Popular Games
Privacy Policy
Version: 1.0 | Last Updated: June 15, 2025 | Effective Date: June 15, 2025
This Privacy Policy (“Policy”) describes how Onlywin (“we,” “us,” or “our”), operating at cfnp.ca, collects, uses, discloses, retains, and protects your personal information when you access or use our Website and services. This Policy should be read in conjunction with our Terms & Conditions and our Responsible Gaming Policy.
We are committed to protecting your privacy and handling your personal data in a transparent, lawful, and responsible manner consistent with applicable Canadian privacy legislation.
1. Introduction
1.1. Scope
This Policy applies to all personal information collected through our Website, mobile applications, customer support channels, email communications, and any other services we provide. It applies to all visitors, registered players, and former players whose data we continue to hold.
1.2. Definitions
For the purposes of this Policy:
- “Personal Information” means any information about an identifiable individual, including but not limited to name, date of birth, address, email, financial details, and device identifiers.
- “Processing” means any operation performed on personal information, including collection, storage, use, disclosure, and deletion.
- “Third Party” means any entity other than you or us.
2. Data We Collect
2.1. Information You Provide Directly
When you register, deposit, withdraw, or interact with our support team, we may collect:
- Identity Data: Full legal name, date of birth, gender (where provided);
- Contact Data: Email address, phone number, residential address, postal code;
- Identity Verification Data: Copies of government-issued ID, utility bills, or other KYC documentation;
- Financial Data: Payment card details (stored securely by payment processors), bank account information, transaction history, deposit and withdrawal records;
- Account Data: Username, password (hashed), Account preferences, communication settings;
- Support Data: Records of communications you have had with our support team, including emails and live chat transcripts.
2.2. Information Collected Automatically
When you access the Website, we automatically collect certain technical information, including:
- Device Data: IP address, device type, operating system, browser type and version;
- Usage Data: Pages visited, Games played, session duration, clickstream data, referring URLs;
- Location Data: Country and province derived from IP address (not precise GPS location unless explicitly requested);
- Cookie Data: Information gathered through cookies and similar tracking technologies (see Section 6).
2.3. Information from Third Parties
We may receive personal information about you from third parties, including:
- Payment processors and financial institutions, for the purpose of transaction verification;
- Identity verification service providers, for KYC compliance;
- Fraud prevention and AML screening services;
- Analytics providers and advertising networks (in aggregated or pseudonymised form).
3. How We Use Your Data
We use your personal information for the following purposes:
- Account Management: To create, maintain, and manage your Account, verify your identity and age, and process transactions;
- Service Delivery: To enable your use of Games, process deposits and withdrawals, and provide customer support;
- Legal Compliance: To fulfil our obligations under applicable anti-money laundering, age verification, responsible gaming, and data protection legislation;
- Fraud Prevention & Security: To detect, investigate, and prevent fraudulent activity, cheating, money laundering, and other prohibited conduct;
- Responsible Gaming: To identify and respond to signs of problem gambling, administer self-exclusion requests, and enforce player protection tools;
- Marketing & Communications: To send you promotional offers, newsletters, and personalised recommendations where you have provided consent or where we have a legitimate interest, subject to your preferences;
- Analytics & Improvement: To analyse usage patterns, improve Website functionality, and enhance the overall player experience;
- Legal Claims: To establish, exercise, or defend legal claims where necessary.
4. Legal Bases for Processing
We process your personal information on the following legal bases:
- Contractual Necessity: Processing necessary to perform the contract we have with you (e.g., account management, payment processing);
- Legal Obligation: Processing required to comply with applicable law (e.g., KYC verification, AML monitoring, tax reporting);
- Legitimate Interests: Processing that serves our legitimate business interests and is not overridden by your privacy rights (e.g., fraud prevention, security, analytics, direct marketing to existing customers);
- Consent: Where we rely on your consent (e.g., certain marketing communications or use of non-essential cookies), you have the right to withdraw consent at any time without affecting the lawfulness of prior processing.
5. Data Sharing & Third Parties
5.1. Categories of Recipients
We may share your personal information with the following categories of third parties:
- Payment Processors: To facilitate deposits, withdrawals, and fraud screening (e.g., Interac, Visa, Mastercard, PayPal, Skrill, Neteller);
- KYC & Identity Verification Providers: To verify your identity and age in compliance with regulatory requirements;
- Game Software Providers: To deliver Games through the Website; these providers may receive session data required to operate their software;
- IT & Hosting Providers: To maintain and operate the Website infrastructure securely;
- Analytics Providers: To help us understand Website usage and improve our services (data is typically processed in aggregated or pseudonymised form);
- Legal & Compliance Advisors: Where necessary for legal advice or proceedings;
- Regulatory & Law Enforcement Authorities: Where required by applicable law, court order, or regulatory directive.
5.2. No Sale of Personal Data
We do not sell, rent, or trade your personal information to unaffiliated third parties for their own marketing purposes.
5.3. Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or substantially all of our assets, your personal information may be transferred to the successor entity. We will notify you by email and/or prominent Website notice prior to any such transfer and advise you of your rights.
6. Cookies & Tracking Technologies
6.1. What Are Cookies
Cookies are small text files placed on your device when you visit a website. We use cookies and similar technologies (such as web beacons, pixel tags, and local storage objects) to operate the Website, remember your preferences, and understand how you use our services.
6.2. Types of Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Strictly Necessary | Essential for Website functionality (login sessions, security tokens) | Session |
| Performance / Analytics | Collect anonymous data on how visitors use the Website to improve performance | Up to 2 years |
| Functional | Remember user preferences (language, currency, last game played) | Up to 1 year |
| Marketing / Targeting | Deliver relevant advertising; track conversions | Up to 2 years |
6.3. Cookie Consent & Management
When you first visit the Website, you will be presented with a cookie consent banner allowing you to accept or customise your cookie preferences. Strictly necessary cookies cannot be disabled as they are required for the Website to function. You may withdraw or modify your consent at any time via the “Cookie Settings” link in the Website footer. You may also manage cookies through your browser settings; however, disabling certain cookies may impair Website functionality.
7. Data Security
7.1. Security Measures
We implement appropriate technical and organisational security measures to protect your personal information against unauthorised access, loss, disclosure, alteration, or destruction. These measures include:
- SSL/TLS encryption for all data transmitted between your device and the Website;
- Encryption of sensitive data at rest (including financial data and identity documents);
- Role-based access controls limiting staff access to personal data on a need-to-know basis;
- Regular security audits, vulnerability assessments, and penetration testing;
- Incident response procedures to address any confirmed or suspected data breach.
7.2. Data Breach Notification
In the event of a personal data breach that poses a real risk of significant harm to affected individuals, we will notify relevant authorities and affected players in accordance with our obligations under applicable law, as promptly as practicable.
8. Data Retention
We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, including the following retention periods:
- Account & Transaction Data: Retained for a minimum of seven (7) years following Account closure, in compliance with AML and financial record-keeping requirements;
- KYC Documentation: Retained for a minimum of five (5) years from the date of verification;
- Support Communications: Retained for three (3) years from the date of the last communication;
- Marketing Preferences: Retained until you withdraw consent or request deletion, subject to legal requirements;
- Technical/Log Data: Typically retained for up to twelve (12) months.
Upon expiry of the applicable retention period, personal information is securely deleted or anonymised.
9. Your Rights
Subject to applicable law, you have the following rights in relation to your personal information:
- Right of Access: You may request a copy of the personal information we hold about you;
- Right to Rectification: You may request correction of inaccurate or incomplete personal information;
- Right to Erasure: You may request deletion of your personal information where it is no longer necessary for the purposes for which it was collected, subject to our legal retention obligations;
- Right to Restriction: You may request that we restrict processing of your personal information in certain circumstances;
- Right to Data Portability: You may request a structured, machine-readable copy of personal information you have provided to us, where processing is based on consent or contract;
- Right to Object: You may object to processing based on legitimate interests, including for direct marketing purposes;
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of the above rights, please submit a written request to [email protected]. We will respond within thirty (30) days, though complex requests may require up to sixty (60) days. We may need to verify your identity before processing your request.
10. International Data Transfers
Some of our third-party service providers (including cloud hosting, analytics, and payment processing providers) may be located outside Canada. Where we transfer personal information internationally, we take appropriate steps to ensure that your data receives an equivalent level of protection, including through contractual safeguards and data processing agreements. If you would like further information about our international transfer mechanisms, please contact us at [email protected].
11. Minors
Our Website is not intended for, and we do not knowingly collect personal information from, individuals below the minimum legal gambling age applicable in their province of residence (18 or 19 years, as applicable). If we become aware that we have inadvertently collected personal information from an individual who does not meet the minimum age requirement, we will take immediate steps to delete that information and close the associated Account. If you believe a minor has registered on the Website, please notify us immediately at [email protected].
12. Changes to This Policy
We may update this Policy from time to time to reflect changes in our data practices, legal obligations, or operational requirements. We will notify you of material changes by posting a prominent notice on the Website and, where we hold your email address, by sending you an email notification. The date of the most recent revision will always be indicated at the top of this Policy. We encourage you to review this Policy periodically.
13. Contact Information
For all privacy-related enquiries, requests, or concerns, please contact our Privacy / Data Protection Officer:
- Email: [email protected]
- Subject Line: Privacy Enquiry – Onlywin
- Website: cfnp.ca
For general support enquiries unrelated to data protection, please contact [email protected].