Privacy Policy

Privacy Policy

Shotz | shotz-nz.org.

Effective Date: 28 May 2026.

Last Updated: 28 May 2026.


1. Introduction

Welcome to Shotz. We are committed to protecting the personal information of every punter who visits or registers with our platform. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our website and services.

Shotz operates in accordance with the Privacy Act 2020 (New Zealand), which is the primary legislation governing how organisations collect and handle personal information in New Zealand. Where relevant, we also align our practices with internationally recognised data protection principles, including those reflected in the General Data Protection Regulation (GDPR), as many of our data processors and payment partners operate across international borders.

By accessing shotz-nz.org, creating an account, or using any of our services — including playing pokies or making transactions in NZD — you acknowledge that you have read and understood this Privacy Policy and consent to the practices described herein.

If you have any questions or concerns about this policy, please contact us at [email protected].


2. Who We Are

Shotz is an online gaming platform offering pokies and related entertainment services to players in New Zealand. References to "we," "us," or "our" throughout this document refer to Shotz and its associated operations accessible via our website.

We take our obligations under New Zealand law seriously, including our responsibilities to the Department of Internal Affairs and the Gambling Commission NZ, who oversee responsible gambling and licensing compliance in this jurisdiction.


3. The Information We Collect

We collect personal information only when it is necessary for a lawful purpose connected with our services, and only to the extent that is necessary for that purpose, consistent with Information Privacy Principle 1 of the Privacy Act 2020.

3.1 Information You Provide Directly

  • Account registration details: Full name, date of birth, email address, phone number, and residential address.
  • Identity verification documents: Copies of government-issued photo ID, proof of address, and any documentation required for Know Your Customer (KYC) and Anti-Money Laundering (AML) compliance under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act).
  • Payment information: Details related to your chosen payment method, which may include bank account details for POLi or bank transfer transactions, card details for Visa/Mastercard payments, Neosurf voucher references, or cryptocurrency wallet addresses. We do not store full card numbers on our servers.
  • Responsible gambling information: Self-exclusion requests, deposit limits, cooling-off periods, and any information you provide when using our responsible gambling tools.
  • Communications: Messages sent to our support team at [email protected], live chat transcripts, and any feedback or complaints you submit.

3.2 Information We Collect Automatically

  • Device and technical data: IP address, browser type and version, operating system, device identifiers, and screen resolution.
  • Usage data: Pages visited, pokies played, time spent on site, click patterns, session duration, and navigation paths.
  • Transaction data: Deposit and withdrawal history, amounts transacted in NZD, transaction timestamps, and payment method used.
  • Cookies and tracking technologies: See Section 9 for full details on our use of cookies.

3.3 Information from Third Parties

  • Payment providers: Transaction confirmation and fraud-check data from POLi, Visa/Mastercard networks, Neosurf, crypto payment processors, and banking partners.
  • Identity verification services: Results from third-party KYC providers used to verify your identity and age.
  • Fraud prevention and AML partners: Risk scores and alerts from compliance screening services.
  • Publicly available sources: Information from public records where required for compliance purposes.

4. How We Use Your Information

We use your personal information for the following purposes:

PurposeLegal Basis
Creating and managing your accountContract performance
Processing deposits and withdrawals in NZDContract performance
Verifying your identity and age (18+)Legal obligation (AML/CFT Act)
Detecting and preventing fraud and money launderingLegal obligation & legitimate interest
Providing customer supportContract performance & legitimate interest
Personalising your pokies experienceLegitimate interest & consent
Sending promotional offers and bonuses (where opted in)Consent
Complying with regulatory reporting obligationsLegal obligation
Enforcing our Terms and ConditionsLegitimate interest
Analysing usage to improve our platformLegitimate interest
Operating our responsible gambling programmeLegal obligation & legitimate interest

We do not use automated decision-making processes that produce legal or similarly significant effects without human review.


5. Responsible Gambling and Sensitive Data

We take responsible gambling seriously. If you use our self-exclusion, deposit limit, or time-out features, the information you provide is treated with the highest level of care and confidentiality.

Information relating to problem gambling behaviour is considered sensitive personal information. We use this data solely to:

  • Enforce restrictions you have.
  • Refer you to appropriate support.
  • Comply with our regulatory obligations under the Gambling Act 2003.

If you or someone you know needs support, please contact the Problem Gambling Foundation helpline: 0800 664 262. This free, confidential service is available to all New Zealanders.

We may share relevant information with the Department of Internal Affairs or the Gambling Commission NZ if required by law or in response to a lawful regulatory request.


6. Sharing Your Information

We do not sell your personal information. We may share it with the following categories of third parties, strictly for the purposes described in this policy:

  • Payment processors: POLi, Visa/Mastercard acquiring banks, Neosurf, cryptocurrency processors, and bank transfer partners — to facilitate your financial transactions.
  • Identity and KYC verification providers: To confirm your identity, age, and eligibility to play pokies on our platform.
  • AML/CFT compliance partners: To meet our obligations under New Zealand's anti-money laundering laws.
  • IT and hosting providers: Cloud infrastructure and data storage providers who process data on our behalf under strict data processing agreements.
  • Customer support platforms: Tools used to manage support tickets and live chat, bound by confidentiality obligations.
  • Regulatory authorities: The Department of Internal Affairs, the Gambling Commission NZ, New Zealand Police, or other authorities when required by law, court order, or to protect the safety of users and the public.
  • Professional advisers: Legal counsel, auditors, and accountants, subject to professional confidentiality obligations.

Where we share data with parties located outside of New Zealand, we take steps to ensure that the overseas recipient is required to protect the information in a manner comparable to the Privacy Act 2020, consistent with Information Privacy Principle 12.


7. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

  • Account information: Retained for the duration of your account and for a minimum of 7 years after account closure, to comply with AML/CFT obligations and tax recordkeeping requirements.
  • Transaction records: Retained for a minimum of 7 years in accordance with New Zealand financial recordkeeping obligations.
  • Identity documents: Retained for the period required under the AML/CFT Act, typically 5 years from the end of the business relationship.
  • Support communications: Retained for 3 years from the date of the interaction.
  • Marketing preferences: Retained until you withdraw consent or request removal.

When your information is no longer required, we securely delete or anonymise it.


8. Your Privacy Rights

Under the Privacy Act 2020, you have the following rights in relation to your personal information:

  • Right of access: You may request a copy of the personal information we hold about you at any time.
  • Right to correction: If your information is inaccurate or incomplete, you may request that we correct it.
  • Right to complain: If you believe we have interfered with your privacy, you have the right to make a complaint to us and, if unsatisfied with our response, to the Office of the Privacy Commissioner (privacy.org.nz).
  • Right to withdraw consent: Where our processing is based on your consent (such as marketing communications), you may withdraw that consent at any time without affecting the lawfulness of prior processing.
  • Right to opt out of direct marketing: You may unsubscribe from promotional emails at any time by clicking the unsubscribe link in any marketing email or by contacting us at [email protected].

To exercise any of these rights, please contact us at [email protected]. We will respond within 20 working days, as required by the Privacy Act 2020. In complex cases, we may extend this period and will notify you accordingly.

We may need to verify your identity before processing your request. This is to protect your information from unauthorised access.


9. Cookies and Tracking Technologies

Shotz uses cookies and similar technologies to operate our website, improve user experience, and deliver relevant content.

9.1 Types of Cookies We Use

  • Essential cookies: Necessary for the website to function. These cannot be disabled and include session management and security cookies.
  • Performance cookies: Help us understand how punters use our site, including which pokies are most popular and where technical issues arise. Data collected is aggregated and anonymous.
  • Functionality cookies: Remember your preferences, such as language settings and previously visited game categories.
  • Marketing and targeting cookies: Used to deliver relevant promotional content, including bonus offers, based on your activity. These are only placed with your consent.

9.2 Managing Cookies

You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of our website. You can update your cookie preferences at any time using the cookie consent tool displayed when you first visit our site.


10. Security of Your Information

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, alteration, or disclosure. These measures include:

  • SSL/TLS encryption for all data transmitted between your device and our.
  • Secure, access-controlled data storage with role-based.
  • Regular security assessments and vulnerability.
  • Staff training on data protection and confidentiality.
  • Two-factor authentication options for account.

While we take all reasonable steps to protect your data, no system is completely infallible. If you believe your account has been compromised, please contact us immediately at [email protected].

In the event of a privacy breach that is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as required under the Privacy Act 2020's mandatory breach notification provisions.


11. Children and Minors

Our services are strictly for individuals aged 18 years and over. We do not knowingly collect personal information from anyone under 18. Age verification is conducted as part of our registration and KYC process.

If we become aware that we have collected information from a person under the age of 18, we will promptly delete that information and close the relevant account. If you believe a minor has registered on our platform, please notify us at [email protected].


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or regulatory guidance. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this.
  • Display a prominent notice on our.
  • Where appropriate, notify registered users by email at the address associated with their.

Your continued use of our platform after any such changes constitutes your acceptance of the updated policy. We encourage you to review this page periodically.


13. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or your personal information, please contact our Privacy team:

Email: [email protected].

Website: shotz-nz.org.

We aim to respond to all privacy-related enquiries within 5 working days and to resolve requests within the timeframes prescribed by the Privacy Act 2020.

If you are not satisfied with our response, you have the right to lodge a complaint with the:

Office of the Privacy Commissioner.

New Zealand's independent authority for privacy matters.

You may also raise concerns relating to gambling compliance with the Department of Internal Affairs or the Gambling Commission NZ.

Shotz responsible gaming