Privacy policy
Effective September 27, 2026 · G & M Enterprises LLC
This policy explains what information Card Room Pro collects, why, and what you can do about it. It covers this website, the Card Room Pro web app and the Card Room Pro iPad app. Card Room Pro is operated by G & M Enterprises LLC.
Who this policy is for
Three groups of people interact with Card Room Pro. Staff of a card room use the apps for work. Players have records held by the card room they visit. Visitors to this website may contact us or ask for a walkthrough.
For player records, the card room is the data controller and Card Room Pro is its processor. We hold that data on the room’s instructions and under a written agreement with the room. Requests about a player record should go to the card room first; we will help if you cannot reach them.
What we collect from staff
Your name, work email address, role and the room you belong to, as set up by your Room Admin. Sign-in events, including the time, the sign-in method (Microsoft or Card Room Pro) and the device role. Actions you take in the app, such as seating a player or adjusting points, are recorded in the room’s audit log against your name.
What we hold about players
On behalf of each card room: the player’s name, contact details, date of birth, government ID details captured at registration, an optional photo, membership number and tier, loyalty points and their history, seating and session history, waitlist entries, tournament entries and results, and any status such as a ban or self-exclusion together with the reason and the staff member who set it.
Government ID is stored encrypted with a key specific to the room and is masked in the apps by default. Only staff whose role allows it can view it, and each view is logged.
What we collect on this website
If you ask for a walkthrough or contact support we collect what you type into the form: your name, role, card room, email, phone and message. Our hosting provider keeps standard server logs, including IP address, browser type and the pages requested, for security and to keep the site running. We do not use advertising cookies or third-party analytics on this site.
How we use it
To provide the service to the card room: seating, waitlists, player records, loyalty, tournaments and reporting. To secure it: sign-in, permissions and the audit log. To support you: answering enquiries and fixing problems. To run our business: billing the card room and meeting our legal obligations. We do not sell personal information and we do not use it for advertising.
Where it is stored and who can see it
Data is stored in Microsoft Azure data centres in the United States. Each card room has its own database. Data is encrypted in transit and at rest. Player photos and room logos are stored in private storage that cannot be reached by URL; the app streams them to signed-in users.
We use Microsoft Entra to sign staff in with Microsoft accounts, Microsoft Azure for hosting, and Apple for distributing the iPad app. These providers process data only to provide their service to us. Our own staff can access room data only to support the room or to keep the service running, and that access is logged.
How long we keep it
Staff account details are kept while the account is active and deleted within 30 days of removal. Audit log entries are kept for the period the room’s regulator requires, because the room must be able to show who did what. Player records are kept for as long as the card room instructs, subject to the same regulatory retention. Website enquiries are kept for 12 months unless you ask us to delete them sooner.
Your choices and rights
Staff can see and correct their details through their Room Admin, and can ask for their account to be deleted (see Support). Players can ask the card room to see, correct or delete their record; the room may have to keep some records, such as self-exclusion and access logs, under its licence. California residents have rights under the CCPA to know, delete and correct personal information and to not be discriminated against for exercising them; we do not sell or share personal information as those terms are defined there. To exercise any right, email [email protected].
Children
Card Room Pro is for staff of licensed venues and for adults of legal gambling age in the venue’s jurisdiction. We do not knowingly hold information about anyone under that age. If a registration slips through, the card room deletes it and we help.
Security
Sign-in is by Microsoft Entra or a Card Room Pro account with a bearer token stored in the device keychain. Kiosks are paired with a one-time code and cannot reach anything beyond their table. All traffic is over HTTPS. Sensitive fields are encrypted with per-room keys that are rotated. We test the apps against the OWASP guidance and review access logs.
Changes to this policy
When we change this policy we update the effective date above and, for material changes, tell each card room’s Room Admin by email at least 30 days before the change takes effect.
Contact
G & M Enterprises LLC, operator of Card Room Pro. Email [email protected] for privacy matters or [email protected] for anything else.