1. About us

Overlog is an independent casino desk publishing at overlog.gg. Under the UK GDPR, the EU GDPR and the California Consumer Privacy Act (CCPA), we act as the data controller for everything described on this page. We do not run casinos, we hold no player wallets, and no bet, deposit or withdrawal ever passes through any system we control. What sits on our servers is a small editorial site and the traffic that reads it, nothing more.

This policy is deliberately written in plain English. If a paragraph confuses you, that is a bug on our side, so email us and we will fix it.

2. The personal data we collect

We collect the bare minimum needed to run a website and answer the people who write to us. There are three sources, and none of them involves an account, a wallet or an ID document.

Analytics from your visit

When cookies are accepted, Google Analytics and Microsoft Clarity record which pages load, how long readers stay, roughly which country the visit came from and what device rendered the page. IP addresses are truncated before they reach us, so the data is aggregated rather than tied to a named individual.

Comments and messages

If you leave a comment on an article or write to the editorial inbox, we keep the name and email address you chose to share plus the text you sent. That is it. We do not enrich the record with third-party data and we do not cross-reference it with your browsing.

Newsletter opt-in

Subscribing to the Overlog newsletter stores your email address, the timestamp you confirmed the opt-in and the IP address that pressed the button, so we can prove the consent was genuine if a regulator asks. Every issue carries a one-click unsubscribe link at the foot of the email.

We do not collect payment details, we never ask for identity documents, we build no advertising profiles of individual readers, and we do not sell, rent or trade personal data with anyone. Full stop.

3. What we keep, why and for how long

The table below is the whole picture. If a piece of data is not listed here, we do not hold it.

Data type Purpose Retention Legal basis
Comments and email (name, address, message) Replying, moderation, editorial follow-up 24 months after the final message Legitimate interest (Art. 6(1)(f))
Newsletter subscription (email, opt-in log) Sending the Overlog newsletter to people who asked for it Until you unsubscribe, then purged inside 30 days Consent (Art. 6(1)(a))
Analytics events (page views, referrer, country, device) Understanding what works so we can prune what does not 14 months, aggregated thereafter Consent (Art. 6(1)(a))
Server logs (truncated IP, timestamp, URL) Security, abuse blocking, technical debugging Rolling 30-day window Legitimate interest (Art. 6(1)(f))
Cookie-consent record Remembering the choice you made in the banner 12 months, or until you clear the browser Legal obligation / consent

4. Our legal grounds (GDPR)

Every activity above sits under one of the two Article 6 grounds shown in the table, and we do not try to squeeze extra uses out of either.

  • Consent covers analytics, Clarity session replay and the newsletter. Nothing loads or lands in the inbox until you have actively opted in, and you can withdraw the consent from the cookie banner or the unsubscribe link at any moment.
  • Legitimate interest covers replying to messages you have chosen to send, running the strictly necessary cookies that keep the layout intact, and holding the short-lived server logs that stop the site being knocked over.

Under the CCPA, Californian readers are treated as if they had the same rights as UK and EU readers by default. That is simpler for everyone than running two parallel privacy regimes.

5. Cookies and tracking

Overlog uses a small, deliberate set of cookies. Strictly necessary ones load on every visit because the layout and consent banner cannot function without them. Everything else, analytics and session replay included, waits for a positive click on the banner before firing.

For the full cookie-by-cookie breakdown, including provider, duration and category, head to the Cookies page. You can revisit the banner at any time to change your mind, and clearing site data in your browser resets the entire record.

6. Who has access to your data

A handful of trusted processors help us keep the site online. Each receives strictly what its job requires, and every one is covered by GDPR-compliant contractual clauses or an equivalent transfer safeguard.

  • Hosting. A European infrastructure provider serves the site and holds the truncated server logs described above.
  • Email. Anything you send to hello@overlog.gg reaches a European mail host that operates under a signed data-processing agreement.
  • Google Analytics. Aggregated, IP-truncated traffic measurement, loaded only after you consent, so we can see which guides earn their place.
  • Microsoft Clarity. Anonymised session replay and heatmaps used to spot broken layouts and dead-end pages, also gated by consent.
  • Newsletter platform. A GDPR-compliant email service stores the subscription list and delivers each issue, with an unsubscribe link at the bottom of every message.
  • Affiliate networks. When you click an outbound casino link, the operator or its network may drop its own attribution cookie on its domain. From that point their privacy policy applies, not ours.

Your rights, in one place

Wherever you live, if you fall under the UK GDPR, the EU GDPR or the CCPA, email hello@overlog.gg with the request and we will action it inside 30 days. No account required, no forms to fill in, no fee.

7. Your rights under the GDPR

If you are covered by the UK GDPR, the EU GDPR, the CCPA or any regime granting equivalent protections, the following rights apply to the data we hold about you.

  • Access. Ask for a copy of everything we have on file linked to you.
  • Rectification. Correct anything wrong, out of date or incomplete.
  • Erasure. The right to be forgotten. One email to hello@overlog.gg and we remove verified records inside the 30-day statutory window.
  • Restriction and objection. Tell us to pause processing, or object to a specific use such as marketing.
  • Withdraw consent. Turn off analytics from the cookie banner, or unsubscribe from the newsletter in one click, without affecting anything else.
  • Portability. Receive your data in a structured, machine-readable format you can hand to another service.
  • CCPA opt-out. Californian readers can request that we do not sell or share personal information. We already do neither, but the confirmation goes on the record.
  • Complaint. Escalate to your local supervisory authority. In the UK that is the Information Commissioner's Office at ico.org.uk; in the EU it is your national data-protection regulator.

8. Contact us

For any privacy question, data-subject access request or concern about how your information is handled, write to hello@overlog.gg. Include enough detail for us to locate the record, typically the email address you originally wrote from and a rough date range, and spell out what you would like us to do.

For general enquiries that are not about privacy, the contact page lists the fastest route to each part of the editorial desk.

9. Updates to this policy

We revisit this page whenever the tooling underneath the site changes or the regulations shift. Every meaningful update bumps the date at the top of the policy, and the previous version is archived internally so we can show the audit trail if a regulator asks. The version live right now is dated 31 July 2026.