How AeroBet handles your personal data
Every spin, deposit and login at AeroBet Casino leaves a data trail — and knowing exactly what happens to that trail is what lets you play with a clear head. This independent review breaks down the privacy practices documented by the operator, Hazy Ltd., for players holding CAD accounts in Canada, from the ID you upload at verification to the cookies that remember your session.
Information the casino collects from Canadian players

AeroBet collects three broad categories of data: what you type in yourself, what your device reveals automatically, and what a payment or verification step requires. The casino launched in 2025 under Anjouan Gaming Licence No. ALSI-152406050-FI4, and that licence — an offshore one, not a Canadian provincial permit — sets the anti-money-laundering rules behind most of the collection.
Registration data you provide yourself
Opening an account means handing over identifying details. According to the operator, that set includes your full name, date of birth (the age gate is non-negotiable), email address, mobile number, residential address, chosen currency — CAD for Canadian players — and account credentials. Communication preferences and language choice sit here too, since the site runs in English and French. Account creation steps are covered on their own page: AeroBet review.
Data your device hands over automatically
The moment a page loads, technical data is logged: IP address, approximate geolocation derived from it, browser type, operating system, screen resolution, referral source and session timestamps. Geolocation matters more than most players realise — it is how the casino enforces its restricted-country list, which blocks registrations from markets including the United States, the United Kingdom, Greece, Cyprus, Ukraine, Israel, Iran, Iraq, Qatar, Moldova and North Korea. Gameplay telemetry (games opened, bet sizes, session length) is recorded as part of running a fair, auditable casino with a published total payout of 96%.
Payment and verification information
Funding data depends on the rail you pick. AeroBet supports Interac, Visa and Mastercard, Apple Pay, MiFinity, MuchBetter, Skrill, Neteller, Neosurf, Paysafecard, iDebit, Instadebit, Revolut, Open Banking and bank transfer, with Bitcoin, Ethereum, Tether (USDT), USD Coin, Litecoin, Dogecoin and BNB Chain available as a secondary crypto option. Card and Interac transactions route through processors that receive the transaction details directly; the casino keeps records of amounts, timestamps and the method used, with a C$30 minimum on both deposits and withdrawals.
KYC is mandatory before your first payout. The documents requested are:
- Valid government-issued ID — passport, driver’s licence or provincial ID card
- Proof of address — a recent utility bill or bank statement
- Confirmation of the payment method used, requested in some cases
- A unique six-digit verification code for transactions over $2,000
- Proof of source of wealth, such as bank statements or employment verification, for deposits or withdrawals exceeding $5,000
Verification is typically approved in about 24 hours, with terms allowing up to 72. Deposit and payout mechanics themselves live elsewhere; here the point is simply that these documents exist as a data category the casino must hold.
| Data category | Where it comes from | Primary purpose |
|---|---|---|
| Identity details | Registration form | Age check, account ownership |
| KYC documents | Uploaded by you before first payout | AML compliance under the Anjouan licence |
| Transaction records | Interac, cards, e-wallets, Open Banking, crypto | Processing deposits and withdrawals |
| Device and IP data | Collected automatically on load | Fraud detection, restricted-market blocking |
| Gameplay telemetry | Generated in-session | Fair play checks, bonus wagering tracking |
| Marketing preferences | Opt-in choices in your profile | Sending or suppressing promotional email |
What the casino does with your information

Collected data serves three jobs: keeping your account running, delivering the games and cashier, and — only if you agree — sending promotions. Nothing in the documented policy allows the sale of player data to advertisers, and marketing consent is separate from the consent you give simply by registering.
Running and protecting your account
Your identity data authenticates every login, links your balance to you and nobody else, and triggers alerts when a session pattern looks wrong — a login from a new country, an unusual deposit spike, a device fingerprint that has never touched the account. Withdrawal limits of 750 CAD per day and 22,500 CAD per month are enforced against your verified identity, not just your username, which is precisely why KYC exists.
Delivering the games and the cashier
Session data keeps your place in a game, applies the right currency, and routes payouts to the method you actually used. Crypto payouts are processed almost instantly after approval, e-wallets take 0–24 hours, Interac and card payouts usually 1–3 days and bank transfers 3–7 days, inside an overall 0–72 hour processing window — every one of those steps needs your transaction history to be readable by the payments team.
Marketing email, and how consent works
Promotional messaging is opt-in. If you accept, the operator uses your email, currency and activity level to target offers such as the welcome package: 600% up to 9,000 CAD + 450 Free Spins, with wagering of 35x (deposit + bonus) and 40x on Free Spins winnings, a 30 CAD minimum deposit, 10-day bonus validity, a 25 CAD max bet while the bonus is active, max cashout of 5x the bonus amount and 150 CAD from Free Spins, and Live Casino games excluded. Withdrawing consent stops the marketing but never the transactional email — payout confirmations and security alerts keep arriving, because they are part of the service.
How your data is secured

The operator states that player data travels over encrypted connections and that payment card details are handled by PCI-compliant processors rather than stored in plain form on the casino’s own systems. Encryption, restricted storage and role-based access work as three layers, and each one covers a different failure mode.
Encryption in transit and at rest
Traffic between your browser and AeroBet runs over SSL/TLS, which is what stops a shared café Wi-Fi from exposing your login or your uploaded ID. Sensitive stored fields — credentials, verification documents — are held in encrypted form. A padlock in your address bar is the visible half of this; the storage half you have to take from the operator’s documentation.
Where data lives and how long
Records tied to gambling activity cannot simply be deleted on request, because the Anjouan licence and anti-money-laundering rules force the operator to retain transaction and verification data for a regulatory period after an account closes. Data is held on secured servers with backups; the practical consequence for you is that “delete my account” and “delete every byte about me” are two different requests, and only the first is granted immediately.
Who can actually open your file
Access is limited by role. Live chat agents on the 24/7 support desk see enough to answer a question; the payments and compliance teams see verification documents; nobody outside those functions should be able to pull your ID scan. Staff accounts are logged, and document uploads happen inside the account area rather than over email — sending a passport photo to a chat agent as an attachment is exactly the habit this structure is meant to break.
Who your information is shared with

Data leaves the casino in three situations only: to service providers who make the platform work, to authorities entitled to demand it, and to a buyer if the business changes hands. Each has a different trigger and a different scope.
Service providers and game studios
Payment processors behind Interac, Visa/Mastercard, Apple Pay, MiFinity, MuchBetter, Skrill, Neteller, Neosurf, Paysafecard, iDebit, Instadebit, Revolut, Open Banking and bank transfer receive the data needed to move money, and blockchain transfers in Bitcoin, Ethereum, Tether (USDT), USD Coin, Litecoin, Dogecoin or BNB Chain are recorded publicly on-chain by design. Game studios receive session and wager data so their titles run and pay correctly — that includes Pragmatic Play, BGaming, Evolution, NetEnt, Hacksaw Gaming, Belatra, Platipus, Evoplay, Endorphina, Playson, Spinomenal, Gamzix, Onlyplay, Nolimit City, Yggdrasil, Red Tiger, Quickspin, Betsoft, Big Time Gaming (BTG), Blueprint Gaming, Novomatic, Playtech, Microgaming, Relax Gaming, Ezugi, Spribe, 3 Oaks, Popiplay, Amatic and Mascot Gaming. Live dealer tables from Evolution and Ezugi stream video of the dealer, never of you.
Legal and regulatory disclosure
The Anjouan regulator, auditors and law-enforcement bodies with a valid legal basis can compel disclosure of identity and transaction records. Suspicious-activity reporting under AML rules happens without notifying the account holder, since advance warning would defeat the point. This is standard for licensed gambling operators and is the trade-off attached to any regulated cashier.
If the business is sold
AeroBet is operated by Hazy Ltd., which also runs the sister casinos Avocasino and Golobet. In a merger, acquisition or asset sale, player databases transfer to the acquiring entity, which inherits the same obligations. Full contractual detail sits in the operator’s rulebook: AeroBet terms and conditions.
The rights you can exercise over your data

You can ask what AeroBet holds about you, correct it, request deletion within the limits of gambling record-keeping law, and switch off marketing at any time. Requests go through the 24/7 live chat or the support email address, and identity confirmation is required first — otherwise anyone could request your file.
Access and portability
A subject access request returns the personal data linked to your account: profile fields, transaction history, verification status, communication preferences. Expect the compliance team to verify you before releasing anything, using the same document standard as KYC.
Correction and deletion
Wrong surname spelling, an outdated address, a changed phone number — these are corrected on request, and keeping them accurate is in your interest, because a payout is checked against the name on your ID. Deletion closes the account and removes marketing data, while transaction and verification records stay for the mandated retention period.
Opting out and self-exclusion
Marketing opt-out is a preference toggle plus the unsubscribe link in every promotional email. If the reason for opting out is control over your play rather than inbox clutter, the tools you want are cooling-off and self-exclusion: Responsible Gambling. A self-exclusion request also suppresses promotional contact, which is the point of it.
Cookies and tracking on the AeroBet site

Cookies keep you logged in, remember whether you chose English or French, hold your currency selection, and let the operator measure which pages and games players actually use. Some are strictly necessary; the rest you can refuse without losing access to the casino.
What the cookies do
- Essential cookies — session authentication, security tokens, load balancing. Block these and login stops working.
- Preference cookies — language, currency, layout and sound settings.
- Analytics cookies — aggregated traffic and behaviour measurement used to fix broken funnels and slow pages.
- Marketing cookies — affiliate attribution and campaign tracking, including the referral tags that credit sites like this one.
Analytics and affiliate tracking
Third-party analytics tools receive pseudonymised identifiers rather than your name, and affiliate parameters record which link brought you to the casino so commissions and welcome-offer eligibility resolve correctly. Because there is no dedicated iOS or Android app, all of this happens in your mobile or desktop browser — the mobile experience is covered separately on this site.
Changing your cookie settings
The consent banner on first visit is where you accept or refuse non-essential categories, and the choice can be revisited later. Browser-level controls give you a second lever: block third-party cookies, clear them on exit, or run a private window. Clearing cookies logs you out and resets your language choice, so expect to sign in again.
Frequently asked questions about AeroBet
What personal information does AeroBet collect?
Registration data such as your name, date of birth, email, phone number, address and CAD currency choice; automatic data including IP address, device type and gameplay activity; and payment records tied to the method you use, from Interac and Visa/Mastercard to Skrill, Neteller or crypto. KYC documents are collected before your first withdrawal.
How does AeroBet protect my data?
The operator states that traffic runs over SSL/TLS encryption, sensitive stored fields are encrypted, and card details are handled by PCI-compliant payment processors. Access is limited by staff role, so support agents cannot open verification documents. The casino holds Anjouan Gaming Licence ALSI-152406050-FI4, which imposes AML and record-keeping obligations on Hazy Ltd.
Can I request deletion of my AeroBet account data?
Yes. Contact the 24/7 live chat or support email and confirm your identity, and the account is closed with marketing data removed. Transaction histories and KYC records stay on file for the retention period required by gambling and anti-money-laundering rules — that portion cannot legally be erased on request.
Does AeroBet share my information with third parties?
Only where necessary: payment processors behind Interac, cards, e-wallets and Open Banking; game studios such as Pragmatic Play, Evolution and NetEnt that need session data to run their titles; and regulators or law enforcement with a valid legal basis. Data may also transfer if Hazy Ltd. sells or merges the business.
How do I opt out of AeroBet marketing emails?
Use the unsubscribe link at the foot of any promotional email, or change the communication preferences in your account profile. Live chat can action it too. Transactional messages — withdrawal confirmations, KYC requests, security alerts — continue regardless, because they are part of operating the account rather than marketing.
Now that you know what data changes hands and why, the next step is checking the cashier and the consent settings for yourself.
