iGaming Finder — Privacy Policy
Version 1.0. Effective 23 August 2026.
This policy explains what personal data iGaming Finder handles, why, and what you can do about it.
It covers two different groups of people, and they have very different relationships with us. Read the part that applies to you.
- Section 2 — you are a customer or a user of the Service. You gave us your data.
- Section 3 — you are named in the information we compile, most likely because a gambling regulator published your name as a director or contact of a licensed company. You never gave us anything, and you did not ask to be here. Section 3 is written for you.
1. Who is responsible
The controller of this data is an individual trading as iGaming Finder, not a company. The controller's full legal name and address are given on request — write to privacy@igamingfinder.com and we will reply with them. You do not need a reason to ask, and asking does not start any other process.
Contact for anything in this policy: privacy@igamingfinder.com.
We are a small operation. There is no data protection officer, and the address above reaches a person, not a queue.
2. If you are a customer or user
2.1 What we hold
- Account data — your email address, the name on the account, your plan, your API keys, and when you accepted our Terms and which version.
- Usage data — the requests you make to the Service, what you searched for, which records you retrieved, credits consumed, timestamps, and the IP address the request came from. We keep this to run the Service, to enforce limits, to bill correctly and to investigate abuse.
- Communications — emails you send us and our replies.
- Product analytics — how the site and dashboard are used.
- Marketing attribution — where you arrived from, if you arrived through a campaign link.
2.2 Why, and on what basis
| Purpose | Basis |
|---|---|
| Providing the Service and your account | Performance of a contract |
| Billing, invoicing and records | Contract, and legal obligation |
| Rate limits, security, abuse investigation | Legitimate interests — running a service that is not abused |
| Product analytics and improvement | Legitimate interests — knowing which parts of the product are used |
| Service emails about your account | Contract |
| Marketing emails | Consent, which you can withdraw at any time |
You can object to processing based on legitimate interests: see section 5.
2.3 Cookies
We use cookies that are strictly necessary for sign-in, security and abuse prevention, and analytics cookies that tell us how the site is used.
Where the law requires it, we ask before we measure anything. If your browser reports a European time zone, nothing is stored on your device until you agree, and refusing is one click and no harder than agreeing. Elsewhere the analytics cookies are set by default and you can switch them off at any time — the same posture every other site already takes with you. Nothing on the site depends on them either way.
We work out which case you are in from your browser's own time zone: not from your IP address, and not through any third party. It is a rough signal, and it is rough in your favour — anything we cannot read is treated as if you had to be asked. Your answer is kept in a single cookie, so the whole site remembers it, including the dashboard on its own sub-domain.
You can change that answer at any time, in either direction: the Cookie settings button at the bottom of this page reopens the question, and the same control sits in the footer of the main site. We ask again a year after your last answer.
3. If you are named in our data
You are most likely reading this because you found your name, business email, phone number or address in iGaming Finder, and you did not put it there.
3.1 Where it came from
Almost always, from a gambling regulator. When a company applies for a licence it files details with the regulator — often including the names of directors and a contact address — and many regulators publish that filing. We collect what the regulator published, from the regulator's own website or files.
Some company and people information comes from commercial data providers rather than from a register. If you ask us, we will tell you which of the two your record came from, and name the source.
3.2 What we hold about you
Only what the source published. In practice that is some combination of: your name, your role or directorship, a business email address, a business phone number, a business or registered address, and the company and jurisdiction the record belongs to. We also record when we observed it.
We do not build a profile of you, we do not track you across the web, and we do not make any automated decision about you.
3.3 Why we hold it, and on what basis
Our basis is legitimate interests: providing business information about a regulated industry to companies operating in it. The information concerned is business information about a person acting in a professional capacity, and in the great majority of cases it is information a public authority chose to publish.
We have weighed that against your interests. You can disagree with our conclusion, and you can object — section 5. You do not have to give a reason.
3.4 What we do not do with it
We do not sell your data as a marketing list, we do not send you marketing, and our Terms require our customers to have their own lawful basis before contacting anyone whose details they found through us. If a customer has contacted you in breach of that, tell us at the address in section 1 — that is a Terms breach and we act on it.
4. Who else sees the data
We use these providers to run the Service. Each processes data only as needed to provide its part.
| Provider | What it does | Where |
|---|---|---|
| Hetzner Online GmbH | Servers and databases | Germany |
| Cloudflare, Inc. | DNS, CDN, bot protection, email routing and sending | Global, incl. United States |
| PostHog, Inc. | Product analytics | United States |
| Functional Software, Inc. (Sentry) | Error monitoring | United States |
| Typesense | Search index | Alongside our servers |
Transfers outside the UK and EEA. PostHog and Sentry are in the United States, and Cloudflare's network is global. Where personal data reaches them it leaves the UK and EEA. Each of these providers processes it under its own published data-processing terms, which carry the safeguards required for such transfers. Those terms are public, and we will name the specific mechanism here once a single one applies across all three.
Product analytics identify our customers by email address. If you are a customer, your email address reaches PostHog. If you are a person in section 3, your data does not go to PostHog at all.
We also disclose data where the law requires it, and to a buyer or successor if the business transfers — see clause 16 of the Terms.
5. Your rights
Whichever section you fall under, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything inaccurate;
- delete it;
- stop processing it, or restrict how we use it;
- object to processing we base on legitimate interests — including everything in section 3;
- receive it in a portable form, where that right applies;
- withdraw consent where we relied on consent.
Write to the address in section 1. We will not ask you to justify the request and we do not charge for it. We aim to respond within one month.
If you object under section 3, we will suppress your record. That means we stop showing it and keep the minimum needed to make sure a later collection from the same source does not quietly reinstate it. If we believe we have a compelling ground to continue, we will tell you what it is rather than ignore you.
One thing we cannot do: change what a regulator published. If the underlying register entry is wrong or should not be public, that is a matter for the regulator, and we will tell you which one and point you at it.
You can also complain to a data protection authority — the one for the country you live in. You do not have to come to ours, and you do not have to contact us first, although telling us is usually faster.
6. How long we keep it
- Account and billing records: for the life of the account and for as long as we must keep financial records afterwards.
- Usage, API and search logs: kept for as long as they are useful to the product — what was asked of the Service is what tells us what to collect next. The IP address and browser identifier attached to those records are used only to investigate abuse, and are not needed once a record stops being recent.
- Register-sourced records: for as long as the source publishes them and they are relevant to the Service, unless you object under section 5.
- Suppression records: indefinitely, because their whole purpose is to keep a deletion from being undone.
7. Security
Access is limited to those who need it. Data is encrypted in transit. Backups are encrypted and held separately. We do not pretend to hold a security certification, because we do not.
8. Changes
We publish the current version here with its effective date. If a change matters to you, we will say so rather than quietly re-date the page. Previous versions stay available.
Version 1.0 — 23 August 2026.