HeyRoller privacy policy: how your data is handled
A casino account can contain identity documents, payment records, device identifiers and detailed behavioural data. This 2026 HeyRoller privacy policy guide explains what information may be collected, why it is processed, which third parties may receive it and how users can manage their privacy rights.
What the HeyRoller privacy policy covers
The HeyRoller privacy policy describes how the platform collects, uses, stores and shares personal information connected with account activity. It covers registration data, device details, browsing behaviour, cookies, marketing preferences, storage practices, security controls and third-party integrations.
The policy should be read before registration because data processing begins as soon as a person interacts with the website or creates an account. Casino privacy is broader than promotional emails because routine operation may involve login records, gameplay preferences, technical identifiers and payment-related information.
Personal data collected by HeyRoller
HeyRoller states that it may collect account registration information, device and browser data, usage analytics and behavioural information. The published examples include usernames, email addresses, operating system details, device identifiers, browser versions, login history, game preferences and browsing patterns.
These categories allow the platform to distinguish accounts, maintain sessions and understand how customers use the website. They can also create a detailed picture of when a person logs in, which pages they open and which types of games attract their attention.
|
Data category |
Examples named by HeyRoller |
Likely operational purpose |
|
Registration data |
Username and email address |
Account creation and communication |
|
Device data |
Operating system and device ID |
Compatibility and security analysis |
|
Browser data |
Browser type and version |
Performance optimisation |
|
Login information |
Dates and frequency |
Account access and security monitoring |
|
Behavioural data |
Game preferences and browsing patterns |
Recommendations and service improvement |
|
Cookie data |
Session and preference information |
Login continuity, analytics and advertising |
|
Communication settings |
Marketing and notification choices |
Message delivery and opt-out management |
The policy gives examples rather than a fully itemised data inventory. Players may therefore need to contact HeyRoller when they want to know exactly which personal records are held against their individual account.
Registration details and identity information
HeyRoller’s privacy page specifically names usernames and email addresses as information provided during account creation. It says these details are used to verify identity and support a smoother service experience.
Casino accounts may also require additional information under separate verification and payment procedures. Identity documents, proof of address and payment ownership evidence should be reviewed alongside the privacy policy because these files contain more sensitive information than a standard email-based registration.
Keeping account data accurate
Players should enter their legal details consistently and correct errors as soon as they are discovered. Inaccurate information can create problems during KYC, password recovery, payment checks and withdrawal review.
The UK GDPR principles include accuracy and require reasonable steps to correct or remove inaccurate personal information. They also require processing to remain lawful, fair, transparent and limited to stated purposes.
Device, browser and technical information
HeyRoller says it may collect the operating system, device ID, browser type and browser version used to access the platform. This information helps the website adapt to different devices and identify performance or compatibility problems.
Technical identifiers can also contribute to security checks, fraud prevention and session monitoring. Players should understand that changing from a familiar device, location or network may create a different technical profile and potentially trigger additional account checks.
Behavioural and gameplay data
The policy states that HeyRoller may record login history, game preferences and browsing patterns. It says this information supports service improvements, recommendations and more efficient navigation.
Behavioural information can reveal more than which game was opened. Repeated logins, preferred categories, session timing and response to promotions can be combined to produce a detailed account profile.
A privacy-conscious user should therefore review personalisation and marketing controls rather than assuming all recommendations are generic. The platform states that communication settings can be adjusted through the account, including marketing emails and in-game notifications.
Why HeyRoller uses personal information
HeyRoller identifies account verification, platform optimisation, browsing improvements and personalised recommendations among its purposes. Its privacy and cookie pages also connect data use with session management, advertising, analytics, security and technical diagnostics.
A transparent privacy framework should connect each category of information with a specific purpose. The ICO identifies purpose limitation, data minimisation and accountability as core UK GDPR principles, meaning data should be collected for defined reasons and limited to what is necessary.
|
Purpose |
Data that may support it |
Player impact |
|
Account operation |
Username, email and session identifiers |
Enables login and account communication |
|
Platform optimisation |
Browser and device information |
Improves compatibility |
|
Recommendations |
Game preferences and browsing activity |
Personalises lobby content |
|
Security |
Device, login and session records |
Helps identify suspicious access |
|
Analytics |
Aggregated usage information |
Supports performance decisions |
|
Marketing |
Preferences and behavioural signals |
Determines promotional communication |
Cookies and similar technologies
HeyRoller uses cookies to support login, session continuity, preferences, analytics and personalised content. Its cookie policy identifies essential, session, persistent, functional, analytics and performance cookies, together with browser storage technologies such as local storage and IndexedDB.
The privacy policy says session-based cookies may expire after 24 hours, while the separate cookie policy says some session cookies expire when the browser closes. Persistent cookies may remain until their expiry date or manual deletion, so users should treat the cookie policy as containing several different retention models.
Cookie consent and control
HeyRoller states that users can manage cookie preferences through its Cookie Control feature and browser settings. The site also explains that blocking cookies may affect login persistence, session management, language choices and personalisation.
ICO guidance says organisations must explain what cookies do and why they are used, while consent must be actively and clearly given unless a valid exemption applies. Cookies that are strictly necessary to provide a requested service may fall within an exemption, but analytics and advertising technologies generally require separate assessment.
Analytics and third-party tracking
The HeyRoller cookie policy names Google Analytics and Google Tag Manager as tools used for aggregated analytics and deployment of tracking scripts. These technologies are described as helping the platform understand user interaction and improve performance.
The presence of a third-party analytics tool means some website information may be processed within an external provider’s technical environment. Players should review cookie choices and the relevant provider information when they want a clearer understanding of how tracking technologies operate.
Third-party services and payment integrations
HeyRoller states that its platform incorporates external services and that those partners follow their own privacy policies. It warns that the terms applied by a third-party feature may not match HeyRoller’s own policy.
The cookie page specifically refers to payment gateways and social media sharing integrations. Payment processors may need transaction, account or device information to authorise payments, investigate fraud and complete withdrawals.
Marketing and communication preferences
HeyRoller allows users to customise marketing emails and in-game notifications. The privacy page says customers may opt out through account settings, while the cookie page also refers to unsubscribe links in promotional emails.
Opting out of promotions should not prevent essential account messages such as password resets, security warnings, document requests or payment updates. These operational communications may remain necessary even when personalised marketing has been disabled.
Data storage and retention
HeyRoller says personal information is stored on secured servers using SSL encryption and regular backups. The policy states that account data is retained while the customer continues using the services and that associated data is removed within 30 days after deactivation or deletion.
This is a broad retention statement and does not explain whether specific records must be retained for fraud, payment, dispute or legal purposes. A user requesting deletion should therefore ask whether any information will remain, what categories are excluded from deletion and which lawful basis supports continued storage.
Security controls described by HeyRoller
HeyRoller lists TLS encryption for sensitive transfers, regular software updates, server-log access restrictions and regular backups among its security measures. It also says staff receive privacy training and that stored information is subject to access controls.
No online service can eliminate every security risk, so players must also protect their side of the account. HeyRoller recommends passwords containing at least eight characters, mixed character types and no common dictionary words.
Useful personal security controls include:
- using a unique password not shared with other websites;
- avoiding saved logins on shared devices;
- keeping the browser and operating system updated;
- avoiding document uploads through public Wi-Fi;
- checking the website address before entering credentials;
- signing out after using a shared computer;
- reporting unexplained login or payment activity immediately.
International data handling
The HeyRoller policy says stored information is not shared outside the European Economic Area. It also states that the platform aims to follow GDPR, the EU e-Privacy Directive and other rules applicable in the user’s jurisdiction.
This statement should be read together with the use of third-party services because integrated providers may operate through complex international infrastructure. Customers seeking certainty should ask where account records, backups, analytics data and support records are physically processed.
The HeyRoller policy does not provide a detailed international transfer mechanism or list of processing locations. That omission does not prove that an unlawful transfer occurs, but it limits the ability of a user to independently assess the full data flow.
Your privacy rights
HeyRoller expressly gives users the ability to review and correct stored data, request deletion after account deactivation and withdraw consent. Requests are directed to the platform through email or customer support.
UK data protection guidance also covers rights such as access, rectification, erasure, restriction, objection and data portability where the relevant legal conditions apply. The availability of a particular right depends on the processing purpose and lawful basis rather than applying identically to every record.
|
Request |
What the user is asking for |
|
Access |
A copy or description of personal data held |
|
Rectification |
Correction of inaccurate or incomplete information |
|
Erasure |
Deletion where no valid retention reason remains |
|
Restriction |
Temporary limitation of specific processing |
|
Objection |
Review or cessation of certain processing activities |
|
Consent withdrawal |
End of processing based specifically on consent |
|
Marketing opt-out |
Cessation of promotional communications |
How to submit a privacy request
A request should identify the account clearly without exposing more personal information than necessary. The user should state which right is being exercised, which data or processing activity is involved and the preferred contact method for the response.
Use this workflow:
- Contact HeyRoller through the confirmed support channel.
- State that the message is a privacy or data protection request.
- Identify the relevant account email.
- Describe the information or action required.
- Ask for acknowledgement and a reference number.
- Provide identity evidence only through a secure channel.
- Retain the original request and all responses.
- Follow up when the stated response period expires.
Privacy complaints in 2026
From 23 June 2026, organisations handling personal data must provide a clear way to raise a data protection complaint. They must acknowledge complaints within 30 days, investigate them appropriately and communicate the outcome.
A complaint may concern incorrect data, unexplained retention, continued marketing, denied access or an unclear response to a deletion request. The message should distinguish the privacy issue from unrelated disputes about bonuses, gameplay or withdrawal timing.
When the response remains inadequate and the relevant jurisdiction permits escalation, the user may seek guidance from the appropriate data protection authority. HeyRoller’s regulatory and corporate position should be verified separately before assuming that a specific external complaint route applies.
Protecting minors’ information
HeyRoller prohibits gambling participation by people under 18 or below another applicable minimum age. The policy asks users to report suspected minor involvement so the platform can take appropriate action.
Age controls protect both the integrity of the account and the personal information of children. Adults should not create accounts for minors, share credentials or permit young people to upload documents through an adult account.
Practical privacy checklist
Privacy risk can be reduced by limiting unnecessary data exposure and monitoring account settings. The user should understand which information is required for account operation and which processing activities remain optional.
Before using HeyRoller, check that:
- the website address is genuine;
- the privacy and cookie policies are accessible;
- optional cookies can be controlled;
- marketing preferences can be changed;
- registration data is accurate;
- payment methods belong to the account holder;
- documents are uploaded only through secure channels;
- account access uses a unique password;
- third-party provider policies have been reviewed;
- support provides a traceable privacy complaint process.
FAQ
What personal data does HeyRoller collect?
HeyRoller lists registration details, device data, browser information, login history, game preferences and browsing patterns.
Why does HeyRoller collect device information?
It says device and browser data are used to improve compatibility, performance and platform functionality.
Does HeyRoller use cookies?
Yes, it uses essential, session, persistent, functional, analytics and performance cookies.
Can I reject optional cookies?
HeyRoller says cookie preferences can be adjusted through Cookie Control and browser settings.
Which analytics services are named?
The cookie policy identifies Google Analytics and Google Tag Manager.
Can I stop marketing emails?
Yes, preferences can be changed in the account or through the unsubscribe link in promotional messages.
How long does HeyRoller retain account data?
It says data is retained during account use and removed within 30 days after deactivation or deletion.
Can I request a copy of my data?
Users may request access to information held about them where the relevant privacy rules apply.