Privacy Policy
Last updated: June 2026
This privacy policy explains how Shabiki collects, uses, stores and protects your personal data. We are committed to safeguarding your privacy in accordance with UK data protection laws and GDPR.
Information We Collect
We collect information you provide during registration: name, email, date of birth, address and payment details. We also collect technical data such as IP address, browser type, device information and cookies.
How We Use Your Data
- Account creation and management
- Processing deposits and withdrawals
- Identity verification (KYC) as required by law
- Preventing fraud and money laundering
- Sending promotional communications (with your consent)
- Improving our services and user experience
Data Storage and Security
All personal data is stored on encrypted servers within the EEA. We use 256-bit SSL encryption for data transmission. Access to personal data is restricted to authorised personnel only. We retain your data for as long as your account is active and for a period after closure as required by regulatory obligations.
Your Rights
Under GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request deletion of your data (subject to legal requirements)
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
Cookies
We use essential cookies for site functionality and analytics cookies to understand how visitors use our site. You can manage cookie preferences through your browser settings. Disabling essential cookies may affect site functionality.
Third-Party Sharing
We do not sell your personal data. We share data only with payment processors, identity verification providers and regulatory authorities as required by law. All third-party partners are contractually bound to protect your data.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will notify registered users by email or through a prominent notice on the website. We encourage you to review this page periodically to stay informed about how we protect your data. The date at the top of this page indicates when the policy was last revised.
Contact
For privacy-related queries, contact our data protection team through the support channels listed on our website. We aim to respond to all data protection requests within 30 days.
Privacy policy and cookies: how your data is handled
A privacy policy explains what personal data the site collects — email address, device details, payment traces — and for what purpose. The cookie policy covers the small files stored in your browser: some keep you logged in, others measure which pages are read so the content can be improved.
Responsible data usage means collecting only what is needed and deleting it once it is no longer required. On Shabiki you can manage cookie consent from the banner or your browser settings, and withdrawing consent does not block access to the informational pages.
Personal data: what the operator collects and how it is protected
Everything typed into the cashier — card details, a document scan, a home address — travels to Shabiki over a channel protected by encryption, so along the way anyone listening on the same public network sees only a meaningless string of characters. Encryption of the connection is the baseline expected of a licensed site, and the padlock next to the address bar is the quickest way to confirm it is switched on before a single field is filled in. What the operator actually keeps is narrower than people assume: identity and contact details for verification, transaction history because financial regulation demands it, and technical records of logins and devices so that someone else getting into the account becomes visible. The operator's own privacy policy sets out that list in full, and it is worth opening once rather than never. As for the blunt question — is it safe to play at Shabiki? — the honest answer rests on exactly these basics: an encrypted connection, a clearly named licence and careful account habits.
Data leaves the operator in a few predictable directions: the payment provider that moves the money, the service that checks documents, and the regulator or the bank when they ask formally. All of that processing happens on the operator's side and not on this site, so a deletion request or a copy of your own file goes to its support desk. On the player's side the useful habits are dull and effective: a password reused nowhere else, two-factor authentication switched on in the account settings, and no logging in from a friend's laptop or a machine in an internet cafe. If a session was left open on a device you no longer have, changing the password closes it faster than hoping nobody looks. A copy of your data or its deletion is not a favour but a right under GDPR, and licensed operators mirror the same procedures in their privacy policies even for players outside the EU. A secure casino keeps every connection behind SSL encryption and spells out its data protection rules in the privacy policy — that combination is what makes a session safe and secure.