- Version
- 1.0
- Effective date
- 20 July 2026
- Last reviewed
- 20 July 2026
This Cookie Policy applies when you visit or use this website. It should be read with our Privacy Policy, which explains the wider handling of personal data. This policy describes the cookies and comparable storage technologies that may be used when you visit the website, browse editorial content, or follow registration links to external operators.
Where the law requires consent, non-essential cookies and similar technologies must not be activated before valid consent has been obtained. A user's refusal or later withdrawal must be respected as technically required. Strictly necessary technologies may operate without consent where they are genuinely required to provide a service requested by the user or to keep the service secure.
1. Scope, cookies and similar storage technologies
A cookie is a small text file that a website asks a browser to store on a device. Cookies can contain an identifier and limited information, allowing a website to recognise the same browser during a session or on a later visit. A "session" cookie normally expires when the browser is closed. A "persistent" cookie can remain until its configured expiry date or until it is deleted.
Websites can also use technologies that are not technically cookies but perform a related function. Examples include local storage, session storage, software development kit storage, pixels, tags and server-side identifiers. Local storage can retain information in a browser without attaching it automatically to every network request; session storage is generally limited to a browser tab or session. Pixels and tags may cause a browser to request a resource and can communicate information such as the page visited, approximate time, device characteristics or referring page.
In this policy, "cookies" is a convenient collective term for cookies and these comparable storage or access technologies. Whether information is personal data depends on what is stored, what it is combined with, and whether a person or device can be identified. The absence of a name does not necessarily mean that information is anonymous.
2. Technologies in use on this site
The editorial website at rivocasino.org.uk is designed to use a minimal set of first-party technologies. Anonymous browsing of guides and information pages does not require you to accept non-essential cookies. Registration, login and play take place on separate operator platforms; those services may set their own cookies when you follow an external link or complete a sign-up journey.
We review this inventory when the website, hosting, measurement tools or registration partners change. If a new non-essential technology is introduced, it should remain disabled until any legally required consent has been obtained.
3. Categories and purposes
Strictly necessary
These technologies support functions that are essential to provide a service expressly requested by a user or to operate the website safely. Depending on the audited implementation, legitimate examples of purpose may include maintaining a secure session, distributing traffic, remembering a privacy choice, preventing fraud or protecting forms. Classification must be based on necessity, not convenience: a technology does not become necessary merely because it benefits the business. These technologies are generally not optional, but unnecessary data collection must still be minimised.
Preferences and functionality
Preference technologies can remember non-essential choices, such as interface or display settings, so they do not need to be selected on each visit. The exact technologies, if any, must be confirmed by audit. Where consent is the applicable legal condition, they must stay off until the user opts in. Disabling them may mean that a preference needs to be entered again, but the website's core content should remain available where practical.
Analytics and measurement
Analytics technologies may measure visits, navigation, errors and performance to help understand how a service is used. Measurement can involve identifiers even when reports are aggregated later. Analytics should not automatically be labelled necessary simply because it helps improve a website. The audit must identify the data collected, configuration, recipients and safeguards. Where required, no analytics storage or access may occur before consent.
Marketing and personalisation
Marketing technologies may seek to measure campaigns, build an audience, limit repeated messages or tailor content across services. This category can create greater privacy risk because data may be combined across contexts. The editorial site does not set first-party marketing cookies. Third-party registration partners may set marketing or measurement technologies after you choose to visit them; those technologies are subject to the partner's own notices and consent rules.
4. First-party and third-party technologies
A first-party cookie is normally set or received by the domain shown in the browser's address bar. It may support functions operated directly for this website. A third-party cookie is set or received by another domain, often when a page loads an embedded service, media, measurement tag or other external resource. Similar distinctions apply to storage and network requests that are not cookies.
"First party" does not mean harmless, and "third party" does not by itself decide whether a technology is lawful. Purpose, necessity, data flows, controllership, retention and user expectations all matter. Where a registration partner or embedded service is involved, its privacy information should explain both the party that places or accesses a technology and any other party receiving the resulting information.
5. Cookie and storage inventory
The table below lists the main categories of cookies and comparable storage that may be encountered when using this website or following registration links. Names and durations may vary by browser, device and partner platform.
| Category | Name / storage key | Party / provider | Purpose | Duration | Consent status |
|---|---|---|---|---|---|
| Strictly necessary | None currently set for anonymous editorial browsing | Rivo Casino / hosting provider | Security, load balancing and service delivery | Session or up to 24 hours if used | Not required where strictly necessary |
| Preferences | Not currently used on the editorial site | — | Remember interface or display choices | — | Off until consent where required |
| Analytics | Not currently deployed | — | Measure visits, navigation and performance | — | Off until consent where required |
| Marketing | Set by registration partners after external link | Third-party operator / affiliate partner | Attribution, campaign measurement and personalisation | Varies by partner (typically 30–90 days) | Subject to partner notices and consent rules |
| Other local/session storage | Browser session storage only where needed for navigation | Rivo Casino | Temporary page state during your visit | Until browser tab is closed | Not required where strictly necessary |
6. Consent, refusal and withdrawing consent
Where consent is required, it must be freely given, specific, informed and indicated by a clear affirmative action. Consent should be granular enough to distinguish relevant non-essential purposes. Silence, inactivity, continued browsing or a pre-selected option should not be treated as agreement. Information should be available before the choice, and accepting should not be made artificially easier than refusing.
Where consent is required for non-essential technologies, you can refuse or withdraw consent through your browser settings or by contacting us. If an on-site cookie preference centre is introduced in future, it will be linked from this page. Until then, browser controls can remove or block stored information as described below, and you may use the Contact & Support page to ask how to withdraw a previous choice.
- Withdrawal should be as easy as giving consent.
- Withdrawal applies from that point onward and does not undo prior processing.
- Previously stored non-essential identifiers should be deleted or disabled where required.
- A minimal record may be needed to remember a refusal or withdrawal.
7. Browser and device controls
Most browsers let users inspect, delete or block cookies and clear local site data. Controls are usually found under privacy, security or site-data settings. Some browsers allow blocking all cookies, only third-party cookies, or data for a particular site. Private-browsing modes may reduce persistence but do not necessarily prevent every network request or form of storage.
- Open the privacy or site-data settings in the browser or device.
- Search for this website and review the data associated with it.
- Delete existing data, or configure blocking for future visits.
- Repeat the process in every browser, profile and device you use.
Blocking all storage can interrupt sign-in, security, navigation or remembered choices. Deleting a record that stores a privacy choice may cause the website to ask again. Browser interfaces change, so consult the current help material from your browser or device provider. Browser settings complement, but do not replace, the website's obligation to obtain consent before non-essential access where the law requires it.
8. Retention and data minimisation
Storage should last only as long as needed for its stated purpose. Session technologies may end when a browser or tab closes, while persistent technologies have a set lifespan. The configured expiry is not always the full retention period: information transmitted to a server may be retained separately, and a returning script may recreate storage. The final inventory must therefore distinguish browser lifetime from server-side retention where relevant.
Retention periods cannot be stated accurately until the audit is complete. Each period must be justified, tested and kept under review. Data should be limited to what is necessary, protected against unauthorised access and deleted or irreversibly anonymised when no longer needed. More information about personal data retention and individual rights belongs in the Privacy Policy.
9. Do Not Track and global privacy controls
Some browsers send a Do Not Track signal, and some products send Global Privacy Control or other preference signals. Legal recognition and technical meaning can vary by jurisdiction and signal. We honour recognised signals where applicable law requires us to do so.
A recognised signal should be honoured where applicable law requires it. Even where a signal is not legally determinative, it can provide useful evidence of a user's preference and should be considered in privacy-by-design decisions. Such signals do not justify setting non-essential technologies before consent, and they should not be described as a substitute for clear on-site information and controls.
10. Policy updates and contact
We may update this policy when technologies, purposes, suppliers, legal requirements or website features change. Material changes should be highlighted appropriately, and fresh consent should be requested where an existing choice does not cover a new purpose or party. The version, effective date and last-reviewed date above should be updated only after the revised text and technical behaviour have been checked.
Questions about this policy, cookie choices or privacy rights can be submitted through the Contact & Support page. Questions can also be sent to privacy@rivocasino.org.uk. Please do not include passwords, payment details or other unnecessary sensitive information in an enquiry.
