Zimpler online casino
Last updated: 1 September 2025
This Zimpler online casino privacy page explains what information may be collected during account and payment activity, where it can come from, why it is processed, who may receive it and how long it may be retained. Data controller: Northbound N.V. Registered address: Emancipatie Boulevard Dominico F. “Don” Martina 31, Willemstad, Curaçao. Final casino domain: zimplercasino.com.
What information may be collected
Account data can include several categories of information that appear during an account, payment or verification journey. Depending on the service and activity, this can include:
- identity;
- contact;
- banking;
- transaction information.
Registration fields, minimum-age information and any additional account data collected:
- Registration requires email address, password, full name, date of birth, country of residence, preferred currency (GBP for the UK account), and optionally mobile phone number.
- Minimum age is 18 years.
- Zimpler account privacy also covers technical account data. Additional account data may include IP address at registration, device fingerprint, language preference, communication consents, username, and account ID.
Data overview
Data | What it may include | Why it may be used |
|---|
Identity | name, date of birth and identification data | verification and account checks |
Contact | email, phone, address and IP address | communication, security and account support |
Banking | bank account details | payment initiation and authentication |
Transaction | amount and transaction details | payment processing, records and troubleshooting |
Identity | What it may include name, date of birth and identification data | Why it may be used verification and account checks |
|---|
Contact | What it may include email, phone, address and IP address | Why it may be used communication, security and account support |
|---|
Banking | What it may include bank account details | Why it may be used payment initiation and authentication |
|---|
Transaction | What it may include amount and transaction details | Why it may be used payment processing, records and troubleshooting |
|---|
For Zimpler transaction privacy, this overview separates ordinary identity and contact details from banking and transaction data connected with payment activity.
Where personal data can come from
Not every piece of information is entered directly into a form. Depending on the service, personal data can come from:
- the player;
- the bank;
- the merchant;
- third-party verification providers.
Third-party data sources, identity databases or enrichment providers used by the casino:
We may receive personal data from:
- Payment data sources include transaction providers. Zimpler payment services, Trustly, Skrill, Neteller and Visa/Mastercard acquiring banks may provide transaction statuses, payer references and fraud scores.
- Verification provider Sumsub — identity verification results, document authenticity scores, PEP and sanctions screening.
- Fraud-prevention provider SEON — device fingerprinting, IP reputation, behavioural risk signals.
- Public registers and sanctions lists were legally required for AML screening.
No additional data enrichment beyond these categories is used unless stated in a specific notice.
Why verification uses personal data
Zimpler verification privacy covers data used to confirm identity, prevent fraud and meet anti-money-laundering or other compliance requirements. Checks can also help confirm that the correct person is using the account or payment method. The process may also include screening or automated checks.
Verification provider, document types, automated or manual review process, decision rules and review retention:
Verification is handled by Sumsub. Documents may include:
- government-issued photo ID (passport, driving licence, national ID);
- proof of address no older than three months;
- a selfie with the ID document;
- proof of payment-method ownership (e.g., screenshot of Skrill account or bank statement);
- source-of-funds or source-of-wealth evidence when triggered.
Zimpler KYC privacy controls also cover review records:
- Automated checks verify document authenticity and screen against sanctions/PEP lists.
- Manual review is performed by trained compliance staff for complex cases or when automated checks are inconclusive.
- The review can result in approved, rejected, or additional information requested.
- Verification records are retained for 5 years after account closure for AML and dispute purposes.
Bank and payment information
- Pay by Bank authentication takes place through the banking journey used to approve a transaction.
- An online banking password should not be sent to a casino through an ordinary message.
- The amount and selected account should be confirmed before the payment is approved.
- Zimpler payment privacy also covers transaction records. Transaction information can include the bank account involved, amount and other payment details.
Payment providers, exact Pay by Bank integration and the division of responsibility between those providers and the casino controller:
- Pay by Bank is provided through the named payment provider and, where available, Trustly.
- These providers redirect the player to their own secure banking environment to authenticate the payment with their bank.
- The casino receives only a token, transaction reference, amount and status — not the player’s online banking credentials or full bank account details.
- For Zimpler Pay by Bank privacy, authentication remains separate from casino records. Payment providers act as independent controllers for the authentication and processing of payment instructions; the casino is the controller for transaction records once received.
- Full payment credentials should only be entered on the provider’s secure page.
How long data may be retained
Closing an account does not necessarily mean that every record is deleted immediately. Financial and compliance records can remain subject to retention requirements. Different data categories can have different retention periods depending on the processing purpose and applicable legal obligation.
Retention periods for account data, transactions, KYC records, support communications, logs, marketing records and cookie data:
- Zimpler retention rules differ by record type. Account and profile data: for the life of the account plus 5 years after closure.
- Transaction records: 5 years from the transaction date.
- KYC/verification records: 5 years after account closure.
- Support communications: 2 years after ticket resolution.
- Server and access logs: 12 months.
- Marketing consent records: retained while consent is valid and for a reasonable period after withdrawal to evidence compliance.
- Cookie data: up to 12 months for analytics/preference cookies; session cookies expire when the browser closes.
After the relevant period, data is securely deleted or irreversibly anonymised.
Who may receive personal data
Zimpler data sharing is limited to relevant purposes. Personal data may be shared with parties involved in a payment, verification or account process. These can include banks, the merchant and payment-system providers. Specialist service providers may also receive data where they are needed to deliver, verify or protect the service. Sharing should be limited to stated purposes.
Payment providers, verification providers, hosting suppliers, communications tools, analytics providers, game suppliers and other material recipients:
- Payment providers include Zimpler payment services, Trustly, Skrill, Neteller, Visa/Mastercard acquiring banks and bank transfer intermediaries.
- Verification provider: Sumsub.
- Fraud prevention: SEON Technologies Ltd.
- Privacy infrastructure includes external service providers. Hosting and CDN: Amazon Web Services (Frankfurt, Germany) and Cloudflare.
- Communications: SendGrid (email delivery), tawk.to (live chat).
- Analytics: Google Analytics 4 (with IP anonymisation), Hotjar (with sensitive field masking).
- Game suppliers: NetEnt, Pragmatic Play, Evolution Gaming, Play’n GO and other studios whose games are available on the platform. They receive user ID and session data but not payment details.
- Professional advisors: legal counsel, auditors, compliance consultants.
- Authorities: regulators, law enforcement, courts, and financial intelligence units when legally required.
Cookies, transfers and privacy rights
Zimpler cookie settings cover consent and tracking choices. Cookie categories, consent controls, analytics tools and advertising technologies:
- Essential cookies: session ID, CSRF token, cookie consent status.
- Preference cookies: language, currency, display settings (persist up to 12 months).
- Analytics cookies: Google Analytics 4 (IP anonymisation) and Hotjar; used to understand usage and improve the service.
- Marketing cookies: pixels from Facebook, Twitter, Google Ads may be set only after consent and only for campaign tracking/retargeting.
- A cookie consent banner (provided by CookieYes) allows users to accept or reject non-essential cookies. Choices are stored for 12 months.
Hosting provider, server locations and international transfer destinations or safeguards:
- Zimpler transfer safeguards apply when UK personal data moves internationally. Primary hosting is with Amazon Web Services (AWS) in the Frankfurt, Germany region (eu-central-1).
- Cloudflare provides CDN and security services and may process limited data at global edge locations.
- Where UK personal data is transferred to a country without applicable UK adequacy regulations, safeguards may include the UK International Data Transfer Agreement or the UK Addendum to EU Standard Contractual Clauses, supported by an appropriate transfer risk assessment and technical measures such as encryption or pseudonymisation.
- Data may also be processed in Curaçao for regulatory and administrative purposes.
Applicable lawful bases for processing by market and purpose:
- Zimpler lawful bases differ by processing purpose. Performance of contract: account management, game provision, payment processing.
- Legal obligation: identity verification, AML checks, record-keeping, disclosure to authorities.
- Legitimate interests: fraud prevention, network security, service improvement and direct marketing where permitted under UK GDPR and PECR.
- Consent: non-essential cookies, marketing emails/SMS where legally required, special category data if ever requested.
For UK players, the applicable framework is UK GDPR and the Data Protection Act 2018, together with other relevant UK privacy rules. Consent may be withdrawn at any time without affecting processing already carried out lawfully.
Zimpler privacy rights depend on the applicable framework. Depending on the applicable law and situation, a player may be able to:
- request access to personal data held about them;
- request correction of inaccurate information;
- request deletion where the data no longer needs to be kept;
- request restriction or object to certain processing;
- request data portability where the conditions apply;
- withdraw consent where consent is the legal basis.
Those rights do not mean every record must be deleted on request.
Procedure, contact channel, identity-check process and response period for exercising privacy rights:
- To exercise any privacy right, contact privacy@zimplercasino.com from the email address registered to the account.
- We may ask for additional information (e.g., account ID, proof of identity) to verify the request.
- We will respond within 30 calendar days, which may be extended by up to 90 days in complex cases; you will be notified of any extension.
- Requests that are manifestly unfounded or excessive may be refused or charged a reasonable administrative fee where permitted by law.
Supervisory authority or complaint body by market:
Zimpler privacy complaints can follow the relevant supervisory route. Northbound N.V. remains subject to the applicable Curaçao privacy framework, while a UK player may also raise a data-protection concern with the UK Information Commissioner’s Office where UK data-protection law applies.
Security, children and privacy contact
Security measures, encryption standards, access controls, fraud-prevention tools, incident response and storage controls:
- Zimpler data security combines technical and organisational controls. Encryption in transit: TLS 1.3 across the entire platform.
- Encryption at rest: AES-256 for databases and backups.
- Access controls: role-based access with multi-factor authentication for staff; least-privilege principle.
- Fraud prevention: SEON for device fingerprinting, IP reputation and transaction monitoring.
- Incident response: documented procedure with 72-hour notification to authorities and affected users where required.
- Storage controls: data hosted on AWS with ISO 27001, SOC 1/2/3 certified infrastructure; regular penetration tests and vulnerability scans.
Minimum age by market and the procedure for handling information relating to an underage account:
- The minimum age for the UK version is 18 years.
- If we discover an underage account, we will immediately close it, void any winnings in accordance with the Terms, and delete all personal data except what is necessary to prevent re-registration (e.g., email hash on a blocklist).
- Parents or guardians who suspect underage use should contact support immediately.
Players should:
- use the normal account and payment routes;
- keep passwords and bank authentication private;
- check the domain before entering sensitive information;
- avoid sending identity documents through ordinary messages;
- review unexpected payment or verification prompts before approving them.
The Zimpler privacy contact details are as follows:
- Data controller: Northbound N.V.
- Privacy contact or Data Protection Officer: Data Protection Officer, Northbound N.V.
- Email: privacy@zimplercasino.com
- Registered company name: Northbound N.V.
- Registered address: Emancipatie Boulevard Dominico F. “Don” Martina 31, Willemstad, Curaçao
- Supervisory authorities: Curaçao Data Protection Authority (controller jurisdiction); UK Information Commissioner’s Office where UK data-protection law applies.