We collect your approximate province (from your IP address) to show you region-appropriate casino content. With your permission, we remember which casinos you've browsed on this site to make better recommendations. We do not sell your data. We do not run advertising trackers. We do not create accounts or store passwords. Your IP address is sent to a geolocation service to determine your province, it is not stored on our servers. You can opt out of personalisation at any time using the privacy preference link in the footer. Optionally, you may subscribe to our newsletter, if you do, we collect your email address and, optionally, your first name, with your express consent. You can unsubscribe in one click at any time.
1 Who We Are and How to Reach Us
CanadaCasinos.io is operated by Kernel Media, a company incorporated in British Columbia, Canada. We publish independent editorial reviews, news, and comparison tools covering licensed online casinos available to Canadian adults.
2 Scope of This Policy and Applicable Law
This Privacy Policy applies to all personal information collected through https://canadacasinos.io and any associated subdomains (collectively, the "Site"). It does not apply to third-party websites linked from the Site, including online casino operators to which we may refer you.
As a British Columbia-based organisation engaged in commercial activity, our primary privacy obligations arise under:
Where the requirements of these laws differ, we apply the most protective standard to all users, regardless of province. For Quebec residents, the additional rights and requirements described in sections 11-13 of this policy apply.
3 What Personal Information We Collect
We collect the minimum personal information necessary to operate this Site. The following table exhaustively lists every category of personal information we collect, the mechanism of collection, and its legal classification.
cc_browsing_v1
cc_privacy_consent
cc_theme
4 Why We Collect Personal Information, Purposes
Pursuant to s.6 of BC PIPA and Principle 2 of PIPEDA's Schedule 1, we identify the purposes for collecting personal information before or at the time of collection. We collect personal information only for the purposes listed below and for no other purpose.
Canadian provinces have different regulatory regimes for online gambling. Ontario has a fully regulated market (iGaming Ontario); Alberta is launching a regulated market in 2026; British Columbia and Quebec operate through provincial monopolies. We use your province to show you content, casino recommendations, and regulatory information that is accurate and legal for your jurisdiction. This is the primary purpose of all geo-detection.
With your explicit consent, we use your browsing history on this Site (specifically, which casino review pages you have visited) to power our "For You" recommendation section and to improve the accuracy of our QuickMatch casino-finder tool. This data is stored exclusively in your browser's localStorage, it is never transmitted to our servers or to any third party. You may withdraw this consent at any time.
We record your privacy consent choice to demonstrate compliance with our obligations under BC PIPA, PIPEDA, and Quebec Law 25. This record is stored as a cookie in your browser for 365 days and is renewed when you update your preferences.
IP addresses are processed transiently by our hosting provider and geolocation service to detect abuse, spam, and fraudulent traffic. No IP addresses are retained in our application database. Standard server access logs maintained by our hosting provider (Hostinger) are governed by their own privacy policy.
4.5 Newsletter & Commercial Electronic Messages
What We Collect and Why
If you choose to subscribe to our newsletter, we collect your email address and, optionally, your first name. We use this information solely to send you editorial content about online casinos in Canada, topics you have selected (News, Reviews, Bonuses, Guides). We do not use your email address for advertising, profiling, or any purpose other than delivering the newsletter you requested.
Double Opt-In Consent Process
We use a double opt-in process to establish express consent under CASL s.6(1)(a):
- You complete the signup form, tick the consent checkbox, and submit. Your subscription is set to pending. No CEMs are sent at this stage.
- We send a confirmation email to the address you provided. This email contains a confirmation link valid for 24 hours and is itself not a CEM (it is a transactional message).
- You click the confirmation link. Your subscription is set to confirmed. Only then may we send you CEMs.
At the time of signup, we record a consent snapshot containing: the exact wording of the consent checkbox shown to you, the privacy policy version in effect, the URL of the signup page, your IP address, and a timestamp. This record is retained for three years after unsubscribe as required by the CRTC's guidance on CASL record-keeping (corresponding to the CASL s.51 limitation period for proceedings).
Every CEM We Send Contains
- Our identity: Kernel Media, operating CanadaCasinos.io
- Our mailing address (CASL Regulations, s.3(a))
- Our contact email: privacy@canadacasinos.io
- A one-click unsubscribe link that remains functional for at least 60 days (CASL s.6(2)(c))
- An RFC 8058-compliant
List-Unsubscribeheader for email client integration
Unsubscribe Mechanism
You can unsubscribe at any time by:
- Clicking the unsubscribe link in the footer of any email we send. This is a GET request, one click, no login, no form, no further action required.
- Using your email client's native unsubscribe, our emails include
List-UnsubscribeandList-Unsubscribe-Postheaders per RFC 8058, allowing Gmail, Apple Mail, and Outlook to offer one-click unsubscribe directly in the email UI. - Contacting us at privacy@canadacasinos.io with a written unsubscribe request.
Unsubscribes are processed immediately, typically within one second of clicking the link. We log the unsubscribe timestamp for compliance purposes. Under CASL s.11(3), unsubscribes must be honoured within 10 business days; we exceed this requirement.
Retention After Unsubscribe
After you unsubscribe, we retain your email address and consent record for three years (corresponding to the CASL s.51 limitation period for CRTC enforcement proceedings). We retain this record only to demonstrate that: (a) we obtained valid consent before sending you CEMs, and (b) we processed your unsubscribe immediately. We do not use your email address to send you further CEMs after unsubscribe. After the three-year retention window, subscriber records are deleted.
Topic Preferences
You may update your content preferences (News, Reviews, Bonuses, Guides) at any time by clicking the "Manage Preferences" link in any email we send. You may also unsubscribe from all emails using the same preferences link. Topic preferences do not affect the legal basis for processing, you subscribed to the newsletter as a whole; topic preferences are a convenience feature.
Email Delivery Infrastructure
We use Postmark (operated by ActiveCampaign, LLC, formerly Wildbit LLC, USA) to deliver transactional and newsletter emails. Your email address and message content are transferred to Postmark's servers in the United States for this purpose. This constitutes a cross-border transfer under PIPEDA and QC Law 25 s.17. We have assessed that Postmark's data handling is limited to message delivery and that their security posture (SOC 2 Type II) is appropriate for this transfer. See Section 5 for full third-party disclosure.
5 Disclosure to Third Parties
We do not sell, rent, trade, or otherwise disclose your personal information to third parties for their own commercial purposes. The following table lists every third party that receives any personal information in the course of your visit to this Site, the information shared, and the purpose.
Data received: Your IP address.
Purpose: To determine your approximate Canadian province so we can display region-appropriate content. The result (a province code) is returned to our server; your raw IP address is not retained by us.
Retention by third party: ip-api.com states it does not log individual query IPs beyond the current request. Please review ip-api.com's privacy documentation for their current retention practices.
Cross-border transfer: Your IP address is transferred to servers outside Canada. Under PIPEDA and QC Law 25, we are required to disclose this. We assessed that this transfer is necessary for the stated functional purpose (geo-appropriate content) and that ip-api.com's data handling is limited to the query lookup function.
Data received: Your IP address.
Purpose: Used as a fallback geolocation service when the primary service is unavailable. Same purpose and data handling as ip-api.com above.
Cross-border transfer: Same disclosure applies as above. Please review ipapi.co's privacy policy for their current practices.
Data received: Your IP address is transmitted to Google's servers when the fonts used on this Site (DM Sans, DM Mono) are loaded from Google's font CDN.
Purpose: Delivery of web fonts used in our design system. We are working to self-host these fonts to eliminate this transfer.
Google's privacy policy: policies.google.com/privacy
Data received: Email address and message content (newsletter and transactional emails such as subscription confirmation and unsubscribe confirmation).
Purpose: Delivery of commercial electronic messages and transactional emails to subscribers who have provided express consent. Postmark also provides delivery logs that form part of our CASL compliance record.
Retention by third party: Postmark retains message activity logs for 45 days by default. Please review Postmark's privacy policy for current practices.
Cross-border transfer: Your email address and message content are transferred to servers in the United States. Under PIPEDA and QC Law 25 s.17, we disclose this transfer. We assessed Postmark's SOC 2 Type II certification as appropriate for this data transfer, which is necessary to deliver the newsletter service you requested.
Legal basis: Performance of the newsletter service requested by the subscriber; CASL s.6 express consent.
Data received: Standard server access logs, which include IP addresses, request timestamps, and page paths. These are maintained by Hostinger as part of normal web server operations.
Retention: Governed by Hostinger's data retention policies. Please review Hostinger's privacy policy.
6 Automated Decision-Making and Profiling
This Site uses two automated systems that involve profiling based on your browsing behaviour. We are required to disclose these under s.12.1 of Quebec Law 25.
- What it does
- Analyses your stated game preference, betting priorities, and (with consent) your casino browsing history on this Site to recommend the single casino most likely to match your needs from our reviewed set.
- Personal information used
- Your answers to the QuickMatch quiz (game type, priority, theme preference); if you have consented to personalisation, your casino browsing history (
cc_browsing_v1) is also used as a weighting signal. - Consequence of the automated result
- A recommendation is displayed. There is no binding decision, you are not excluded from any service, denied any opportunity, or scored in any way that has consequences beyond which casino card appears first. You may view all reviewed casinos regardless of the recommendation.
- Your rights
- You may request that a human review any recommendation concern by contacting privacy@canadacasinos.io. You may also simply ignore the recommendation and browse our full casino list independently.
- How to opt out
- Choose "Essential Only" in our privacy preferences. This disables the browsing history signal used in personalisation. The quiz-based recommendation (using only your quiz answers) continues to function without your browsing history.
- What it does
- Displays a section on the homepage and sidebar titled "Based on Your Browsing" showing casino reviews you have previously viewed on this Site.
- Personal information used
- Your casino browsing history (
cc_browsing_v1), stored exclusively in your browser's localStorage. This data is never transmitted to our servers. - Consequence of the automated result
- Previously-viewed casinos are surfaced for convenience. No scoring, ranking in external systems, or consequential decisions are made.
- How to opt out
- Choose "Essential Only" in our privacy preferences. This immediately deletes the
cc_browsing_v1localStorage key from your browser and hides the "For You" section. The section will not reappear unless you re-enable personalisation.
7 Cookies, localStorage, and Local Storage
The following table is the complete inventory of every cookie and local storage item this Site writes to your browser. There are no third-party advertising or analytics cookies. No tracking pixels. No fingerprinting scripts.
You can delete all of the above at any time through your browser's settings.
In most browsers: Settings → Privacy → Clear browsing data → Cookies and site data.
You may also use the "Essential Only" option in our privacy preferences, which
removes cc_browsing_v1 immediately.
8 Retention and Deletion
We retain personal information only for as long as necessary for the purposes for which it was collected, or as required by applicable law. The following retention schedule applies:
- Province cookie (
sbc_user_province): 12 hours from creation. Automatically deleted by your browser on expiry. - Province localStorage (
cc_province_v2): Persistent until manually cleared, but re-queried and refreshed on each visit if more than 30 minutes old. - Browsing history (
cc_browsing_v1): Persistent in your browser until you withdraw personalisation consent (immediate deletion) or clear your browser data. Maximum of 10 casino entries retained at any time. Never held on our servers. - Privacy consent cookie (
cc_privacy_consent): 365 days. Renewed on your next visit if you update your preferences. - Server access logs (Hostinger): Governed by Hostinger's data retention policies, typically 30-90 days.
- Subscriber records (newsletter): Retained during active subscription and for three years after unsubscribe. The three-year window corresponds to the CASL s.51 limitation period for CRTC enforcement proceedings. After this period, subscriber records are permanently deleted.
- Consent & event audit log (newsletter): Retained for a minimum of three years from the date of last activity on the subscriber record (subscribe, confirm, unsubscribe). This log is required by CASL s.10 to demonstrate that consent was validly obtained and that unsubscribes were processed promptly. Events are anonymised (IP address and user-agent removed) but not deleted until the retention period expires.
When personal information is no longer required for any of the stated purposes and no legal retention obligation requires us to keep it, it is deleted or anonymised in accordance with s.35 of BC PIPA.
9 Security Safeguards
We implement security safeguards appropriate to the sensitivity of the personal information held, as required by s.10 of BC PIPA and Principle 7 of PIPEDA.
- TLS encryption: All data transmitted between your browser and this Site is encrypted using TLS 1.2 or higher.
- No server-side PI storage: Province codes derived from geolocation are passed to page rendering and are not written to our application database. There is no user database on this Site.
- Browser-only storage: Browsing history and preference data is stored exclusively in your browser. It cannot be accessed by our servers and is not transmitted over the network.
- Access controls: WordPress administrative access is restricted to authorised personnel and protected by strong credential requirements.
- Third-party security: Our hosting provider (Hostinger) maintains physical and network security for our servers. We have reviewed their security documentation and determined that their safeguards are appropriate for the limited personal information we process.
In the event of a privacy breach that creates a real risk of significant harm, we will notify the Office of the Privacy Commissioner of Canada (OPC) and affected individuals as required under PIPEDA s.10.1, and the Commission d'accès à l'information (CAI) within 72 hours as required by Quebec Law 25 s.63.2.
10 Your Rights
You have the following rights with respect to your personal information. These rights apply to all visitors. Additional rights for Quebec residents are listed in Section 11.
You may request access to personal information we hold about you.
Because we hold very limited PI (province code in cookies only, not associated with your identity), we will describe what we hold by category.
BC PIPA s.23, response within 30 business days.
If you believe we hold inaccurate personal information about you, you may request a correction.
BC PIPA s.24.
You may withdraw consent to non-essential data collection (personalisation) at any time by selecting "Essential Only" in our privacy preferences. Withdrawal takes effect immediately.
BC PIPA s.8; PIPEDA Principle 3.8.
If you are unsatisfied with our response to a privacy concern, you have the right to complain to the applicable regulator.
BC PIPA s.47; PIPEDA s.11.
If you are a newsletter subscriber, you may withdraw your consent to receive commercial electronic messages at any time by clicking the unsubscribe link in any email we send.
Withdrawal is effective immediately, no login, no form, no cost, no delay. We will not send further CEMs after you unsubscribe.
CASL s.11(3), processed immediately, within the 10-business-day statutory maximum.
To exercise any of the above rights, contact our Privacy Officer at privacy@canadacasinos.io. We will respond within 30 business days as required by BC PIPA s.26.
11 Additional Rights for Quebec Residents
- Right to de-indexation (s.28.2): You may request that we take reasonable steps to de-index any hyperlinks that make personal information about you available on this Site if their dissemination causes you harm.
- Right to erasure (s.28.1): Where personal information was collected from you as a minor (under 18), or where the information is no longer necessary for the purpose for which it was collected, you may request its deletion.
- Right to data portability (s.27): You may request that personal information you provided to us be communicated to you or to any person or organisation you designate, in a structured, commonly used technological format.
- Privacy by default (s.9): Our systems are configured so that the highest level of privacy protection is applied by default. Non-essential data collection (personalisation) is OFF by default and requires your explicit opt-in.
- Automated decision-making (s.12.1): See Section 6 of this policy for our full disclosure regarding QuickMatch and personalised recommendations.
- Language rights: Quebec residents may request French-language versions of this policy and all privacy-related communications. Contact: privacy@canadacasinos.io
Complaints from Quebec residents may be directed to the
Commission d'accès à l'information (CAI):
www.cai.gouv.qc.ca |
Tel: 1-888-528-7741
12 Children's Privacy
This Site is intended exclusively for adults of legal gambling age in their jurisdiction. We do not knowingly collect personal information from minors. We do not target our content at persons under the age of 18.
If you are a parent or guardian and believe that a minor has provided personal information through this Site, please contact us immediately at privacy@canadacasinos.io. We will take prompt steps to delete any such information from our systems and, where applicable, from the browser-based storage described in this policy.
13 How to Complain to a Regulator
If you are not satisfied with our response to a privacy concern, you have the right to complain directly to the applicable privacy regulator. There is no cost to file a complaint with any of these bodies.
14 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or our services. When we do:
- The "Last updated" date at the top of this policy and in the page header will be revised.
- If the changes are material, meaning they significantly affect your rights or the way we handle your personal information, we will display a notice on this Site for at least 30 days following the update.
- If the changes require your renewed consent (e.g., a new category of data collection), we will reset the consent banner and request your fresh consent before the new processing begins.
We recommend reviewing this policy periodically. The current version is always available at https://canadacasinos.io/privacy-policy/.