Legal

Privacy Policy

What we collect, why, who sees it, and what you can ask us to do about it.

Last changed 2 September 2026

1. Who controls your data

Open Standard LLC, a Wyoming limited liability company, is the controller of the personal data described here. It operates slop.com and slop.us, and this policy covers both. You can reach us about your data at SUPPORT_EMAIL, or by post at Open Standard LLC, 30 N Gould St Ste N, Sheridan, WY 82801, United States.

We have not appointed a data protection officer, and we have not appointed a representative in the European Union or the United Kingdom.

2. What we collect

We collect the following, and this list is meant to be exhaustive rather than illustrative.

  • ACCOUNT: your email address, a cryptographic hash of your password (never the password itself), when the account was created, whether the email has been confirmed, which site the account belongs to, and the optional public username you choose. On slop.us we also collect your date of birth, because the sweepstakes is open to people aged 21 or older. It is stored and never shown back on the site.
  • PREFERENCES: whether you hide your statistics from other players, the games you have saved as favourites, your play limits, breaks from play, and any activity reminder you have set.
  • SESSIONS: a hash of each session token, when it was issued, when it expires, and whether it was revoked. The token itself is not stored.
  • SIGN-IN ATTEMPTS: failed sign-in attempts against an email address, with the time and the network address they came from, so that a password cannot be guessed without limit and so that an attack across many accounts from one place can be slowed. These are deleted when you sign in successfully.
  • SECURITY: if you enable an authenticator app, the secret that app shares with us and the recovery codes we give you, stored in a form we can check but not read back.
  • MONEY: deposit addresses issued to you, transactions credited to your balance, your balances by asset, withdrawals and their destination addresses, and the one-time codes issued to authorise them. On slop.us, your Gold Coin purchases, Sweeps Coin grants and redemption requests.
  • REDEMPTIONS ON SLOP.US: the legal name, state of residence and payout address you give us with a redemption request. Prizes are paid to identified winners.
  • MAIL-IN ENTRIES ON SLOP.US: the entry codes you generate, and for each card we receive, the state and date of its postmark. We do not keep the mailing address written on the card once the card has been read.
  • PLAY: every bet, meaning the game, the stake, the parameters you chose, the seeds and nonce, the result and the settlement.
  • LOCATION: the approximate location we read from your connection on each request, which is the country and, in the United States, the state. We use it to apply the territory rules. It is not stored on your account.
  • TECHNICAL: the requests your browser makes to us, and the errors they produce.

We do not collect identity documents or biometric data, because we do not run automated identity verification. If we ask you for a document by email when reviewing a withdrawal or a redemption, we keep what you send with the record of that review.

We do not collect precise device geolocation. We do not run behavioural or keystroke profiling.

3. Why we use it, and on what basis

  • To operate your account, hold your balance, settle your bets and pay your prizes, because it is necessary to perform our contract with you.
  • To keep the site and your account secure, including the sign-in throttle and the one-time code on withdrawals, because we have a legitimate interest in preventing account takeover and fraud, and so do you.
  • To apply the age and territory rules of each site, because we have a legal obligation to and a legitimate interest in offering the site only where we may.
  • To keep the records of bets, balances and transactions that the law requires us to keep, because we have a legal obligation.
  • To detect and prevent money laundering and the funding of crime, and to report where required, because we have a legal obligation.
  • To operate the responsible gambling controls you ask for, because it is necessary to perform our contract with you.

We do not sell personal data. We do not share it with advertisers. We do not build advertising profiles.

4. Blockchain data, which is public and permanent

A deposit, a withdrawal or a prize payment is a transaction on a public blockchain. The addresses involved, the amounts and the times are public, permanent, and outside the control of anybody, including us. Anyone can read them and nobody can erase them.

This has a consequence worth stating plainly. If you deposit from an address that is publicly associated with you, or withdraw to one, that association is public. We cannot undo it, and a deletion request to us cannot reach it.

We screen deposit and withdrawal addresses against risk data in order to meet our obligations. That screening links an address to your account in our records.

5. Who else sees it

We share personal data with the following.

  • The providers that run our infrastructure and deliver our email, who process it on our instructions and for no purpose of their own.
  • An automated review service that reads withdrawal requests held for review. It receives the amounts, timings, account age, deposit and play totals and destination address of the request, and uses a language model run by a third-party provider to produce a risk opinion for the person reviewing it. It does not receive your email address, your name or your network address, and it makes no decision on its own.
  • Any authority we are legally required to report or disclose to.
  • A professional adviser, or a company that acquires this business, where a transaction requires it and subject to confidentiality.

A report of suspicious activity is confidential by law, and we are generally prohibited from telling you one has been made.

6. Where it is held, and for how long

Data is processed in the United States and in the countries where our infrastructure providers operate. Where that involves a transfer out of the country you live in, it is made under the safeguards the law requires.

We keep account, transaction, bet and verification records for at least five years after an account closes, because the law on money laundering requires it. That period is longer than most people expect and it is not something we can shorten at your request.

Failed sign-in records are kept for minutes, not months. Bet records are kept for the full retention period, because they are the evidence of what a game paid.

7. Your rights

Depending on where you live, you can ask us to do the following.

  • Give you a copy of the personal data we hold about you.
  • Correct it where it is wrong.
  • Delete it, subject to the records we are required to keep, which is most of them.
  • Restrict or object to a use based on our legitimate interests.
  • Give you your data in a portable form.

Write to SUPPORT_EMAIL from the email address on your account. We will answer within the time the law allows, and we will tell you if we are refusing part of a request and why.

You can also complain to the data protection authority where you live. Doing so does not require you to complain to us first, though it usually helps.

8. Changes

We will publish a change here before it takes effect, and we will tell account holders directly where the change is material.