Your data

We never receive your players' names.

Not at any stage. Not for any deliverable. It is a design decision, not a promise to be careful.


How it works

You hash. We analyse. You re-identify.

You generate a salted hash of your player number before anything leaves your building, and you keep the salt and the key map. Everything we hand back is keyed to your hash, so you re-identify it inside your own systems to run the mail, the email or the host call.

We run a property of our own. We know exactly what your database is worth and exactly why handing it to another operator would be an unreasonable thing to do. So the engagement is built so that you never have to.

Four tiers. Two of them never move.

00

Public

Trade-area demographics, competitor counts, published financials, industry benchmarks. No agreement required.

01

Aggregate

Segment-level counts and averages. No player rows at all. This covers qualification and the opening work of an audit.

02

Pseudonymized

The working file. Hashed identifiers and behaviour. We never receive your salt or your key map.

03

Identified — stays with you

Exists only inside your environment. If a campaign needs identified records, it happens on your systems, under your credentials, with your staff. Many engagements never reach this tier.

The detail

Everything below is published because it should be checkable.

Exactly what a working file containsEvery field is either non-identifying or a true-or-false flag.+
Identity and geography
Hashed player identifier. Tier or segment code. Months since enrolment. Distance band from the property, banded rather than an address. Postal or ZIP prefix only, and only where the trade area is dense enough that a prefix cannot re-identify a household.
Value and behaviour
Trips in total and by month. Coin-in in total and by month. Theoretical win. Actual win. Average bet, time on device, trip length. Game families by share of coin-in. Days since last visit.
Reinvestment and cost
Free play issued and redeemed. Comps issued and redeemed by category. Promotional and gift cost attributed to the player. Non-redeemable played. Offer response by offer code.
Contactability
Flags only. Email on file. Email opted in. Address on file. Address validated. Phone on file. SMS opted in. Self-excluded or restricted, and those rows are excluded from every targeting deliverable we produce.
How AI is usedWe use it heavily. You should know precisely what that means for your data.+
What reaches a model
Hashed identifiers and behavioural fields. Never a name, never an address, never a contact detail, because we do not hold any.
Which systems
Commercial and enterprise tiers of established providers, under terms that exclude customer content from model training. The providers and governing terms are named in the data-handling addendum, and we tell you in writing before any of them change.
Where it sits
A per-client encrypted workspace. No shared workspace, no cross-client pooling, and no combining one client's data with another's for any purpose, including benchmarking, without separate written consent.
What we never do
No consumer AI accounts for client work. No pasting client data into free or personal tools. Your data never trains, tunes or improves any model, ours or a vendor's, and never informs work for another property.
Our own floor, in reverse
Benchmarks drawn from our property are aggregate only. No client ever receives unit-level data from another operator, and that includes us.
Transfer, access, retention and destructionThe operational commitments, in plain terms.+
Transfer
Through a channel your IT approves. Our preference is a shared folder inside your own cloud tenant, where you grant named guest access and revoke it in one click, because nothing then leaves your perimeter. Secure file transfer into a client-specific directory is the alternative. Never email attachments. Never a drive handed over at a conference.
Access
Named individuals only, listed in the addendum and updated in writing. Multi-factor authentication. Logged. No personal devices, no personal cloud storage.
Retention
Ninety days past acceptance of the deliverable by default. Longer only where the engagement requires it and you have agreed in writing.
Destruction
Certified in writing within thirty days of termination, covering every copy including working files and backups.
Breach
Notification within twenty-four hours of discovery, with what we know at that point rather than after an internal investigation concludes.
Audit and insurance
You may audit our handling on reasonable notice, for the life of the engagement and twelve months after. Cyber and errors-and-omissions cover naming you as additional insured.
Tribal data sovereigntyAsked at the outset rather than discovered late.+
Sovereignty
We ask early whether your nation asserts sovereignty over information generated on tribal land, and whether it must remain within tribal systems or tribal jurisdiction. If it does, that requirement governs and everything above bends to it.
Vendor licensing
We complete tribal gaming agency vendor licensing where the threshold applies, and we disclose these practices as part of that process.
Domicile
Our contracting entity is United States domiciled and client data is held in United States infrastructure. Where your jurisdiction imposes additional obligations, those are addressed in the addendum rather than assumed away.

If anything here falls short of your standard, tell us and we will meet yours instead.