Stay Casino Australia

Privacy Policy

What this site collects, what it never touches, and how to control cookies. Written under the Privacy Act 1988 and the Australian Privacy Principles.

This privacy policy explains what stay-casinosau.com does with information about the people who read it. We publish an editorial site about one casino brand. No bets are taken here and no money is held, and a payment card or an identity document never reaches us. Below: what our server records, which cookies the site sets, how long it is kept, and what you can ask us to do about it.

What this privacy policy covers

It applies to stay-casinosau.com and every page on it, including reviews, guides and these legal pages. It does not apply to Stay Casino itself, or to any other site you reach through a link from here.

The gap between the two is wide. Once you leave this domain, the operator’s own privacy notice takes over, and it collects far more than we do because it has to: account details, deposit and withdrawal records, verification documents. Stay Casino is run by Metlait SRL under Anjouan licence ALSI-202509073-FI2, so read its policy alongside the site terms and conditions.

Nothing here needs an account. You can read the Stay Casino review page or compare payment methods without telling us who you are. The people behind the site are listed on the page covering who runs this Stay Casino review site.

What information we collect

Technical data recorded automatically

Our server writes a log entry each time a page or file is requested: your IP address, the user-agent string your browser sends, operating system and device class, the referring URL, the pages requested, the timestamp and the HTTP status. An IP address yields location at country or state level, and we attempt nothing finer.

Aggregated audience measurement

Separately from raw logs, we read figures in aggregate: sessions, page views, average reading time, entry and exit pages, the desktop-to-mobile split and traffic sources in broad categories. Totals and percentages only, attached to no name, and no profile of an individual reader comes out of them.

Information you send us yourself

Email us or use a contact form and we receive what you type: your handle or name, your email address and the message. It answers your question and does nothing else. Please do not send account numbers, passwords or copies of identity documents; anything of that kind gets deleted instead of filed.

What we never collect

To be explicit, since this is the question readers ask most: no payment card numbers, no bank details, no crypto wallet keys, no KYC documents (driver’s licence, passport, Medicare card, utility bills), no casino credentials, balances or betting history. The site carries neither a registration form nor a login, and there is no wallet and no deposit page. Data of that type lives in the operator’s systems.

Why we handle this information

  • Delivering the site: serving pages to the right device and keeping them available.
  • Security: spotting scraping, spam, brute-force attempts and denial-of-service traffic, then blocking them.
  • Audience measurement: seeing which guides get read and where readers stop.
  • Improving the material: deciding what to expand, correct or retire based on how pages perform.

Under Australian Privacy Principle 3 we collect only what is reasonably necessary for running an editorial site, and under APP 6 we use it for the purpose it was collected for. Operations of our size are not always caught by the Privacy Act 1988 (Cth), the statute governing data protection in Australia; we treat the APPs as our standard regardless. For readers in the EU or UK, essential logging rests on legitimate interests and the other categories on consent you can withdraw.

Cookies and similar technologies

A cookie is a small text file a site asks your browser to store, so the next request is recognised as coming from the same browser. Local storage works much the same way. This page doubles as our cookie policy, listing everything the site sets.

Cookie types this site uses

Type Purpose Retention Can you switch it off?
Essential Session continuity, load balancing, security checks, storing your banner choice so it stops asking. Session; 12 months for the consent record Not via the banner; browser blocking works but breaks parts of the site.
Analytics Counts visits and page views, measures reading time, records entry pages and device class. Aggregated only. Up to 14 months, then totals only Yes: decline on the banner, change it later, or block in the browser.
Preference Remembers display settings such as a dismissed notice, so the site looks the same next visit. Up to 12 months Yes. No content is withheld if you do.

We set no advertising cookies and run no third-party ad-network pixels.

Managing cookies

A banner on your first visit offers accept or decline for the non-essential categories, and your choice holds until you clear it. Change it later through the cookie settings link in the footer. Browser controls are the harder switch, applying to every site you visit:

  • Chrome: Settings → Privacy and security → Third-party cookies; Delete browsing data clears what is stored.
  • Safari: Settings → Privacy → Manage Website Data. On iPhone or iPad: Settings → Apps → Safari → Clear History and Website Data.
  • Firefox: Settings → Privacy & Security → Cookies and Site Data, where Enhanced Tracking Protection can be set to Strict.

What changes if you block them

Block analytics and preference cookies and you lose nothing visible: no content sits behind a consent wall. Blocking the essential ones produces a different result. The banner returns on every page load, because your choice cannot be stored, and settings reset as soon as you navigate.

Analytics and third-party services

Audience figures come from a standard analytics tool set to aggregate reporting, with IP anonymisation enabled where it is offered. Our hosting and content delivery provider processes each request to serve a page and keeps short-lived security logs of its own.

Do Not Track and Global Privacy Control

The Do Not Track header was never standardised and most of the web ignores it. We treat it, and the newer Global Privacy Control signal, as an opt-out of analytics and preference cookies wherever the tools recognise it. Where a tool reads neither, declining on the banner is the reliable route.

When we disclose information

  • Hosting and infrastructure providers, since a page cannot be served without a server processing the request.
  • Our analytics processor, which receives aggregated event data under contract and may not use it for its own purposes.
  • Where the law requires it: a court order, a valid law enforcement request, or a lawful direction from a regulator acting under statute.
  • To protect the site, for example passing abusive IP ranges to a security provider.

We do not sell, rent or trade personal information, and no arrangement exists under which reader details reach Stay Casino or any other gambling operator. Following an outbound link hands over neither your email address nor your reading history. Hosting may sit outside Australia; where information is handled overseas we take reasonable steps under APP 8 to ensure comparable protections.

How long we keep it

Nothing is kept indefinitely. Raw server logs run on a rolling window, normally 30 to 90 days, then get deleted or rotated out. Event-level analytics data is retained up to 14 months, after which only aggregated totals survive. Emails stay in the inbox for up to 12 months after the conversation closes, and the record of your cookie choice lasts 12 months.

Your rights under the APPs

  • Access (APP 12): ask what we hold about you and receive a copy.
  • Correction (APP 13): if something is wrong or out of date, ask us to fix it.
  • Anonymity and pseudonymity (APP 2): read the whole site without identifying yourself, and write to us under a handle.
  • Deletion on request: ask us to remove correspondence you sent and we will, unless a law requires us to keep it.
  • Opting out of measurement, through the banner or your browser settings.

One honest limitation applies to access requests. Since we collect no account identifiers, most of what our logs hold cannot reliably be linked to a named person, and an IP address alone is not enough for us to be confident the records are yours; handing them to the wrong requester would be the worse outcome. Correspondence you emailed us is easy to supply. We answer within 30 days.

Making a complaint

Raise it with us first. If our answer does not resolve it, complain to the Office of the Australian Information Commissioner, the federal privacy regulator, at oaic.gov.au or on 1300 363 992. Complaints are free.

How we protect information

The whole domain runs over HTTPS with modern TLS, so traffic between your browser and our server is encrypted in transit. Administrative access runs on individual credentials, not shared logins, and hosting software is kept patched. We hold no reader database, so a breach here has nothing of yours to lose beyond an email you chose to send us.

Australia’s Notifiable Data Breaches scheme covers eligible breaches likely to cause serious harm. On becoming aware of one we would assess it within 30 days and, where the threshold was met, notify the OAIC and the individuals affected, plus a notice on the site since email addresses may be the only contact details we hold.

Children and under-18s

This site is for adults aged 18 or over, and nothing here is presented to appeal to minors. We do not knowingly collect personal information from anyone under 18; if you believe someone under that age has sent us details, contact us and the material gets deleted. Parents wanting a technical block rather than a policy statement should look at BetBlocker or Gamban, which cover offshore sites that Australian registers do not reach. Both are set out in our responsible gambling guide for Australia.

Changes to this privacy policy

This policy was last updated on 25 August 2026, and the date at the top of the page always reflects the current version. Where a change materially affects how information is handled, a notice goes on the site for a reasonable period. Continuing to use the site after a revised version is published means you accept it.

Privacy contact

Questions about this policy, access and correction requests, and complaints go to [email protected]. Tell us what you are asking for, roughly when you visited if the question concerns logs, and an email address we can reply to. We respond within 30 days.

Anything the casino holds sits beyond our reach: account data, verification documents, deposit records and closure requests go to [email protected] or the operator’s live chat.

About this policy

This document describes how stay-casinosau.com actually operates as at August 2026, checked against the site’s configuration rather than copied from a template. It is written against the Privacy Act 1988 (Cth) and the APPs, and it is not legal advice. It says nothing about the obligations of the casino operator we write about.