Skip to main content

HeyRoller privacy policy: how your data is handled

A casino account can contain identity documents, payment records, device identifiers and detailed behavioural data. This 2026 HeyRoller privacy policy guide explains what information may be collected, why it is processed, which third parties may receive it and how users can manage their privacy rights.

What the HeyRoller privacy policy covers

The HeyRoller privacy policy describes how the platform collects, uses, stores and shares personal information connected with account activity. It covers registration data, device details, browsing behaviour, cookies, marketing preferences, storage practices, security controls and third-party integrations.

The policy should be read before registration because data processing begins as soon as a person interacts with the website or creates an account. Casino privacy is broader than promotional emails because routine operation may involve login records, gameplay preferences, technical identifiers and payment-related information.

Personal data collected by HeyRoller

HeyRoller states that it may collect account registration information, device and browser data, usage analytics and behavioural information. The published examples include usernames, email addresses, operating system details, device identifiers, browser versions, login history, game preferences and browsing patterns.

These categories allow the platform to distinguish accounts, maintain sessions and understand how customers use the website. They can also create a detailed picture of when a person logs in, which pages they open and which types of games attract their attention.

Data category

Examples named by HeyRoller

Likely operational purpose

Registration data

Username and email address

Account creation and communication

Device data

Operating system and device ID

Compatibility and security analysis

Browser data

Browser type and version

Performance optimisation

Login information

Dates and frequency

Account access and security monitoring

Behavioural data

Game preferences and browsing patterns

Recommendations and service improvement

Cookie data

Session and preference information

Login continuity, analytics and advertising

Communication settings

Marketing and notification choices

Message delivery and opt-out management

The policy gives examples rather than a fully itemised data inventory. Players may therefore need to contact HeyRoller when they want to know exactly which personal records are held against their individual account.

Registration details and identity information

HeyRoller’s privacy page specifically names usernames and email addresses as information provided during account creation. It says these details are used to verify identity and support a smoother service experience.

Casino accounts may also require additional information under separate verification and payment procedures. Identity documents, proof of address and payment ownership evidence should be reviewed alongside the privacy policy because these files contain more sensitive information than a standard email-based registration.

Keeping account data accurate

Players should enter their legal details consistently and correct errors as soon as they are discovered. Inaccurate information can create problems during KYC, password recovery, payment checks and withdrawal review.

The UK GDPR principles include accuracy and require reasonable steps to correct or remove inaccurate personal information. They also require processing to remain lawful, fair, transparent and limited to stated purposes.

Device, browser and technical information

HeyRoller says it may collect the operating system, device ID, browser type and browser version used to access the platform. This information helps the website adapt to different devices and identify performance or compatibility problems.

Technical identifiers can also contribute to security checks, fraud prevention and session monitoring. Players should understand that changing from a familiar device, location or network may create a different technical profile and potentially trigger additional account checks.

Behavioural and gameplay data

The policy states that HeyRoller may record login history, game preferences and browsing patterns. It says this information supports service improvements, recommendations and more efficient navigation.

Behavioural information can reveal more than which game was opened. Repeated logins, preferred categories, session timing and response to promotions can be combined to produce a detailed account profile.

A privacy-conscious user should therefore review personalisation and marketing controls rather than assuming all recommendations are generic. The platform states that communication settings can be adjusted through the account, including marketing emails and in-game notifications.

Why HeyRoller uses personal information

HeyRoller identifies account verification, platform optimisation, browsing improvements and personalised recommendations among its purposes. Its privacy and cookie pages also connect data use with session management, advertising, analytics, security and technical diagnostics.

A transparent privacy framework should connect each category of information with a specific purpose. The ICO identifies purpose limitation, data minimisation and accountability as core UK GDPR principles, meaning data should be collected for defined reasons and limited to what is necessary.

Purpose

Data that may support it

Player impact

Account operation

Username, email and session identifiers

Enables login and account communication

Platform optimisation

Browser and device information

Improves compatibility

Recommendations

Game preferences and browsing activity

Personalises lobby content

Security

Device, login and session records

Helps identify suspicious access

Analytics

Aggregated usage information

Supports performance decisions

Marketing

Preferences and behavioural signals

Determines promotional communication

Cookies and similar technologies

HeyRoller uses cookies to support login, session continuity, preferences, analytics and personalised content. Its cookie policy identifies essential, session, persistent, functional, analytics and performance cookies, together with browser storage technologies such as local storage and IndexedDB.

The privacy policy says session-based cookies may expire after 24 hours, while the separate cookie policy says some session cookies expire when the browser closes. Persistent cookies may remain until their expiry date or manual deletion, so users should treat the cookie policy as containing several different retention models.

Cookie consent and control

HeyRoller states that users can manage cookie preferences through its Cookie Control feature and browser settings. The site also explains that blocking cookies may affect login persistence, session management, language choices and personalisation.

ICO guidance says organisations must explain what cookies do and why they are used, while consent must be actively and clearly given unless a valid exemption applies. Cookies that are strictly necessary to provide a requested service may fall within an exemption, but analytics and advertising technologies generally require separate assessment.

Analytics and third-party tracking

The HeyRoller cookie policy names Google Analytics and Google Tag Manager as tools used for aggregated analytics and deployment of tracking scripts. These technologies are described as helping the platform understand user interaction and improve performance.

The presence of a third-party analytics tool means some website information may be processed within an external provider’s technical environment. Players should review cookie choices and the relevant provider information when they want a clearer understanding of how tracking technologies operate.

Third-party services and payment integrations

HeyRoller states that its platform incorporates external services and that those partners follow their own privacy policies. It warns that the terms applied by a third-party feature may not match HeyRoller’s own policy.

The cookie page specifically refers to payment gateways and social media sharing integrations. Payment processors may need transaction, account or device information to authorise payments, investigate fraud and complete withdrawals.

Marketing and communication preferences

HeyRoller allows users to customise marketing emails and in-game notifications. The privacy page says customers may opt out through account settings, while the cookie page also refers to unsubscribe links in promotional emails.

Opting out of promotions should not prevent essential account messages such as password resets, security warnings, document requests or payment updates. These operational communications may remain necessary even when personalised marketing has been disabled.

Data storage and retention

HeyRoller says personal information is stored on secured servers using SSL encryption and regular backups. The policy states that account data is retained while the customer continues using the services and that associated data is removed within 30 days after deactivation or deletion.

This is a broad retention statement and does not explain whether specific records must be retained for fraud, payment, dispute or legal purposes. A user requesting deletion should therefore ask whether any information will remain, what categories are excluded from deletion and which lawful basis supports continued storage.

Security controls described by HeyRoller

HeyRoller lists TLS encryption for sensitive transfers, regular software updates, server-log access restrictions and regular backups among its security measures. It also says staff receive privacy training and that stored information is subject to access controls.

No online service can eliminate every security risk, so players must also protect their side of the account. HeyRoller recommends passwords containing at least eight characters, mixed character types and no common dictionary words.

Useful personal security controls include:

  • using a unique password not shared with other websites;
  • avoiding saved logins on shared devices;
  • keeping the browser and operating system updated;
  • avoiding document uploads through public Wi-Fi;
  • checking the website address before entering credentials;
  • signing out after using a shared computer;
  • reporting unexplained login or payment activity immediately.

International data handling

The HeyRoller policy says stored information is not shared outside the European Economic Area. It also states that the platform aims to follow GDPR, the EU e-Privacy Directive and other rules applicable in the user’s jurisdiction.

This statement should be read together with the use of third-party services because integrated providers may operate through complex international infrastructure. Customers seeking certainty should ask where account records, backups, analytics data and support records are physically processed.

The HeyRoller policy does not provide a detailed international transfer mechanism or list of processing locations. That omission does not prove that an unlawful transfer occurs, but it limits the ability of a user to independently assess the full data flow.

Your privacy rights

HeyRoller expressly gives users the ability to review and correct stored data, request deletion after account deactivation and withdraw consent. Requests are directed to the platform through email or customer support.

UK data protection guidance also covers rights such as access, rectification, erasure, restriction, objection and data portability where the relevant legal conditions apply. The availability of a particular right depends on the processing purpose and lawful basis rather than applying identically to every record.

Request

What the user is asking for

Access

A copy or description of personal data held

Rectification

Correction of inaccurate or incomplete information

Erasure

Deletion where no valid retention reason remains

Restriction

Temporary limitation of specific processing

Objection

Review or cessation of certain processing activities

Consent withdrawal

End of processing based specifically on consent

Marketing opt-out

Cessation of promotional communications

How to submit a privacy request

A request should identify the account clearly without exposing more personal information than necessary. The user should state which right is being exercised, which data or processing activity is involved and the preferred contact method for the response.

Use this workflow:

  1. Contact HeyRoller through the confirmed support channel.
  2. State that the message is a privacy or data protection request.
  3. Identify the relevant account email.
  4. Describe the information or action required.
  5. Ask for acknowledgement and a reference number.
  6. Provide identity evidence only through a secure channel.
  7. Retain the original request and all responses.
  8. Follow up when the stated response period expires.

Privacy complaints in 2026

From 23 June 2026, organisations handling personal data must provide a clear way to raise a data protection complaint. They must acknowledge complaints within 30 days, investigate them appropriately and communicate the outcome.

A complaint may concern incorrect data, unexplained retention, continued marketing, denied access or an unclear response to a deletion request. The message should distinguish the privacy issue from unrelated disputes about bonuses, gameplay or withdrawal timing.

When the response remains inadequate and the relevant jurisdiction permits escalation, the user may seek guidance from the appropriate data protection authority. HeyRoller’s regulatory and corporate position should be verified separately before assuming that a specific external complaint route applies.

Protecting minors’ information

HeyRoller prohibits gambling participation by people under 18 or below another applicable minimum age. The policy asks users to report suspected minor involvement so the platform can take appropriate action.

Age controls protect both the integrity of the account and the personal information of children. Adults should not create accounts for minors, share credentials or permit young people to upload documents through an adult account.

Practical privacy checklist

Privacy risk can be reduced by limiting unnecessary data exposure and monitoring account settings. The user should understand which information is required for account operation and which processing activities remain optional.

Before using HeyRoller, check that:

  • the website address is genuine;
  • the privacy and cookie policies are accessible;
  • optional cookies can be controlled;
  • marketing preferences can be changed;
  • registration data is accurate;
  • payment methods belong to the account holder;
  • documents are uploaded only through secure channels;
  • account access uses a unique password;
  • third-party provider policies have been reviewed;
  • support provides a traceable privacy complaint process.

FAQ

What personal data does HeyRoller collect?

HeyRoller lists registration details, device data, browser information, login history, game preferences and browsing patterns.

Why does HeyRoller collect device information?

It says device and browser data are used to improve compatibility, performance and platform functionality.

Does HeyRoller use cookies?

Yes, it uses essential, session, persistent, functional, analytics and performance cookies.

Can I reject optional cookies?

HeyRoller says cookie preferences can be adjusted through Cookie Control and browser settings.

Which analytics services are named?

The cookie policy identifies Google Analytics and Google Tag Manager.

Can I stop marketing emails?

Yes, preferences can be changed in the account or through the unsubscribe link in promotional messages.

How long does HeyRoller retain account data?

It says data is retained during account use and removed within 30 days after deactivation or deletion.

Can I request a copy of my data?

Users may request access to information held about them where the relevant privacy rules apply.