Vegastars privacy policy

VegaStars NZ privacy policy - data categories, why we process, cookies, retention, NZ Privacy Act 2020 alignment and player rights.

18+ | Gamble Responsibly | T&Cs Apply

5 / 5 editorial ratingIndependent review of vegastars-new-zeeland.com

This notice explains how Neptune Projects S.R.L. handles personal data when Kiwi visitors browse, register, deposit or play on VegaStars. Furthermore, it sets out lawful grounds, data categories and the rights NZ players can exercise. It sits alongside the Terms and Responsible Gambling pages. We drafted it with the NZ Privacy Act 2020 in mind, while also reflecting broader GDPR-shaped controls the operator applies across markets.

Data controller and privacy contact

Neptune Projects S.R.L. is the controller, a Costa Rican company registered under number 3-102-900308. Its corporate address is in San Jose, Canton 18 Curridabat, District Granadilla, Costa Rica. The controller runs a dedicated privacy mailbox at [email protected]. Moreover, that inbox deals with access requests, complaints and erasure questions from NZ residents. Players who want to take a matter further can also contact the Office of the Privacy Commissioner in Wellington.

What this notice covers for Kiwi visitors

This notice applies to every point of contact with the brand: lobby, cashier, live chat, promo emails and verification flows. In addition, it covers data produced by analytics, fraud screening and bonus eligibility checks. The controller treats Kiwi residents as data subjects under Costa Rican rules and the NZ Privacy Act 2020. Consequently, the safeguards set out below apply wherever the servers sit.

Types of personal information we collect

The operator collects eight broad data categories, each linked to a specific service or compliance duty. As a result, the amount of information held about a Kiwi player builds up over time as deposits, withdrawals and game rounds add up. The list below reflects the controller's internal classification.

Identity and contact data

This bucket includes full legal name, date of birth, residential address, nationality, email and phone number. Additionally, it holds copies of verification documents such as passports, driving licences and proof of address. Furthermore, the controller keeps a record of declarations made during sign-up, including the 18-plus confirmation required by the Terms.

Account and transaction data

The platform logs every deposit, withdrawal, bonus credit, wager and game session against the account identifier. In addition, the controller stores payment-instrument metadata, chargeback markers and cashier notes per transaction. The cashier shows NZ$ while the internal ledger sits in EUR; the controller therefore keeps the FX rate used at each conversion.

KYC and AML records

The controller retains KYC results, sanctions and PEP screenings, plus source-of-funds evidence, for as long as law requires. Moreover, the operator runs a risk-based model with Simplified, Customer and Enhanced Due Diligence tiers, so the stored data volume scales with the player’s risk profile.

Technical and usage data

The platform captures IP address, approximate location at city or country level, device identifiers, browser type, operating system, cookie IDs, session timestamps and security logs. Similarly, the platform records crash diagnostics to keep the lobby stable.

Communications, RG signals, preferences and feedback

Four more buckets complete the picture. First, all support tickets, live chats and email threads are retained. Next, responsible gambling signals such as session length, deposit cadence and tool usage feed the operator's player-protection model. Then, marketing and cookie preferences are recorded against the account. Finally, the operator keeps any survey or feedback responses a player chooses to share.

Why the operator processes your data

Processing splits into five buckets. To begin with, the controller needs your data to run the core service - account access, gameplay, deposits, withdrawals, promotions and customer care. In addition, identity verification, AML monitoring, sanctions screening, fraud prevention and responsible gambling outreach all draw on the same dataset. Furthermore, technical telemetry supports security monitoring, incident response and platform improvements. Moreover, the operator uses aggregated analytics for reporting, forecasting, finance and audit duties. Finally, marketing messages rely on consent that you can withdraw at any time.

The controller uses four legal bases familiar from European frameworks, mapped onto the offshore licence regime. Specifically, the contract with you covers gameplay, payments and account upkeep. Furthermore, legal obligation covers AML, sanctions and reporting duties. In addition, legitimate interest supports fraud prevention, security monitoring and platform improvement. Lastly, consent applies to marketing and any non-essential cookies. Consequently, you can withdraw consent for those last two streams without losing access to the casino itself.

Cookies and similar technologies

The platform uses cookies, software development kits and pixel-style tools to run core features and measure performance. Importantly, four categories are involved, as the table below shows.

Cookie FamilyPurposeConsent Required
EssentialSign-in, security tokens, fraud screening, core lobby featuresNo
FunctionalLanguage choice, layout preferences, performance diagnosticsOptional
AnalyticsAggregated usage measurement and product improvementYes
AdvertisingCampaign measurement and, where permitted, relevant marketingYes

You can block non-essential cookies through your browser or device settings at any time. However, blocking essential ones may break sign-in or the cashier. Therefore, the cookie banner offers granular toggles so NZ players can keep essentials active while switching off marketing trackers.

How we share personal information

The main rule is simple: the controller does not sell or rent personal information. Furthermore, the operator shares data only within a closed list of recipients, and only where a disclosure is necessary or lawful. Specifically, those recipients fall into five groups.

  • Service providers: Hosting, security, KYC and AML vendors, payment processors, fraud screening firms, game studios and CRM tools.
  • Group companies: Affiliated entities of the licensee, on a strict need-to-know basis for operations, support and compliance.
  • Regulators and authorities: Where law or licence conditions require disclosure to gaming, AML, tax or law-enforcement bodies.
  • Business-transfer recipients: A potential buyer or successor entity in a merger, acquisition or restructuring, subject to equivalent protections.
  • With your consent: For example, publishing a leaderboard nickname or sharing data with a referred friend.

Cross-border transfers and storage locations

Personal data may move between Costa Rica, Cyprus, the Autonomous Island of Anjouan and other jurisdictions where the operator uses processors. Therefore, NZ player data is not held solely on New Zealand servers. To close that gap, the controller applies contractual safeguards and equivalent-protection clauses so the standard of care stays at or above NZ Privacy Act 2020 expectations. In addition, identity and payment fields are encrypted in transit and at rest.

Retention Periods

Retention is set according to purpose. Specifically, AML and tax records are kept for as long as local law requires, which is usually several years after an account closes. Furthermore, transactional history is held for as long as the operator could face a related claim or investigation. Moreover, marketing data is deleted once consent is withdrawn or after a set inactivity window. Finally, the dormant-account rule in the Terms means inactive balances still require record-keeping until the file is closed.

Player rights under the NZ Privacy Act 2020

Kiwi players hold a familiar set of rights, set out below for clarity. Importantly, you can exercise any of them by emailing [email protected] with proof of identity attached.

  1. Right of access: Request a copy of the personal information held about you.
  2. Right to correction: Ask for inaccurate or outdated data to be updated.
  3. Right to erasure: Request deletion where retention is no longer justified.
  4. Right to restriction: Pause certain processing while a dispute is open.
  5. Right to portability: Receive a structured export of contract-based or consent-based data.
  6. Right to object: Push back on processing grounded in legitimate interests.
  7. Right to withdraw consent: Switch off marketing or non-essential cookies without losing service access.

Furthermore, NZ residents can complain to the Office of the Privacy Commissioner if they think the controller has fallen short. Although the operator is based offshore, the Privacy Act 2020 still gives Kiwi players a domestic escalation route.

Protecting children

VegaStars is an 18-plus service, and the operator treats underage prevention seriously. In addition, age declarations are taken at sign-up, identity documents confirm date of birth, and any account suspected of belonging to a minor is locked. Moreover, balances held by underage users are frozen pending a source-of-funds review and may be returned to the original deposit method. Consequently, parents who suspect a minor has used the platform should contact support straight away.

Security Measures

The controller uses encryption, network segmentation and least-privilege access to limit who can see personal data internally. Similarly, vendor contracts include data-protection clauses and security review obligations. Although no platform is immune to incidents, the operator keeps an incident response plan with notification steps for affected players and, where required, regulators.

Marketing choices for New Zealand players

Marketing email, SMS and push messages depend on opt-in consent given at sign-up or later through the account preferences screen. Furthermore, every promotional message includes a one-click unsubscribe link. In addition, withdrawing marketing consent does not stop transactional emails such as withdrawal confirmations or KYC requests, because those messages support the contract itself.

Changes to this notice

The controller may update this notice to reflect new services, regulator guidance or changes in technology. Therefore, check the revision date at the foot of the page from time to time. Moreover, material changes are sent by email to active account holders, so NZ players can review the new wording before they continue using the platform.

FAQ

No. The operator does not sell or rent personal data. Furthermore, sharing is confined to the closed list of service providers, group companies, regulators, business-transfer recipients and parties you have consented to.

Data may be held and processed in Costa Rica, Cyprus, Anjouan and other vendor sites. Contract terms, though, hold the protection level equivalent to what the NZ Privacy Act 2020 expects.

Write to [email protected] from your registered account address and include a photo ID. That lets the team confirm who you are before any records go out, normally within a reasonable timeframe.

Promotional emails and SMS will stop. The controller still sends transactional messages, though, such as withdrawal confirmations, KYC notices and security alerts, since those support the contract.

Yes. Where the operator confirms the holder is under 18, play is suspended, the file is closed, and any leftover balance is dealt with according to the Terms.

Verification files are held for as long as AML and gaming rules demand, which usually extends past the account's active life. They can also be kept longer while a claim or investigation remains open.

Privacy complaints in New Zealand go to the Office of the Privacy Commissioner. You can contact the office via privacy.org.nz after giving the operator a fair opportunity to reply first.