may also build interest profiles from your visit, which is exactly what a rejected advertising cookie prevents. The operator’s own binding wording sits here: Fortunica terms and conditions.

Frequently asked questions about Fortunica

What personal information does Fortunica collect?

Registration data such as name, date of birth, email, phone and address; automatic data including IP address, device and browser details and game session logs; and payment records from Visa, Mastercard, Skrill, Neteller, ecoPayz, bank transfer or crypto. Verification adds a government photo ID, a selfie with that ID, and a recent bank statement or utility bill.

How does Fortunica protect my data?

Traffic runs over TLS/SSL encryption, card details stay with the payment processors rather than the casino, and verification files sit behind restricted internal access. Because the operator is licensed offshore by the Anjouan Offshore Financial Authority rather than the UK Gambling Commission, oversight standards differ — so strong unique passwords and secure uploads matter more than usual.

Can I request deletion of my Fortunica account data?

You can request account closure and erasure of marketing data at any time by writing to support from your registered email. Identity and transaction records tied to anti-money-laundering duties are retained for a statutory period regardless, so deletion realistically means the account is frozen and promotional contact stops, not a full wipe.

Does Fortunica share my information with third parties?

Yes, with defined processors: payment providers such as Visa, Mastercard, Skrill, Neteller and ecoPayz; game studios including Pragmatic Play, Novomatic, Playson and Hacksaw Gaming; identity verification partners; analytics and affiliate platforms; and regulators where legally required. Because the operator is Curacao-registered, some processing happens outside the UK and EEA.

Read the operator’s own privacy wording in full before you upload a single document, and remember that Fortunica’s terms restrict United Kingdom customers. If you are outside the restricted list and want to check the current cashier and verification flow for yourself, open the casino directly.