Privacy Policy
Last updated: April 2026
This Privacy Policy explains what personal information ChipReign collects when you visit chipreign.com, why we collect it, who we share it with, and the rights you have under UK GDPR, the California Consumer Privacy Act and the Australian Privacy Act 1988. The short version: we collect very little, we do not sell it, and you can ask us to delete any of it.
Contents
- Who is ChipReign and how to contact us
- What personal information we collect
- How we use your personal information
- Legal bases for processing (UK GDPR)
- Who we share your information with
- International data transfers
- Cookies and tracking technologies
- How long we keep your information
- How we protect your information
- Your rights under UK GDPR, CCPA and the Australian Privacy Act
- Automated decision-making and profiling
- Children and young people
- Changes to this privacy policy
- How to file a privacy complaint
- FAQ
- Document history
Who Is ChipReign and How to Contact Us
ChipReign is an independent casino review site operating at chipreign.com. For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller for the personal information you share with us. For the purposes of the California Consumer Privacy Act (CCPA), we are the business handling your personal information. For the purposes of the Australian Privacy Act 1988, we treat the Australian Privacy Principles as binding on our handling of personal information relating to Australian readers, regardless of whether we meet the A$3 million turnover threshold.
This privacy policy sits alongside our Terms of Service, Cookie Policy and Affiliate Disclosure as the core legal framework for using chipreign.com. For editorial or corrections questions, see Contact.
If you have questions about this Privacy Policy or want to exercise your rights, email us at privacy@chipreign.com. We respond within 10 business days on rights requests, sooner where the law requires a shorter window.
What Personal Information Does ChipReign Collect?
ChipReign collects three narrow categories of personal information: what you give us when you contact us or subscribe, what your browser sends automatically when you load a page, and what our analytics and security tools log to keep the site running and spam-free.
We do not collect payment information. We do not process gambling transactions. We do not verify your identity for KYC purposes. None of that happens on chipreign.com. Any deposits, withdrawals or account activity sit entirely with the operator you sign up to.
Information you give us
- Email address, if you subscribe to our newsletter or email us a question.
- Message content, when you write to us at any of our published addresses.
- Comment or review text, if we enable commenting or review forms on a page and you choose to post. Comments require a display name and email (email not published).
- Correction requests, including any information you supply to explain why a claim on our site needs updating.
Information collected automatically
- IP address (a unique numeric label assigned to your connection).
- Approximate location derived from your IP address at country or region level, used to serve the correct jurisdictional version of a page (US, UK or Australian English and the right regulator citations).
- Browser type, version and language settings.
- Device type (desktop, mobile, tablet) and screen resolution.
- Referring URL (the page you arrived from).
- Pages visited, time on page and scroll depth via our analytics provider.
- Cookie identifiers set by first- and third-party cookies (see Cookies and tracking below).
What we do not collect
We do not collect payment card numbers, bank account details, government identification numbers, biometric data, or health data. We do not ask for your date of birth (we ask that you confirm you are over 18 or 21 where required; we do not record the input). We do not place session recording tools on chipreign.com and we do not use any tool that captures keystrokes or form entries beyond what you explicitly submit.
How We Use Your Personal Information
We use the information above for four purposes, and only these four:
- To run the website. Serve pages, remember your cookie consent, keep the site fast under load, and route you to the correct jurisdictional version of a page.
- To respond to you. When you email, submit a correction, or leave a comment.
- To improve the site. Aggregated analytics showing which articles are read, which links are clicked, and where readers drop off. We use this to prioritise editorial work, not to profile you.
- To protect the site. Block spam, bots, scraping and attacks; meet our legal obligations around bad-faith content and abuse reporting.
We do not use your personal information to build advertising audiences, sell it, rent it, auction it through real-time bidding, or share it with third parties for their own marketing purposes. And we do not plan to. If that ever changes, this policy will be updated first and we will notify email subscribers directly.
Legal Bases for Processing (UK GDPR)
Under UK GDPR and EU GDPR, we must identify a lawful basis for every piece of processing we carry out. Ours:
| Processing activity | Lawful basis |
|---|---|
| Serving pages and running the site | Legitimate interests (operating the site you requested) |
| Responding to emails and corrections | Legitimate interests and, where you initiate contact, consent |
| Analytics cookies | Consent (you must opt in via the cookie banner before analytics fires) |
| Strictly necessary cookies | Legitimate interests (site cannot function without them) |
| Email newsletter | Consent (you must explicitly subscribe) |
| Spam and abuse prevention | Legitimate interests (protecting the site and other users) |
| Complying with a regulator request or court order | Legal obligation |
Where we rely on legitimate interests, we have run a balancing test confirming that our interest in operating the site does not override your rights and freedoms. You have the right to object to processing based on legitimate interests; see the rights section below.
Who We Share Your Information With
A short list. We work with a small number of third parties who process personal information on our behalf under contractual data-processing terms. They are listed below by category.
- Hosting provider. Rocket.net, which operates the infrastructure chipreign.com runs on and receives standard server logs, including IP addresses, to deliver pages to you.
- Content delivery and security. Cloudflare, which sits in front of the site to filter bots, mitigate attacks and cache content closer to your location. Cloudflare processes IP addresses and request headers.
- Analytics. Google Analytics (with IP anonymisation enabled) where you have consented to analytics cookies. We do not enable Google Signals and we do not share Analytics data for advertising purposes.
- Email delivery. The provider we use for newsletters (disclosed at the point you subscribe).
- WordPress. The content management system that publishes the site. Core WordPress does not ship personal information off-site; plugins can, and every active plugin that does is listed in this section.
We also disclose personal information where we are legally required to: in response to a valid subpoena, court order, regulator request or law-enforcement investigation under applicable law. We do not hand data to third parties outside that legal framework.
International Data Transfers
ChipReign’s infrastructure is US-based. If you are reading from the UK, EEA or Australia, your personal information is transferred to and processed in the United States.
For UK and EEA readers, transfers rely on the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or the UK Addendum to the EU SCCs, as appropriate. Where our US service providers participate in the EU-US Data Privacy Framework and its UK Extension, we rely on that too.
For Australian readers, we take reasonable steps to ensure any overseas recipient of your personal information handles it in a way consistent with the Australian Privacy Principles, as required by APP 8.
Cookies and Tracking Technologies
chipreign.com uses first-party cookies that are strictly necessary for the site to function and optional analytics cookies that fire only after you opt in.
The full list of cookies, their purpose, duration and provider lives on our Cookie Policy. You can manage your preferences at any time via the cookie banner or your browser settings. Declining non-essential cookies does not affect your ability to read articles on the site.
How Long We Keep Your Information
| Category | Retention period |
|---|---|
| Server access logs (IP, URL, timestamp) | 30 days, rolling |
| Cloudflare security logs | Per Cloudflare’s policy, typically up to 7 days |
| Google Analytics user-level data | 14 months (minimum retention setting) |
| Email correspondence | 24 months after last contact, or longer if required to defend a legal claim |
| Newsletter subscriber email | Until you unsubscribe, plus 30 days for audit |
| Published comments / reviews | Until you request removal, or the article is unpublished |
Where law or regulator guidance requires longer retention (tax records, for example), we follow the longer period and only for the specific records affected.
How We Protect Your Information
The site runs on TLS 1.3 encryption end-to-end. Our admin accounts use strong unique passwords and two-factor authentication. Infrastructure access is restricted to named editorial operators. We run automated vulnerability scans on plugins and themes, and we apply security patches within the normal patch window published by WordPress core and our host.
No system is perfectly secure. If we identify a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours as UK GDPR requires, notify the OAIC where the breach is likely to result in serious harm to Australian residents (as required under the Notifiable Data Breaches scheme), and notify affected individuals where the risk to them is high.
Your Rights Under UK GDPR, CCPA and the Australian Privacy Act
You have the right to see what personal information we hold about you, correct it if it is wrong, ask us to delete it, restrict how we use it, object to certain processing, and complain to the regulator in your country if you think we have got something wrong.
The specific rights differ slightly by jurisdiction. Below is what applies to you, broken down by where you live.
UK and EEA residents (UK GDPR / EU GDPR)
- Right of access. Ask us for a copy of the personal information we hold about you.
- Right to rectification. Have inaccurate information corrected or incomplete information completed.
- Right to erasure. Ask us to delete your personal information, subject to legal exceptions.
- Right to restrict processing. Limit what we do with your information while we resolve a dispute or accuracy question.
- Right to data portability. Receive a structured, machine-readable copy of information you provided under consent or contract.
- Right to object. Stop us processing your information for legitimate interests or direct marketing.
- Right to withdraw consent. Where we rely on consent, you can withdraw it at any time without affecting prior lawful processing.
- Right to lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk) or your national supervisory authority in the EEA.
California residents (CCPA and CPRA)
- Right to know what personal information we collect, why we collect it, who we share it with, and the categories of sources.
- Right to delete personal information we have collected, subject to statutory exceptions.
- Right to correct inaccurate personal information we hold about you.
- Right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioural advertising, so there is nothing for you to opt out of today.
- Right to limit the use of sensitive personal information. We do not collect sensitive personal information as defined by the CPRA.
- Right to non-discrimination. We will not deny you service, charge you different prices or deliver a different quality of experience because you exercised a privacy right.
- Right to know about automated decision-making. We do not use automated decision-making or profiling that produces legal or similarly significant effects on you. See the dedicated section below.
California residents who believe their rights have been violated can complain to the California Privacy Protection Agency (CPPA) at cppa.ca.gov or the California Attorney General’s Office at oag.ca.gov/privacy/ccpa.
Australian residents (Australian Privacy Act 1988)
- APP 12, Access. Request a copy of the personal information we hold about you.
- APP 13, Correction. Ask us to correct inaccurate, out-of-date, incomplete, irrelevant or misleading personal information.
- Anonymity and pseudonymity (APP 2). You can interact with chipreign.com without identifying yourself, except where the law requires otherwise.
- Unsolicited personal information (APP 4). If we ever receive personal information about you that we did not solicit, we will determine whether we could have collected it lawfully; if not, we will destroy or de-identify it.
- Right to complain. Contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe your privacy rights have been breached.
Everyone else
If you live outside the UK, EEA, California or Australia, we still apply the spirit of the rights above. You can email privacy@chipreign.com to request access, correction, deletion or a stop to processing, and we will respond. Local law may give you additional or different rights; where applicable, those apply as written.
Automated Decision-Making and Profiling
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you. No algorithm on chipreign.com decides whether you see a particular bonus, get a different price, or receive a different level of service based on a profile we built about you.
Recommendations on the site are editorial (the team decides what to highlight) and the content you see is served based on your IP region to give you jurisdictionally correct information. That routing is not automated profiling under Article 22 of UK GDPR, the new CCPA rules effective 1 January 2026, or the Australian automated decision-making provisions commencing 10 December 2026.
Children and Young People
chipreign.com is not directed at anyone under 18. Under UK and Australian law, the legal minimum age for online gambling content is 18. Under US law, the legal minimum varies by state and product (typically 18 or 21). We take reasonable steps to prevent under-18s from engaging with the site, including age-gate affirmations before linking to operators and prominent 18+ / 21+ messaging in the footer of every page.
We do not knowingly collect personal information from anyone under 18. If you believe a child under 18 has submitted personal information to us, email privacy@chipreign.com and we will delete it promptly. For US readers, this covers the Children’s Online Privacy Protection Act (COPPA) obligations in the under-13 context and the expanded CCPA protections for under-16 data that took effect on 1 January 2026.
Changes to This Privacy Policy
We update this policy when the facts change: new processors, new regulators, new legal obligations, or new features on the site. Every update moves the “Last updated” date at the top and is logged in the Document History table at the bottom.
For material changes, we will also post a notice at the top of the homepage and, where we have your email, email our subscribers before the change takes effect. Material changes include: new categories of personal information collected, new purposes, new third-party processors handling non-trivial categories of data, or any change that reduces your rights.
How to File a Privacy Complaint
If you believe ChipReign has handled your personal information incorrectly, email privacy@chipreign.com with the details. If you are not satisfied with our response, you can escalate to the regulator in your country: the UK ICO, the California Privacy Protection Agency, or the Australian OAIC.
Contact us first so we have a chance to investigate and respond. Most privacy complaints are resolved within a single email exchange.
- UK / EEA: UK Information Commissioner’s Office, ico.org.uk/make-a-complaint
- California: California Privacy Protection Agency, cppa.ca.gov
- Australia: Office of the Australian Information Commissioner, oaic.gov.au/privacy/privacy-complaints
Frequently Asked Questions
What personal data do casino affiliate sites collect?
Casino affiliate sites typically collect IP address, browser and device information, referral URL, pages visited, and any details you submit voluntarily (email, comment text). ChipReign does not collect payment data, identity documents, or gambling transaction data, because those sit with the operator.
Is my IP address personal data under GDPR?
Yes. The UK ICO and EU Court of Justice have confirmed that dynamic and static IP addresses are personal data when they can be linked (directly or indirectly) to an identifiable person. We treat IP addresses as personal data throughout this policy.
How do I request deletion of my data?
Email privacy@chipreign.com with “Data deletion request” in the subject line. We will confirm receipt within 5 business days and complete the deletion within 30 days (sooner where CCPA or UK GDPR mandates). Some data may be retained where the law allows or requires it.
Do you share my data with casino operators?
No. When you click an outbound link to a casino, the operator may set its own cookies and log your visit; that is between you and them, governed by their privacy policy. ChipReign does not pass personal information to operators beyond what an affiliate tracking link conveys (a referral identifier, not your identity).
How long do you retain personal data?
Server logs: 30 days. Analytics: 14 months. Email correspondence: 24 months after last contact. Newsletter subscriber email: until you unsubscribe. Longer retention applies only where a specific legal obligation requires it.
Does the CCPA apply to websites outside California?
The CCPA applies to businesses that meet certain thresholds and collect personal information from California residents. Regardless of whether we meet those thresholds, ChipReign honours CCPA rights for California residents as a matter of policy, because it is the right standard to hold.
What rights do Australians have over their personal information?
Australian residents have rights under the 13 Australian Privacy Principles, including the right to access (APP 12), correct (APP 13), be informed about collection, choose anonymity where practical, and complain to the Office of the Australian Information Commissioner about any alleged breach.
How do I contact the ICO, CPPA or OAIC about a complaint?
ICO (UK): ico.org.uk/make-a-complaint or 0303 123 1113. CPPA (California): cppa.ca.gov. OAIC (Australia): oaic.gov.au/privacy/privacy-complaints or 1300 363 992. Contact ChipReign first via privacy@chipreign.com so we have a chance to resolve the issue.
Document History
| Date | Change |
|---|---|
| 2026-04-19 | Initial publication. |