1. Who we are and how to reach us

CasinoHub ("CasinoHub", "we", "us") operates the website casinohub.app and the streaming tools reachable from it. For the processing described here we are the controller as defined in Article 4(7) GDPR.

Data protection enquiries and requests to exercise your rights: contact@casinohub.app. We answer requests under Articles 15 to 22 GDPR within one month and will tell you if we need longer, as Article 12(3) permits.

Where we act only on a streamer's instructions — for example when we store the chat of their channel or run their loyalty-point system — that streamer is the controller for that data and we are their processor. In that case, address requests about that data to the streamer; we will help them answer you.

2. What we collect

Streamer accounts. Email address and password (stored only as a hash), username, display name, avatar, biography and the settings you create. If you connect a platform, we store the access and refresh tokens for that connection, your channel identifier and channel name. If you configure your own mail server, we store those SMTP credentials so scheduled mail can be sent.

Content you create. Bonus hunts, stream layouts, widget configurations, store items, giveaways, tournaments, blog posts and similar records, including anything you upload such as images, sounds and video.

Viewers and chat participants. When someone takes part in your channel, we store their platform username and display name, their platform user identifier, and the record of what they did: chat messages shown in your overlays, loyalty-point balances, redemptions, giveaway and raffle entries, balance guesses, slot and song requests. Where a viewer signs in on our site to check a balance, we additionally store the account identifier supplied by the platform they signed in with.

Technical data. IP address, browser and device information, and timestamps, recorded in server logs. Clicks on outbound links we generate — the "Powered by CasinoHub" credits, short links and affiliate links — are logged with the referring source, so streamers can see where their traffic comes from.

Analytics. See section 7.

We do not knowingly process special categories of personal data as defined in Article 9 GDPR, and you should not send us any.

To provide the service to account holders — creating and running your account, overlays, bot, widgets and integrations. Legal basis: performance of a contract, Article 6(1)(b) GDPR.

To run channel features for viewers — showing chat in an overlay, awarding and spending loyalty points, entering giveaways, recording requests and guesses. Legal basis: performance of a contract where a viewer has signed in with us, otherwise our and the streamer's legitimate interest in operating the channel features the viewer chose to take part in, Article 6(1)(f) GDPR.

To keep the service secure and working — abuse prevention, rate limiting, fraud and spam defence, diagnosing faults, backups. Legal basis: legitimate interests, Article 6(1)(f) GDPR.

To communicate with you — replies to your enquiries, and service messages about outages, security or material changes. Legal basis: contract and legitimate interests.

Analytics and any marketing email. Legal basis: your consent, Article 6(1)(a) GDPR, which you may withdraw at any time with effect for the future.

To meet legal obligations, such as retention duties or lawful requests from authorities. Legal basis: Article 6(1)(c) GDPR.

4. We do not sell your data, and we do not hand your identity to third parties

CasinoHub collects data about streamers and about the viewers who take part in their channels. We do not sell personal data. We do not trade, rent or otherwise make personal data available to third parties for those third parties' own purposes, and we do not use it for cross-context behavioural advertising.

Casinos, gambling operators, affiliate partners, sponsors and advertisers never receive personally identifying data about you from us. Where a streamer or an operator is shown click and conversion statistics, those are aggregate counts — how many clicks a link received and from which source — and never the identity of the individuals behind them.

There are exactly three situations in which personal data leaves our systems, and none of them is a sale. First, service providers who process data strictly on our instructions under a contract meeting Article 28 GDPR; they are listed in section 6. Second, the streaming platform a piece of data came from, when the feature requires it — for example when the bot posts a reply into the same chat the message came from. Third, where we are legally obliged to disclose, or where disclosure is necessary to establish, exercise or defend legal claims.

If we were ever to be involved in a merger, acquisition or asset sale, personal data could form part of the transferred assets. We would tell you before it happened and before any new privacy policy applied to you.

5. Streaming platform connections

Connecting a platform is always your choice and always uses that platform's own authorisation flow. We never see or store your password for Twitch, Kick, YouTube, Discord or Spotify. We request the narrowest set of permissions each feature needs, and you can disconnect any platform at any time in your dashboard, which deletes the stored tokens.

YouTube. CasinoHub uses YouTube API Services. By connecting YouTube you also agree to the YouTube Terms of Service at https://www.youtube.com/t/terms. Google's privacy policy is at https://policies.google.com/privacy and describes how Google handles data. You can revoke CasinoHub's access to your YouTube data at any time through the Google security settings page at https://myaccount.google.com/permissions. We use the YouTube Data API only for the connected channel: to find the active broadcast, read the live chat for the chat overlay and command handling, post the bot's replies, carry out moderation actions you ask for, and read stream and channel status. We store live-chat data only for as long as the overlay needs it and delete it on the schedule in section 8.

Twitch, Kick, Discord and Spotify. We use each platform's API only for the connected account and only for the features you enable — reading and posting chat, follower and subscriber events, Discord notifications, and the currently playing track for the Spotify widget. Your use of those platforms remains governed by their own terms and privacy policies.

Platform data stays scoped to the streamer who connected it. One streamer's data is never exposed to another.

6. Processors and sub-processors

We use a small number of providers who process personal data on our behalf under Article 28 GDPR contracts. They may not use the data for their own purposes.

Supabase — database, authentication, file storage and server functions. Vercel — website and application hosting. Google — YouTube API Services for connected YouTube channels, and Google Analytics as described in section 7. Intuition Machines (hCaptcha) — bot protection on sign-up and sign-in forms. Twitch, Kick, Discord and Spotify — for the connections you enable. An email provider of your choosing, where you configure your own SMTP server for outgoing mail.

Some of these providers are established in the United States or process data there. Such transfers take place on the basis of the European Commission's Standard Contractual Clauses under Article 46(2)(c) GDPR and, where the provider is certified, the EU-US Data Privacy Framework, together with additional safeguards where required.

We will keep this list current. If we add a processor that materially changes how your data is handled, we will update this policy and, where the change requires it, ask for your consent.

7. Cookies, local storage and analytics

Strictly necessary cookies and local storage keep you signed in, remember your session and protect forms against automated abuse. These are required for the service to function and are set on the basis of Article 6(1)(f) GDPR and the corresponding exemption for strictly necessary storage under the ePrivacy rules.

Analytics. Our public website and the streamer dashboard use Google Analytics to understand which pages are used and where problems occur. Google Analytics sets cookies and processes your IP address and usage events; Google acts as our processor for this and may transfer data to the United States under the safeguards described in section 6. Google's own information is at https://policies.google.com/privacy.

Analytics is not loaded on OBS browser sources — overlay and widget pages carry no analytics at all, because they are software windows rather than visitors.

You can object to Google Analytics using Google's browser add-on at https://tools.google.com/dlpage/gaoptout, by using your browser's cookie controls, or by sending a request to contact@casinohub.app. Where we rely on your consent for analytics, you may withdraw it at any time with effect for the future, and withdrawal does not affect the lawfulness of processing carried out beforehand.

8. How long we keep data

Account data is kept for as long as your account exists. When you delete your account we delete or irreversibly anonymise your personal data without undue delay, except where we must keep something to meet a legal obligation or to defend a legal claim.

Live chat messages captured for overlays are short-lived by design and are removed automatically on a rolling schedule; they are a display buffer, not an archive.

Loyalty-point balances, redemptions and entries are kept while the streamer's channel features remain active, so balances a viewer earned are not silently lost.

Server logs and click records are kept only as long as they are useful for security and statistics, and are then deleted or aggregated so that no individual remains identifiable.

Platform tokens are deleted as soon as you disconnect that platform.

9. Your rights

Under the GDPR and the UK GDPR you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21), and the right to withdraw consent at any time (Article 7(3)).

You also have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you (Article 22). We do not carry out such decision-making.

To exercise any of these, write to contact@casinohub.app from the address associated with your account, or — if you are a viewer without an account with us — tell us the platform and username you used so we can find the right records. We do not charge for this. We may ask for information to confirm your identity, but only what is genuinely needed.

You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement (Article 77 GDPR).

Viewers: much of what we hold about you exists because a streamer runs channel features you took part in. If we act as that streamer's processor we will pass your request to them and support them in answering it.

10. Security

Data is encrypted in transit. Access to production data is restricted to the people who need it. Database access is enforced at row level, so one account's data is not reachable from another's session, and overlay pages used in OBS run without any signed-in session at all.

Platform tokens and mail credentials are stored so that they are not readable through the public interface. Passwords are never stored in plain text.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by Article 33 GDPR and inform you where Article 34 requires it.

11. Children

CasinoHub is not intended for children. Because our tools are used by streamers whose content concerns casino games, the service is directed exclusively at adults aged 18 or over, and you must be 18 or over to hold an account.

We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, write to contact@casinohub.app and we will delete it.

12. International users

We apply the standard described here to everyone, wherever you are. If you are in the United Kingdom, references to the GDPR should be read as references to the UK GDPR and the Data Protection Act 2018, and the supervisory authority is the Information Commissioner's Office.

If you are in a jurisdiction with additional rights — for example a right to know, delete or opt out of sale under California law — those rights are available to you as well. As stated in section 4, we do not sell personal data and do not share it for cross-context behavioural advertising.

13. Changes to this policy

We may update this policy as the service changes. The date at the top always reflects the current version.

If a change materially affects how we handle your personal data, we will tell you before it takes effect — by email or a notice in the dashboard — and, where the change relies on consent, we will ask for it rather than assume it.

In short: we collect data about streamers and about the viewers who take part in their channels, because the features cannot work otherwise. We never sell it, and we never hand your identity to casinos, sponsors, advertisers or any other third party for their own purposes.

Questions about this document? Contact us and we'll answer directly.