safety trust or policyUpdated 11 August 2026

Privacy and data policy

A plain-language privacy policy describing the data we collect, how it is stored, the cookies we set, and how to request a deletion.

Privacy and data policy · Monopoly Live Editorial

What we collect

The categories of data this site handles

This is an editorial site. It is not a gambling platform, it does not process deposits or withdrawals, and it does not run player accounts. The site collects the minimum data needed to publish pages, answer reader mail, and comply with the audit and disclosure rules that govern any website that links to a real-money operator. The three categories below cover everything that touches a reader's visit.

Direct data is what a reader sends us on purpose. A contact form message, an email to the editorial address, a story tip, a correction, a partnership enquiry, or an attachment that arrives with any of the above. Direct data is used to reply to the reader, to keep a dated record of the exchange, and to publish a public correction if the message is one. Direct data is stored in the desk's mailbox and in the desk's publishing archive. The storage period is twenty-four months from the date of the last exchange, after which the record is deleted unless the desk has a specific reason to keep it.

Analytics data is what the publishing platform collects automatically. Page views, anonymised session identifiers, the country of origin as published by the IP-to-country database, the referring page where one exists, the device class, and the browser family. Analytics data is used to understand which editorial pages help readers and which do not, and to plan future coverage. Analytics data is stored for thirteen months and is not joined to any direct data record.

Advertising data is what the third-party advertising network collects under its own privacy notice. The site runs sponsored content and affiliate links to real-money operators; the network serves the ads and measures clicks, viewability and conversions. The network's privacy notice governs that data, not this one. A reader who does not want the network to record a visit should block the network's cookies at the browser level before reading any page on the site that carries a sponsored link.

What we never collect

The desk does not collect a reader's name unless the reader sends it. The desk does not collect a reader's address, phone number, date of birth, PAN, Aadhaar, banking details or any government identifier. The desk does not collect a reader's real-money play history, deposit history or withdrawal history because the desk has no visibility into those records and does not ask for them. A reader who is asked for any of the above by an email claiming to be from the desk is being asked by a fraudster; the desk's published contact channel is the only channel the desk uses.

Why we hold it

How each category is used, and for how long

a paper notebook open on a desk with a fountain pen and a stack of reader letters held with a brass clip
Reader correspondence is the most direct data the desk holds. The retention rule is twenty-four months from the last exchange.

Direct data is used to reply to the reader who sent it, and to keep a record of what the desk said in reply. The reply uses the channel the reader used to contact the desk. A correction request produces a public correction note published on the page that contained the error, with a dated record of the original sentence, the corrected sentence, and the source the reader supplied.

Analytics data is used to plan editorial coverage. The desk looks at which pages are read, in what order, and for how long; the desk does not join those signals to a reader's identity because the platform does not collect identity at that layer. Analytics data is aggregated monthly and the raw logs are deleted after thirteen months. The aggregated monthly view is retained for as long as the desk publishes, because it informs long-term coverage decisions.

Advertising data is used to decide whether sponsored content is worth the editorial space it takes. The desk reads the network's reports on clicks and conversions in aggregate form. The desk does not see what individual readers clicked and does not ask to see it. The network's own privacy notice covers the network's processing.

What the desk will not do with reader data

The desk will not sell a reader's name, email or correspondence to a third party. The desk will not share a reader's message with the operator the message is about, unless the reader has asked the desk to do so. The desk will not pass a story tip to a third party without the reader's consent, except where the tip is a public document the reader has already published. The desk will not contact a reader using an address the reader did not supply.

Cookies

The cookies this site sets, and what each one does

Cookie inventory

What is in the browser when a reader visits

The list below covers the cookies the site itself sets. Third-party cookies set by the advertising network are listed separately, on the network's own privacy notice, which the network links from every ad it serves.

Cookie name, purpose, retention and whether it is strictly necessary
NamePurposeRetentionNecessary
editorial_sessionIdentifies the reader's session for analytics aggregation.13 months from the last visit.No, optional.
preferencesStores the reader's reduced-motion and language preferences.Until the reader clears browser storage.Yes, for accessibility.
affiliate_refRecords the page the reader used to reach a sponsored operator.30 days from the click.No, used for commission accounting only.
consent_stateRecords whether the reader accepted or rejected non-essential cookies.12 months from the choice.Yes, for compliance.

A reader who rejects non-essential cookies at the consent banner will still see the editorial content; the sponsored links will still resolve but the affiliate commission accounting will not be tied to that visit. A reader who clears browser storage will reset all four cookies above and be asked to make the choice again on the next visit.

Reader rights

What a reader can ask the desk to do with their data

A reader who has sent the desk a direct message, been mentioned in a published correction, or has a record in the desk's publishing archive has four rights under the Digital Personal Data Protection Act, 2023, and under this site's own policy. The rights are: a copy of the data the desk holds, a correction to any data the desk holds that is wrong, a deletion of the data the desk holds, and a transfer of the data the desk holds to another party in a machine-readable form.

The four rights are exercised by writing to the editorial address published on the contact page. The desk acknowledges a request within five working days of receiving it and responds substantively within thirty days, in line with the Act's requirement. A request does not need to use any particular form; a clear email that names the right being exercised and identifies the data subject is enough.

A deletion request removes the data subject's record from the active desk systems. Records the desk is required to keep for tax, accounting or audit purposes are retained only for the period the law requires, then deleted. Records that have been published as part of a dated correction are retained as part of the public record; a reader who wants the published correction itself deleted can ask, and the desk will respond with what is and is not deletable under the desk's corrections policy.

What the desk will not do with a rights request

The desk will not charge a fee for responding to a first rights request. The desk will not require a reader to open an account or supply a government identifier to make the request. The desk will not share the request with the operator the request is about. The desk will not refuse the request because the reader used a different channel from the one the desk publishes.

Compliance and contact

The legal basis the desk relies on, and how to reach the editor

a paper record card with a hand-drawn note on data permissions beside a fountain pen
The desk's data basis is the Digital Personal Data Protection Act, 2023, plus the desk's own published retention rules.

The legal basis for processing reader data is the Digital Personal Data Protection Act, 2023, and the rules the desk has published on this page. Where the Act requires consent for a specific processing activity, the desk asks for that consent before the processing starts. Where the Act permits processing for a legitimate use without consent, the desk identifies the use on this page.

Where a reader's data is held by a third-party processor on the desk's behalf, the desk publishes the processor's identity on the processors subpage. The desk's current processors are the publishing platform (for hosting and analytics), the email service (for editorial correspondence), and the advertising network (for sponsored content). Each processor operates under its own contract with the desk and under the Act.

How to reach the editor

The editorial address is published on the contact page. A reader who has a privacy concern should write to that address with the word "privacy" in the subject line. The desk acknowledges privacy mail within five working days and resolves it within thirty. A reader who is not satisfied with the response can approach the Data Protection Board of India, whose contact details are on the Board's own website.

Reader questions

Questions readers ask about data and privacy

Short answers that link to the longer treatment. Where the honest answer is that the desk does not know, that is the answer given.

What should I do first if a withdrawal stalls?

Check the operator's status page, write a dated record of the last successful transaction, and escalate through the operator's customer-care channel. The desk does not have visibility into operator payment queues and cannot intervene on a reader's behalf.

The desk will publish a dated note if the same operator shows a pattern of stalled withdrawals across multiple readers, but the desk does not name operators until the pattern is verified against a primary document.

Is it safe to share a PAN copy with an operator?

A regulated operator will ask for a PAN copy as part of KYC under the Prevention of Money Laundering Act. Sharing the copy with a regulated operator is part of the law the operator is required to follow. Read the operator's published privacy notice before sharing the copy, and share only what the operator has asked for.

The desk does not recommend any specific operator. A reader who is being asked for a PAN copy by an unlicensed platform should refuse and walk away.

Where can I check if a platform is recognised?

Check the regulator's public list for the state where the reader is playing. The Promotion and Regulation of Online Gaming Act, 2025 establishes the National Online Gaming Commission as the federal licence authority; the Commission's public list is the federal reference. State-level lists exist for state-recognised operators.

The desk is not a regulator and does not certify platforms. The desk publishes the federal, state and litigation layers on the is-legal page.

How long does the desk keep reader correspondence?

Twenty-four months from the date of the last exchange, after which the record is deleted unless the desk has a specific reason to keep it. A published correction is retained as part of the public record for as long as the page is published.

A reader who wants their correspondence deleted earlier can ask under the rights section above. The desk will respond within thirty days.

Does the desk sell reader data?

No. The desk does not sell a reader's name, email or correspondence to a third party. The desk does not share a reader's message with the operator the message is about, unless the reader has asked the desk to do so.

Advertising data is collected by the network under its own privacy notice. The desk does not see what individual readers clicked and does not ask to see it.