BANANABET

Legal

Privacy policy

Bananabet is non-custodial and account-free: there is no email address, no password and no name on file. This page sets out the little we do hold, why we hold it, and what you can ask us to do with it.

Last updated 11 August 2026

1.Who is responsible

Bananabet Gaming Ltd. is the controller of the personal data described here. For any privacy question or request, write to privacy@bananabet.gg.

2.What we collect

We do not ask for your name, date of birth, email or payment details to play. What we hold is the following, and nothing beyond it unless a check under our AML and KYC policy is triggered.

Wallet address
The public address you connect. It is the only identifier we hold for you, and it is what a balance, a bonus claim and a withdrawal are attached to.
Session identifier
A single HttpOnly, SameSite cookie that keeps you signed in to your play session. It is not used for advertising and it is not shared.
IP address and network
Recorded at connection and at bonus claim, for fraud prevention, one-bonus-per-person enforcement, rate limiting and geographic restriction. We derive a coarse subnet from it for the same purposes.
Play records
Every bet: game, stake, outcome, multiplier, payout, seed pair, nonce and timestamp. Required to settle rounds, to let you verify them, and to meet record-keeping obligations.
Transaction records
Deposits, withdrawals and staking activity, including on-chain transaction hashes. These are public on the chain regardless of what we hold.
Support correspondence
Anything you send us by email, kept with the account it concerns so the next person handling a query can see the history.
Technical logs
Request metadata, error traces and approximate timings, used to keep the service up and to investigate abuse.

3.Why we are allowed to hold it

  • Performance of a contract — settling your bets, crediting your balance and processing withdrawals cannot be done without the address and the play record.
  • Legitimate interests — preventing fraud, multi-accounting and bonus abuse, rate limiting, and keeping the service secure and available.
  • Legal obligation — anti-money-laundering checks, sanctions screening, and retaining transaction records for the period the law requires.
  • Consent — where you opt in to something optional, which you can withdraw at any time without affecting play.

4.Cookies and local storage

We use one essential cookie: the session identifier described above. It is HttpOnly, so page scripts cannot read it, and it expires when the session lapses. Removing it signs you out; nothing on this site will work without it.

Your browser also holds a few preferences in local storage — whether sound is muted, your current client seed, and interface state. These never leave your device and are not personal data to us. Clearing site data removes them.

We do not run third-party advertising cookies, cross-site trackers or advertising pixels.

5.Who we share it with

We do not sell personal data, and we do not share it for anyone else's marketing. It is disclosed only to:

  • Infrastructure providers who host the service and store its data under contract, acting on our instructions.
  • Compliance and sanctions-screening providers, where a check is required under the AML policy.
  • Law enforcement, regulators or courts, where we are legally required to disclose, or where disclosure is necessary to investigate fraud or protect the service.

Where data is transferred outside your country, we rely on the safeguards recognised in your jurisdiction — standard contractual clauses or an adequacy decision, as applicable.

6.What is public regardless

Deposits, withdrawals and staking transactions happen on Robinhood Chain, which is a public ledger. Anyone can see the amounts, the addresses and the timing, permanently. That is a property of the chain, not a disclosure we make, and it cannot be erased on request.

7.How long we keep it

  • Play and transaction records — for the retention period required of gambling operators, typically five years from the transaction, and longer where an investigation is open.
  • Anti-abuse records — bonus claims and the addresses and networks tied to them are kept for as long as the one-claim-per-person rule needs to be enforceable.
  • Self-exclusion records — kept for the length of the exclusion and after it, because the whole point of the record is that it survives you asking us to forget it.
  • Technical logs — a short rolling window, typically 90 days.

8.Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, have it erased, restrict or object to how we use it, and receive it in a portable form. To exercise any of these, write to privacy@bananabet.gg from — or signing with — the wallet address concerned, so we can be satisfied it is yours.

We answer within one month. Erasure is not absolute: where a record is held under a legal retention obligation, or is part of a self-exclusion or fraud-prevention record, we will restrict its use rather than delete it, and tell you which applies. You also have the right to complain to your local data protection authority.

9.Security

Server seeds are never sent to the browser before rotation, session cookies are HttpOnly and SameSite, and requests are rate limited per player. Data is encrypted in transit. No system is perfect — but note that we hold no password to steal, and the keys that control your funds never touch our infrastructure.

10.Children

The service is not for anyone under 18. We do not knowingly collect data from minors, and where we discover it we delete it and close the access.

11.Changes

Updates are published here with a new date at the top. Where a change materially affects how we use your data, we will make it prominent rather than quietly repost the page.

Privacy policy · Bananabet