Privacy Policy

Effective Date: February 4, 2025

PENN Entertainment, Inc. (“PENN Entertainment”, “Us” or “We”) Privacy Policy outlines the collection, use, processing and disclosure of your personal information. This Privacy Policy applies to this website and all of the products, services, websites, mobile applications, social media services, and the properties and services owned, managed or operated by us, our subsidiaries, or our partners on our behalf in the United States that link to this Privacy Policy (the “Services”), unless otherwise indicated. Where additional information is required to explain our privacy practices, we post supplementary privacy notices.

LIST OF TOPICS COVERED

    Consent

    Categories of Personal Information Collected and Processed

    Out of Scope

    Sources of Personal Information

    Sensitive Personal Information

    Legal Basis and Purposes for Processing Your Information

    Disclosures of Personal Information

    Cookies and Similar Technologies Policy

    Retention

    Security

    Links to External Websites

    Sale

    Consumers Under 16 Years of Age

    Changes to the Privacy Policy

    Contacting PENN Entertainment

 

Consent

By accessing and using the Services, including when you visit our websites, make reservations, make online purchases, request information from us, download or launch our mobile applications, or when the application is running on your device in the background, you expressly consent to the collection, use, processing, disclosure, and retention of your personal information and sensitive personal information that you and other parties provide to us as a result of such use in accordance with this Privacy Policy, the terms of use for the specific part of the Services you are accessing and using (each and collectively “Terms of Use”), and as permitted by applicable law. You may withdraw your consent at any time by contacting us at [email protected] at any time, or if you disagree with the Terms of Use or this Privacy Policy, you should immediately discontinue use of the Services.

Please note that the Services may be hosted in countries other than yours. By accessing the Services, you expressly consent to the transfer of your information outside of your home country, which may provide for different data protection laws than in your country.

Categories of Personal Information Collected and Processed

To provide you with all of the requested Services, we collect and process the following categories of personal information:

  • Identifiers, such as first and last name, home or other physical address, which includes the name of a street, the name of a city or town, state of residency, and zip code, date of birth, gender identity, age, photograph, job status, employment information, unique personal identifiers or other similar identifiers.

  • Messages, Comments, and other User-Generated Content that you choose to provide to us voluntarily, including comments, messages, and other content you post to the Services.

  • Unique Personal Identifiers, such as social security number, driver’s license number, passport number, license plate number, telephone number, email address, Internet Protocol address, device identifiers and advertising identifiers, Cookies, beacons, pixel tags, or similar technology, player ID, or loyalty program ID.

  • Player Information, such as play activity, depending on how you use the Services, which could include system-generated player identifiers.

  • Commercial Information, including records of products or services purchased, obtained, or considered.

  • Transaction Information, such as bank information (e.g. bank statement, void cheque), reservation information, and purchase history.

  • Geolocation Data obtained and derived from your mobile device when you access the Services by or through such mobile device;
    1. The applicable laws of the jurisdiction in which you reside may require that we verify your physical location when engaging in placing wagers through the Services. You can only place wagers through the Services from within certain jurisdictions’ boundaries. Accordingly, we collect your Geolocation Data and verify your physical location using geolocation technology and geo-verification service providers. If you do not permit your geolocation to be known (i.e. disable GPS, Wi-Fi and/or Bluetooth), we will not be able to provide such wagering services to you. We may store a record confirming your geolocation within a jurisdiction for up to ten (10) years as required by applicable laws and regulations.
    2. Certain features within the Services will make use of your Geolocation Data, including geolocation verification provided by GeoComply or other similar geolocation verification service providers. Your use of the Services will require you to, and you hereby consent to us transmitting, collecting, maintaining, processing and using your Geolocation Data as described in this Privacy Policy. You may turn off the location services within your device’s settings at any time or by notifying us in writing that you would like to withdraw such consent. Turning off location services on your device will prohibit you from using certain core features and functionalities of the Service including but not limiting to wagering services.

  • Internet or Other Electronic Network Activity and Other Information that are automatically obtained from the devices and/or browsers that you use to access our Services, such as your device type; IP address; device and advertising identifiers, probabilistic identifiers, and other unique online identifiers; time zone setting and location; browser type and version; browser plug in types and versions; operating system and platform information; Internet service provider; pages that you visit before and after using the Services, browsing history, and search history; the date and time of your visit; information about the links you click, pages you view, and advertising you interact with, within the Services and other information about how you interact with our Services or other services you use to connect with us, such as Facebook and Twitter information; the technology on the devices you use to access these Services; audio, electronic, visual, thermal, olfactory, or similar information; or if your device experiences an error with our Services, we collect information about the error (e.g. the time the error occurred, the feature being used, the state of the application when the error occurred, and any communications or content provided at the time the error occurred).

  • Inferences, which may be drawn from any of the categories of personal information described above to create profile(s) reflecting your preferences, characteristics, predispositions, interests, and behavior.
We strive to minimize collection, use, processing, and disclosure of your personal information to the extent that is reasonably necessary and proportionate to providing you with Services you requested and/or as otherwise permitted and/or required by applicable laws.

Out of Scope

This Privacy Policy does not apply to the following information:

  • Aggregated, pseudonymized, and/or de-identified data, derived from information described above and that we do not attempt to reidentify or link back to you, may be used for research, evaluation, and/or other analytical purposes by us or third parties.

Sources of Personal Information

In addition to collecting information directly from you, we may also receive the above noted categories of personal information from other sources, including affiliates, other users of the Services, identity verification services and databases, advertising partners, internet service providers, data analytics providers, operating system providers, publicly available sources, government entities, social networks, and other entities as required by and in compliance with applicable privacy laws.

Sensitive Personal Information

Subject to your place of residency, we may collect personal information that is deemed to be sensitive personal information under applicable privacy laws. We may collect the following sensitive personal information for the purposes listed below:

  • Precise Geolocation Information of Your Device consistent with your device’s permission settings, to provide you with Services available at your location, including personalized marketing. Where use of this information is for marketing purposes, you may withdraw your consent at any time, subject to applicable privacy laws.

  • Biometric Information via Facial Recognition Technology or Other Technology to identify you, for the limited purpose of ensuring the security and confidentiality of our Services, physical locations, and assets, fulfill legal and regulatory obligations, and as otherwise permitted by, and consistent with, applicable laws. Our third-party service provider, Jumio, collects biometric information via facial recognition or similar technology from an image (e.g., a selfie) or video (including audio) and from an image of your face as it appears on an identification document that you provide. Jumio may share such data with its service providers to perform I.D. check services and/or with PENN Entertainment for limited purposes where necessitated. Jumio may collect, process, re-collect, otherwise obtain, and store such data for this process or to improve its services, and for the long-term proof of inspection of your provided form of identification. Jumio will destroy such biometric information in its possession one year after the deactivation or termination of your account with us.
    • At certain physical locations operated by PENN, including casinos, hotels, and racetracks, we utilize mobile mechanical devices and stationary camera systems with Facial Recognition Technology capturing images and biometric information at such physical locations for ensuring the safety nd security of our patrons and personnel, our premises, and to meet our regulatory obligations, such as keeping trespassed patrons from entering the property. We limit the sharing of biometric information to our service providers ass necessary and proportionate to fulfilling our legitimate business purpose and where required by law. We will delete the biometric information as soon as it is no longer required for us to maintain to fulfill business and security purposes and/or legal regulatory obligations.

  • Racial & Ethnic Origins to provide you with personalized advertisement and marketing material for and/or in the Services.

  • Driver’s License and Social Security Numbers to provide you with Services, to comply with our legal obligations, including without limitation, relevant gaming regulatory requirements.
Legal Basis and Purposes for Processing Your Information

We may use the personal information we collect for the following business purposes:

  • Provide you with access and use of the Services you requested, including uniquely identifying and authenticating patrons, maintaining and servicing accounts, process payments/transactions, and ensure other features of the Services are properly administered;
  • Processing and fulfilling purchases or hotel reservations;
  • Provide customer service, facilitate communication to respond to patron requests, inquiries, comments and concerns;
  • Administer responsible gaming exclusion, loyalty, product research and other similar programs; 
  • Deliver marketing, promotional, and advertising materials for, and/or within, the Services, including personalized advertising for the patron; 
  • Analyze and improve the Services, programs, offerings and processes for operational effectiveness and viability of current and prospective services. We, personalize offers for individual patrons, measure traffic and usage trends, assess responsible gaming data, and conduct product research (including, conducting interviews with research participants), provide online surveys and assess findings to improve our products and services;
  • Ensure security and integrity of the Services, including troubleshooting, debugging to identify and repair errors that impair existing functionality;
  • Comply with applicable laws regulatory obligations and to maintain the integrity of our business, - including risk mitigation, fraud preventions, or ensuring that we keep underage or excluded persons from engaging with our Services; and
  • Any other purposes disclosed to you at the time of collection to obtain your consent or where necessary or advisable in good faith.
Disclosures of Personal Information

We may disclose the personal information we collect to the following parties, who may be located outside the United States, for business purposes including but not limited to:

  • Affiliates, Subsidiaries and Other Business Partners: management and analytics, providing you with the Services, website and data hosting, customer service, providing your account, security and performance monitoring, and related activities.
  • Service Providers & Contractors: providing you with products and service, payment processing, website and data hosting, customer service, advertising and marketing (including counting ad impressions, ensuring compliance with industry standards, personalization, and analytics), analytics services, security and performance monitoring, maintaining and servicing accounts, fulfilling orders and transactions, verifying customer identity, research, verifying customer information, and auditing.
  • Those With Whom You Share Content: any information or content that you voluntarily post, submit, or otherwise disclose to the Service, becomes available to the public, except as limited by any privacy settings you select. Subject to your privacy settings, any content that you voluntarily make public may be searchable by others. If you remove information or content that you posted to the Services, copies may remain viewable in cached and archived pages of the Services, or if other users have copied or saved that information or content. Please note that such removal does not ensure complete or comprehensive removal of the content or information posted (for example, your content or information may remain visible because it was copied and posted or reposted by a third party).
  • Marketing Partners: to provide account linking services and promotional offers, where you consented.
  • Third Parties in Compliance with Applicable Law: to respond to subpoenas, court orders, legal process, government and law enforcement requests; to fulfill regulatory or administrative authorities’ requirements; to establish, protect and/or exercise our rights to defend against legal claims; to investigate, prevent and take action against suspected illegal activities and suspected fraud; to protect the rights, reputation, safety and security of our Services, employees, users of our Services, and/or the public; and to prevent, investigate and take action against any violation of the Terms of Use, our policies or agreements, or as otherwise required by law.
  • Other Corporate Entities: in the event of a corporate transaction like business merger, consolidation, acquisition, sale of assets, joint venture, or in the unlikely event of bankruptcy.

Subject to your consent, we may disclose your personal information for purposes not identified above.

Parties acting on our behalf are authorized to collect, use, disclose, and/or store personal information only to the extent described in this Privacy Policy, subject to applicable laws.

Cookies and Similar Technologies Policy

Cookies: A "Cookie" is a small text file placed on a device when a user visits a website (including our Services). Cookies can be sessional or persistent and are not programs that download on a user's system and damage files (such as, viruses or worms) or send information to third parties about websites visited (such as, spyware). A persistent Cookie remains on your device after you close your browser. Persistent Cookies may be used by your browser on subsequent visits to the Service. Persistent Cookies can be removed by following your browser's directions. A sessional Cookie is temporary and disappears after you close your browser. You can set your browser to refuse certain Cookies or to indicate when a Cookie is being sent. However, some features of the Service may not function properly if the ability to accept Cookies is limited or disabled.

We may send one or more Cookies to your device that uniquely identifies your browser and enables us to recognize repeat visitors, facilitate a visitor's ongoing access to and use of the website, track your usage of the Services over time and compile data that can allow content and speed of access improvements and targeted offers (e.g., the pages you view, the links you click and other actions you take on the Services), and enhance your navigation through the Services. Information (i.e., domain names and IP addresses) and data may be automatically collected through the standard operation of our internet servers at our discretion using Cookies.

You can opt-out of the installation of Cookies or delete Cookies previously installed by updating your settings in the internet browser you use to visit our Services. However, visitors should note that Cookies may be necessary for optimal functionality of our websites.

Other Internet Technologies: We may also use other standard internet technologies, such as flash technologies, web beacons, or pixel tags, and other similar technologies, to deliver or communicate with Cookies and track your use of our websites. For example, we may include web beacons in e-mail messages or newsletters to determine whether messages have been opened and acted upon. The information obtained with such technology enables us to customize the Services offered and measure the overall effectiveness of our online content, advertising campaigns, and our Services.

By using our Services, you consent to the installation and use of Cookies and similar technologies by or on behalf of us as described above.

Retention

Your personal information will be retained for so long as reasonably necessary and proportionate for the purposes outlined above in this Privacy Policy based on criteria such as duration required to provide services to you, including for backup, archival, fraud prevention or detection, audit, or as otherwise required by law. After the retention period has elapsed, your information will be appropriately de-identified by removing identifying details in accordance with our Data Retention and Destruction Policy, De-identified information can be retained in accordance with applicable law. We may use remote backup features that will send information from your device and/or browser to be stored on servers operated by or on behalf of us and our affiliates. Except to the extent specifically prohibited by applicable law, we have no responsibility for any data transmitted to and from your device and/or computer and we recommend that you make regular back-ups of all information and data on your device and/or computer.

Security

We care about the security of your personal information and take reasonable physical, technological and administrative measures in an attempt to protect and safeguard your personal information against loss, theft, and unauthorized access, use, disclosure or modification. However, we cannot ensure or warrant the security of any information you provide to us as no system is perfect, nor can we guarantee that unauthorized access or theft of data will not occur. User discretion is advised when submitting personal information to the Services.

For features on our websites that require a login or password, you are responsible to protect against unauthorized access by signing off when finished using a shared computer or device and to safeguard the confidentiality of your username and password.  We strongly encourage that you do not share this information with anyone.

Links to External Websites

We may have links to external websites in our Services. By accessing an external website from our Services, you hereby release us from any and all liability for your use of such link and third-party website. We have no control over the content of external websites, and therefore are not responsible for the security and privacy policies protocols or content that appears on these external websites. Your visit and use of such external websites is voluntary and may be subject to such third-party’s rules and policies, which you are encouraged to review. If you choose to interact third party social networking service, we may receive information about you that you have made available to the third party social networking service. Also, the third party social networking service may receive information about you from us.

Sale

Sale is defined as selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by the business to another business or third party for monetary or other valuable consideration.

By the definition above, we do not sell personal information of our users.

Consumers Under 16 Years of Age

Our Services are intended for consumers over the age of 21, subject to exceptions in the case of racing and pari-mutuel operations, where wagering may be permissible by law to those 18 years and older.. We do not intentionally collect the personal information of consumers under the age of 16, nor do we intentionally share or sell the personal information of such consumers. If you have reasons to believe that we may have accidentally received personal information of an individual under the age of 16, please contact us immediately at [email protected]

Under penalty of law, underage individuals are not allowed to loiter on casino property nor to participate in any gaming activity, including any racing pr pari-mutuel activity.  To comply with law, we reserve the right to request appropriate government issued identification from any individuals while they are present on our property.

Consumer Rights

Subject to your place of residence, you may be entitled to exercise certain rights with respect to your personal information, as described below:

  • Right to Access and Confirm Processing: You may request access and or confirm processing of your personal information once in a calendar year. You may have the right to know what personal information the business has collected about you, including the categories of personal information, the categories of sources from which it is collected, the business or commercial purposes for collecting, selling, or sharing it, and the categories of third parties to whom we disclose it.

  • Portability: Subject to exceptions, you may obtain a copy of your personal information we collected during the preceding twelve (12) months of your request, in a readily useable format where processing is done via automated means.

  • Deletion: Subject to certain exceptions, you may request deletion of your personal information in our control.

  • Correct Inaccuracies in your Personal Information: You can also update or correct your account information and electronic message preferences at any time by logging in to your account and changing your profile settings. 

  • Opt-out of Sale and Sharing for Targeted Advertising: We do not sell your personal information for monetary or other valuable consideration. However, you may request opt-out of having your personal information processed for purposes of targeted advertising by managing your preference on the cookie banner that appears when you browse our website or by visiting the NAI Opt-Out Page: http://www.networkadvertising.org/choices, where you can learn more about NAI members who deliver tailored targeted advertisement and your choices to opt-out of receiving them. Please note that even if you opt-out of receiving targeted advertisements, you may still see general advertisements without personalization while you visit websites. NAI members are solely responsible for honoring your opt-out requests.

  • Limit Use and Disclosure of Sensitive Personal Information (Where Applicable): Subject to exceptions, you may limit the use and disclosure of your sensitive personal information for purposes necessary to provide you with the Services you requested by clicking the “Limit the Use and Disclosure of My Sensitive Personal Information” link.

  • Designate Authorized Agent: You may be entitled, in accordance with applicable law, to submit a request through an authorized agent.

  • Shine the Light (California Residents Only): California residents who provide certain personal information in connection with obtaining products or services for personal, family or household use are entitled to request and obtain from us once a calendar year information about the customer information we shared, if any, with other businesses for their own direct marketing uses. If applicable, this information would include the categories of customer information and the names and addresses of those businesses with which we shared customer information for the immediately prior calendar year.
Changes to the Privacy Policy

We reserve the right to amend this Privacy Policy at any time. We advise you to periodically review this policy for any updates, which will be accompanied by a new “effective date” indicated above.

Contacting PENN Entertainment

To submit a request to exercise your rights, designate an authorized agent to exercise your rights on your behalf, and/or for any questions, you may contact us by calling 1 (866) 978-5118, by emailing our Privacy Compliance Officer at [email protected], and/or by mail at:

Privacy Compliance Officer
PENN Entertainment, Inc.
825 Berkshire Blvd.
Wyomissing, PA 19610

We will process your request upon receipt after verifying your identity. You also may be entitled, in accordance with applicable law, to appeal our refusal to take action on your request by contacting our Privacy Compliance Officer.