18+

Adults only

Important: age verification

This website is intended only for people aged 18 or older. Magic Match-room is free entertainment using virtual crystals only and does not offer deposits, withdrawals or cash prizes.

Magic Match-room
Privacy Terms Cookies
Back to home

Privacy and data protection

Privacy Policy

This policy explains how information is handled when you use the Magic Match-room website and locally embedded game.

Last updated: 3 August 2026

Website operator

Magic Match Rooms Digital Entertainment Pty Ltd
Level 10, 20 Martin Place, Sydney NSW 2000, Australia
info@magicmatchrooms.com
Return to homepage

Privacy policy document sections

1. Scope and purpose of this policy

This Privacy Policy explains how Magic Match Rooms Digital Entertainment Pty Ltd (referred to as “Magic Match-room”, “we”, “us” or “our”) handles personal information when you visit magicmatchrooms.com, use the locally embedded Magic Match-room mini game, make a privacy enquiry, or otherwise communicate with us. It is intended to provide transparent information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles where those laws apply, and with the General Data Protection Regulation (“GDPR”) where the GDPR applies to a visitor or a particular processing activity.

The website is designed as a free, account-free entertainment experience. It uses virtual crystals only. We do not provide real-money gambling, deposits, withdrawals, cash prizes, financial accounts or paid game items through this website.

2. Data controller and contact details

The website operator and data controller is Magic Match Rooms Digital Entertainment Pty Ltd, located at Level 10, 20 Martin Place, Sydney NSW 2000, Australia. Privacy questions and requests may be sent to info@magicmatchrooms.com. The email address is displayed as plain text to reduce automatic harvesting and is not a clickable link.

Where another organisation independently determines why and how it processes information connected with your device, browser, internet service or communications service, that organisation may be a separate controller. Examples may include your internet provider, browser provider or email provider. Their handling practices are governed by their own notices and are outside our direct control.

3. Information we may collect

3.1 Information stored in your browser

The website uses local browser storage to remember whether you confirmed that you are at least 18 and whether you accepted or declined non-essential cookies. These values are stored on your device and are read by the website on later visits. The current website does not use these values to identify you by name.

3.2 Technical request and security information

When a website is delivered through a web server or hosting provider, technical records may be created automatically. Depending on the hosting configuration, such records may include an IP address, request date and time, requested file, response status, transferred data volume, browser type, operating system, referring page, general device information and security-event information. These records may be necessary to deliver the site, diagnose errors, prevent abuse and protect the service.

3.3 Information you choose to provide

If you contact us, we may receive the information contained in your message, such as your name, email address, the content of your request, supporting material and any other information you voluntarily provide. Please do not send sensitive information, identity documents, payment information or information about another person unless it is necessary and lawful to do so.

3.4 Game interaction information

The supplied mini game runs locally in the same website project and uses randomly generated game outcomes, virtual balances and interface state. The current build does not require an account and does not transmit game outcomes to an external analytics, advertising or payment service. If the site is later changed to add telemetry, analytics, advertising, cloud saves or accounts, this policy and the consent interface must be updated before those features are activated.

4. Why we use information

We may use information only for defined and legitimate purposes, including:

  • delivering website files and the embedded game to your browser;
  • remembering age confirmation and privacy preferences;
  • responding to enquiries, complaints and legal requests;
  • maintaining security, detecting technical faults and preventing misuse;
  • establishing, exercising or defending legal claims;
  • meeting applicable legal, regulatory, accounting and record-keeping duties; and
  • improving accessibility, reliability and compatibility using aggregated or de-identified information where reasonably possible.

We do not sell personal information. The current website does not use behavioural advertising, third-party tracking pixels, cross-site profiling or automated decision-making that produces legal or similarly significant effects.

5. Lawful bases under the GDPR

Where the GDPR applies, processing must have a lawful basis. Depending on the context, we may rely on one or more of the following:

  • Consent: where you make a genuine, informed and specific choice, including a future optional analytics feature. Consent may be withdrawn without affecting processing that was lawful before withdrawal.
  • Contract or pre-contract steps: where processing is necessary to provide a service you requested or to respond before entering into an agreement.
  • Legal obligation: where applicable law requires us to retain, disclose or otherwise process information.
  • Legitimate interests: where necessary for secure website operation, fraud prevention, service integrity, error diagnosis, legal defence or proportionate business administration, provided those interests are not overridden by your rights and freedoms.
  • Vital interests or public task: only in the unusual circumstances where the relevant legal conditions are met.

Strictly necessary browser storage used to remember a privacy choice or age confirmation is used to provide the requested site functionality and maintain the integrity of the access controls. Optional non-essential storage will not be activated merely because you continue browsing.

6. Data minimisation, accuracy and privacy by design

We aim to collect only information that is reasonably necessary for the stated purposes, keep it accurate where accuracy matters, limit access, and design the service so that privacy-protective settings are the default. The current website avoids registration, payment collection, third-party advertising scripts and remote font or script services. All front-end assets are stored within the project.

7. Disclosure and service providers

We may disclose limited information to service providers that support hosting, infrastructure security, error investigation, professional advice, legal compliance or business continuity. Providers may process information only for authorised purposes and should be subject to appropriate confidentiality, security and data-protection obligations.

We may also disclose information when reasonably necessary to comply with law, respond to a lawful authority, protect a person’s safety, investigate misuse, enforce our terms, or establish, exercise or defend legal claims. We do not disclose information to data brokers for sale.

8. International data transfers

The operator is based in Australia. A visitor may access the site from another country, and infrastructure or professional service providers may operate in multiple jurisdictions. Where the GDPR applies to a restricted transfer of personal data outside the European Economic Area, we will use an available lawful transfer mechanism where required, such as an adequacy decision, approved standard contractual clauses, or another permitted safeguard, together with supplementary measures where appropriate.

No transfer mechanism can remove every risk created by foreign law or internet transmission. We assess transfers proportionately and seek to minimise the information involved.

9. Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, security and dispute-resolution requirements. Browser choices remain on your device until you clear site data, use browser controls, or the storage is otherwise removed. Enquiry correspondence may be retained while the matter is active and for a reasonable period afterwards to document the response and protect legal rights. Server security logs, if enabled by the host, should be retained for a limited operational period unless a specific incident or legal obligation requires longer retention.

When information is no longer required, we take reasonable steps to delete it, anonymise it or place it beyond practical use, subject to lawful backup cycles and mandatory retention obligations.

10. Security

We use reasonable technical and organisational measures appropriate to the nature of the service and the risks involved. Measures may include local asset hosting, access restrictions, software maintenance, secure configuration, backups, logging, incident response and minimisation of collected data. No website, device or transmission method is completely secure, and we cannot guarantee absolute security.

If we become aware of a personal-data breach, we will investigate and take steps required by applicable law. Where notification thresholds are met, affected individuals and the relevant regulator will be notified within the applicable timeframe.

11. Your privacy rights

Depending on your location and the law that applies, you may have rights to:

  • request access to personal information we hold about you;
  • request correction of inaccurate or incomplete information;
  • request deletion or restriction of processing in qualifying circumstances;
  • object to processing based on legitimate interests or to direct marketing;
  • receive certain information in a structured, commonly used and machine-readable format and request portability where applicable;
  • withdraw consent at any time where consent is the lawful basis;
  • not be subject to certain solely automated decisions with legal or similarly significant effects; and
  • complain to a competent supervisory authority.

These rights are not absolute. We may need to verify identity proportionately, clarify the request, retain information required by law, or decline a request where a lawful exception applies. We will explain the relevant reason where permitted.

12. How to exercise a right

Send a clear request to info@magicmatchrooms.com. State the right you wish to exercise, the relevant interaction or approximate date, and enough information for us to locate the records without asking for unnecessary data. We may request limited verification to prevent unauthorised disclosure. Where the GDPR applies, we normally respond without undue delay and within one month, subject to permitted extensions for complex or multiple requests. Australian access and correction requests will be handled within a reasonable period.

13. Children and age restriction

The website is intended only for users aged 18 or older. We do not knowingly solicit personal information from children through this site. A visitor who indicates that they are under 18 is directed away from the website. If you believe a child has provided personal information, contact us so that we can investigate and take appropriate action.

14. Cookies and local storage

The current site uses local browser storage for age and cookie-choice preferences. It does not activate advertising, third-party analytics or cross-site tracking cookies. Detailed information, including storage names and preference controls, appears in the Cookie Policy. Rejecting non-essential cookies does not block access to the free website, although strictly necessary preference storage may still be used to remember the rejection.

15. Complaints

Please contact us first at info@magicmatchrooms.com so we can investigate. We aim to acknowledge a privacy complaint promptly and provide a reasoned response after reviewing the relevant facts. In Australia, eligible complaints may be raised with the Office of the Australian Information Commissioner. In the European Economic Area or United Kingdom, you may also lodge a complaint with the supervisory authority responsible for your habitual residence, place of work or the alleged infringement.

16. Changes to this policy

We may update this policy when the website, law, technology or our practices change. The “Last updated” date identifies the current version. Material changes will be presented appropriately before they take effect, and renewed consent will be requested where required. Archived versions may be retained for compliance and dispute-resolution purposes.

17. Contact

Privacy enquiries: info@magicmatchrooms.com

Postal address: Magic Match Rooms Digital Entertainment Pty Ltd, Level 10, 20 Martin Place, Sydney NSW 2000, Australia

Magic Match-room

Free fantasy entertainment for Australian adults. Virtual crystals only; no deposits, purchases, withdrawals or cash prizes.

Website operator Magic Match Rooms Digital Entertainment Pty Ltd Level 10, 20 Martin Place, Sydney NSW 2000, Australia info@magicmatchrooms.com
Support resources GamCare GambleAware GAMSTOP
Privacy Policy Terms & Conditions Cookie Policy Responsible Play

© 2026 magicmatchrooms.com. All rights reserved.

18+ · Free play · No real-money prizes

Privacy choice

Important notice about cookies

This website uses strictly necessary local browser storage to remember your age confirmation and cookie choice. No advertising or third-party tracking cookies are active.