Privacy notice
This site is published by the Cashier Limits editorial team.
The publisher named above is the controller of the personal data this site handles. That data comes from two sources only: the server’s access logs and emails sent to the site’s mailbox. The site sets no cookies, runs no analytics and loads nothing from other sites, and its fonts are served from its own server. The cookies page gives the detail. No personal data is sold, or shared with anyone for marketing.
Server access logs
Each request to the site is written to an access log with the IP address, the time, the page requested and the user-agent the browser sends. Legitimate interests are the lawful basis for these logs: keeping the site secure, and finding and fixing faults so that it keeps running. Logs are kept for thirty days, long enough to look into an attack or a fault after it happens, and are then deleted. Each day a short record is taken from the previous day’s log: which pages Googlebot and Bingbot fetched, counted only when the request is checked against Google’s and Microsoft’s own address records, the responses those crawlers received, and which pages returned an error. That record holds no visitor’s IP address, user-agent or other detail about a person, and it is used only to see whether search engines can reach the site’s pages.
Emails to the mailbox
An email brings the sender’s address, any name attached to it and whatever the message contains. It is used to answer the message and to act on it, such as re-reading a casino’s page after a reported figure. The basis is again legitimate interests, here answering the people who write in and keeping the sheet correct. Emails are kept for twelve months after the matter is closed, so that a later message on the same matter can be read alongside the first, and are then deleted. A correction that changed the sheet is logged on sheet changes without the sender’s name or address. Sending an email is voluntary; reading the site needs nothing from the reader.
Providers and transfers
The hosting provider keeps the access logs, and a content delivery network passes each request on to the server and forwards email sent to the mailbox to the editorial team’s inbox at an email service provider, each on the publisher’s behalf.
Hostinger hosts the site on a server in the United Kingdom. Cloudflare, Inc., a company based in the United States, passes each request on to that server, handling visitors’ IP addresses and request details to do so; it also runs the site’s DNS and forwards email sent to the mailbox. Transfers to Cloudflare rely on the UK Extension to the EU-U.S. Data Privacy Framework, under which Cloudflare is certified. (stated )
Rights over personal data
The Information Commissioner’s Office (ICO) sets out the rights that UK data protection law gives people over their personal data. Those that can apply to the logs and emails held here are:
- Access: asking whether personal data is held or used, and for a copy of it.
- Rectification: challenging data that is inaccurate and asking for it to be corrected.
- Erasure: asking for data to be deleted, which an organisation must do in some circumstances.
- Restriction: asking for the use of data to be limited, including keeping it from deletion, which applies only in certain circumstances.
- Objection: asking for data used on the basis of legitimate interests to stop being used, which has to be agreed to only in certain circumstances.
The right to data portability applies only where an organisation relies on consent or uses the data for a contract with the person. This site relies on neither, so that right does not arise here. No decision about anyone is made by automated means, and no profiles are built.
A request about an email can name the address it was sent from. A request about the access logs needs the IP address and the approximate time of the visit, since the logs hold no name or email address. Because an IP address can be shared, the publisher may ask for enough detail to be confident the request concerns the person making it.
Complaints
A complaint about how this site handles personal data goes first to the publisher. Since 19 June 2026, the Data (Use and Access) Act 2025 has required every organisation to give people a clear way to complain, to acknowledge a complaint within thirty days, to look into it without undue delay while keeping the person informed, and to give the outcome. The thirty days are for acknowledging a complaint, not for resolving it.
The ICO also accepts complaints at any time. The ICO recommends giving the organisation a chance to finish its own handling first, and asks people to use its complaint form. Its guidance for the public is on how to make a data protection complaint.
Requests about these rights, and complaints, can be sent to the site’s mailbox.
Write to contact@cashierlimits.com.