Marvel casino logo 1
Marvel casino logo 1
Get You Bonus!

Your Privacy at Marvel Casino

This Marvel Casino privacy policy explains how Marvel on marvel2.com may collect, use, disclose, store, and protect personal data when you browse the website, register an account, contact support, or use online casino services. It is intended for users in Poland and should be read together with the applicable terms and conditions, account rules, bonus rules, responsible gaming information, and any notices presented when particular data is requested. Privacy information matters because an online casino may process identity, contact, device, payment, transaction, and gaming data. Knowing what happens to this information helps you make informed decisions before creating an account or submitting documents. The purpose of this page is therefore to provide a clear and practical overview rather than conceal important details behind technical language.

Data protection also depends on the specific operator, licence, and contact details identified on the website. Before depositing money, you should check the footer, registration form, terms and conditions, and account area for the current legal entity, licence information, privacy contact, and effective date. If any statement on this page conflicts with a mandatory notice displayed during registration or verification, the more specific and current notice should be reviewed carefully. You should not send identity documents by an unverified channel or provide more information than requested. By using Marvel, you should also take reasonable steps to protect your password, devices, and payment accounts.

Scope of the Marvel Casino Privacy Policy

This privacy policy generally applies when you visit marvel2.com, create or use an account, play games, claim promotions, complete identity checks, make payments, communicate with customer support, or interact with marketing messages. It may also cover data generated through cookies, security logs, fraud-prevention systems, and interactions with third-party suppliers integrated into the service. The precise scope can depend on which services are available to you in Poland and whether you use the website on a computer, smartphone, or another compatible device. Separate notices may apply to particular promotions, surveys, payment methods, or responsible gaming tools. Those notices should be read alongside this page because they may explain a more specific processing activity.

This page does not automatically govern websites, payment portals, social media platforms, or applications operated independently by third parties. If you follow an external link, the receiving organisation may collect information under its own privacy policy and terms and conditions. Marvel cannot describe every independent provider’s practices in a general policy, so you should review the relevant notice before entering data. This distinction is especially important when using an e-wallet, bank, identity verification service, or game supplied by another company. Leaving the Marvel Casino website does not necessarily mean that the same controller, security standards, or retention periods continue to apply.

Who Controls Your Personal Data

The data controller is the legal entity that determines why and how personal data is processed. Its official name, registered address, contact details, and, where applicable, data protection contact should be identified in the current legal documentation available on marvel2.com. Users should rely on those published details rather than assume that the brand name Marvel is itself the legal operator. This distinction is important when exercising privacy rights, submitting a complaint, or asking which gaming licence applies. If the controller information is unclear, contact support before registering or sending documents.

Some service providers act as processors, meaning that they handle information on the controller’s documented instructions. Other organisations, such as banks, e-wallets, regulators, game providers, or fraud-prevention agencies, may act as independent controllers for their own legal purposes. Their responsibilities and legal bases can therefore differ from those described in the Marvel Casino privacy policy. In certain situations, two organisations may jointly determine aspects of processing and must allocate their responsibilities appropriately. The relevant privacy notice should clarify the arrangement when it materially affects you.

Personal Data Marvel Casino May Collect

The information processed by an online casino depends on how you interact with it. Basic browsing can generate technical information, while registration, payment, or withdrawal requests normally require substantially more data. The operator should follow data minimisation principles and request information that is relevant to account administration, security, legal compliance, and service delivery. Some fields are mandatory because the account cannot be operated lawfully or securely without them. Optional fields should be identified where practical, and declining to provide optional information should not be treated as consent to unrelated processing.

The following categories illustrate information that may be collected directly from you, automatically from your device, or from authorised third parties:

  • Identity data, including name, date of birth, nationality, and identity-document details.
  • Contact data, such as residential address, email address, and telephone number.
  • Account data, including username, encrypted password, preferences, and account status.
  • Financial data, including payment method, masked card details, bank account information, and transaction history.
  • Verification data, such as copies of documents, proof of address, source-of-funds evidence, or a verification image.
  • Gaming data, including games played, wagers, wins, losses, bonuses, session history, and responsible gaming settings.
  • Technical data, including IP address, device identifiers, browser, operating system, language, time zone, and security logs.
  • Communication data, including emails, live-chat transcripts, complaints, call records, and survey responses.
  • Marketing data, such as communication choices, campaign engagement, and promotion eligibility.

Information may also be received from payment providers, identity verification services, public registers, fraud-prevention databases, affiliates, or regulatory sources where lawful. For example, a payment provider may confirm whether a transaction succeeded without disclosing complete card credentials. An identity service may return a verification result or indicate that additional evidence is required. Data obtained from third parties should be limited to what is reasonably needed for the stated purpose. If information is collected from a source other than you, the operator should provide the disclosures required by applicable data protection law unless a lawful exception applies.

Personal data must be processed for defined purposes and supported by an appropriate legal basis. Common purposes include creating and administering an account, delivering games, processing payments, verifying identity and age, preventing fraud, meeting anti-money laundering duties, providing customer service, enforcing rules, and improving website performance. Processing can also support safer gambling measures, including the application of limits, self-exclusion, and risk indicators. Data should not be reused for an incompatible purpose without a valid legal basis and any notice required by law. The table below provides a general guide; the operator’s current notice should confirm the exact position.

Processing activityTypical data involvedPossible legal basisWhy it may be necessary
Account registration and administrationIdentity, contact, account dataContract; legal obligationTo create, secure, and operate an account
Deposits and withdrawalsFinancial, identity, transaction dataContract; legal obligationTo process payments and prevent misuse
Identity and age verificationDocuments, identity, verification resultsLegal obligation; legitimate interestsTo confirm eligibility and meet compliance duties
Fraud and security monitoringDevice, IP, account, payment, gaming dataLegitimate interests; legal obligationTo protect users, funds, and systems
Responsible gaming controlsGaming activity, limits, account statusLegal obligation; legitimate interestsTo apply safeguards and account restrictions
Customer support and complaintsContact, account, communication dataContract; legitimate interests; legal obligationTo answer requests and keep an audit trail
Service analyticsCookie, device, and usage dataConsent or legitimate interests, as applicableTo measure and improve website performance
Direct marketingContact details and marketing choicesConsent or legitimate interests, where permittedTo send relevant offers and service news

A contract may justify processing needed to provide a service you requested, but it should not be stretched to cover unrelated advertising. Legal obligations may require checks, record keeping, reporting, or cooperation with competent authorities. Legitimate interests can support proportionate security, fraud prevention, service improvement, and legal-claim management after balancing those interests against your rights. Consent should be specific, informed, freely given, and easy to withdraw when it is the relevant basis. Withdrawal does not make earlier lawful processing invalid, and it may not stop processing supported by another legal ground.

Account Verification, Payments, and Regulatory Compliance

Online casino operators commonly perform know-your-customer checks to confirm identity, age, address, and payment ownership. Depending on risk and regulatory requirements, users may be asked for an identity card or passport, proof of address, payment evidence, or information about the source of funds. These checks help prevent underage gambling, account theft, fraud, money laundering, and prohibited payment activity. Additional documents may be requested if information is incomplete, inconsistent, expired, or associated with unusual activity. Verification should be conducted through an authorised and secure upload process rather than an unknown email address or informal messaging service.

Payment information is used to process deposits, refunds, withdrawals, chargebacks, and account reconciliations. The online casino may share necessary details with banks, card networks, e-wallets, payment gateways, or compliance providers, each of which may have its own legal responsibilities. Transaction monitoring may consider value, frequency, location, device, payment ownership, and account behaviour to identify security or compliance risks. A withdrawal can be delayed while a lawful verification or fraud review is completed, subject to the terms and conditions and applicable rules. Privacy rights generally cannot be used to require the deletion of records that must be retained under anti-money laundering, accounting, tax, gaming, or legal-claim obligations.

Players can reduce avoidable delays by keeping account information accurate and using a payment method held in their own name where required. Documents should be readable, current, and limited to what the verification request reasonably requires. Before uploading a file, confirm that the page uses a secure connection and belongs to marvel2.com or an expressly identified verification provider. Do not share your password, one-time security code, or complete card security code with customer support. If a request appears suspicious, stop and verify it through the official support channel listed on Marvel.

Cookies and Similar Technologies

Cookies are small files or identifiers stored or accessed on a device to support website operation, security, preferences, analytics, and advertising. Similar technologies include local storage, pixels, tags, software development kits, and device identifiers. Some technologies are necessary to keep a user signed in, balance website traffic, remember privacy choices, or prevent attacks. Others measure performance, personalise content, or evaluate advertising campaigns. Where Polish or European rules require consent, non-essential technologies should not be activated until an appropriate choice has been made.

Cookie categories may include:

  1. Strictly necessary technologies for authentication, security, payment routing, and privacy preference storage.
  2. Functional technologies that remember language, display, game, or account preferences.
  3. Analytics technologies that measure visits, errors, page performance, and aggregated user journeys.
  4. Advertising technologies that support campaign measurement, audience selection, or frequency control.

A cookie banner or preference centre should explain available categories, their purposes, providers, and relevant durations. Users should be able to reject non-essential cookies as easily as they accept them where consent is required. Browser settings can also delete or block cookies, although blocking necessary technologies may disrupt login, payments, or security functions. Deleting cookies may remove saved preferences and cause the consent banner to appear again. For precise information about individual technologies, consult the current cookie notice and preference tool on the website.

How Personal Data May Be Used for Security and Safer Gambling

Security monitoring can involve account logins, IP addresses, device signals, payment patterns, failed authentication attempts, and changes to important account details. These signals help detect credential theft, duplicate accounts, collusion, bonus abuse, chargeback fraud, and automated attacks. Reviews may be automated at an initial stage, but significant restrictions should receive appropriate human consideration where required. Information may also be used to investigate complaints, preserve evidence, enforce the terms and conditions, or establish and defend legal claims. Security controls should be proportionate and should not justify unlimited surveillance or indefinite retention.

Gaming activity may also be analysed to support responsible gaming obligations and player protection. Relevant indicators can include long sessions, rapid increases in spending, repeated deposit attempts, cancelled withdrawals, night-time activity, or frequent changes to limits. Depending on the rules that apply, the operator may display safer gambling messages, request further information, restrict marketing, apply account limits, or suspend access for review. These measures are intended to reduce harm and comply with regulatory duties, though they cannot replace a user’s own spending controls. Players in Poland should confirm whether the offered service is lawful and authorised for their location before participating.

Where profiling or automated tools are used, the privacy policy should explain their general purpose, the categories of information involved, and any material consequences. You may have a right to object to certain profiling or request human intervention where a decision is based solely on automated processing and produces legal or similarly significant effects. Not every automated security signal constitutes such a decision, as many merely flag an account for staff review. The operator may also need to withhold specific fraud-detection logic where disclosure would undermine security. Even then, it should provide meaningful privacy information to the extent legally possible.

Sharing Personal Data With Third Parties

Marvel Casino should not sell personal data merely because a user creates an account. Nevertheless, operating a gaming website can require carefully controlled disclosures to suppliers and authorities. Recipients may include hosting providers, cloud services, game studios, payment processors, identity verification companies, fraud-prevention tools, customer support platforms, analytics providers, professional advisers, auditors, group companies, regulators, and law enforcement bodies. Each disclosure should have a valid purpose and legal basis. Processors should be bound by contractual confidentiality, security, and data-processing obligations appropriate to their role.

Information may be shared in circumstances such as:

  • Processing a deposit, withdrawal, refund, or payment investigation.
  • Confirming identity, age, address, payment ownership, or source of funds.
  • Supplying a game, recording a wager, or resolving a game-round dispute.
  • Detecting fraud, money laundering, cyberattacks, duplicate accounts, or prohibited conduct.
  • Applying responsible gaming measures or an applicable self-exclusion scheme.
  • Responding to a lawful request from a court, regulator, tax authority, or law enforcement body.
  • Obtaining legal, audit, insurance, technical, or professional support.
  • Managing a merger, restructuring, financing, or sale subject to suitable safeguards.

Third-party access should be limited to the information reasonably required for the service or obligation. A game provider, for example, may need a pseudonymous player identifier and gameplay data but not necessarily a complete identity document. A payment provider may require identity and transaction details but should not receive unrelated marketing preferences. Where a recipient acts independently, its own privacy policy governs the purposes it determines. Users should review those notices, particularly before choosing a payment method or completing an external verification process.

International Data Transfers

Some suppliers or group companies may process information outside Poland or the European Economic Area. An international transfer can occur when data is stored abroad, accessed remotely from another country, or sent to a recipient located outside the relevant jurisdiction. Different countries do not always provide equivalent privacy protections. For this reason, transfers should take place only where a lawful transfer mechanism and suitable safeguards exist. The operator should also consider practical risks, including government access, supplier security, and the sensitivity of the transferred information.

Possible safeguards include an adequacy decision, approved standard contractual clauses, binding corporate rules, or another mechanism permitted by data protection law. Supplementary technical and organisational measures may be required, such as encryption, access restrictions, pseudonymisation, logging, and contractual limits on onward transfers. In limited situations, a statutory derogation may apply, but exceptions should not become the routine basis for large-scale transfers. Users may request information about relevant safeguards, subject to necessary redactions for confidentiality and security. The current policy should identify transfer arrangements in enough detail to allow an informed understanding.

International infrastructure can support reliable games, fraud prevention, customer service, and payment processing, but convenience does not remove privacy responsibilities. Marvel and its providers should assess vendors before appointment and review their controls during the relationship. Contracts should address security incidents, assistance with user rights, deletion or return of data, and the use of subcontractors. If a supplier changes its processing location, the transfer assessment may need to be updated. These controls help keep protection consistent even when information crosses borders.

Data Security and Account Protection

No internet service can promise absolute security, but proportionate technical and organisational measures can reduce risk significantly. Common controls include encryption in transit, secure password storage, network protection, access controls, monitoring, backups, vulnerability management, staff training, and incident-response procedures. Sensitive data should be available only to authorised personnel who need it for defined duties. Providers should be assessed for security capability, and access should be removed when it is no longer required. Regular testing and review are important because cyber threats and system configurations change over time.

Users also play an essential role in account protection. Choose a unique, strong password that is not used on email, banking, or another gambling website, and enable multi-factor authentication if available. Keep devices and browsers updated, avoid logging in on public computers, and do not follow unexpected links that claim urgent account action is required. Check the domain carefully before entering credentials, particularly after clicking an advert or search result. Contact official support immediately if you notice an unknown login, unexpected payment, changed contact detail, or password-reset message.

Useful security practices include:

  • Use a password manager to generate and store a unique password.
  • Protect the email account linked to Marvel Casino with multi-factor authentication.
  • Never disclose one-time codes, passwords, or complete payment credentials.
  • Log out after using a shared device and avoid unsecured public Wi-Fi for payments.
  • Review account and banking activity regularly for unfamiliar transactions.
  • Upload verification files only through the official secure process.

If a personal data breach creates a risk to individuals, the controller should assess it promptly, take containment measures, and notify the competent authority where legally required. If the breach is likely to create a high risk, affected users may also need to be informed without undue delay. A notification should describe the nature of the incident, likely consequences, and practical protective steps where possible. Not every technical event is a reportable personal data breach, but each suspected incident should be assessed appropriately. Users should report suspected phishing or account compromise promptly rather than waiting for financial loss.

Data Retention and Deletion

Personal data should be kept only for as long as necessary for the purpose for which it was collected and for any overriding legal requirement. Retention periods can differ considerably across data categories. Account and transaction records may need to remain available after closure to meet anti-money laundering, gaming, accounting, tax, fraud-prevention, or legal-claim duties. Technical logs may be retained for a shorter security period, while unresolved complaints can require records until the dispute and relevant limitation period end. Marketing records may include a suppression entry so that an opt-out is respected rather than accidentally reversed.

When deciding how long to keep information, relevant factors include:

  1. The duration of the account and the service relationship.
  2. Mandatory retention periods under applicable law or licence conditions.
  3. The sensitivity, volume, and security risk of the information.
  4. The need to investigate fraud, complaints, chargebacks, or regulatory concerns.
  5. Applicable limitation periods for bringing or defending legal claims.
  6. Whether the data can be anonymised for statistical purposes.

Account closure does not always result in immediate deletion. The operator may first restrict active use and retain a protected record for required compliance purposes. When a retention period expires, information should be securely erased, anonymised, or placed beyond ordinary operational use unless another legal ground requires continued storage. Properly anonymised information is no longer personal data if re-identification is not reasonably possible. Backups may follow a controlled deletion cycle rather than being altered immediately, but access should remain restricted during that period.

Your Data Protection Rights in Poland

Subject to applicable law and relevant exceptions, individuals in Poland may have rights under the General Data Protection Regulation and related national rules. These rights help you understand and influence how organisations handle your personal data. A request is generally free, although a reasonable fee or refusal may be permitted for manifestly unfounded or excessive requests. The controller may ask for proportionate identity verification before disclosing or changing account information. This protects users from fraudulent requests made by another person.

Depending on the circumstances, your rights may include:

  • Access to personal data and information about its processing.
  • Rectification of inaccurate data and completion of incomplete information.
  • Erasure where there is no overriding ground for continued processing.
  • Restriction of processing in specified situations.
  • Objection to processing based on legitimate interests or direct marketing.
  • Data portability for eligible information processed by automated means.
  • Withdrawal of consent where processing relies on consent.
  • Protection concerning solely automated decisions with significant effects.
  • The right to lodge a complaint with a competent supervisory authority.

Rights are not absolute. For instance, an erasure request may be limited where records must be retained to comply with anti-money laundering law, resolve a dispute, protect legal claims, or satisfy a regulator. An access response may also redact information that would adversely affect another person’s rights, reveal protected legal advice, or compromise security. Where a request cannot be fulfilled fully, the controller should normally explain the reason and available complaint routes. Requests should be sent to the privacy contact identified in the current legal notice on marvel2.com.

The competent Polish supervisory authority is the President of the Personal Data Protection Office, commonly referred to as the UODO. You may have the right to complain to that authority if you believe personal data has been processed unlawfully. It is often practical to contact the controller first, as many issues can be resolved through correction, clarification, or an account review. Contacting the operator does not remove your right to approach the supervisory authority. For legal advice about a particular dispute, consult an appropriately qualified professional.

Marketing Communications and User Preferences

Marvel Casino may wish to communicate service news, game releases, bonuses, competitions, or personalised promotions. Direct marketing must follow applicable electronic communications and data protection rules. Depending on the channel and circumstances, marketing may rely on consent or another legally permitted basis. Registration should not be treated as unlimited permission to send every type of promotional communication indefinitely. Users should be told which channels may be used, such as email, SMS, telephone, push notification, or on-site message.

You can usually change marketing preferences in the account area, through an unsubscribe link, or by contacting customer support. An opt-out should be implemented without undue delay, although a message already scheduled may occasionally arrive while the request is processed. Stopping marketing does not prevent essential service communications about security, payments, account status, responsible gaming, legal updates, or changes to the terms and conditions. A limited suppression record may be retained to ensure the marketing preference continues to be respected. If you close an account or self-exclude, marketing controls should be applied in accordance with applicable responsible gaming duties.

Personalisation can use account history, game preferences, location, campaign engagement, or other permitted information to select potentially relevant content. Users should be informed where profiling is used for marketing and should be able to object to direct-marketing profiling at any time. Sensitive compliance information should not be repurposed casually for promotional targeting. Marketing should also avoid encouraging activity that conflicts with known safer gambling restrictions. These boundaries support both privacy and responsible commercial practice.

Children, Age Restrictions, and Eligibility

Online casino services are not intended for children. The minimum permitted age depends on applicable law, licence conditions, and the terms and conditions, and users must satisfy the requirement stated during registration. Identity and age checks may be used to prevent underage access. Providing false information or using another person’s documents can result in account restrictions, reporting, and other consequences described in the applicable rules. Parents and guardians should consider device controls where minors may access shared computers or smartphones.

If the operator becomes aware that a child’s data has been collected contrary to the service rules or law, it should investigate and take appropriate steps. These may include blocking the account, preserving records required for a regulatory review, returning funds where applicable, and deleting information that has no lawful reason to remain. Immediate deletion may not always be possible if evidence must be retained for legal or safeguarding purposes. A parent or guardian who believes a minor has submitted data should contact the official privacy or support channel promptly. They should provide enough information to locate the account without sending unnecessary documents in the first message.

Age verification must itself respect privacy principles. The operator should request proportionate evidence, use secure channels, and limit access to authorised staff or verification providers. Where a third-party age-checking service is used, its role and privacy notice should be made clear. Verification records should not be retained indefinitely merely because they might be useful. The same standards of security, purpose limitation, and accountability apply to age-check information as to other personal data.

Relationship With the Terms and Conditions

The privacy policy and the terms and conditions serve different but connected purposes. The privacy policy explains the handling of personal data, while the terms and conditions govern account eligibility, payments, bonuses, game rules, prohibited conduct, withdrawals, complaints, and account closure. Reading only one document can therefore leave important gaps. A payment dispute, for example, can involve both transaction rules and the processing of financial or verification data. A responsible gaming restriction can likewise involve contractual controls and personal-data analysis.

Users should review the following documents before depositing:

  • The current terms and conditions and any country restrictions.
  • This privacy policy and the separate cookie notice.
  • Bonus terms, wagering requirements, and promotion-specific rules.
  • Payment limits, fees, verification requirements, and withdrawal procedures.
  • Responsible gaming tools, self-exclusion rules, and support information.
  • Complaint handling and alternative dispute resolution procedures, where available.

References such as “all rights reserved” generally concern intellectual property in the website, branding, software, design, or content. They do not cancel statutory consumer or privacy rights and should not be interpreted as permission to process personal data without a valid legal basis. Similarly, accepting the terms and conditions does not automatically amount to valid consent for every optional use of information. Each processing activity must rest on the appropriate legal ground. This separation improves transparency and helps users understand which rules apply to a particular issue.

Updates to This Privacy Policy

Privacy practices may change when laws, licences, suppliers, technologies, payment methods, or services are updated. The policy should therefore display an effective date or last-updated date and be reviewed periodically. Minor editorial changes may be published on the website, while material changes should be communicated more prominently where appropriate. A material update could involve a new processing purpose, significant new data category, different controller, or important international transfer. Users should have a fair opportunity to read relevant changes before they take effect where the law requires it.

Continued website use should not be presented as consent where valid consent is legally required. If a new optional purpose depends on consent, the operator should obtain an appropriate choice rather than rely only on an updated policy. Processing based on legal obligation, contract, or legitimate interests may be updated through notice where that is the correct legal approach. Archived versions can help explain which wording applied at a given time, although the current version governs present practices. You should save relevant notices if you are involved in an active complaint or data-rights request.

Check this page, the cookie notice, and the legal area of Marvel periodically, particularly before submitting new documentation or using a new payment method. If an update is unclear, ask support which provision applies to your account and country. Do not rely on unofficial copies, forum posts, or search snippets, as they may be incomplete or outdated. The version published on marvel2.com should identify the current framework. Regulatory rights continue to apply regardless of how frequently the document is reviewed.

Contacting Marvel About Privacy

Questions about privacy, rights requests, security concerns, or suspected misuse should be sent through the official contact channel listed in the current website footer, account area, or legal notice. Use a clear subject such as “privacy request”, describe what you need, and identify the relevant account without including unnecessary sensitive information. Do not place a password, one-time code, full payment credential, or unredacted identity document in an initial email. Support may direct you to a secure verification route if evidence is needed. Keep a copy of the request and any case number for your records.

A useful request should state whether you seek access, correction, deletion, restriction, portability, objection, consent withdrawal, or information about a processing activity. It should also identify any relevant date range, transaction, communication channel, or account issue. A focused request can be answered more efficiently than a vague demand for every record held across all systems. The controller should respond within the period required by applicable law and notify you if a lawful extension is necessary. Complex requests, large volumes of records, or identity concerns can require additional time.

If you report a security incident, include the time you noticed it, the affected account feature, and any suspicious message or transaction, but avoid forwarding malicious files without instruction. Change compromised passwords immediately and contact your bank or payment provider if financial credentials may be affected. For unresolved data protection concerns, you may contact the competent supervisory authority, including the UODO in Poland where appropriate. This Marvel Casino privacy policy is designed to help users understand the main privacy considerations, but the controller details and official notices displayed on marvel2.com remain essential. Review them carefully before using the online casino or providing personal data.