CrocoSlots Privacy Policy
Policy version: 8 April 2026
This Privacy Policy explains how personal data is collected, used, shared, retained and protected in connection with CrocoSlots accounts and casino services.
Metlait SRL is the data controller. The company is registered in Costa Rica under number 3-102-911867 at El Guayaval, Residencial La Campina Casa Numero Q-11, Cartago, El Guarco, Tejar, 30801, Costa Rica.
Personal data collected
The personal data processed can include:
- Identity data: name, username, date of birth, gender, nationality and identification-document details.
- Contact data: residential address, proof of address, email address and telephone number.
- Financial data: payment details, deposits, withdrawals, transaction history and source-of-funds or source-of-wealth documents.
- Gaming data: games played, wagers, bonus use, login times and responsible-gaming interventions.
- Technical data: IP address, approximate location, device, browser, operating system, time zone and security records.
- Communication data: support messages, account notices and marketing preferences.
- Voluntary data: other information supplied during account use or support contact.
Data is collected directly from the account holder and, where required, from payment providers, identity-verification services, AML and politically exposed person databases, regulatory authorities, responsible-gaming databases and marketing partners.
How personal data is used
Personal data is processed where needed to:
- create and operate the account;
- process deposits and withdrawals;
- verify identity, age, location and payment ownership;
- meet KYC, anti-money-laundering and responsible-gaming obligations;
- prevent fraud, account abuse and security threats;
- provide support and resolve disputes;
- maintain and improve service performance;
- personalise services and send marketing where consent or another lawful basis applies.
The legal basis depends on the activity and can include performance of a contract, legal obligations, consent and legitimate interests in security, fraud prevention and service improvement.
Sharing personal data
Information can be shared only where necessary with companies in the same corporate group, game providers, payment processors, identity and AML verification providers, hosting or technical services, marketing partners, professional advisers, regulators and law-enforcement bodies where legally required.
Service providers are required to use the data for defined lawful purposes and apply appropriate security obligations. Personal data can also be transferred as part of a merger, acquisition or business sale, with notice provided where required.
Cookies and similar technologies
The website can use essential cookies for security, session management and core functions. Analytics and marketing technologies can also be used to measure performance, understand site use and personalise communications. Where consent is required, non-essential cookies are activated only after that consent is given and can be disabled through the available cookie settings.
International transfers
Some service providers process data in other countries. International transfers use appropriate safeguards, including recognised adequacy decisions or Standard Contractual Clauses where applicable.
Data retention
Personal data is retained only for the period required to provide services, meet legal obligations, prevent fraud and resolve disputes. Anti-money-laundering records are retained for at least five years after account closure. Data that is no longer required is deleted, anonymised or de-identified.
Privacy rights
Depending on the applicable law, an account holder’s rights can include:
- access to personal data;
- correction of inaccurate or incomplete data;
- deletion where no legal retention duty applies;
- restriction of processing;
- data portability;
- objection to legitimate-interest or direct-marketing processing;
- withdrawal of consent;
- lodge a complaint with the relevant data protection authority.
Solely automated decision-making is not part of standard account processing. If it is used in a specific case, the account holder is notified as required by applicable law.
Privacy requests are handled by the Data Protection Officer. Requests can be sent to [email protected] with the subject line “Data Protection Request”. The request must identify the registered account and the right being exercised; additional identity verification may be required before account data is disclosed or changed.
Data security
Personal data is protected through physical, technical and organisational controls. These include restricted access, authenticated systems, role-based permissions, secure data centres, staff privacy training and controlled deletion of information that is no longer required.
No online system can remove every security risk. Account passwords must remain private, and suspected unauthorised access should be reported to support immediately.
Minors
CrocoSlots services are not available to anyone below 18 or the higher legal gambling age in their jurisdiction. Personal data connected to confirmed underage use is removed or otherwise handled as required by law and account rules.
Policy changes
This Policy can be updated when legal requirements, processing activities or service providers change. Material changes may be communicated to account holders where required by law.

