Privacy and personal-data handling for Boomerang Bet accounts

Last updated: 21 September 2026.

This policy explains the categories of personal information connected with a Boomerang Bet account, why those records may be processed, how they can be shared and protected, and which choices or legal rights may apply. It covers website and mobile-browser activity, registration, identity verification, betting and gaming records, payments, support communication, marketing preferences and safer-gambling interactions.

The policy should be read with the current Terms and Conditions, cookie controls and any jurisdiction-specific notice displayed during registration. Where a legal requirement conflicts with an optional preference, the legal obligation controls.

Data collected directly from the account holder

Registration data can include legal name, date of birth, residential address, country, preferred currency, email, phone number, username and security credentials. Verification data may include identity documents, photographs, liveness results, proof of address, nationality, occupation, tax or identification numbers and source-of-funds evidence when required.

Financial records can include payment method, masked card or bank details, wallet addresses, transaction amounts, currencies, dates, status, provider references and ownership evidence. Full card security codes should not be stored or requested through ordinary support messages.

Data groupExamplesPrimary purpose
IdentityName, DOB, ID, selfieAge, KYC and account-owner verification
ContactEmail, phone, addressService messages, recovery and legal notices
FinancialMethod, amount, masked details, walletDeposits, withdrawals, AML and fraud control
ActivityBets, games, bonuses, session historySettlement, product operation and dispute review
DeviceIP, browser, device identifiers, logsSecurity, diagnostics and abuse prevention
PreferencesLanguage, currency, marketing choicesAccount configuration and communication control

Information generated through use

Technical records may include IP address, device and browser type, operating system, language, login times, page interactions, referral information, cookie identifiers, approximate location and security events. Activity records include selections, stakes, accepted odds, game rounds, outcomes, deposits, withdrawals, bonus status and safer-gambling settings.

Automated monitoring can identify duplicate accounts, unusual device changes, payment inconsistency, coordinated betting, bonus abuse, fraud indicators or signs of gambling harm. A flag does not necessarily determine an outcome by itself; manual review may follow.

Purposes and legal bases

Data may be used to create and administer the account, deliver sportsbook and casino services, settle transactions, perform identity and age checks, prevent fraud, meet anti-money-laundering obligations, maintain security, answer support requests, manage promotions and apply safer-gambling controls.

Depending on the applicable law, processing can rely on contract, legal obligation, legitimate interests, consent or protection of vital interests. Marketing based on consent can be withdrawn. Records required for legal compliance or dispute defence cannot necessarily be erased when consent is withdrawn.

  • Contract: account operation, ticket settlement, game history and payment instructions.
  • Legal obligation: KYC, AML, sanctions, tax, regulatory reporting and record retention.
  • Legitimate interests: security monitoring, fraud prevention, service diagnostics and claim defence.
  • Consent: optional marketing, non-essential cookies and specific communication choices where required.
  • Safer gambling: risk detection, limits, exclusions and intervention records.

Cookies and comparable technologies

Essential cookies keep sessions secure, remember authentication state and support account functions. Preference cookies store language or display choices. Analytics measure performance and navigation. Marketing technologies can measure campaign activity or personalise messages where permitted.

Non-essential cookies should be controllable through the consent interface. Blocking all cookies can prevent sign-in, cashier operation or game launch when the affected cookie is technically necessary. Browser deletion does not erase server-side account records.

Cookie classTypical functionChoice
Strictly necessaryAuthentication, security and load balancingRequired for core service
PreferencesLanguage, currency and interface settingsCan usually be changed
AnalyticsPerformance and usage measurementConsent or opt-out may apply
MarketingCampaign attribution and tailored promotionOptional where law requires consent

Sharing and international processing

Information can be shared with payment processors, identity-verification suppliers, fraud and security vendors, game and sportsbook technology providers, hosting and communication services, professional advisers, group companies and competent authorities. Each recipient should receive only the data needed for its role.

A provider may process information outside the account holder’s country. Where required, transfer safeguards can include adequacy decisions, contractual clauses or other lawful mechanisms. A transfer does not remove applicable confidentiality and security duties.

Retention and deletion

Account data is retained for as long as needed to provide the service, meet KYC and AML duties, preserve self-exclusion controls, investigate fraud, settle disputes and comply with tax or regulatory requirements. Different record classes can have different retention periods.

Closing an account does not trigger immediate deletion of every record. Transaction, verification, complaint and exclusion information may need to remain restricted and archived. When the retention purpose expires, data should be deleted or irreversibly anonymised.

Individual rights

Depending on location, rights may include access, correction, deletion, restriction, portability, objection, withdrawal of consent and review of certain automated decisions. A request must identify the account and may require verification so that data is not released to an impersonator.

Requests should specify the right being exercised and the relevant data or period. A response can be limited where disclosure would affect another person, compromise fraud controls or conflict with a legal retention duty. A complaint can also be raised with the competent data-protection authority.

  1. Submit the request through the current privacy or support contact.
  2. State the account email and precise right requested.
  3. Complete proportionate identity verification.
  4. Receive confirmation, clarification or a reasoned response.
  5. Escalate to the relevant authority if the response remains disputed.

Security and personal responsibility

Administrative, technical and organisational controls can include encrypted transmission, access controls, logging, segregation, monitoring, backups and incident response. No internet service can promise absolute security. Users should keep passwords unique, enable additional authentication where offered and report suspicious access quickly.

Do not send an unmasked card, password or recovery code through ordinary email. Verification files should be uploaded through the secure account route named by support. Public Wi-Fi should be avoided for payments and document submission.

Children, safer gambling and policy changes

The service is not intended for persons below the legal gambling age. Age checks and identity evidence may be used to prevent underage access. Parents and guardians can use device controls and blocking tools to reduce accidental access.

Safer-gambling information can be processed to apply limits, exclusions and risk interventions. Policy changes should be dated and presented through the site or account. Material changes may require a new notice or consent where the law demands it.