MobilePay Official Site: Read How We Handle Your Data

Exclusive welcome offer

Claim bonus
MobilePay

This policy explains what personal data the operator collects, why it collects it, how long it keeps it and what rights you hold under the General Data Protection Regulation and the Bundesdatenschutzgesetz. It applies to account holders, visitors and anyone contacting support. Processing takes place in accordance with Article 13 and Article 14 GDPR, and nothing here reduces rights that statute grants you.

1. Controller and Data Protection Officer

Responsibility for processing rests with the operating company named in the site imprint.

  • 1.1 Controller: the licensed operating company behind the MobilePay official site, whose registered address and commercial register entry appear in the Impressum.
  • 1.2 Data protection officer: reachable at the postal address in the Impressum, marked for the attention of the Datenschutzbeauftragter, or at help@mobileplay.com.
  • 1.3 Supervisory authority: the competent Landesdatenschutzbehörde for the operator's registered seat.
  • 1.4 Scope: this policy covers the website, the mobile browser interface and any payment confirmation step routed through a connected application.

2. Categories of Data Collected

Data reaches the operator in three ways: you supply it, your device transmits it automatically, or a payment provider returns it.

Confirmation steps completed inside the MobilePay app generate transaction metadata that flows back to the operator, and the table below sets out what each category covers.

Category
Examples
Source
Registration data
Name, date of birth, address, email, telephone number
You
Identification data
Identity document, proof of address, document numbers
You
Financial data
Deposits, withdrawals, payment method, transaction times
You and payment provider
Gameplay data
Titles opened, stakes, session duration, loyalty points
Automatic
Technical data
IP address, device type, browser, operating system, time stamps
Automatic
Protection data
Deposit limits, session timers, self-exclusion entries, reality check settings
You and system
Communication data
Chat transcripts, emails, complaint records
You
Registration data
ExamplesName, date of birth, address, email, telephone number
SourceYou
Identification data
ExamplesIdentity document, proof of address, document numbers
SourceYou
Financial data
ExamplesDeposits, withdrawals, payment method, transaction times
SourceYou and payment provider
Gameplay data
ExamplesTitles opened, stakes, session duration, loyalty points
SourceAutomatic
Technical data
ExamplesIP address, device type, browser, operating system, time stamps
SourceAutomatic
Protection data
ExamplesDeposit limits, session timers, self-exclusion entries, reality check settings
SourceYou and system
Communication data
ExamplesChat transcripts, emails, complaint records
SourceYou

3. Purposes and Legal Bases

At MobilePay official site, each processing operation rests on a defined legal basis, and none happens without one.

  • 3.1 Contract performance (Art. 6(1)(b) GDPR): opening and running your account, crediting deposits, executing withdrawals, awarding loyalty points and handling support requests.
  • 3.2 Legal obligation (Art. 6(1)(c) GDPR): age verification, identity checks, anti-money-laundering duties, source-of-funds enquiries, tax records and enforcement of statutory deposit ceilings.
  • 3.3 Legitimate interests (Art. 6(1)(f) GDPR): fraud prevention, detection of duplicate accounts, bonus abuse monitoring, network security and improvement of the MobilePay site.
  • 3.4 Consent (Art. 6(1)(a) GDPR): marketing emails, promotional messages and non-essential cookies, withdrawable at any point with effect for the future.
  • 3.5 Vital and public interests (Art. 6(1)(d) and (e) GDPR): player protection measures, including intervention where risk indicators appear.

4. Automated Decisions and Profiling

Some checks run without human involvement, and you deserve a clear statement of which.

  • 4.1 Risk scoring: transaction patterns generate automated indicators that may restrict deposits, even where you attempt to deposit again.
  • 4.2 Limit enforcement: self-imposed caps register at payment level as well as operator level, so an automated block applies if you switch methods.
  • 4.3 Verification triage: document checks may route automatically, with higher loyalty tiers receiving accelerated processing.
  • 4.4 Human review: you may request human intervention, express your view and contest any automated outcome under Art. 22(3) GDPR.

5. Recipients and Transfers

Data leaves the operator only where a purpose above requires it, and every recipient works under a contract satisfying Art. 28 GDPR. The MobilePay official site discloses the following categories of recipient.

  • 5.1 Payment providers: transaction data, sufficient to settle deposits and return funds to the originating instrument.
  • 5.2 Game suppliers: session data needed to run the titles you open, without registration details.
  • 5.3 Verification services: identity and address data for document checks.
  • 5.4 Regulatory authorities: data required under gambling and anti-money-laundering law, disclosed on lawful request.
  • 5.5 IT and hosting providers: technical data under processing agreements.
  • 5.6 Third countries: transfers outside the EEA occur only under standard contractual clauses or an adequacy decision.

6. Retention Periods

At MobilePay official site, nothing is kept indefinitely, and deletion follows automatically once the relevant period expires.

Data type
Retention period
Reason
Registration and identification data
5 years after account closure
Anti-money-laundering law
Financial and transaction records
10 years
Commercial and tax law
Self-exclusion entries
Duration of the exclusion plus statutory period
Player protection
Gameplay records
5 years after account closure
Regulatory audit
Support correspondence
3 years from the end of the calendar year
Limitation periods
Technical log files
90 days
Security and fraud prevention
Marketing consent records
Until withdrawal plus 3 years
Evidence of consent
Registration and identification data
Retention period5 years after account closure
ReasonAnti-money-laundering law
Financial and transaction records
Retention period10 years
ReasonCommercial and tax law
Self-exclusion entries
Retention periodDuration of the exclusion plus statutory period
ReasonPlayer protection
Gameplay records
Retention period5 years after account closure
ReasonRegulatory audit
Support correspondence
Retention period3 years from the end of the calendar year
ReasonLimitation periods
Technical log files
Retention period90 days
ReasonSecurity and fraud prevention
Marketing consent records
Retention periodUntil withdrawal plus 3 years
ReasonEvidence of consent

7. Cookies and Tracking

The MobilePay app confirmation flow sets no advertising identifiers, and cookie handling on the website follows §25 TTDSG.

  • 7.1 Essential cookies: session management, login state and security, set without consent as they are technically necessary.
  • 7.2 Functional cookies: language preference, favourites tab, lobby filter settings.
  • 7.3 Analytical cookies: aggregated usage measurement, set only after consent.
  • 7.4 Marketing cookies: set only after explicit opt-in through the consent banner.
  • 7.5 Withdrawal: you may change cookie settings at any time through the banner link in the site footer.

8. Your Rights

At MobilePay official site, you hold the following rights and may exercise any of them free of charge, with a response due within one month.

  • 8.1 Access (Art. 15): obtain confirmation of processing and a copy of your data.
  • 8.2 Rectification (Art. 16): correct inaccurate or incomplete records.
  • 8.3 Erasure (Art. 17): request deletion, subject to statutory retention duties that override it.
  • 8.4 Restriction (Art. 18): limit processing while a dispute over accuracy or lawfulness runs.
  • 8.5 Portability (Art. 20): receive data you supplied in a structured, machine-readable format.
  • 8.6 Objection (Art. 21): object to processing based on legitimate interests, including profiling.
  • 8.7 Withdrawal of consent (Art. 7(3)): stop consent-based processing at any point, without effect on past lawfulness.
  • 8.8 Complaint (Art. 77): lodge a complaint with a supervisory authority in your place of residence or work.

9. Security Measures

Technical and organisational measures under Art. 32 GDPR protect the data held on the MobilePay site, and the list below covers the principal ones.

  • 9.1 Encryption: transport encryption across all connections and encryption at rest for identification documents.
  • 9.2 Access control: role-based permissions, with document access limited to verification staff.
  • 9.3 Authentication: payment confirmation by fingerprint or code inside the payment application, removing the need to enter card details on a device keyboard.
  • 9.4 Monitoring: logging of access to sensitive records and automated alerts on irregular patterns.
  • 9.5 Breach notification: notification to the supervisory authority within 72 hours and to affected persons where a high risk arises.

10. Data Provision and Consequences of Refusal

Some data you must supply, and the effect of withholding it differs by category.

  • 10.1 Mandatory for contract: registration details, without which no account can open.
  • 10.2 Mandatory by law: identity and address documents, without which no withdrawal can clear.
  • 10.3 Optional: marketing preferences, refusal of which affects nothing beyond receiving offers.
  • 10.4 Consequence: failure to provide requested verification documents within thirty days may lead to account closure and return of deposits.

11. Minors

No MobilePay official site account may be opened by anyone under 18, and the operator processes no data knowingly relating to minors. Where evidence of an underage account emerges, the account closes, gameplay is voided and the data is deleted save where retention law requires otherwise. Parents or guardians who suspect that a minor has registered should contact help@mobileplay.com immediately.

12. Changes to This Policy

This policy may change where law, technology or processing purposes change. The operator publishes each revision here with an updated version date, and notifies registered users by email at least seven days before material changes take effect. Continued use after that date constitutes acknowledgement of the revised version.