Privacy Policy
Effective date: 27 March 2026
This Privacy Policy explains how WinShark collects, uses, stores, discloses, and protects personal data when you visit or use au-winsharkcasino.com, including when you register an account, use gambling services, make payments, contact support, participate in promotions, or otherwise interact with WinShark online casino services in Australia.
WinShark is committed to handling personal data in a lawful, fair, and transparent manner. As a provider of gambling-related services, WinShark may act as a data controller in relation to the personal information processed through WinShark Casino, WinShark Casino Australia, WinShark casino AU, Casino WinShark, and associated services. In addition to contractual requirements necessary to provide an account and process gameplay, WinShark may process personal data to comply with legal obligation requirements, including anti-money laundering, counter-terrorism financing, identity verification, fraud prevention, consumer protection, and responsible gambling obligations.
By registering an account and using WinShark online services, you acknowledge that your personal data will be processed as described in this privacy policy. Where processing is based on consent, you may withdraw that consent at any time; however, this will not affect the lawfulness of processing carried out before withdrawal and may limit WinShark’s ability to provide certain services.
Who We Are
For the purposes of this Privacy Policy, WinShark is the brand operating the website au-winsharkcasino.com. References in this document to WinShark, WinShark Casino, WinShark online casino, WinShark online, Win Shark, and Win Shark casino refer to the same brand and related service environment.
If you have any questions about this Privacy Policy or wish to exercise your user rights, you may contact:
- Email: [email protected]
Scope of This Privacy Policy
This Privacy Policy applies to personal data collected through:
- the website au-winsharkcasino.com
- account registration and account management processes
- deposits, withdrawals, and payment verification procedures
- customer support communications
- bonus, promotion, loyalty, and marketing communication systems
- identity verification, KYC, AML, and CFT checks
- technical monitoring, analytics, and security tools
- any other interactions with WinShark Casino Australia services
This policy is intended to reflect applicable privacy principles relevant to Australia, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and where relevant, internationally recognised privacy standards such as gdpr-style transparency, lawful basis, and user rights concepts for cross-border service operations. References: Privacy Act 1988 (Cth); Australian Privacy Principles; Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).
Information We Collect
WinShark may collect and process a broad range of personal data depending on how you use the website and services.
Information You Provide Directly
This may include:
- full name
- date of birth
- residential address
- billing address
- email address
- telephone number
- username and account credentials
- preferred language and communication preferences
- records of consents and responsible gambling settings
- payment-related details submitted during deposits or withdrawals
- information contained in support requests, complaints, and correspondence
- survey responses, promotion entries, and account verification submissions
Gambling and Transaction Data
To operate WinShark casino AU services, WinShark may collect:
- betting history
- game activity records
- wagering behaviour
- deposit and withdrawal history
- account balance information
- bonus usage records
- payment method metadata
- transaction timestamps
- chargeback or disputed transaction records
- self-exclusion or gambling limit settings
Technical and Device Information
When you access WinShark online platforms, WinShark may automatically collect:
- IP address
- device identifiers
- browser type and version
- operating system
- log-in times and session data
- geolocation data derived from technical signals
- cookie data and similar tracking information
- referral URLs and pages viewed
- crash logs, event logs, and security monitoring records
KYC, AML, and CFT Verification Information
To meet legal obligation requirements, WinShark may request and process identity verification documents and related information, such as:
- government-issued identification
- proof of address documents
- proof of payment ownership
- bank statements where necessary for verification
- source of funds or source of wealth information
- facial verification or liveness check results where used
- sanctions, politically exposed person, or adverse media screening results
Information from Third Parties
WinShark may also receive personal data from:
- identity verification providers
- fraud prevention databases
- payment processors
- financial institutions
- analytics providers
- game providers
- public registers or public records
- regulators, law enforcement, or government authorities
- affiliated companies within the corporate group
How We Use Your Information
WinShark processes personal data only where there is a valid reason to do so. Depending on the circumstances, data processing may be necessary for contract performance, compliance with legal obligation, legitimate business interests, protection of vital interests, public interest considerations, or consent where required.
Providing Gambling Services
WinShark uses personal data to:
- create and administer your account
- verify eligibility and age
- process bets and gaming activity
- manage deposits and withdrawals
- provide customer support
- maintain account management records
- administer bonuses, promotions, and loyalty features
- enforce terms and conditions and platform rules
Compliance With Legal and Regulatory Duties
WinShark may process personal data to comply with obligations relating to:
- aml and cft monitoring
- kyc and identity verification
- anti-fraud screening
- responsible gambling controls
- prevention of underage gambling
- tax, accounting, and audit requirements
- complaint handling and dispute resolution
- lawful requests from regulators or public authorities
Fraud Prevention and Platform Security
Personal data may be used for:
- detecting suspicious transactions
- preventing bonus abuse and collusion
- identifying unauthorised account access
- securing systems and networks
- investigating misuse of the website
- maintaining audit trails and internal compliance records
Research, Analytics, and Service Improvements
WinShark may use personal data, or data in aggregated and de-identified form, to:
- analyse website performance
- improve user experience
- identify technical issues
- conduct internal reporting
- enhance responsible gambling interventions
- improve risk management and compliance systems
Marketing Communication
WinShark may use your contact details and account activity information to send service-related messages and, where permitted by law, marketing communication relating to products, promotions, responsible updates, or features relevant to WinShark Casino Australia.
Marketing communication may include:
- promotional emails
- bonus or event notifications
- reminders about unfinished registration or verification steps
- customer retention messages where legally permitted
You may opt out of direct marketing at any time by:
- following the unsubscribe instructions included in the marketing email
- contacting [email protected] and requesting removal from marketing lists
Please note that even if you opt out of marketing, WinShark may still send non-promotional service communications that are necessary for account operation, legal compliance, security, payment processing, or responsible gambling purposes.
Obtaining Personal Information
WinShark obtains personal information through both direct and indirect channels.
Information Collected Directly From You
WinShark collects information when you:
- fill in registration forms
- upload verification documents
- make deposits or request withdrawals
- contact customer support
- participate in promotions or surveys
- set responsible gambling limits
- submit complaints or disputes
- use the website, games, or account dashboard
Information Collected Indirectly
WinShark may collect information from third-party providers and publicly available sources, including:
- electronic verification systems
- payment and banking service providers
- fraud and risk intelligence services
- analytics and cookie technologies
- affiliates or referral partners where applicable
- regulatory or law enforcement notices
- publicly accessible sanctions or enforcement lists
If WinShark receives personal data from a third party, it will process that information only where reasonably necessary for service provision, legal compliance, security, or legitimate operational purposes.
Cookies and Similar Technologies
WinShark uses cookies and comparable technologies to support website functionality, improve security, analyse usage, and personalise certain service features.
These technologies may be used to:
- keep you logged in securely
- remember your settings
- measure traffic and site performance
- detect unusual activity or bot behaviour
- support fraud prevention controls
- improve navigation and service improvements
Some cookies are necessary for the operation of the website, while others support analytics or user experience. You can manage certain cookie preferences through your browser settings; however, disabling essential cookies may affect the functionality of WinShark online services.
Data Recipients
Access to personal data is limited to persons and organisations that have a legitimate need to know the information for the purposes described in this Privacy Policy.
Recipients may include:
- authorised employees involved in account management, compliance, payments, support, risk, and security
- companies within the same corporate group where operationally necessary
- external compliance consultants, auditors, and legal advisers
- data processors providing hosting, analytics, support, verification, and payment services
- software suppliers and technical infrastructure partners
- responsible gambling and fraud monitoring providers
All such access should be subject to appropriate confidentiality, contractual, and security controls.
Releasing Data to Third Parties
WinShark may disclose personal data to third parties where necessary and proportionate for lawful business and regulatory purposes.
This may include disclosure to:
- payment processors to complete deposits and withdrawals
- banks and financial institutions involved in transaction processing
- identity verification and kyc service providers
- aml and cft screening providers
- fraud prevention agencies and security vendors
- game providers and platform integration partners where needed for gameplay or investigations
- professional advisers, auditors, and insurers
- law enforcement bodies, courts, regulators, or government agencies when required by law
- prospective purchasers, investors, or corporate restructuring participants subject to confidentiality obligations
WinShark may also release data where it reasonably believes disclosure is necessary to:
- comply with a legal obligation
- protect the rights, safety, and property of WinShark, its users, or the public
- investigate suspected illegal activity
- enforce contractual terms
- respond to complaints, disputes, or regulatory inquiries
WinShark does not sell personal data in the ordinary commercial sense.
International Data Transfers
Because online gambling services, technical infrastructure, and third-party data processors may operate across multiple jurisdictions, personal data may be transferred to or accessed from countries outside Australia.
Where cross-border disclosure occurs, WinShark will take reasonable steps to ensure that the recipient handles personal data in a manner consistent with applicable privacy protections. Such steps may include:
- contractual data protection clauses
- vendor due diligence
- technical access restrictions
- encryption and security standards
- transfer impact reviews where appropriate
By using WinShark online casino services, you acknowledge that some international data processing may be necessary for the delivery, security, and compliance of the platform.
Data Retention
WinShark retains personal data only for as long as necessary for the purposes for which it was collected, including legal, regulatory, tax, accounting, audit, fraud prevention, and dispute resolution requirements.
For certain records, particularly those relevant to aml, cft, and kyc obligations, WinShark may be required to keep data for at least 5 years after the end of the business relationship or after the completion of a transaction, depending on the applicable legal requirement and record type. References: Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth); AUSTRAC guidance materials.
Retention periods may vary depending on:
- the type of data collected
- the purpose of processing
- legal and regulatory obligations
- limitation periods for legal claims
- ongoing investigations or disputes
- responsible gambling and fraud monitoring needs
Once retention is no longer necessary, WinShark will take reasonable steps to securely destroy, delete, or de-identify personal data.
Where the law permits, you may request erasure of personal data after mandatory retention periods have expired. However, this right is not absolute and may be limited where WinShark must continue to retain information to comply with legal obligation requirements, establish or defend legal claims, or maintain necessary business records.
Security of Your Data
WinShark applies technical and organisational measures designed to protect personal data against unauthorised access, misuse, alteration, loss, or disclosure.
These measures may include:
- ID and password access controls
- role-based internal access restrictions
- secure hosting environments
- encryption of data in transit using ssl or equivalent protocols
- encryption and hashing where appropriate
- firewall and intrusion monitoring systems
- anti-fraud and anomaly detection tools
- logging, audit trails, and access monitoring
- staff confidentiality obligations and training
- document handling controls for kyc materials
Although WinShark takes reasonable steps to secure personal data, no internet transmission or storage environment can be guaranteed to be completely secure. Users are responsible for keeping account credentials confidential and for notifying WinShark immediately if they suspect unauthorised use of their account.
Accuracy of Information
WinShark relies on the accuracy of personal data provided by users in order to comply with gambling, payment, and regulatory obligations. You should ensure that the information you provide is complete, accurate, and up to date. WinShark may suspend account functions, restrict withdrawals, or request additional verification if information appears inaccurate, inconsistent, or incomplete.
Your Rights
Subject to applicable law, you may have rights in relation to your personal data, including the right to:
- request access to personal data held about you
- request correction of inaccurate or outdated personal data
- request clarification about how your data processing is carried out
- withdraw consent where processing depends on consent
- object to certain direct marketing activities
- request erasure in limited circumstances after retention obligations expire
- request restriction of certain processing where legally applicable
- lodge a complaint about how your personal data is handled
These user rights are not absolute. WinShark may refuse or limit a request where permitted by law, including where the request would prejudice fraud prevention, aml or cft obligations, legal proceedings, regulatory reporting, security measures, or the rights of others.
To exercise your rights, contact:
WinShark may request sufficient information to verify your identity before responding to a privacy-related request.
Complaints and Contacting Us
If you believe that WinShark has not handled your personal data in accordance with applicable privacy requirements, you may contact WinShark first so that the matter can be reviewed and addressed.
Contact email:
If you are not satisfied with the response, you may have the right to lodge a complaint with the Office of the Australian Information Commissioner or another competent supervisory or regulatory authority, depending on the nature of the issue and the jurisdiction involved. Reference: Office of the Australian Information Commissioner, www.oaic.gov.au.
Children and Age Restrictions
WinShark services are intended only for persons who are legally permitted to use gambling services in their relevant jurisdiction. WinShark does not knowingly collect personal data from underage individuals. If WinShark becomes aware that personal data has been submitted by a person who is not legally eligible, it may take steps to suspend the account, cancel associated activity where appropriate, and delete or retain relevant data as required by law.
Updates to This Privacy Policy
WinShark may amend this Privacy Policy from time to time to reflect legal, regulatory, operational, or technological changes. The updated version will be posted on au-winsharkcasino.com with the revised effective date.
Where changes are material, WinShark may take additional steps to bring the update to your attention through service notifications or account communications where appropriate. Continued use of WinShark Casino after the effective date of an updated Privacy Policy will signify acknowledgement of the revised terms, except where additional consent is required by law.
Legal References
This Privacy Policy has been prepared with regard to principles and obligations arising under the following sources, as applicable:
- Privacy Act 1988 (Cth)
- Australian Privacy Principles
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- guidance published by AUSTRAC
- guidance published by the Office of the Australian Information Commissioner
For questions about this privacy policy, personal data, data retention, identity verification, consent withdrawal, or other privacy matters relating to WinShark, WinShark Casino, or WinShark online casino services, please contact [email protected].
