Privacy Policy
How we handle personal data, cookies, verification, payments and support for Vegas Hero.
Last updated July 22, 2026
Privacy Policy
We set out below how we handle personal data for Vegas Hero and the services associated with our historical casino operation. This page explains the main privacy principles that applied to our platform, the types of information connected with account creation, gameplay, payments, verification, support and responsible play, and the way we used that information in the course of operating our services.
Who we are
Vegas Hero was operated by Genesis Global Limited, a company registered in Malta. The platform held B2C gaming licences from the Malta Gaming Authority (MGA) under licence number MGA/CRP/314/2015 and from the UK Gambling Commission (UKGC). Our platform served players in the United Kingdom, Canada, the Nordic countries and parts of Europe, and supported transactions in GBP, EUR, USD, CAD and ZAR.
The casino is closed and is described here as a historical operator. This privacy policy reflects the services, controls and player interactions associated with that operation.
Scope of this policy
This policy covered personal data that arose when players registered an account, used our games, contacted support, participated in promotions, completed identity checks or requested withdrawals. It also covered technical and operational data connected with secure access to our platform, payment handling, mobile use and account safety.
We collected and used information only as required to run our services, meet regulatory expectations, process transactions, maintain account security and provide player support. Where a specific legal basis or retention period was required for administrator completion, it must be inserted precisely for the relevant processing activity.
Information we handled
The information associated with our platform typically included account details, contact details, transaction records, payment-method information, verification records, gameplay history, device and session data, support communications and responsible-gambling settings. We also handled the data needed to administer a loyalty programme, manage promotions and maintain account integrity.
Players could use Visa, Mastercard, Skrill, Neteller, ecoPayz and Paysafecard, with a standard minimum deposit of 10. Deposits and withdrawals could involve different settlement times depending on the payment method used. E-wallet withdrawals were typically instant to 24 hours, while cards and bank transfers usually took 1 to 5 business days.
How we used data
We used personal data to operate player accounts, process deposits and withdrawals, fulfil identity checks, maintain security, respond to support requests, apply responsible-gambling tools and administer platform features such as loyalty benefits and promotions. We also used information to protect against fraud, abuse, unauthorised access and other risks to our services.
Our platform offered a welcome package for new players and a multi-tier loyalty programme with account managers, exclusive bonuses, faster withdrawals, prize draws and personalised gifts. Data linked to those features was handled so that we could deliver the relevant benefit, track eligibility and maintain accurate account records.
Verification and KYC
Identity verification was required before the first withdrawal. That process included photo ID, proof of address and proof of payment ownership. We used verification information to confirm identity, protect player accounts, meet platform requirements and support secure payment processing.
Where the relevant administrator fields require a more detailed retention rule, that rule should be added exactly for the applicable jurisdiction and processing purpose. We did not add any invented retention period here.
Cookies and platform technology
Our services used website technologies and cookies to provide secure sign-in, session continuity, account functionality, language and locale support, analytics where enabled, and other operational features needed for the platform to function properly. Any cookie categories, consent flows, storage periods or vendor details that must appear in a full legal implementation should be added using administrator-approved facts only.
Because this page is a privacy policy, we keep the description focused on the handling of personal data and operational cookies rather than promotional material.
Security
We used 128-bit SSL encryption and PCI DSS-compliant gaming infrastructure to help protect data in transit and support secure payment handling. Security measures also extended to access control, payment verification and account monitoring.
No system can eliminate every risk, but our platform was designed to handle player information with a strong security posture appropriate to the services we operated.
Support and communication
Players could contact us through 24/7 Live Chat, email ticketing and international telephone lines. We used support communications to investigate account queries, manage verification issues, resolve payment questions and handle privacy-related requests.
Where a contact email, postal address or data-protection contact point is required for a final published version, that information should be added only from administrator-approved source data.
Responsible gambling
We offered deposit limits, session reminders, wagering and loss limits, cool-off periods and permanent self-exclusion. These tools helped players manage their activity and supported safer play across our platform.
Requests connected with responsible-gambling settings could require secure handling of account data so that the chosen limits or exclusions were applied correctly and could be enforced on the account.
Sharing and service providers
Our services depended on third-party providers for payment processing, game supply, live dealer content, platform infrastructure and related operational support. The platform included games from NetEnt, Microgaming, Play’n GO, Evolution Gaming, Quickspin and Yggdrasil, across jackpots, video slots, RNG tables and live dealer games.
Where processing involved service providers, we expected those parties to handle personal data only for the relevant operational purpose and in line with contractual and regulatory obligations. Specific processor names, service roles, jurisdictions and transfer mechanisms should be added only where administrator-approved facts exist.
International operations and transfers
Our platform operated across multiple markets, including the United Kingdom, Canada, the Nordic countries and parts of Europe. Because of that reach, player data could be processed in environments linked to more than one jurisdiction.
Any final statement on international transfers, safeguards, adequacy measures or transfer mechanisms must be based on exact administrator-approved details for the applicable route, destination and legal structure. We do not invent those mechanisms here.
Data retention
We kept personal data only as long as needed for the operation of the platform, compliance obligations, account administration, dispute handling, security controls and recordkeeping connected with our services. Specific retention periods should be inserted only where exact administrator guidance is available for the relevant data category.
Your rights
Depending on the applicable jurisdiction, players may have rights to access, correct, delete, restrict or object to certain processing, and to manage consent-based features where those apply. Requests were handled through the support channels connected with our platform.
Where a jurisdiction-specific rights notice is required, it should reflect the exact legal framework for the published version and the markets covered by the page.
Children and age restriction
Our services were intended for adults only. The platform applied an age restriction of 18 and was not designed for minors. If an account indicated age-related concerns, the account could be reviewed and restricted in line with applicable procedures.
Changes to this policy
We could update this policy to reflect operational, legal or technical changes affecting our services, payments, verification processes, security controls or support channels. Any updated version would take effect from the stated date of publication on the page.
Contact
Questions about privacy, account data or platform handling of personal information could be raised through the support channels listed above. Any legal notice address, data-protection contact or controller contact point for a final published version must be entered from administrator-approved source details only.