By Fiona Nicoll – Updated June 2026
Casino Classic privacy policy decoded for Canadian players
Casino Classic has been collecting personal data about Canadian players since 2000. Over twenty-five years, that data infrastructure has grown to encompass millions of account records, identity verification documents, payment transaction histories, and detailed behavioural records of how players engage with the Games Global and Evolution Gaming library. In 2026, the platform operates under two distinct regulatory frameworks for different Canadian populations: the AGCO/iGaming Ontario through Apollo Entertainment Limited for Ontario players, and the Kahnawake Gaming Commission for players in other provinces. Each framework carries data handling obligations that shape how Casino Classic collects, uses, retains, and shares your personal information. This guide translates those obligations into plain language.
The regulatory framework governing Casino Classic’s privacy practices
Casino Classic’s privacy obligations in 2026 come from two primary sources for Canadian players. For Ontario accounts operated by Apollo Entertainment Limited, the AGCO’s requirements incorporate Ontario’s Freedom of Information and Protection of Privacy Act and Canada’s federal PIPEDA, with iGaming Ontario providing regulatory oversight of the operator’s compliance. For players in other provinces, the KGC’s licensing standards and PIPEDA apply. PIPEDA is the floor below which no Canadian player’s data can be handled regardless of which version of the platform they access – it applies as federal law across all provinces independently of licensing jurisdiction.
Casino Classic is part of the Casino Rewards Group – a network of fifteen-plus casino properties under shared operational infrastructure. That group membership adds a dimension to the privacy analysis that single-platform casino privacy guides typically don’t address: data flows within a corporate group that extends beyond the individual Casino Classic platform. The privacy framework must account for how data shared within the Casino Rewards Group is governed, and what protections apply to intra-group data transfers.
The platform uses 256-bit RSA encryption as certified by USERTrust – a more robust encryption standard than the 128-bit SSL more commonly cited across the industry – and all games are independently audited by eCOGRA for operational integrity alongside game fairness.
What data Casino Classic collects from Canadian players
Data provided directly at registration and account management:
| Category | Specific data points |
|---|---|
| Identity data | Full legal name, date of birth, gender, nationality |
| Contact data | Home address, email address, phone number |
| Verification data | Government-issued photo ID, proof of address, payment method documentation |
| Financial data | Card details, e-wallet credentials, bank information, CA$ transaction history |
| Account preferences | Responsible gambling settings, marketing consent, language preferences |
Data collected automatically through platform use:
| Category | Specific data points |
|---|---|
| Technical data | IP address, device type, browser version, operating system |
| Behavioural data | Games played, session duration, bet sizes, win and loss records |
| Location data | IP-based geolocation for provincial eligibility verification |
| Loyalty program data | Points earned, tier status, redemption history, cross-property activity |
| Communication data | Live chat transcripts, email support records |
| Cookie data | Session authentication, preference storage, analytics, marketing tracking |
The loyalty program data category is specific to Casino Rewards Group properties and represents a data dimension absent from standalone casino accounts. Casino Classic’s integration with the group’s shared loyalty infrastructure means your point accumulation, tier progression, and redemption activity across all group properties form part of the data profile held about you. This cross-property data is used for loyalty program administration – which is the core value the program delivers – and is governed by the privacy terms applicable to the Casino Rewards Group infrastructure.
How Casino Classic uses your personal data
Casino Classic processes Canadian player data for the following specific purposes:
- Account creation, authentication, and ongoing management
- Processing CA$ deposits, withdrawals, and bonus transactions
- Identity verification and KYC compliance under Canadian AML legislation
- Fraud detection, prevention, and financial crime investigation
- Regulatory compliance and reporting to the AGCO, iGaming Ontario, and KGC as applicable
- Responsible gambling monitoring – analysing behavioural patterns to identify potential harm indicators and restrict marketing to high-risk accounts
- Customer support and complaint resolution
- Casino Rewards Group loyalty program administration
- Platform development and game library improvement
- Marketing communications – with explicit prior consent only
The responsible gambling monitoring purpose carries specific weight given my research focus on gambling harm in Canada. Casino Classic’s AGCO licence requires specific measures to limit marketing to players identified as high-risk through behavioural analysis. That monitoring only works if the platform has access to your session and wagering data. From a policy perspective, this is a regulatory data processing requirement that serves player welfare directly rather than primarily serving commercial interests.
Third parties who may receive your data
| Third party category | Purpose | Notes |
|---|---|---|
| Casino Rewards Group entities | Loyalty program administration, duplicate account detection, group compliance | Shared infrastructure across 15+ properties |
| Payment processors | Processing CA$ transactions | Interac, Visa, Mastercard, Skrill, Neteller, iDebit |
| Identity verification providers | KYC and age verification | Third-party document authentication |
| Regulatory authorities | Legal compliance and reporting | AGCO, iGaming Ontario, KGC |
| IT and infrastructure providers | Platform hosting and security | Cloud servers and cybersecurity services |
| Analytics providers | Platform performance analysis | Usage and engagement tracking |
| Marketing platforms | Delivering consented communications | Email and content delivery |
| eCOGRA | Game and platform auditing | Independent certification body |
The Casino Rewards Group sharing requires the clearest explanation. Casino Classic shares administrative and compliance data within the group for three core operational purposes: managing the shared loyalty point and tier system across all properties, detecting duplicate accounts across the network, and maintaining group-level AML compliance. This is operational data sharing disclosed in the privacy policy and necessary for how the group’s shared infrastructure functions. It does not mean personal gambling data is shared with other group casinos for independent marketing targeting without your separate consent.
Casino Classic states that personal data is not sold to third-party advertisers. Under PIPEDA, such sales would require explicit consent that standard account creation flows cannot legally provide.
Data security
Casino Classic protects player data through 256-bit RSA encryption on all data transmission – certified by USERTrust and representing a stronger encryption standard than 128-bit SSL. eCOGRA’s ongoing platform audits cover operational integrity alongside game fairness, providing independent third-party oversight of platform data handling practices. Regular security assessments are conducted under the platform’s AGCO and KGC compliance obligations.
Data retention
| Data type | Retention period | Basis |
|---|---|---|
| Identity and KYC documents | 5 years post-account closure | Canadian AML legislation |
| Financial transaction records | 5 years post-transaction | Financial compliance |
| Game session history | 3 years | Dispute resolution |
| Support records | 3 years | Complaint documentation |
| Marketing consent records | Consent duration plus 1 year | PIPEDA compliance |
| Technical access logs | 12 months | Security monitoring |
Your rights as a Canadian player under PIPEDA
- Right of access – request a complete copy of all data Casino Classic holds about you
- Right to correction – request updates to inaccurate personal information
- Right to withdraw consent – for marketing and non-essential processing, opt out at any time
- Right to complain – file with the Office of the Privacy Commissioner of Canada; Ontario players can additionally escalate to iGaming Ontario
- Right to account closure – Casino Classic must close your account on request, subject to retention obligations
PIPEDA access requests must be addressed within 30 days. Contact the live chat support team to initiate any data rights request.