Wincrown Guides

How to Protect Your Identity Documents

This page covers which channel to use for casino verification, how much of each document to send, and what to keep for yourself afterwards.

Australian player routeBonus and payments checkedMobile-first game guide

Quick answer

What matters on this page

Verification before a larger withdrawal is routine and mostly unavoidable. The exposure comes from sending more than the check requires, or sending it through a channel never built to receive identity documents.

Three habits cover most of the risk: upload inside the account, cover what the check does not need, and keep your own dated copy of what you sent.

An identity document is reusable by whoever ends up holding it, which is why a casino request deserves the same care as a bank one.

Upload inside the account, not over chat

Use the verification form in your own logged-in account. Email and chat attachments pass through systems with broader internal access and longer retention, so an agent asking you to email documents is a reason to confirm the route first.

Check the page address before attaching anything. The domain should match the site you deposited on, character for character, and the connection should be encrypted. A link that arrived by message is worth typing by hand.

Where an account offers no upload form and documents can only go by email, treat that as a finding about the operator, not an inconvenience.

What the check actually needs

Each check has a narrow purpose. Identity confirms name and date of birth, address confirms where you live, payment ownership confirms the method is yours, and source of funds applies to larger play.

Send the pages requested and stop there. A full bank statement answers an address check with a complete spending history attached, more than was asked for.

CheckWhat it provesSend only
IdentityName and date of birthGovernment photo ID, details legible
AddressAddress held on the accountOne recent bill or statement page with name and address
Payment ownershipThe method is in your nameThe card or wallet view specified, redacted to the stated rule
Source of fundsWhere larger deposits came fromThe documents named, for the period named
Selfie or livenessThe ID holder is the account holderThe frame the account form asks for, taken in the form
AgeYou are an adultUsually covered by the identity document

Redaction: cover what is not being checked

Follow the operator's stated redaction rule where there is one. An over-redacted file is normally rejected and re-sent, and a second upload doubles the exposure. Where no rule is published, ask support in writing first.

On a card image, the security code and the middle digits are commonly covered while the cardholder name and visible end digits remain. On a statement used for an address check, unrelated transaction lines can be covered.

Flatten the file before sending. Photos carry location and device metadata, and a box drawn over text in a PDF can sometimes be removed again. Export to a flat image, then try to select the text you covered.

Keep a record of what you sent

Save a copy of every upload exactly as sent, in a dated folder, with the confirmation screen or email. When a document is requested again, that record shows what the operator already holds.

Note the date, the file, the channel and who asked. A later claim that nothing arrived is answered by the note, not by uploading the same document a third time.

Requests that did not come from the operator

Impersonation follows verification closely, because a document request feels normal once an account exists. Signals worth checking: unprompted contact, a deadline attached, a sender domain that differs from the site, a form hosted outside the account, and any request for a password or one-time code.

No legitimate verification needs your account password, your card PIN or a code sent to your phone. Support can see what it needs from its own side.

Verify by opening the account yourself and looking for a pending request there. If the message was genuine the account will show it; if not, nothing was lost.

Retention, breaches and the Australian position

Ask how long documents are kept and whether they are deleted when an account closes. The answer belongs in the privacy policy, and its absence from that policy is itself informative.

If documents you uploaded are caught in a breach, keep the notification, change the account password and any password reused elsewhere, and tell your bank where payment details were involved. Where the identity document itself is exposed, ask the issuer about a replacement number.

Australian privacy law may not reach an offshore operator. The Privacy Act 1988 and the OAIC apply to organisations with an Australian link, while online casino services may not be offered or advertised to people in Australia under the Interactive Gambling Act 2001, which the ACMA enforces. Your own copies and the operator's written policy are the practical protection. Gambling Help Online is free and confidential on 1800 858 858.

Check first

Before you click through

  • Upload form opened inside the logged-in account, on the exact deposit domain.
  • Only the requested pages attached, with unrelated detail covered.
  • Redaction flattened into the image and tested by selecting the text.
  • Your own dated copy and the confirmation saved for every upload.

Best route

Simple Wincrown flow

  1. Find the verification section in the account before your first larger deposit.
  2. Ask support in writing which pages are required and what may be covered.
  3. Prepare flattened, renamed copies and upload them through the account form.
  4. File your copies with the date and channel, then read the retention clause.

Wincrown AU

Ready to check the live offer?

Open Wincrown, check the current offer and choose the game or bonus that fits your session.

Play here

Next pages

Keep the decision clean

FAQ

Short answers

Can I send documents by email if support asks?

Prefer the upload form in the account and say so. Where no form exists, ask support to confirm the request inside the account, then send only the requested pages and keep the thread.

How much am I allowed to redact?

Cover what the specific check does not need, and follow the operator's published rule where there is one. Over-redacting usually produces a rejection and a second upload, which increases exposure.

Is the photo of my ID on my phone safe to reuse?

Not as stored. Camera files carry location and device metadata and sit in backups and chat histories. Keep verification copies in one folder you control, and strip metadata before sending.

What should I do if my documents are in a data breach?

Keep the notification, change any reused password, and contact your bank if payment details were exposed. Where the identity document is affected, ask the issuer about a replacement number.