Privacy Policy

Last updated: April 6, 2025

This privacy policy applies to mcluck-casino.us.com, an independent affiliate review website. We are not affiliated with McLuck Casino (mcluck.com). This policy describes what data we collect and how it is used.

1. Information We Collect

We collect only information you voluntarily provide (e.g., via contact forms). We also collect non-personally identifiable data through analytics tools: page views, device type, approximate location, and referring URLs. No financial or payment information is collected on this site.

2. How We Use Information

Analytics data is used to improve site content, navigation, and performance. We do not sell, rent, or trade any user data to third parties.

3. Affiliate Links

This site contains affiliate links. When you click a link and register with McLuck Casino, we may receive a commission from the casino operator. This does not affect the price you pay or the bonuses you receive. Affiliate relationships do not influence our editorial content, ratings, or recommendations.

4. Cookies

We use essential cookies required for site functionality and analytics cookies (e.g., Google Analytics) to understand site usage. You may disable cookies in your browser settings. Disabling cookies does not affect your ability to read site content.

5. Third-Party Links

External links on this site (including to McLuck Casino) are governed by the privacy policies of those respective sites. We are not responsible for data practices on third-party platforms.

6. Your Rights

Under applicable US privacy law, you may request information about data we hold about you, request deletion of your data, or opt out of analytics tracking. To exercise these rights, contact us via the details below.

7. Contact

For privacy-related inquiries: [email protected]. We respond within 5 business days.

Privacy Practice Details

Data Categories

We separate the data this site touches into four buckets. First, voluntary submissions through the contact form (your name, email, message text). Second, automatically-collected technical data through standard server logs (IP address, user agent, request timestamps, referring URL). Third, analytics data via Google Analytics 4 (pseudonymous client IDs, page paths, event names). Fourth, affiliate-tracking data passed through to McLuck via cookies set on click-through (these belong to McLuck's affiliate platform, not to us). We do not collect financial information at any time on this site - all gameplay activity happens entirely on McLuck's own infrastructure, governed by the platform reliability audit we publish.

Cookie Inventory

The cookie table below lists every cookie this site sets, including those placed by third-party analytics and affiliate platforms. All cookies are categorized as either Essential (required for the site to function), Analytics (anonymous traffic measurement), or Marketing (third-party affiliate identifiers).

Cookie NamePurposeCategoryDurationSet By
_gaVisitor identification for analyticsAnalytics2 yearsGoogle Analytics
_ga_*Session identification per propertyAnalytics2 yearsGoogle Analytics
session_idMaintains form stateEssentialSessionThis site
cookie_consentRemembers your consent choiceEssential365 daysThis site
aff_click_idAffiliate click attributionMarketing30 daysMcLuck affiliate
aff_refAffiliate referrer trackingMarketing30 daysMcLuck affiliate

Legal Basis for Processing

For US visitors, we operate under the consent and legitimate-interest frameworks defined by the California Consumer Privacy Act (CCPA), the Colorado Privacy Act (CPA), Virginia's CDPA, Connecticut's CTDPA, and Utah's UCPA. For visitors from the European Economic Area, we rely on the consent legal basis defined by the General Data Protection Regulation (GDPR) Article 6(1)(a). Analytics and marketing cookies are loaded only after explicit consent through the banner shown on first visit.

Your Rights Under CCPA, CPA, and Similar Laws

If you are a resident of California, Colorado, Connecticut, Utah, Virginia, or any other state with comprehensive consumer-privacy legislation, you have the following rights: the right to know what personal information we hold, the right to delete that information, the right to correct inaccurate information, the right to opt out of the sale or sharing of personal information, the right to limit use of sensitive personal information, and the right not to receive discriminatory treatment for exercising these rights. Requests are submitted via email to [email protected] and are honored within 45 days as required by law.

Children's Privacy

This site is not directed at anyone under the age of 21. We comply with the Children's Online Privacy Protection Act (COPPA) and do not knowingly collect any personal information from individuals under 13 years of age. If a parent or guardian believes their child has provided us with personal information, contact us immediately so we can delete it. This 21+ age boundary is stricter than COPPA's 13-year baseline because the site discusses sweepstakes gaming, which McLuck restricts to ages 21+ across all states as documented in our McLuck state and age eligibility map.

Data Retention Periods

Contact form submissions: retained for 12 months from the date of last interaction. Server logs: retained for 30 days. Google Analytics data: retained at the GA4 default of 14 months. Affiliate tracking cookies: 30 days per the McLuck affiliate platform's standard window. After the retention period expires, data is either deleted or fully anonymized so it can no longer be linked to an individual user.

Security Practices

The site is served exclusively over HTTPS with TLS 1.3. Form submissions are validated server-side and rate-limited to prevent abuse. We do not store passwords, payment methods, or any sensitive financial information. The server runs behind a hosted firewall with DDoS protection. In the unlikely event of a security incident affecting personal data, we follow state-specific notification requirements (typically 30 to 45 days) and notify affected individuals directly via the contact email they provided.

International Data Transfers

Our hosting infrastructure is located in the United States. If you visit this site from outside the US, your data is processed on US-based servers. Where the GDPR applies, we rely on the European Commission's adequacy decisions and Standard Contractual Clauses (SCCs) where applicable. The same data-export protections apply to the broader information about McLuck Sweeps Coin handling that we document - your account creation on McLuck itself is also governed by US-based data processing.

Third-Party Services We Use

Google Analytics 4 (analytics), Cloudflare (CDN and DDoS protection), the McLuck affiliate platform (affiliate-click tracking). Each operates under its own privacy policy, which we link to in the cookie banner. We do not share our analytics data with any other party. Affiliate-click data is shared with McLuck only to confirm attribution for paid commissions - never combined with any personal identifier we hold.

Changes to This Privacy Policy

We may update this policy from time to time to reflect changes in our practices, in the law, or in the services we use. Material changes are announced at the top of this page and via the cookie consent banner where appropriate. The "Last updated" date at the top of this page always reflects the most recent revision. We recommend reviewing this policy at the start of each new gaming session, particularly if you have just enabled new features described on our McLuck app capabilities breakdown.

How to Contact the Privacy Team

For all privacy-related requests - including the rights described above, questions about our processing activities, or to file a complaint - the privacy team can be reached at [email protected]. We respond to every privacy email within 5 business days. For California residents specifically, you may also designate an authorized agent to submit requests on your behalf. The same contact channel handles requests related to our responsible gambling resource page and any takedown requests for content that touches your personal information.

Affiliate Compensation Transparency

This site earns affiliate commissions when readers register at McLuck through one of our tracking links. Our commission structure is fixed per qualified registration (cost-per-acquisition or CPA), not a share of player losses or wagers. Total annual affiliate revenue is reported in the editorial transparency note linked from the author and editorial standards page. Affiliate revenue does not influence which platforms we cover, how we score them, or which weaknesses we publish about them.

Privacy FAQ

Do you sell my personal information?

No. We do not sell, rent, or trade personal information to any third party for monetary or other valuable consideration. Under the California Consumer Privacy Act definition of "sale", our use of affiliate cookies does not constitute a sale because no personal identifier is transmitted - only an anonymous click-attribution token. The Global Privacy Control (GPC) signal is honored automatically on every page visit.

How long until my deletion request is honored?

We process deletion requests within 30 days for most US-state laws and within 30 calendar days for CCPA specifically. EU GDPR requests are processed within 30 days as required by Article 12(3). Once deletion is processed, we send a confirmation email and the relevant data is purged from active systems within 7 additional days. Backups are aged out within 90 days.

Can I opt out of analytics?

Yes. The cookie banner shown on first visit lets you reject analytics cookies. After dismissal, no Google Analytics or similar tracker loads. You can change your preference at any time via the small "Cookie preferences" link in the footer. Browser-level options such as Do Not Track and Global Privacy Control are honored as the equivalent of a banner rejection.

What about email marketing?

We do not currently operate any email-marketing program. If we add one in the future, subscription will be opt-in only with a clear unsubscribe link in every message. We will never add an email address to any list without explicit consent. Inquiries directed at the affiliate platform's bonus offers - including those documented in our McLuck promotional calendar - are handled by McLuck's own privacy team and governed by McLuck's privacy policy.

Is the contact form encrypted?

Yes. All form submissions are transmitted over TLS 1.3. The form payload is encrypted in transit and stored on a hosted database with at-rest encryption (AES-256). Access to stored submissions is restricted to two named editors who undergo annual security training. The same security posture extends to any account-related question routed through the McLuck onboarding guide.

Do you use AI training?

No. We do not use any data collected from this site to train artificial intelligence or machine learning models. We do not license or sell our content to any AI training platform. We have configured robots.txt and HTTP headers to discourage automated AI crawlers from harvesting site content. The same protections apply to all the editorial work referenced from our editorial standards page.

What if I am from a country not mentioned above?

If you are visiting from a country with comprehensive data-protection legislation (such as Canada under PIPEDA, Brazil under LGPD, the UK under UK GDPR, or Australia under the Privacy Act), we honor the rights granted under your local law to the same extent we honor CCPA rights for California residents. Submit your request via the same privacy email channel and indicate your country of residence so we can apply the correct framework. Players in McLuck-eligible US states should also review the geography-specific guidance on our McLuck state legality and redemption tracker.

Privacy impact of using the McLuck mobile app

When you use the McLuck native mobile app, additional data flows occur entirely outside this site - through McLuck's own infrastructure. Those data flows are governed by McLuck's privacy policy, not this one. Our coverage of the McLuck app and what it tracks is documented from a user-experience perspective in our McLuck mobile app review, but legal authority over those mobile flows rests entirely with McLuck Casino LLC.

Additional Privacy Notes

A handful of privacy topics come up often enough to warrant their own short notes below. Each addresses a question we regularly receive from readers regarding our data practices.

Browser fingerprinting

We do not employ browser-fingerprinting techniques. The analytics solution we use relies on first-party cookies that respect the cookie banner choice. No canvas fingerprinting, WebGL signature collection, or audio context probing happens on any page of this site - including pages that embed external charts such as our state-by-state availability dashboard.

Logs and incident retention

Web server access logs are retained for 30 days for security incident-response purposes and then automatically purged. In the event of a confirmed security incident, the relevant slice of logs is preserved as long as needed to investigate, after which it is destroyed. The same retention discipline applies to logs we generate when readers access the VIP loyalty tier breakdown and other high-traffic content pages.

Vulnerability disclosure

If you discover a security vulnerability in this site, report it confidentially to [email protected]. We respond within 5 business days and aim to remediate confirmed vulnerabilities within 30 days. Coordinated disclosure to the public is encouraged after the vulnerability is fixed. We do not currently operate a paid bug-bounty program.