Royal Mushroom Privacy Policy

Version 2.1 · Last updated 12 August 2026 · Applies to all players of Royal Mushroom

This policy explains what Mycelion Entertainment N.V. does with your personal data as the controller of it. We collect what is needed to run a licensed gambling account and nothing beyond it, and we never sell personal data to anyone.

1. What we collect

  • Account data: name, date of birth, e-mail, phone number, address, currency and password hash.
  • Verification data: identity document, selfie, proof of address and, where regulation requires, evidence of source of funds.
  • Financial data: deposits, withdrawals, the last four digits of a card, wallet identifiers and transaction references. We never store a full card number or CVV — those stay with the payment provider.
  • Gameplay data: bets, wins, bonuses, session times, limits set and self-exclusion status.
  • Technical data: IP address, device and browser, and the cookies described in our Cookie Policy.
  • Support data: chat transcripts, e-mails and call notes.

2. Why we hold it, and on what basis

PurposeLegal basis
Opening and running your accountPerformance of a contract
Age, identity and anti-money-laundering checksLegal obligation
Fraud prevention, fair play and site securityLegitimate interest
Responsible-gaming monitoring and interventionsLegal obligation and legitimate interest
Marketing e-mail and SMSConsent, withdrawable at any time

3. Who sees it

Data is shared only with parties who need it: payment providers and banks, identity-verification and anti-fraud services, game suppliers for the rounds you play, the hosting and analytics processors that run the site, and the Curaçao Gaming Authority or another regulator where the law requires. Every processor works under a written contract that limits them to our instructions. Transfers outside the EEA are covered by standard contractual clauses.

4. How long it is kept

Account, transaction and verification records are held for five years after an account closes, because anti-money-laundering law requires it. Marketing consent records are held for three years after withdrawal. Support transcripts are kept for two years. Self-exclusion records are kept permanently — that is the point of them. Anything outside a retention rule is deleted or anonymised.

5. Your rights

You can ask for a copy of your data, correct anything inaccurate, ask for deletion, object to processing based on legitimate interest, ask us to restrict processing while a dispute is open, and receive your data in a portable format. Marketing consent can be withdrawn from the account panel or from the unsubscribe link in any message, and withdrawal takes effect immediately.

Two limits are worth stating plainly: we cannot delete records the law requires us to keep, and we cannot lift a self-exclusion by treating it as a deletion request. Write to privacy@royal-mushroom.example; we answer within 30 days. You may also complain to the supervisory authority where you live.

6. Security

Traffic is encrypted with TLS, passwords are stored only as salted hashes, verification documents are held in encrypted storage with access limited to the compliance team, and access to player data is logged and reviewed. Should a breach ever put you at risk, we will tell you and the regulator without undue delay.

A note on this build. Royal Mushroom is a demonstration website. It collects no personal data at all: there is no registration, no server-side account and nothing leaves your browser. The only storage used is your browser's own, for the cookie banner and the dismissed welcome strip.