WW Games
PricingAbout
EnglishENРусскийRUEspañolES
Request a demo
  1. WW Games
  2. /
  3. Trust/
  4. Data protection
Trust

How player data is stored and protected

What a WW Games casino keeps about its players, where it lives, who on your team can see it, what is kept out of logs and AI tools, and the parts of data handling the product does not automate yet.

Request a demo
How player data is stored and protected

On this page

  • Whose data is it, and where does it live?
  • What does the platform store about a player?
  • Why are IP addresses and devices recorded?
  • How are passwords and secrets protected?
  • What is kept out of logs and error reports?
  • Who on your team can see player data?
  • How long are backups kept?
  • Does the AI copilot see player data?
  • Can players ask for their data to be deleted or exported?

Whose data is it, and where does it live?

The players are the operator's, and so is their data. Each brand runs as its own deployment with its own database, so one operator's players are never stored alongside another's. The hosting provider and region are agreed per deployment.

How brands are isolated

In data-protection terms the operator decides what player data is collected and why; WW Games runs the platform that stores and processes it. If your market requires a written agreement on that processing, raise it before signing.

How the separation between brands works — deployments, databases, entry points — is set out on security. Provider and region are not published, for the reason given there: it helps someone attacking a brand more than someone evaluating one.

What does the platform store about a player?

What an account, a wallet and fraud checks need: sign-in details, an optional profile, where the account was registered from, a device identifier, and the history of money and play. It does not store card numbers.

Card details are entered on the payment provider's page, not on the casino's. The platform receives the result of a payment, not the card, which keeps card data out of the brand's database altogether. How payments flow is on payments.

Account and sign-in
Email, or the Telegram ID, username, name, photo and language Telegram shares at sign-in; Google sign-in and passkeys where used.
Profile
A display name and date of birth, both optional and entered by the player.
Registration
The IP address, country and city the account was registered from.
Device
A browser device identifier and the last IP seen with it, used only as a fraud signal.
Money and play
Balances, transactions, deposits, withdrawals, bonuses and game rounds — the ledger an operator is obliged to keep.
Acquisition
Who invited the player and which partner or campaign they came from, for referral and affiliate settlement.

Why are IP addresses and devices recorded?

To catch fraud that costs operators money: several accounts run by one person, players referring themselves, and bonus abuse. Registration IPs and device identifiers are what those patterns are recognised by.

The device identifier comes from the player's browser and is treated as a signal, never as proof: it feeds a risk score that staff review, and a decision to hold a player is made by a person. How that works — without the thresholds, which are not published — is on anti-fraud.

How are passwords and secrets protected?

Player and staff passwords are stored only as bcrypt hashes, never as text. Staff two-factor secrets are encrypted, players can sign in with passkeys, and sessions can be revoked at once.

A hash cannot be turned back into the password, so a copy of the database does not give anyone the passwords in it. Passkeys go further: there is no shared secret for a phishing page to capture. For the back office, sign-in requires a two-factor code and sensitive actions ask for it again — described on security.

What is kept out of logs and error reports?

Passwords, access and refresh tokens, two-factor codes and secrets, Telegram sign-in data, API keys and crypto wallet material are replaced with a placeholder before anything is written to logs, the audit log or the error tracker.

One list of sensitive fields drives every place data is written — request logs, error handling, the staff audit log, event records and the error tracker — so a new secret is protected everywhere by adding it once. The error tracker is also configured not to collect personal data by default.

Logs are where data leaks without anyone noticing: a debugging line that prints a request body can put thousands of passwords into a file nobody thinks of as sensitive. Removing them at the point of writing is the only reliable fix.

Who on your team can see player data?

Only staff given the permission. Seeing players, balances and transactions is granted separately from acting on them, and every sensitive action — and every sign-in attempt — is recorded with who, what, when and from where.

A support agent can be allowed to read a player's history without being able to move money or change the account. Reading the audit log is itself a separate permission, and what it stores is sanitised so that credentials never end up in it. The full model is on security.

How long are backups kept?

A full copy of the brand's database is taken every night and kept for a few days in object storage, with a minimum number of copies always retained. Older copies are deleted automatically.

Short retention is a data-protection choice as much as a storage one: a copy that no longer exists cannot leak. The order of operations — verify, upload, verify again, only then prune — and the recovery point are on security.

Does the AI copilot see player data?

No. The back-office AI copilot answers from the platform's operator guide, has no access to players or balances, and is instructed not to ask for, repeat or process players' personal data. Its conversations are deleted after 90 days.

The language model is reached with provider-side data collection turned off and zero-data-retention routing on by default, and a deployment can point the copilot at a model on its own infrastructure. The copilot is switched on per brand, only for operators who want it — see AI copilot.

Can players ask for their data to be deleted or exported?

Not by themselves: the product has no self-service account deletion or data export for players today. How such requests are answered is the operator's decision; ask us how they are handled on your deployment.

We would rather say this than imply a feature that is not there. What the admin panel does offer is closing a player's access with a ban, and marketing respects it: banned players are left out of on-site notifications.

WW Games holds no third-party security or privacy certification; the full list of what we do not claim is on security.

Read next

  • SecurityOne deployment and one database per brand, verified nightly backups, 56 back-office permissions, step-up confirmation on 19 operations and a full audit log.
  • Anti-fraudEvery player scored automatically for multi-accounting, self-referral and bonus abuse, with a review queue, player dossiers and withdrawal holds.
  • AI copilotAn AI copilot in the WW Games back office answers staff questions about the admin panel and translates promos into seven languages. It sees no casino data.

Data protection questions

Is our player data shared with other casinos on the platform?

No. Each brand has its own deployment and database, so there is no place where two operators' players are stored together.

Does the platform store card numbers?

No. Card details are entered on the payment provider's page; the platform receives the result of the payment, not the card.

How are passwords stored?

As bcrypt hashes only. Players can also sign in with passkeys, Telegram or Google, which involve no password at all.

Why does the platform record IP addresses and devices?

For fraud detection: multi-accounting, self-referral and bonus abuse are recognised by shared IPs and devices. The device identifier is a signal for staff review, not an automatic verdict.

Can a player delete their account themselves?

Not today. There is no self-service deletion or data export in the product; how such requests are answered is decided by the operator.

Where is the data hosted?

On infrastructure agreed per deployment. The provider and region are not published, for security reasons.

Ask the questions your market requires

Bring your data-protection questionnaire; we will answer it for your deployment and show the controls in the admin panel.

Request a walkthrough
WW Games

A White Label platform for launching and scaling online casinos. Web and Telegram, Sportsbook, payment integrations and an Admin Panel.

Follow us

Platform

  • All platform features
  • Features
  • What's included
  • Technology
  • Gallery
  • White label casino
  • Telegram casino
  • Game providers
  • Pricing

Compare

  • All comparisons
  • White label providers compared
  • WW Games vs Scalara
  • White label vs turnkey
  • SoftSwiss alternative
  • Slotegrator alternative
  • EveryMatrix alternative
  • Build vs buy

Solutions

  • All solutions
  • For affiliate teams
  • Who it fits

Company

  • About WW Games
  • Trust
  • Licensing guides
  • Market guides
  • Security
  • How a launch works
  • Frequently asked questions
  • Glossary
  • LLM Info
  • Request a demo

Contacts

  • Telegram
  • business@wwgames.tech
  • All contacts

© 2026 WW Games. All rights reserved.

18+A B2B solution for licensed operators. Please play responsibly.