Privacy Policy
PIPEDA-aligned data handling for Canadian players
This Privacy Policy explains how Tao Fortune Casino Canada collects, uses, retains and protects your personal information, and describes the rights you hold under PIPEDA (Personal Information Protection and Electronic Documents Act) and applicable provincial statutes. Effective 1 January 2026.
1. Who we are and how to contact us
Tao Fortune Casino Canada is a sweepstakes brand operated by Tao Fortune Holdings Ltd., registered in Nova Scotia. Our privacy officer is reachable at [email protected]. Reader mail is also welcomed at the customer support portal and via the address published on our terms of service page. Under PIPEDA, all Canadian users have the right to request access to their personal data, request corrections, and request deletion subject to legal retention requirements.
2. What we collect
| Category | Data | Purpose | Retention |
|---|---|---|---|
| Identity | Full name, DOB, photo ID | AML / KYC compliance | 7 years |
| Contact | Email, mailing address | Communication, prizes | Account life + 3 y |
| Financial | Interac email hash, card last 4, wallet address | Deposit / redemption processing | 7 years |
| Behavioural | Session logs, spins, IP | Fraud detection, RG signals | 90 days rolling |
| Device | Device attestation ID, OS ver | Security, app support | 30 days |
| Marketing | Consent state, campaign IDs | Personalisation (opt-in) | Until withdrawn |
3. How we use your data
We use collected data to run the sweepstakes platform, process Interac and other payment flows, verify age and identity, protect against fraud and money laundering, deliver support through the help centre live chat, comply with tax reporting (T5) for prizes above CAD 500 per calendar year, and — only with your explicit consent — send marketing communications. We do not sell personal information to third parties. Ever.
4. Third parties who touch your data
| Vendor | Role | Jurisdiction |
|---|---|---|
| Interac Corp. | e-Transfer rail | Canada |
| Stripe | Card processing | US / IE (SCC-covered) |
| Fireblocks | Crypto custody | US (SCC-covered) |
| Cloudflare | CDN & DDoS | Global (SCC) |
| iTech Labs | RNG certification | AU |
| Freshdesk | Support ticketing | US (SCC) |
Data collection minimisation over time
5. Your rights under PIPEDA
You have the right to (i) know what personal information we hold about you, (ii) request that we correct inaccuracies, (iii) request deletion of data not required by legal retention rules, (iv) withdraw marketing consent at any time, and (v) file a complaint with the Office of the Privacy Commissioner of Canada. Requests are processed within 30 days. Escalation runs through the privacy officer to Priya on the editorial team — see the Priya Doucette editorial bio for context on our transparency principles.
6. Cookies and tracking
| Cookie | Purpose | Duration |
|---|---|---|
| tf_session | Login session | Session |
| tf_wallet | Wallet currency preference | 90 days |
| tf_locale | Language (en-CA / fr-CA) | 365 days |
| tf_cmp | Cookie consent state | 365 days |
| _ga | Anonymised analytics (opt-in) | 2 years |
You can decline analytics cookies at any time via the consent banner on the Tao Fortune casino homepage. Session and wallet cookies are functional and cannot be disabled without breaking the login flow.
Where our data is stored (geographic split)
7. Security
All data in transit is protected by TLS 1.3. Data at rest uses AES-256 with keys managed in AWS KMS. Passwords are hashed with Argon2id at OWASP-recommended parameters. 2FA is available (and default for VIP accounts). Device attestation runs on the mobile companion app to protect biometric logins. Full details are audited annually by an external firm — the summary is published every February.
8. Retention and deletion
We retain identity and financial data for seven years as required by federal anti-money-laundering regulations. Behavioural data rolls off on a 90-day window. Marketing consent state is retained until you withdraw. On account closure, we delete or anonymise all non-mandatory data within 30 days and confirm deletion by email.
9. Children
Tao Fortune is strictly 19+ (18+ in Alberta, Manitoba and Quebec). We do not knowingly collect data from persons under the applicable minimum age. If we detect underage sign-up, we immediately close the account and delete all associated data.
10. Changes to this policy
Material changes are announced 30 days in advance via email and via a banner on the Tao Fortune casino homepage. The current version and change log are always available on this page. If you disagree with a proposed change, you may close your account with no consequences before the change takes effect.
Frequently asked questions
How do I request a copy of my data?
Email [email protected]. We deliver a JSON export within 30 days.
Can I delete my account?
Yes. Contact the help centre live chat. Deletion completes within 30 days.
Are cookies personalised for me?
No — analytics runs on anonymised aggregates unless you opt in to marketing personalisation.
Where can I read the responsible-play policy?
On the responsible-play control panel.
What if I disagree with your privacy practices?
File with the Office of the Privacy Commissioner of Canada at priv.gc.ca and let us know at [email protected] so we can address it directly.
Privacy is not a legal document; it is a promise, and the document exists to hold us to it. We keep this page updated in real time and welcome the help centre live chat community's scrutiny of every clause. The related terms of service page and cash-out banking rails pages contain the operational hooks that make this policy enforceable in practice.
Your data journey — what happens to a signup
When you create an account at Tao Fortune we collect your email, chosen password (hashed with Argon2id at OWASP-recommended parameters, so we never see the plaintext), date of birth and province of residence. That data is written to a Canadian-hosted database in Montreal within 200 milliseconds and replicated to a Toronto standby within 500 milliseconds. Nothing else. We do not enrich your data by cross-referencing external identity providers unless you explicitly enable a "Sign in with Google" or "Sign in with Apple" flow (available Q4 2026 on the mobile companion app). We do not query credit bureaus, and we do not run behavioural surveillance on your other online activity.
Your data becomes richer only when you take actions. First deposit: we log a hashed payment fingerprint (never the raw card number). First redemption: we ask for identity documents and store the hashes for AML compliance. First live-chat interaction: the transcript is stored encrypted for 90 days. Every one of these expansions is visible in your account audit log, which you can pull on demand via the customer support portal.
Data minimisation in practice
Every year, Priya and the compliance team run a "field audit" of the account schema. The goal is to remove any field that has not been used in a decision-making process for six months. Since 2023 we have removed nine fields this way, including phone number (moved to optional), postal-code-based province inference (replaced with explicit province selection) and referral source tracking (kept only in aggregate). The current schema is smaller than any of our peer sweepstakes brands, and it will keep shrinking. The sweepstakes 101 guide explains why this matters even for a promotional-contest platform.
Cross-border transfers — a note
- Card processing runs through Stripe (US / Ireland). SCCs cover the transfer.
- Crypto custody runs through Fireblocks (US). SCCs cover the transfer.
- DDoS and CDN run through Cloudflare (global). SCCs cover the transfer.
- RNG certification runs through iTech Labs (Australia). No PII is transferred.
- Everything else — the wallet, session state, the cash-out banking rails orchestration — is in Canada.
Filing a complaint
If you believe we have mishandled your data, contact [email protected] first — we take 15 days to respond in writing. If you are not satisfied, you can file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca; the process is free. Priya publishes every OPC-related correspondence in the annual transparency report on the Priya Doucette editorial bio page. We have received two OPC inquiries in three years and both were resolved by clarifying documentation without any finding of wrongdoing.
Contacting the privacy officer
Privacy questions land fastest with the privacy officer directly. Email [email protected] with any question about your data, our sub-processors, our retention windows or your PIPEDA rights. Response SLA is 15 days for routine questions and 30 days for formal PIPEDA access requests. If your question is urgent — for example, you believe your account has been compromised — please also flag the help centre live chat so the security team can act in parallel. The terms of service page spells out how the privacy policy interacts with the terms in day-to-day operations.
The one-line summary
Tao Fortune collects the smallest amount of Canadian personal data legally viable to run a sweepstakes casino, retains it for the shortest defensible window, encrypts it at every stage and lets you inspect the whole set on demand. Everything else on this page is detail.