Contact dpo
If you have questions about the data we collect, how long we keep it or how to exercise your rights under the Australian Privacy Act, write to [email protected]. We respond within thirty days as required under the Act. For complaints about how we handled a privacy request you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
For readers in the European Union covered by the GDPR, the same procedure applies — we honour the right of access, the right of erasure, the right to rectification and the right to data portability. Requests should include enough information to identify the data concerned (for an email thread, the thread subject and approximate date is usually enough). We never ask for photocopies of government documents to verify a data request; a signed email from the address on record is sufficient.
What we collect
When you visit gamblegorilla.bet our server logs record your IP address, user-agent string, requested URL and timestamp. We use a self-hosted analytics tool that stores an anonymised identifier in your browser so we can distinguish returning readers from new ones. If you email us, we keep the email thread. If you click an affiliate link we pass an anonymous click identifier to the operator so they can attribute your account to our referral; we do not share your email, name or any other personal detail with the operator.
We do not run any form of fingerprinting (canvas, audio, WebGL or screen-size matrix). We do not run server-side tracking pixels (no Facebook Conversions API, no TikTok Events API). The analytics identifier mentioned above is scoped to the browser cookie that stores it — if you clear cookies the counter restarts from zero. Readers who want nothing at all stored in their browser can enable Do Not Track in the browser preferences and the analytics identifier will not be set.
How we use
Logs are used to debug the site, measure which reviews are read and to improve the pages that bring the most value to readers. Analytics are used in aggregate — we look at how many sessions reached a page, not at individual journeys. Email is used to answer your message. Click identifiers are used to confirm that referrals were made and to pay the editorial team. We never resell logs, analytics or email contents and we never run retargeting advertising.
Aggregated analytics inform editorial decisions: pages that attract no readers are retired, pages that are visited often get re-tested more often than quarterly. We never produce reports in which an individual reader is identifiable. The editorial team sees a dashboard with totals per URL per week — nothing more granular than that. Click identifiers used for referral attribution are deleted from our side thirty days after the first attribution report is reconciled with the operator.
Security
Server logs and analytics data are stored on a European hosting provider that is certified to ISO 27001 and GDPR-aligned, with disk encryption at rest and TLS 1.3 in transit. Access to the production environment is limited to two editors, both using hardware security keys. Email is held on a managed Microsoft 365 tenant with multi-factor authentication. If a breach ever occurs that could affect you, we will notify you by email and publish a notice on this page within seventy-two hours of discovery.
We publish a security contact at [email protected] for responsible disclosure of vulnerabilities. Reports are acknowledged within forty-eight hours and reward amounts are agreed in advance where applicable; we do not pursue researchers who follow the standard disclosure norms. The site runs behind strict-transport-security (HSTS) with preload, a content-security policy that forbids inline scripts, and subresource-integrity hashes on every externally-hosted asset we include (currently none).
Retention
Server logs are kept for ninety days and then purged. Analytics data is aggregated monthly; the raw hits older than ninety days are deleted. Email threads are kept for twenty-four months unless a longer period is required for tax or accounting reasons. Click identifiers passed to operators are retained by the operator under their own privacy policy, which you should review before signing up.
Where a reader has exercised the right to erasure, the matching email thread is deleted immediately and the deletion is confirmed in writing. Where a reader has requested access, we provide the data in a human-readable form (PDF or plain text) and in a machine-readable form (JSON) within thirty days. Operator click identifiers are outside our retention schedule because they are held by the operator; the operator's policy is linked from every CTA on this site.
Third parties
We embed only two third-party resources on this site: a self-hosted font and a Cloudflare DNS layer in front of our hosting provider. Cloudflare sees your IP address because every HTTP request passes through them. We do not embed Google Analytics, Google Ads, Facebook Pixel, LinkedIn Insight, TikTok Pixel or any similar tracker. Operators you click through to have their own trackers; those are their responsibility, not ours.
We never sell data to brokers, we never share logs with third-party analytics, and we never share email contents outside the editorial team. The one exception is a legally compelled disclosure — if law enforcement issues a valid Australian warrant we comply and record the compulsion in a transparency note on this page. No such warrants have been issued at the time this policy was last updated.