1. Who we are
Bonusphere ("we", "us", "our") operates the website bonusphere.com — an independent casino-review guide for Canadians and a free rewards-club where members earn virtual coins for everyday activity. We are not a gambling operator: we do not accept bets, deposits, or wagers.
2. Scope
This policy applies to all visitors and registered members of bonusphere.com. By using our site or services, you acknowledge this policy.
3. Data we collect
Information you provide
- Account details: name (display name), email, password (stored only as a one-way salted hash — we never see or store your password in plain text)
- Optional profile data such as language preference
- User submissions: review text, bonus reports, mission content
- Communications you send us (support requests, feedback)
Information collected automatically
- Device and browser information, operating system, screen size
- IP address (used for security, fraud detection, and approximate geo-location)
- Pages visited, time on page, click events
- Cookies and similar technologies (see section 7)
- Server logs (timestamp, requested URL, user-agent) kept for security and abuse prevention
Information from third parties
- Affiliate-network postbacks from casinos: a hashed click identifier confirming that a referred user registered or made a first deposit, so we can credit affiliate commission. We do not receive your casino account details, gameplay history, or identity beyond what is strictly required for attribution.
4. How we use your data
- Provide and maintain your rewards-club account
- Credit and track virtual coins, levels, referrals, and partner-program activity
- Send transactional emails (account verification, password reset, security alerts, account changes)
- Send opt-in communications about new reviews, missions, raffles (you can unsubscribe at any time via the link in every email)
- Detect and prevent fraud, abuse, and multi-accounting
- Analyse aggregate usage to improve our product
- Comply with legal obligations
5. Legal bases for processing
We process your data on one or more of the following bases (under PIPEDA in Canada and GDPR alignment where applicable):
- Contract performance — account creation, rewards-club services, the coins ledger
- Legitimate interest — fraud prevention, basic analytics, service security
- Consent — marketing emails, non-essential cookies (opt-in only)
- Legal obligation — responding to lawful requests, retention for accounting purposes
6. How we share your data
We do not sell your personal data. We share data only with the following categories of recipients:
- Hosting and infrastructure providers (server, CDN, transactional email delivery)
- Analytics providers — privacy-respecting tools used in aggregate form (see section 7)
- Casino affiliate networks, but only the minimum needed for commission attribution (a click identifier, not personal data such as name or email)
- Law-enforcement and regulators if compelled by a valid legal request
7. Cookies and tracking
- Strictly necessary — login session, CSRF protection. Cannot be disabled without breaking core functionality.
- Functional — language preference, dismiss-state of onboarding banners and welcome modal.
- Analytics — aggregate usage measurement. You can opt-out via your browser's Do-Not-Track setting or by disabling non-essential cookies.
- Affiliate — short-lived click identifiers stored on your browser when you click an outbound casino link, used to attribute the referral. Typical lifespan: 30 days.
You can manage cookies in your browser settings. Disabling strictly-necessary cookies will prevent login.
8. How long we keep your data
- Account data: while your account is active and for 24 months after closure (for anti-fraud and accounting). After that — deleted or anonymised.
- Server and security logs: typically 90 days
- Affiliate click identifiers: typically 30 days
- User submissions (reviews, bonus reports): kept while your account is active; anonymised when you delete your account
9. Your rights
Subject to applicable law (PIPEDA in Canada, GDPR if you are an EU resident, and equivalent regimes in other jurisdictions), you may:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your account and associated personal data (subject to legal-retention requirements)
- Export your data in a portable, machine-readable format
- Withdraw consent for marketing communications (one click in any email, or from your profile)
- Lodge a complaint with your local privacy regulator — for Canada, the Office of the Privacy Commissioner of Canada
To exercise these rights, write to [email protected]. We respond within 30 days.
10. Children
Bonusphere is strictly for adults aged 18+ (19+ in BC, NB, NL, NS, ON, PE, QC, SK). We do not knowingly collect data from minors. If you believe a minor has registered, contact us immediately at [email protected] and we will close the account and delete the data.
11. International data transfers
Our servers are located in Germany (EU). Data may be transferred to and processed in jurisdictions outside Canada under appropriate safeguards (such as standard contractual clauses). We do not transfer personal data to jurisdictions without adequate data-protection standards.
12. Security
We use industry-standard measures to protect your data: HTTPS-only transport, hashed passwords (bcrypt), restricted server access, regular security updates, and CSRF protection. No system is 100% secure; in the unlikely event of a breach affecting your personal data, we will notify you and the relevant regulator without undue delay and in accordance with applicable law.
13. Third-party links
Our reviews link to external casinos, regulators, and informational resources. Once you leave bonusphere.com, the destination site's own privacy policy applies. We are not responsible for the data practices of third parties.
14. Changes to this policy
We may update this policy as our services, technology, or applicable law evolve. Material changes will be announced via in-product notice and (for registered members) email at least 14 days before they take effect. Continued use of the Site after a change indicates acceptance of the updated policy.
15. How to contact us
Email: [email protected]
For general inquiries: [email protected]