Privacy Policy
How LottoBC Mobile collects, uses, discloses and protects your personal information under the Freedom of Information and Protection of Privacy Act (British Columbia).
-
1. Who we are, and where this policy applies
This website and all gambling services are operated by the British Columbia Lottery Corporation (BCLC), a Crown corporation of the Province of British Columbia, at 74 West Seymour Street, Kamloops, BC, V2C 1E2, Canada. As a public body, BCLC handles personal information in accordance with the Freedom of Information and Protection of Privacy Act (British Columbia) ("FIPPA"). This policy applies to lottobcmobile.co and to promo.lottobcmobile.co.
Data controller / public body: British Columbia Lottery Corporation (BCLC)
Privacy Officer, BCLC, 74 West Seymour Street, Kamloops, BC V2C 1E2, Canada
privacy@lottobcmobile.co
General account enquiries can be sent to support@lottobcmobile.co; privacy requests should go to the Privacy Officer. -
2. Information we collect
We collect: identity and contact information (full name, date of birth, residential address in British Columbia including city and postal code, phone, email); verification / KYC information (identity documents, age and residency verification results, credit-bureau match results and, where relevant, source-of-funds information); account and transaction information (username, hashed password, deposits/withdrawals, limited payment instrument details, transaction history and the limits you have set); gambling activity (entries, plays, selections, time spent, wins and losses, responsible-gambling choices); compliance and integrity information (Game Break / Voluntary Self-Exclusion status, AML monitoring, fraud and risk assessments, support communications); location and residency information used to confirm you are within British Columbia; and technical data (IP address, device and browser information, cookies and similar technologies).
-
3. Purposes and authority for collection
We collect personal information under section 26 of FIPPA, because it relates directly to and is necessary for a program or activity of a public body authorized by the Gaming Control Act (British Columbia). Section 27 of FIPPA requires us to tell you the purpose of the collection, the legal authority for it, and who to contact about it — that is the purpose of this section and of the Privacy Officer details above.
We use personal information to provide the gambling service and manage your Account; verify your identity, age and British Columbia residency (KYC); meet legal obligations under the AML legislation and report to FINTRAC; maintain game integrity and fairness; meet our obligations as a Crown corporation overseen by the Independent Gambling Control Office (IGCO); support responsible gambling and administer Game Break (Voluntary Self-Exclusion); prevent fraud and ensure security; and, with your consent, send marketing. -
4. Marketing and consent
We send commercial electronic messages only where you have opted in, consistent with Canada's Anti-Spam Legislation (CASL). Consent is granular and is collected as two separate consents: (1) product news about LottoBC Mobile, and (2) promotional offers, bonuses and other inducements. Under B.C. Reg. 215/2025 the direct marketing of an inducement requires its own separate written consent, with a mechanism to withdraw it; ticking the box for product news never enables promotional offers, and neither box is ever pre-ticked. Every message identifies the sender by its full legal name, gives its mailing address and at least one further contact valid for at least 60 days, and contains a working unsubscribe link; unsubscribe requests are actioned within 10 business days. We keep evidence of each consent — date, time, IP address and the exact wording that was shown. Our marketing is directed at adults (19+), excludes minors, and is targeted only at British Columbia. You can change your preferences in your account at any time.
-
5. Automated monitoring and profiling
We analyse account and play data automatically for three purposes: anti-money-laundering monitoring, fraud and account-takeover detection, and the detection of markers of harm associated with problem gambling. The data analysed is limited to deposit, withdrawal and play activity, session times and frequency, changes to limits, device and location signals, and the results of previous checks. The consequences for you may include a request for further information, a temporary restriction on deposits or play, a targeted responsible-gambling message, or a referral to support services. No decision to close an account, void a play or refuse a withdrawal is made by the system alone: automated output is reviewed by a member of staff before any such decision takes effect, and you may ask for that decision to be reviewed by a person and explained to you.
-
6. Location information
We confirm that you are within British Columbia each time you register, deposit or play. We do so from your IP address and, where your device offers it and you permit it, from GPS or Wi-Fi positioning. Location is checked at registration, at each login and before a deposit or play. We keep the result of each check — the province determined, the method used and the timestamp — together with the IP address, for 12 months for compliance and audit purposes, and we do not build a movement history from it. If a check does not confirm that you are in British Columbia, registration, deposits and play are refused; informational pages remain available. You may dispute a location decision through Customer Support and we will review it.
-
7. Disclosure to third parties
We do not sell your information. We disclose it only where necessary: to payment providers; to KYC / verification providers; to FINTRAC; to the Independent Gambling Control Office; and to law-enforcement or regulators where required by law. Service providers act under contract on our behalf, are permitted to use the information only for the purpose we engaged them for, are bound to the security requirements of FIPPA section 30, must notify us of any privacy incident without delay, and must return or destroy the information at the end of the engagement.
-
8. Storage and cross-border handling
The primary database, backups and archive copies are located in Canada.
Categories of service provider and the country in which each processes personal information: payment processing — Canada; identity and age verification (KYC) — Canada; hosting and backup — Canada; email delivery for transactional and consented marketing messages — Canada; customer support tooling — Canada.
Where processing outside Canada becomes necessary, it is carried out only on the authority of section 33.1 of FIPPA, and only after a documented assessment of the disclosure, which records what information is involved, the jurisdiction it goes to, the authority relied on and the safeguards applied. A summary of that assessment is published in this section before the processing begins. This applies in particular to analytics or advertising tags such as Google Analytics 4 and Google Ads, which transfer data to the United States: none is in use, and none will be enabled before the assessment has been completed and documented.
Contractual obligations on providers: written agreement before any personal information is shared; use restricted to our documented instructions; no onward transfer without our written consent; security controls consistent with FIPPA section 30; notification of any privacy incident without unreasonable delay; audit and inspection rights; and return or secure destruction of the data on termination. -
9. Retention
We keep personal information only as long as necessary for the purposes described above and to meet legal obligations. Retention by category:
KYC and AML records, including identity documents and transaction records — 5 years from the closure of the account or the transaction, as required by the PCMLTFA.
Play and betting history — 5 years from the date of the play.
Game Break (Voluntary Self-Exclusion) records — for the term of the exclusion plus 7 years.
Account and profile data — for the life of the account plus 24 months after closure.
Access and security logs — 12 months.
Location-check results — 12 months.
Consent records for cookies — at least 24 months.
Marketing consent and unsubscribe records — 3 years from the withdrawal of consent, as evidence of compliance with CASL.
Customer support correspondence — 24 months.
When no longer required, information is securely destroyed or de-identified. -
10. Your rights and how to make a request
Under FIPPA you may request access to, and correction of, your personal information. A request for access must be made in writing — by email to privacy@lottobcmobile.co or by post to the Privacy Officer at the address above — and should describe the records you are looking for. To protect your privacy we may ask you to verify your identity before responding. We respond within 30 days, the time limit set by section 7 of FIPPA. That limit may be extended in the circumstances FIPPA permits; if we extend it, we tell you why and when to expect the response. There is no charge for access to your own personal information. If we refuse a request in whole or in part, we tell you the reason, the provision of FIPPA relied on, and that you may ask the Office of the Information and Privacy Commissioner for British Columbia to review the decision.
-
11. Security and privacy breaches
We use technical and organisational measures — including encryption in transit and at rest, access controls, logging and staff training — and we operate a privacy management program covering accountability, training, incident response and periodic review.
If a privacy breach occurs and it could reasonably be expected to result in significant harm to an affected individual, we notify the affected individuals and the Office of the Information and Privacy Commissioner for British Columbia without unreasonable delay. Our internal target is to assess and, where the threshold is met, report within 72 hours of the breach being discovered. We maintain a register of all privacy breaches, including those that do not meet the notification threshold, and retain it for review by the Commissioner. -
12. Privacy Impact Assessments
Before we introduce a new system, program or activity that involves personal information, or make a significant change to an existing one, we complete a Privacy Impact Assessment. New processing is not launched until the assessment has been completed and any recommendations have been addressed.
-
13. Cookies
See our Cookies Policy for details of cookies and similar technologies, the categories we use, how long consent lasts and how to withdraw it through "Manage cookies" in the footer.
-
14. Minors
Our services are for persons aged 19 and over only. We do not knowingly collect information from minors. Where we establish that an account holder is under 19, the account is closed, plays are void and information collected is retained only as long as necessary to document the closure and meet our regulatory obligations.
-
15. Complaints
If you have a privacy concern, contact our Privacy Officer first at privacy@lottobcmobile.co. We acknowledge a privacy complaint within 2 business days and give a substantive answer within 30 days. If it remains unresolved, you may complain to the Office of the Information and Privacy Commissioner for British Columbia (OIPC): PO Box 9038, Stn. Prov. Govt., Victoria, BC V8W 9A4; telephone 250-387-5629 or toll-free in B.C. 1-800-663-7867; email info@oipc.bc.ca; complaint and review forms are published at oipc.bc.ca.
-
16. Changes and contact
We may update this Policy from time to time. The current version is always available here, with its effective date and version number, and previous versions are listed in the change log below. Privacy enquiries: Privacy Officer, BCLC, 74 West Seymour Street, Kamloops, BC V2C 1E2, Canada, privacy@lottobcmobile.co.
Change log
| Version | Date | What changed |
|---|---|---|
| 2.0 | 26 August 2026 | Named the data controller and Privacy Officer; replaced GDPR wording with the FIPPA authority for collection; expanded storage and cross-border handling; added retention periods by category, the access-request procedure, breach notification, automated monitoring, location collection, granular marketing consent, Privacy Impact Assessments, OIPC contact details and the scope of the two domains. |
| 1.0 | 25 June 2026 | First published version of the Privacy Policy. |