Jump to a section
1. What is collected
The record grouped by how long it is held, because the retention period is the part players actually want to know and the part the law fixes.
| Held for | What sits in that bucket | What forces the period |
|---|---|---|
| Permanently | Self-exclusion and permanent-closure records | An exclusion that expires is an exclusion that can be walked around |
| Five years from the last transaction | Deposit and payout ledgers, the payment instruments used, stakes, sessions, game logs and offer history | Anti-money-laundering record-keeping and the ability to reconstruct a disputed round |
| Five years from account closure | Name, date of birth, identity documents, address evidence, email, phone and postal address | Age and identity obligations that survive the account itself |
| Three years | Chat transcripts, email threads and notes from calls | Evidence if a decision is later challenged |
| Two years | IP addresses, device and browser characteristics, device fingerprint | Catching duplicate accounts and making exclusions stick |
| Two years past withdrawal of consent | Marketing consents, opt-outs and campaign responses | Proving we stopped contacting you when you asked |
| While the account is open | Deposit, loss and stake limits, session and reality-check settings | They are only useful while there is an account to apply them to |
Two things are absent from that table on purpose: there is no biometric processing anywhere in the product, and nothing here was bought from a data broker.
2. What it is used for
Six purposes, and no others:
- Running the account — registration, sign-in, play, cashier.
- Legal and regulatory duties — age verification, anti-money-laundering monitoring, sanctions screening, licence obligations, record keeping.
- Payments — processing deposits and payouts and investigating failures.
- Security and fraud prevention — detecting duplicate accounts, enforcing exclusions, blocking account takeover.
- Player protection — applying the limits you set and identifying patterns that suggest someone may need support.
- Marketing, only with consent — withdrawable at any time from the account menu.
Personal information is not sold, and play data is not used to build profiles for sale or for third-party advertising.
Automated decisions. Some fraud, anti-money-laundering and player-protection checks run automatically. Where an automated decision materially affects you — a held withdrawal, a suspended account — you can ask for human review at dataoffice@oxibet-canada.org.
3. Who else sees it
Only parties that need it to deliver the service, or where the law requires disclosure:
- Payment providers — Interac, card acquirers, iDebit, Instadebit, MuchBetter, ecoPayz and others, to move the money.
- Verification and screening services — to confirm identity, age and sanctions status.
- Game studios — a pseudonymous player reference only, enough to run the game and settle the round. No name and no contact details.
- Regulators and law enforcement — where legally required, including suspicious transaction reporting.
- Technology suppliers — hosting, email, analytics and chat, under contract and limited to what the service needs.
- Professional advisers — auditors and lawyers, under confidentiality.
Transfers outside Canada. Some processors operate in the European Union and the United Kingdom. Those transfers are covered by contractual protections requiring a comparable standard of protection, and PIPEDA requires that this be disclosed rather than assumed.
4. Your rights
Rights available under PIPEDA, and under Law 25 for Québec residents, with how to exercise each.
| Right | What it covers | How | Reply within |
|---|---|---|---|
| Access | A copy of what is held about you | Email dataoffice@oxibet-canada.org | 30 days |
| Correction | Fixing inaccurate or incomplete records | Account settings, or email dataoffice@oxibet-canada.org | 30 days |
| Withdraw consent | Stopping marketing or consent-based processing | Account → Communication preferences | Immediate |
| Deletion | Erasing anything not subject to statutory retention | Email dataoffice@oxibet-canada.org | 30 days |
| Portability | Your data in a structured, machine-readable form | Email dataoffice@oxibet-canada.org | 30 days |
| Human review | Review of an automated decision | Email dataoffice@oxibet-canada.org | 30 days |
| Complain | Escalation to the federal regulator | priv.gc.ca | Set by the OPC |
Deletion cannot override a statutory retention period. Identity, financial and play records are held for five years under anti-money-laundering rules, and self-exclusion records are kept permanently — precisely so that an exclusion cannot be worked around.
5. Cookies
Four categories are in use. Only the first is set without asking, because without it the site does not function.
Each category, whether it is set before you say yes, and how long it survives.
| Set without asking? | Category | Survives | What it does |
|---|---|---|---|
| Yes | Strictly necessary | Session, up to 12 months | Keeps you signed in, secures the cashier, spreads load, blocks fraud |
| No | Functional | 12 months | Remembers language, currency, layout and game preferences |
| No | Measurement | 24 months | Aggregate usage figures that tell us which pages fail |
| No | Partner attribution | 60 days | Credits a registration to whoever referred it |
Preferences can be changed at any time from the cookie banner, or cookies blocked in your browser — though blocking the strictly necessary category will prevent sign-in and deposits from working. Global Privacy Control signals are honoured for the measurement and attribution categories.
6. Security, retention and breach notification
How it is defended. Traffic runs over TLS 1.3. Identity documents and financial records are encrypted where they sit, not just where they travel. Staff access is granted by role, logged on every read, and kept to the minimum the job needs — identity documents in particular are visible to the verification team and nobody else.
How long it stays. The table above is the answer. Where a period is fixed by statute, that period wins over a deletion request; where nothing is fixed, the record is erased or anonymised beyond recovery as soon as the reason for holding it has gone.
If something goes wrong. A breach carrying a genuine risk of serious harm triggers two notifications without delay — one to the people affected, one to the Office of the Privacy Commissioner of Canada. PIPEDA requires both. The notice you receive says what occurred, which categories of data were involved, and what to do at your end.
Adults only. Nobody below the legal gambling age should be here, and nothing is knowingly collected from them. An account discovered to belong to someone underage is closed and its data destroyed, save for anything the law obliges us to keep.
7. Contacting the data office
Access requests, corrections, deletions and any other data question go to dataoffice@oxibet-canada.org. Include the email address on your account so the records can be located — identity is verified before anything is released or changed, which is a protection rather than an obstacle.
If the response does not satisfy you, the Office of the Privacy Commissioner of Canada accepts complaints at priv.gc.ca. Residents of Québec may also approach the Commission d’accès à l’information du Québec.
Last reviewed 26 August 2026. Material changes are notified by email and in-account at least 14 days in advance.
Questions Canadians ask
How do I get a copy of my data?
Email dataoffice@oxibet-canada.org from the address on your account. Identity is verified first, then the response comes within 30 days in a structured format.
Can my data be deleted?
Partly. Marketing data, preferences and correspondence can go. Identity, financial and play records must be kept for five years under anti-money-laundering rules, and self-exclusion records are permanent so that an exclusion cannot be circumvented.
Is personal information sold?
No. It is not sold, and play data is not used to build profiles for third-party advertising. It is shared only with processors delivering the service and with authorities where the law requires it.
Is my data stored in Canada?
Not exclusively. Some processors operate in the EU and the UK, covered by contractual protections requiring a comparable standard. PIPEDA requires this to be disclosed, which is why it is stated here.
Anything not covered here goes to the support desk, staffed in English and French around the clock.
Register Now- Terms and Conditions — the account rules these sit alongside
- About — the security position in more detail
- Responsible Gambling — how exclusion records are used