Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared and protected when you use the Pinco version of the Pinco online casino services available via pincob.com (the "Website"). It applies to all players, prospective players, and other visitors who access or interact with the Website, whether they create an account or simply browse.
The processing of personal data is carried out in accordance with applicable data protection laws, including the UK General Data Protection Regulation ("UK GDPR"), the UK Data Protection Act 2018, relevant EU/EEA data protection rules where applicable, and-where relevant for Mexican users-the Federal Law on Protection of Personal Data Held by Private Parties and its regulations in Mexico.
You must be at least 18 years old (or the minimum legal age for gambling in your jurisdiction, if higher) to use the Website. This Privacy Policy is effective from 6 November 2025 and reflects our practices as of that date.
Who We Are
Operating Company and Website
The Pinco services offered through pincob.com (the "Service") are operated by:
- Data controller: Carletta N.V., a company organised under the laws of Curaçao, with its registered address at Perseusweg 27A, Curaçao. Carletta N.V. is responsible for determining the purposes and means of processing personal data collected through the Service.
- Licensing information: Carletta N.V. operates under sub-license number 8048/JAZ2017-003, issued by Antillephone N.V. in Curaçao. This license relates to online gaming activity under Curaçao jurisdiction and does not constitute a licence from the UK Gambling Commission to offer services legally within the territory of the United Kingdom.
Group and Service Providers
- Payment processor subsidiary: Certain payment-related services for Pinco on pincob.com are provided by B.W.I. Black-Wood Limited, a company based in Cyprus, acting as our payment processor and service provider.
- Infrastructure and hosting: Technical infrastructure and servers supporting the Service are located in several jurisdictions, including the Netherlands and Belize, and may be operated by third-party hosting and IT service providers on our behalf.
Contact and Data Protection Officer
- General and privacy enquiries: You can contact us at [email protected] for any questions about this Privacy Policy or our handling of your personal data.
- Data Protection Officer (DPO) / data protection team: Carletta N.V. has appointed a data protection function. You can reach our DPO or data protection team by emailing [email protected] and including "Data protection" in the subject line.
- Postal correspondence for privacy matters: Data Protection Officer, Carletta N.V., Perseusweg 27A, Curaçao.
What Personal Data We Collect
Account and Identification Data
- Registration details: When you create a Pinco account on pincob.com, we collect information such as your full name, username, password, date of birth, country of residence and preferred language.
- Contact information: We collect your email address (for example, the address used to register your account) and, where provided, your telephone number, postal address and other contact details used for verification or communication.
KYC and Verification Data
- Identity documents: To comply with Know-Your-Customer ("KYC"), anti-money laundering ("AML") and other regulatory obligations, we may collect copies of identification documents (such as passport, national ID, driving licence), selfies, and proof of address documents (such as utility bills or bank statements).
- Verification information: We may obtain information from third-party verification providers (for example, confirmation of your age, identity, address, source of funds or sanctions screening results) to assess your eligibility and comply with legal obligations.
Payment and Financial Data
- Transaction details: When you deposit or withdraw funds, we process data such as payment method, card type and partially masked card number, wallet identifiers, transaction amounts, currencies, timestamps, and payout or chargeback records.
- Billing and banking data: Depending on the payment method, we may receive IBAN, bank account details, or other financial identifiers from you or from our payment processor B.W.I. Black-Wood Limited and other payment service providers.
Technical and Device Data
- Device identifiers: We collect technical information such as IP address, device type and model, operating system, browser type and version, language settings, approximate location based on IP, and similar device or network identifiers.
- Log and usage data: Our systems automatically record log data, including access dates and times, pages viewed, referring URLs, clickstream data, login attempts, session duration, and technical error or performance logs.
Behavioural and Profile Data
- Gaming and betting history: We record details of your gameplay and betting activity, including games played, stakes, winnings and losses, session duration, limits set, self-exclusion status, and responsible gambling interactions.
- Preference and interaction data: We may collect information on your selected language, preferred games, promotions engaged with, interactions with customer support, and responses to surveys or feedback forms.
Cookies and Similar Technologies
- Cookies and trackers: When you visit Pinco on pincob.com, we use cookies, web beacons, pixels, SDKs and similar technologies to recognise your browser or device, remember your preferences and analyse usage patterns. For more details, see the "Cookies & Tracking Technologies" section below.
Special Categories of Data
- Sensitive data: We do not purposefully request sensitive personal data (such as health information or religious beliefs). However, information related to responsible gambling (for example, if you tell us about gambling-related harm or health issues) may indirectly reveal sensitive information and will be handled with heightened care and confidentiality.
Legal Basis for Processing
Contractual Necessity
- Provision of the Service: We process personal data that is necessary to enter into and perform our contract with you (UK GDPR Article 6(1)(b)), including creating and managing your Pinco account on pincob.com, verifying your identity, processing deposits and withdrawals, enabling gameplay, handling customer support requests and administering your participation in promotions or loyalty schemes.
Compliance with Legal Obligations
- Regulatory and AML/KYC duties: We process your identity, transaction and behavioural data where required to comply with applicable laws and regulations (UK GDPR Article 6(1)(c)), including anti-money laundering and counter-terrorist financing rules, responsible gambling obligations, record-keeping, accounting and tax requirements, as well as requests from competent authorities in Curaçao, the UK, the EU/EEA, Mexico or other relevant jurisdictions.
Legitimate Interests
- Service integrity and security: We process personal data to prevent fraud, abuse of bonuses, chargebacks, account takeover, money laundering, system misuse and other illegal or irregular activity, and to ensure network and information security. This is based on our legitimate interests (UK GDPR Article 6(1)(f)), balanced against your rights and freedoms through appropriate safeguards (such as access controls and minimisation).
- Analytics and service improvement: We use aggregated and pseudonymised data to analyse how Pinco is used on pincob.com, improve our games, features, user interface and performance, and conduct statistical reporting. Where feasible, data is aggregated or anonymised to reduce privacy impact.
- Business operations: We process data to manage our business, including internal administration, compliance management, auditing, risk management, and corporate governance, relying on our legitimate interests while respecting data protection principles.
Consent
- Marketing communications: We rely on your consent (UK GDPR Article 6(1)(a) and relevant electronic communications rules) for sending email or other electronic direct marketing about Pinco offers on pincob.com, unless another lawful basis applies. You can withdraw your consent at any time, as explained in the "Your Rights" section.
- Cookies and similar technologies: For non-essential cookies and similar tracking technologies (for example, analytics and advertising cookies), we rely on your consent obtained through our cookie banner or settings tools.
- Certain profiling activities: Where required by law (including in Mexico), we obtain your consent before carrying out profiling that produces legal effects or similarly significant effects on you, or before re-using data for materially different purposes.
Mexican Law Alignment
- Mexican legal bases: For Mexican users, we process personal data in line with the Federal Law on Protection of Personal Data Held by Private Parties and its regulations. Consent is generally required for processing, subject to statutory exceptions (for example, to comply with legal obligations or perform a contract), and we support ARCO rights (Access, Rectification, Cancellation and Opposition) as detailed under "Your Rights".
Purpose of Processing
Provision and Management of the Service
- Operating your account: To register and authenticate your Pinco account on pincob.com, enable login, maintain your account settings, and manage your balances, bonuses and loyalty benefits.
- Gaming and transactions: To provide casino games, record bets, calculate winnings and losses, settle bets, process deposits and withdrawals and maintain accurate transaction and gameplay records.
Compliance, Risk Management and Responsible Gambling
- KYC, AML and sanctions checks: To verify your identity, age and residence, assess your risk profile, conduct AML and counter-terrorist financing checks, and comply with sanctions and other regulatory screening requirements.
- Responsible gambling controls: To apply limits, self-exclusion measures and cooling-off periods; monitor behaviour for signs of problem gambling; manage self-exclusion requests received via [email protected]; and keep records of our responsible gambling interactions.
Customer Support and Communications
- Support services: To respond to your queries, complaints and requests sent to [email protected], investigate incidents, resolve disputes, and communicate operational information about your account and use of the Service.
- Service notifications: To send transactional communications, such as changes to this Privacy Policy, updates to terms, security alerts, and important information about your account or transactions.
Marketing, Personalisation and Analytics
- Marketing communications: With your consent where required, to send you promotional offers, newsletters, bonuses and tailored campaigns related to Pinco on pincob.com, by email or other channels.
- Personalised content: To customise the display of games, recommendations, promotions and content based on your previous activity, preferences and profile, in order to make your experience more relevant.
- Analytics and performance: To understand how users interact with the Website, diagnose technical problems, measure the effectiveness of promotions, and improve site performance and user experience.
Business Operations and Legal Protection
- Internal administration: To conduct audits, financial reporting, regulatory filings, internal control activities and corporate governance.
- Legal claims and enforcement: To establish, exercise or defend legal claims; to enforce our terms and conditions; to detect and prevent fraud, abuse or other harmful activities; and to cooperate with law enforcement or regulators where legally required.
Disclosure & Sharing
Service Providers and Group Entities
- Payment processors and banks: We share relevant payment and identification data with payment service providers, including B.W.I. Black-Wood Limited in Cyprus, card schemes, banks and e-wallet providers to process deposits, withdrawals, refunds and chargebacks.
- IT and hosting providers: We use third-party IT, hosting, cloud and security providers (including servers located in the Netherlands and Belize) to host the Website, store data and maintain our technical infrastructure.
- Verification and risk management providers: We may share identity, address and transaction data with third-party KYC/AML, fraud-prevention and risk-scoring providers to verify your details and help detect suspicious activity.
Analytics, Marketing and Affiliates
- Analytics services: We may share pseudonymised or aggregated usage data with analytics providers to help us understand how Pinco is used on pincob.com and to improve our Service.
- Marketing partners and advertising networks: Where you have given consent (if required by law), we may share limited identifiers (such as cookies, device IDs or hashed email addresses) with advertising networks and marketing service providers to deliver or measure personalised marketing relating to our Service.
- Affiliates and introducers: We may share necessary information with affiliates or introducers that referred you to us for the purpose of attributing traffic or commissions, in line with our contractual arrangements and applicable law.
Authorities, Regulators and Legal Recipients
- Regulators and supervisory authorities: We may disclose information to regulators, licensing bodies and supervisory authorities, such as Antillephone N.V. in Curaçao, the Information Commissioner's Office in the UK, EU/EEA data protection authorities, and-in relation to Mexican users-Mexican data protection authorities, where required or permitted by law.
- Law enforcement and courts: We may share data with law enforcement agencies, courts and other public authorities if we are legally obliged to do so, or if disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate suspected illegal activity.
Business Transfers
- Corporate transactions: If Carletta N.V. or any part of its business related to Pinco on pincob.com is involved in a merger, acquisition, sale of assets, reorganisation, financing or similar transaction, your personal data may be transferred as part of that transaction, subject to appropriate confidentiality and data protection safeguards.
Aggregated and Anonymised Data
- Non-identifiable information: We may share aggregated or anonymised information that does not identify you personally with third parties (for example, to publish statistics about general usage patterns). Such data is not considered personal data under applicable law.
International Transfers
Locations of Processing
- Within the UK and EEA: Some of our processing and storage may take place within the UK and the European Economic Area (for example, via servers located in the Netherlands or service providers established in the EEA).
- Outside the UK and EEA: Personal data may also be transferred to and processed in countries outside the UK and EEA, including Curaçao, Cyprus, Belize and other jurisdictions where our group companies, service providers or infrastructure are located. These countries may have data protection laws that are different from those in your home country and may not be recognised as offering an equivalent level of protection by the UK or EU authorities.
Safeguards for International Transfers
- Contractual safeguards: Where we transfer personal data from the UK or EEA to countries that do not benefit from an adequacy decision, we implement appropriate safeguards such as the UK International Data Transfer Agreement or Addendum, and/or the European Commission's Standard Contractual Clauses, together with additional technical and organisational measures where necessary.
- Service provider obligations: We require our service providers and partners to protect your data in accordance with applicable data protection laws, to process it only for specified purposes and to implement appropriate security measures.
- Other legal bases: In certain cases, we may rely on your explicit consent, the necessity of the transfer for the performance of a contract concluded in your interest, or other legal derogations recognised under the UK GDPR or applicable Mexican law.
Your Acknowledgement
- Risk and transparency: By using the Pinco Service on pincob.com, you acknowledge that your data may be transferred internationally as described above. We will always take steps to ensure that your data is treated securely and in accordance with this Privacy Policy.
Data Retention
General Principles
- Retention aligned with purpose: We retain personal data only for as long as reasonably necessary to fulfil the purposes described in this Privacy Policy, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements, or to resolve disputes and enforce our agreements.
- Legal and regulatory requirements: Retention periods may vary depending on applicable laws in Curaçao, the UK, the EU/EEA, Mexico and other relevant jurisdictions, particularly in relation to AML/KYC and gambling regulations.
Indicative Retention Periods
- Account and identification data: Core account data (such as your name, contact details and account history) is normally kept for the duration of your active account and for up to five (5) years after closure of your account, unless a longer period is required to comply with legal obligations or to resolve disputes.
- KYC and AML data: Identity verification documents, risk assessments and AML records are typically retained for at least five (5) years after the end of the business relationship or the date of the last transaction, or longer where local AML or regulatory rules require extended retention.
- Transaction and payment data: Financial records relating to deposits, withdrawals and betting transactions are kept for periods required by applicable accounting, tax and gambling laws, generally for five (5) to seven (7) years.
- Responsible gambling records: Data relating to self-exclusion, limits and responsible gambling interactions is retained for at least the duration of the restriction or self-exclusion and for a subsequent period (often up to five (5) years) where necessary to comply with regulatory obligations and prevent circumvention.
- Marketing data: Marketing preferences and consent records are retained for as long as you remain subscribed and for a reasonable period (for example, up to two (2) years) after you unsubscribe, to demonstrate compliance with consent requirements.
- Cookies and analytics data: Cookie data is retained in line with the lifetime of the specific cookie (see "Cookies & Tracking Technologies"). Analytics data may be stored in aggregated or pseudonymised form for longer periods where it does not identify you directly.
Deletion and Anonymisation
- Deletion criteria: When personal data is no longer necessary for the purposes for which it was collected, and no legal obligation or legitimate interest requires further retention, we will delete or anonymise it in a secure manner.
- Backups and logs: Data stored in backups or system logs may be retained for limited periods for security, continuity and audit purposes, and will be securely overwritten or anonymised according to our retention schedules.
Your Rights
Rights Under UK and EU Data Protection Law
- Right of access: You have the right to obtain confirmation as to whether we process personal data about you and, if so, to receive a copy of that data together with information about how it is processed.
- Right to rectification: You can request correction of inaccurate personal data and completion of incomplete data relating to you.
- Right to erasure: In certain circumstances (for example, where data is no longer necessary for the purposes for which it was collected or where you withdraw consent and no other legal basis applies), you can request that your personal data be deleted. This right may be restricted where retention is required by law, particularly for AML or regulatory purposes.
- Right to restriction of processing: You may request that we restrict processing of your data (for example, while we verify its accuracy or where you have objected to processing).
- Right to data portability: For data you have provided to us, which we process based on your consent or on a contract, you may request a copy in a structured, commonly used and machine-readable format and ask us to transmit it to another controller where technically feasible.
- Right to object: You have the right to object at any time to processing based on our legitimate interests, and we will stop such processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or where processing is necessary for legal claims. You may also object at any time to processing for direct marketing, in which case we will stop marketing to you.
- Rights related to automated decision-making: Where we use automated decision-making, including profiling, that produces legal or similarly significant effects, you have the right to obtain human intervention, express your point of view and contest the decision, subject to applicable legal limitations.
- Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
Rights Under Mexican Law (ARCO Rights)
- Access: Mexican users may request information about the personal data we hold about them and the conditions of its processing.
- Rectification: You may request correction of inaccurate or incomplete personal data.
- Cancellation: Subject to legal or contractual limitations, you may request that your personal data be cancelled (deleted) when it is no longer necessary for the purposes for which it was collected.
- Opposition: You may oppose the processing of your personal data for specific purposes, including for marketing or profiling, where allowed by law.
How to Exercise Your Rights
- Contact point: To exercise any of your rights, please contact us at [email protected] with sufficient information to identify you and your account, and clearly describe your request.
- Verification: We may ask you for additional information (for example, a copy of an ID document or security questions) to verify your identity before fulfilling your request, to protect your data from unauthorised access.
- Response timeframe: We aim to respond to all valid requests within one month (30 days) from receipt. This period may be extended by up to two additional months where necessary due to complexity or number of requests, in which case we will inform you of the extension and reasons.
- Free of charge: Requests to exercise your rights are generally free of charge. However, we may charge a reasonable fee or refuse to act on requests that are manifestly unfounded or excessive, particularly due to their repetitive character, in accordance with applicable law.
- Limits to rights: Certain rights may be restricted by legal obligations (for example, AML/KYC and record-keeping obligations) or by the need to protect the rights and freedoms of others. Where we cannot fully comply with your request, we will explain the reasons, where permitted by law.
Marketing and Cookies Preferences
- Marketing opt-out: You can opt out of marketing emails at any time by using the "unsubscribe" link included in our emails or by contacting [email protected]. Even if you opt out, we may still send non-promotional messages relating to your account or transactions.
- Cookie controls: You can manage your cookie preferences via our cookie banner or settings (where available) and through your browser settings, as described in the "Cookies & Tracking Technologies" section.
Cookies & Tracking Technologies
Types of Cookies and Technologies
- Strictly necessary cookies: These cookies are essential for the proper functioning of the Pinco Service on pincob.com, enabling core features such as account login, security, navigation and access to secure areas. They cannot be disabled via the cookie banner, but you may disable them in your browser (which may affect site functionality).
- Functional and preference cookies: These cookies remember your choices, such as language, region, and display preferences, to provide a more personalised experience.
- Analytics and performance cookies: These cookies collect information about how visitors use the Website, such as pages visited, time spent and error messages, helping us improve the performance and usability of the Service.
- Advertising and targeting cookies: These cookies are used to deliver adverts that are more relevant to you and to measure the effectiveness of our marketing campaigns. They may be set by us or by third-party advertising networks with our permission.
- Other tracking technologies: We may use web beacons, pixels, tags, SDKs and similar technologies in conjunction with cookies to recognise users, track interactions with emails or advertisements, and improve our offerings.
First-Party and Third-Party Cookies
- First-party cookies: These are set directly by pincob.com to support the operation of Pinco and enhance your experience.
- Third-party cookies: These are set by third parties (such as analytics or advertising providers) to provide services to us or to you, in accordance with their own privacy and cookie policies.
Legal Basis and Consent
- Necessary cookies: We use strictly necessary cookies based on our legitimate interests in providing a secure and functional Service.
- Non-essential cookies: For analytics, advertising and other non-essential cookies, we rely on your consent as required under UK e-privacy rules and comparable laws. You may give or withdraw consent via our cookie banner or settings tools.
Cookie Management
- Browser settings: Most browsers allow you to view, manage, delete or block cookies. Please refer to your browser's help section for instructions. If you delete or block cookies, some features of the Website may not function correctly.
- In-site controls: Where available, you can adjust your cookie preferences at any time via the cookie banner or a dedicated cookie settings panel on pincob.com.
- Do Not Track and similar signals: At present, the Service does not respond to all "Do Not Track" signals. However, you can manage tracking through the options described above.
Data Security
Technical and Organisational Measures
- Encryption: Data transmitted between your browser and our servers is protected using transport layer security (TLS) with modern protocols (TLS 1.2 or higher) and strong cryptographic ciphers. Where appropriate, data at rest is encrypted using industry-standard algorithms.
- Access controls and authentication: Access to personal data is restricted to authorised personnel and service providers on a need-to-know basis, protected by strong authentication mechanisms, including multi-factor authentication for administrative access where feasible.
- Network and systems security: We employ firewalls, intrusion detection and prevention systems, anti-malware tools, secure configuration practices and regular patching to reduce vulnerabilities in our infrastructure.
- Monitoring and logging: Security events and system activities are logged and monitored to detect unusual behaviour, fraud attempts or other security incidents in a timely manner.
Governance, Training and Audits
- Policies and procedures: We maintain internal data protection and information security policies governing how personal data is handled throughout its lifecycle.
- Staff training: Employees and contractors with access to personal data receive training on data protection, confidentiality and information security obligations.
- Testing and reviews: We conduct regular security assessments, which may include vulnerability scans, penetration testing and third-party reviews, to evaluate and improve the effectiveness of our controls.
- Industry standards: Our security practices are designed to align with recognised international standards such as ISO/IEC 27001 and SOC 2, and we may work with vendors who hold such certifications, even if Pinco or pincob.com is not itself certified unless expressly stated elsewhere.
Incident Response and Breach Notification
- Incident management: We maintain incident response procedures to detect, investigate and respond to suspected data breaches or security incidents involving personal data.
- Notification obligations: Where required by UK GDPR, EU GDPR, Mexican law or other applicable regulations, we will notify relevant supervisory authorities and affected individuals of a personal data breach without undue delay.
- No absolute guarantee: While we implement appropriate security measures, no system can be guaranteed to be 100% secure. You are responsible for keeping your account credentials confidential and using unique, strong passwords.
Complaints & Contacts
Contacting Us First
- Primary contact: If you have any questions, concerns or complaints about this Privacy Policy or our handling of your personal data, please contact us first so we can try to resolve the issue directly.
- Email: [email protected]
- Postal address: Data Protection Officer, Carletta N.V., Perseusweg 27A, Curaçao.
Complaint Procedure
- Submit your complaint: Send us a detailed description of your concern by email to [email protected] (or by post), including your account details and any relevant evidence.
- Acknowledgement: We will acknowledge receipt of your complaint within a reasonable time, typically within seven (7) days of receiving it.
- Investigation: We will investigate your complaint, which may involve reviewing system logs, consulting with internal teams and, if necessary, requesting additional information from you.
- Response: We aim to provide a substantive response within one month (30 days) of receiving your complaint. If we cannot respond within this period due to complexity or volume of complaints, we will inform you of the delay and the expected timeframe.
- Further steps: If you are not satisfied with our response, you may escalate the matter to a relevant supervisory authority or seek other legal remedies, as described below.
Supervisory Authorities
- United Kingdom (UK): If you are located in the UK, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom. Website: https://www.ico.org.uk. Telephone: +44 303 123 1113.
- European Economic Area (EEA): If you are located in the EEA, you may lodge a complaint with your local data protection authority. Contact details for EEA supervisory authorities are available via the European Data Protection Board's website.
- Mexico: Mexican users may submit complaints to the competent Mexican data protection authority, such as the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI). Information on how to file a complaint is available on INAI's official website.
You may exercise your right to lodge a complaint without prejudice to any other administrative or judicial remedy.
Updates
Changes to This Privacy Policy
- Review and update: We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, technological developments or the way Pinco operates on pincob.com.
- Versioning and date: Each version of this Privacy Policy is identified by an effective date. The current version is effective from 6 November 2025 and is referred to as "Last updated: November 2025".
Notification of Material Changes
- Advance notice: For significant or material changes that materially affect your rights or the way we process your personal data, we will provide you with prior notice, where practicable at least 30 days before the changes take effect.
- Notification methods: We may notify you through a combination of methods, including emails sent to your registered email address, in-account messages, notifications in your player dashboard and prominent banners or notices on pincob.com.
- Your options: If you do not agree with the updated Privacy Policy, you may choose to stop using the Service and request closure of your Pinco account on pincob.com. Continued use of the Service after the effective date of any changes will constitute your acknowledgement of the updated Policy.
Record of Material Changes
- Change log: Material changes may include, for example, updates to the categories of personal data collected, clarification of our legal bases for processing, introduction of new service providers or transfer mechanisms, or expansion of your rights and choices.
- Access to previous versions: Where required by law or good practice, we will retain previous key versions of this Privacy Policy and make them available upon reasonable request, so that you can understand how our practices have evolved over time.