Data We Collect and Why
Key facts about data we collect and why
NoLimitCoins CA collects three categories of data: account data (email, name, date of birth, province), transactional data (GC/SC balances, game history, purchase records), and technical data (IP address, browser fingerprint, device type for fraud prevention). We do not sell personally identifiable information to third-party data brokers. All data is stored on servers protected with AES-256 encryption at rest and TLS 1.3 in transit. Account data is retained for 7 years from last activity for legal compliance purposes under Canadian anti-money laundering regulations. You may request a full data export or deletion by contacting our support team.
| Data Category | Purpose | Retention Period |
|---|---|---|
| Account Identity | Authentication, KYC compliance | 7 years from last activity |
| Game History | Dispute resolution | 3 years |
| Technical and Device | Fraud prevention | 90 days rolling |
| Purchase Records | Financial compliance | 7 years statutory |
| Cookie and Session | Login management | Session lifetime only |
Cookie Policy
We use strictly necessary cookies for session authentication and platform functionality. Analytics cookies (aggregated and non-personal) help improve game load performance and navigation. You may opt out of analytics cookies without affecting platform access. We do not use cross-site tracking cookies or third-party advertising cookies. Our full terms of service detail your rights regarding data processing under applicable Canadian privacy legislation including PIPEDA.
Your Rights Under PIPEDA
Accessing and correcting your data
The Personal Information Protection and Electronic Documents Act (PIPEDA) grants Canadians the right to access personal data held about them and to correct inaccurate information. To request a full data export or correction, submit a written request via the contact page. We respond to access requests within 30 days. Data provided for account verification cannot be deleted while the account remains active but will be anonymised within 90 days of permanent account closure.
Third-Party Services and Data Sharing
Who we share limited data with
We share minimal account data with three categories of third parties: payment processors (for redemption transactions only), identity verification services (for KYC), and analytics aggregators (non-personal, session-level data only). No social media platform or advertising network receives personally identifiable information. Our payment processors operate under PCI-DSS compliance. Identity verification partners are bound by the same PIPEDA obligations as NoLimitCoins CA directly.
Data Retention Schedule — How Long We Keep Each Data Class
Explicit retention windows tied to legal obligations
NoLimitCoins Canada follows a data-minimisation principle grounded in PIPEDA compliance. Every category of personal data has an explicit retention window driven by either regulatory requirement (identity documents), operational necessity (session logs), or legitimate contractual interest (transaction history). At the end of the retention window, data is either deleted, anonymised beyond recovery, or archived to cold storage with access restricted to compliance staff only. The table below is the authoritative reference; if you have a question about a specific record type not covered here, our privacy office responds to enquiries within five business days. Payment-flow records referenced here overlap with the disclosures on the PCI-DSS card handling page, so cross-referencing both gives a complete picture.
| Data Category | Retention Window | Purpose | Post-Window Action |
|---|---|---|---|
| Account credentials | Lifetime of account + 12 mo | Access continuity | Anonymised then deleted |
| KYC identity docs | 7 years post-verification | Regulatory audit | Cold-archive then delete |
| Transaction history | 7 years | Financial recordkeeping | Anonymised aggregate kept |
| Session/telemetry logs | 13 months | Security & product | Deleted |
| Marketing preferences | Lifetime of account | Opt-in tracking | Deleted at closure |
| Support ticket history | 5 years | Continuity of service | Anonymised then deleted |
| Chat / community posts | Lifetime + 30 days | Community integrity | Deleted |
| Marketing cookies | 13 months | Advertising | Auto-expire |
Storage figures are per active account and exclude the game-state cache that is stored locally on your device. The KYC document footprint is by far the largest because scanned documents are stored at legal-hold resolution to remain usable in a compliance audit up to seven years later. All other categories are compact and add up to a few hundred kilobytes over the account lifetime. If you want to see the full extent of what we hold about you, submit a Data Subject Access Request through the account dashboard. Responses are delivered within 30 calendar days and typically arrive far sooner. Any player wondering how jackpot wins affect data footprint should note that jackpot-tier verification adds a video-attestation record, described on the jackpot winner data handling page.
International Data Transfers, Sub-Processors and Cloud Regions
NoLimitCoins Canada operates a Canadian data-residency posture for the vast majority of stored personal data. Player identity documents, financial records, and account credentials are held on infrastructure physically located in Canadian AWS regions (ca-central-1 in Montreal and a warm-standby capacity in Ontario). Some ancillary services — email delivery, transactional fraud scoring, and support ticket routing — use sub-processors whose infrastructure may sit in the United States or the European Union. Every sub-processor is bound by data-processing agreements that mirror PIPEDA obligations and requires them to notify us of any request for data by a foreign government within 24 hours.
| Sub-Processor | Purpose | Data Region | Data Held |
|---|---|---|---|
| Postmark | Transactional email | US (SOC 2) | Email address only |
| Cloudflare | CDN + WAF | Global edge | IP addresses (ephemeral) |
| Sift Science | Fraud scoring | US (SOC 2) | Behaviour signals hashed |
| Zendesk | Support ticketing | Canada | Ticket text and metadata |
| Sumsub | KYC ID verification | EU (ISO) | Doc images (temporary) |
| Google Pay | Payment processing | Regional | Tokenised card refs only |
| Apple Pay | Payment processing | Regional | Tokenised card refs only |
Children's Privacy — The 18+ Guarantee
NoLimitCoins Canada is strictly an adult-only platform. The registration flow enforces an 18-plus age gate through mandatory date-of-birth entry with device-fingerprint cross-checks and, at KYC time, government photo ID that confirms adult status independently. If we ever discover an underage account, the account is immediately closed, all data is quarantined and deleted within 30 days, and any pending balance is refunded through the original payment method where possible. Parents or guardians who suspect a minor has accessed the platform can contact the privacy office through a dedicated address printed at the bottom of every page and receive a response within 24 hours.
Your PIPEDA Rights and How to Exercise Them
Every Canadian resident who holds a NoLimitCoins account has enforceable rights under the Personal Information Protection and Electronic Documents Act. These include the right to access your data (a Data Subject Access Request), the right to correct inaccuracies, the right to withdraw consent for future processing (which typically results in account closure), and the right to lodge a complaint with the Office of the Privacy Commissioner of Canada if you believe your rights have been violated. All requests are handled by a named Data Protection Officer whose contact is published on the platform's contact page. Members with VIP status can request a personal walkthrough of their data holdings through the VIP manager data controls workflow.
Cookie Categories, Consent Management and Opt-Out Controls
NoLimitCoins Canada uses cookies across four distinct categories, each with its own consent status and opt-out mechanism. Strictly necessary cookies power the login session and cannot be disabled without breaking core functionality. Functional cookies remember your preferences (theme, language, volume) and can be disabled without affecting gameplay. Analytics cookies feed anonymised behaviour data to the product team's internal dashboards and can be disabled through the cookie banner or the account dashboard. Marketing cookies power personalised promotional messaging and are opt-in only — no marketing cookie is set unless you explicitly consent. Every consent decision is versioned and audit-logged so you can review your historical choices at any time.
The consent banner appears on your first visit and any subsequent visit after a material privacy-policy update. It offers three primary actions: Accept all, Reject non-essential, and Customise. The customise view lets you toggle each category independently. Consent decisions are stored for 13 months and re-prompted after that window, which aligns with best-practice consent-refresh cadence recommended by the Office of the Privacy Commissioner of Canada.
Third-Party Marketing Partners and Advertising Networks
NoLimitCoins Canada shares limited, hashed marketing signals with a small number of vetted advertising partners. These signals allow the platform to reach lookalike audiences on Meta, Google, and TikTok networks without exposing your identity to those platforms. The signals shared are limited to hashed email addresses and generic behaviour buckets — never raw personal data or specific gameplay history. You can opt out of this cross-channel marketing entirely through the account dashboard, at which point the platform stops sharing any signals about your account with third parties. Opting out does not affect the free-value earning pathways on the platform in any way; the only thing that changes is the ads you see on third-party services.
The DPA framework with each marketing partner mirrors PIPEDA obligations and includes explicit requirements around data retention on their side. Marketing partners are contractually barred from retaining shared signals beyond the specific campaign window in which the signal was used. Independent audits verify compliance annually, and any breach of the DPA framework results in immediate termination of the partnership. The privacy office publishes a summary of these audits on the transparency portal for members who want visibility into the specific partner list and their compliance postures.
Breach Notification Commitment — What Happens If Something Goes Wrong
In the extremely unlikely event of a personal-data breach affecting NoLimitCoins Canada players, the platform commits to notifying affected members within 72 hours of confirmed detection, notifying the Office of the Privacy Commissioner of Canada in parallel, and posting a public breach notice on the transparency portal within the same window. Notifications include the specific data categories affected, the number of records involved, the platform's initial containment and mitigation actions, and clear guidance on what individual members should do to protect themselves (typically: password rotation, 2FA verification, credit monitoring if payment data is implicated). This 72-hour commitment exceeds the statutory PIPEDA minimum by a wide margin and reflects a serious posture on breach transparency.
Contact for Privacy Enquiries — Named Data Protection Officer
NoLimitCoins Canada has appointed a named Data Protection Officer whose contact details are published on the platform's contact page and reproduced on this page for convenience. The DPO responds personally to every enquiry within five business days, and is authorised to escalate any complex case directly to the Office of the Privacy Commissioner of Canada without gating from operational management. This structural independence is deliberate — it ensures privacy governance is not subordinated to commercial pressure at any point in the decision chain. Any player who feels their concerns have not been adequately handled through standard support can request the DPO by name.