Privacy notice • Version dated 11 October 2026
1. Who controls the data?
The intended website operator and data controller is MANUEL DANIEL CASTILLO, responsible for goldenluckparty.com. The operator must provide verified contact details and confirm their regulatory/privacy obligations before public launch. Questions can be sent through our contact form.
2. Information we use
We use an unguessable random guest identifier stored in an essential browser cookie to associate your device with your virtual coin balance, daily reward flags, spin count and refill usage. We use a PHP session cookie for essential security controls, your adult-age self-declaration during that session and CSRF protection. Our games do not require names, passwords, payment information or account registration.
If you choose to use the contact form, we collect the name, email address, message and submission time you supply. Please do not send sensitive personal details. Hosting services may process technical request information and security logs as part of ordinary infrastructure operation; their exact retention settings depend on the chosen host.
3. Why we use the information
Guest identifiers and sessions are used to provide the games you request and keep transactions and the service secure. Contact information is used to review and, where contact details have been made available to the operator, respond to enquiries. Depending on the circumstances, our intended lawful bases under UK GDPR are performance of the requested service and legitimate interests in essential security and responding to messages. The operator should confirm the final legal assessment.
4. Storage, sharing and international transfers
Guest game records and contact messages are stored in non-public server files outside the public document root, within the hosting account. There are no payment processors, advertising trackers, analytics scripts, third-party game engines or external gameplay APIs in this build. Hosting suppliers may process data as processors; the operator must assess their arrangements and any international transfers before publication.
5. Retention and deletion
The guest identifier cookie is set for up to 90 days. Server-side guest records do not currently expire automatically; the operator must implement a documented retention/deletion schedule before public launch. Contact messages are likewise retained until manually deleted by the operator; a maximum 90-day retention policy is recommended and should be operationally enforced. Removing cookies stops this browser from identifying the existing guest record but does not automatically delete the server copy.
6. Your rights
Depending on the law and circumstances, you may request access, correction, erasure, restriction, portability or object to certain processing, and complain to the UK Information Commissioner's Office (ICO). To locate guest records, you may need to supply the identifier stored in your browser. Use our contact form to begin an enquiry.
7. Security and children
Cookies are set with HttpOnly and SameSite controls, and Secure on HTTPS. Game updates use server-side validation and file locks. The website is designed for adults aged 18 and over; it must not knowingly be used by children.
8. Updates
We will update this notice when service operations or data handling change. The operator must review this draft for actual hosting, data controller details and retention controls before going live.