18+ only ยท Sweepstakes model โ€” no real-money gambling ยท Problem Gambling Help
Brass padlock on a glowing electric-blue circuit-board surface with soft drifting fog
๐Ÿ” Data & Privacy

Spree Casino US
Privacy Policy

How spree-casino.us.com handles reader data, cookies, analytics, and state-law privacy rights โ€” documented in plain language, updated on a 90-day cycle.

Data Practices, Cookie Use & Reader Rights โ€” Extended Notes

The summary above documents the core elements of how spree-casino.us.com handles reader data. The notes below extend the policy with practical operational detail, the specific third-party processors we use, the cookie inventory by category, and the steps a reader can take to exercise the rights granted under US state privacy laws.

The data we actually collect

spree-casino.us.com is an editorial review site, not an account-bearing platform. We do not require reader registration, and we do not store personally-identifiable account data. The data we do collect is limited to standard web-analytics signals: anonymised IP-derived city/state, browser user-agent, referring URL, time-on-page, and the affiliate-click event when a reader follows an outbound link to Spree Casino. All analytics are processed by Google Analytics 4 with IP anonymisation enabled and reader-identifier hashing applied.

The third-party processors we use

Three processors touch reader data: Google Analytics 4 (anonymised analytics), Cloudflare (CDN edge + DDoS protection), and the affiliate-network operator that handles outbound click attribution to Spree Casino. None of these processors receives or stores reader email, phone, name, or address โ€” because we do not collect that data in the first place.

Cookies, by category

Strictly necessary cookies (3 total) handle session continuity, CSRF protection on form submissions, and language preference. These cannot be disabled because the site would not function without them. Analytics cookies (4 total, all from Google Analytics 4) record anonymised page-view data. Marketing cookies (2 total, both from the affiliate-network operator) attribute outbound click events. Analytics and marketing cookies can be declined entirely via the cookie banner; the site functions in full without them.

Your rights under US state privacy laws

California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA) residents are entitled to: the right to know what data is collected, the right to delete personal data, the right to correct inaccurate data, the right to opt out of sale or sharing, and the right to non-discrimination for exercising any of these rights. Because we do not collect personally-identifiable data, the practical scope of these requests is limited to the analytics-event history tied to your browser identifier.

How to exercise a privacy request

Email [email protected] from the same browser session whose analytics-event history you wish to access, modify, or delete. Include in your message the approximate date range of your visits and any URL you specifically remember visiting. We will respond within 30 days. Requests can also be submitted via postal mail to the address listed in our company-contact section, although this channel is materially slower (typical resolution: 6โ€“8 weeks).

How long we retain analytics data

Anonymised analytics records are retained for 26 months from collection, in line with Google Analytics 4 default retention policy. Affiliate-click attribution records are retained for 90 days after the click event, sufficient to reconcile the commercial transaction with our affiliate-network partner. All retention windows are publicly listed in the Google Analytics 4 admin settings for this property.

Children and platform suitability

Sweepstakes casino content is restricted to adult audiences. spree-casino.us.com publishes no content directed at minors, and we do not knowingly collect data from any reader under 18. If a parent or guardian believes a minor has interacted with the site, contact [email protected] โ€” we will immediately purge any analytics-event history associated with the relevant browser fingerprint upon request.

Policy updates and version history

Material updates to this privacy policy are flagged in the "Last reviewed" timestamp at the top of the page and accompanied by a one-line change summary at the bottom. Readers who want the full historical version archive can request it via [email protected]. Editorial topics referenced from this policy โ€” including the Spree payment rail data handling overview and the broader loyalty program data-collection note โ€” are maintained on their own dedicated pages with independent revision histories.

Data-Sharing, International Visitors & Security Posture

Data we never share

spree-casino.us.com does not sell, rent, trade, or otherwise commercialise reader data. The site does not maintain advertising partnerships beyond the single affiliate relationship with Spree Casino, and the affiliate-network operator receives only the anonymised click-event record required to attribute commission. We do not run programmatic advertising, do not embed tracking pixels from advertising networks, and do not participate in any data co-op or audience-marketplace exchange.

International visitors

spree-casino.us.com is targeted at US-resident readers and the editorial content covers US-only sweepstakes platforms. International visitors are welcome to read the content but may find limited practical applicability โ€” for example, Spree Casino itself does not operate outside the United States. The site's data-handling practices apply uniformly regardless of visitor origin, and international visitors retain the same access and deletion rights that US-state-law residents enjoy.

Security posture for the site itself

The site is served exclusively over HTTPS with TLS 1.3, HSTS enabled with a 1-year max-age, and a Cloudflare-managed certificate rotation cadence. Form submissions (limited to the editor-contact channel) are CSRF-protected. The site has never sustained a security incident. Penetration testing is run quarterly by an independent third-party security firm with results reviewed by the editorial operations team; the most recent test cycle completed in May 2026 with zero findings above informational severity.

Data minimisation as default

The single guiding principle of the site's data handling is minimisation. We collect only the data we directly need to operate the site, we keep it for only as long as we directly need it, we share it only with the processors who directly need it for the same operational purpose. The structural simplicity of this design is intentional and it materially reduces the surface area available to a determined attacker.

Cookie controls and the consent banner

The site uses a standard consent banner that appears on first visit and persists the reader's choice for 12 months. Choosing "Decline non-essential" disables all analytics and marketing cookies; the site functions in full. Choosing "Accept all" enables the analytics and marketing categories described above. Re-opening the banner to change a prior choice is available via the persistent "Cookie preferences" link in the site footer.

Reference pages with related data notes

Topic-specific data handling notes appear on a small number of dedicated reference pages where the data context is materially different: the redemption rail data handling overview documents what we capture during an outbound payment-related click, and the VIP program editorial data scope documents how aggregated tier-distribution figures are sourced from publicly disclosed operator transparency reports rather than from any reader-specific account telemetry. Both pages are reviewed alongside this main privacy policy on the same 90-day cadence.

Contacting the data-protection lead

For any privacy-related request โ€” access, deletion, correction, complaint, or general question โ€” the fastest route is email to [email protected]. Responses are issued within 30 days as required by US state law, and most requests resolve inside 5 business days in practice. Postal-mail requests are accepted but slower; the postal address is listed in the site footer.

Plain-Language Summary & Quick FAQ

The two paragraphs below summarise the entire privacy posture of this site in plain language for readers who want the headline answer without working through the full legalese.

The headline summary

spree-casino.us.com does not collect, store, or process any personally-identifiable reader data. The site uses standard anonymised web analytics (Google Analytics 4 with IP anonymisation), serves over HTTPS through Cloudflare's CDN, and runs no advertising programs of any kind. Outbound affiliate clicks to Spree Casino are attributed via a third-party affiliate network in a strictly anonymised event format. There is no reader account on this site, no newsletter list, no comment system, and no data sale or sharing of any kind.

Three most-asked privacy questions

Do you keep my browsing history? No. We see only anonymised aggregate analytics. Do you sell my data? No, and the site does not participate in any advertising-network or data-marketplace exchange. What happens if I email you? Editorial email correspondence is retained for 12 months for editorial-process integrity, then permanently deleted. The fastest way to exercise any privacy right under your state's law is email to [email protected], with a typical resolution time of 5 business days.

Affiliate Disclosure: spree-casino.us.com is an independent affiliate review site. We earn a commission when users register via our links. This does not affect our editorial ratings. Spree Casino is a sweepstakes platform โ€” no real money wagering is involved. 18+ only. If you have concerns about gambling habits, visit our Responsible Gaming page or call the NCPG Helpline: 1-800-522-4700.