Privacy policy
What we collect, why, who else sees it, and how to get it back or get rid of it. No pre-ticked boxes and no data sales.
The short version
We collect what we need to run an account, take a payment and stop fraud — and nothing else. We do not sell personal data, we do not share it with bookmakers, and we do not build advertising profiles.
No data broker has ever received a record from us, and none ever will. Our revenue is subscriptions.
SportPulse Analytics Ltd., 18 Harbour View, 115 26 Athens, is the data controller. Our data protection contact is privacy@sportpulse.example.
What we collect
| Account | Email address, display name, password hash, country |
|---|---|
| Subscription | Plan, analyst subscribed to, billing history, partial card details held by our processor |
| Usage | Pages viewed, picks opened, alerts clicked — aggregated for product decisions |
| Technical | IP address, browser and device type, session identifiers |
| Support | Messages you send us and our replies |
| Analyst applications | The record link you supply and the verification result |
Card numbers never touch our servers. Payments are processed by our payment processor, which holds the card data under its own policy.
Why we use it, and on what basis
- To provide the service you asked for — performance of a contract.
- To take payment and issue invoices — performance of a contract and legal obligation.
- To detect fraud, multi-accounting and record manipulation — legitimate interests.
- To send service emails such as pick alerts and billing notices — performance of a contract.
- To send the weekly brief — consent, withdrawable in one click.
- To keep accounting records — legal obligation.
We do not carry out automated decision-making that produces legal effects for you. Fraud signals are reviewed by a person before an account is closed.
Who else sees it
Only processors that are necessary to run the service, each under a data processing agreement and none permitted to use your data for their own purposes.
| our payment processor | Payments and invoicing |
|---|---|
| Email provider | Transactional email and the weekly brief |
| Cloud hosting (EU region) | Application and database hosting |
| Error monitoring | Crash reports, IP truncated |
We may disclose data where the law requires it, or to establish or defend a legal claim. If we are ever asked to hand over data by an authority, we tell you unless we are legally forbidden from doing so.
Cookies
We use strictly necessary cookies for sessions and security, and one first-party analytics cookie that measures page views without cross-site tracking. There are no advertising cookies and no third-party trackers on this site.
You can refuse the analytics cookie in the banner or clear it at any time; the service works normally without it.
How long we keep it
| Account data | While the account is open, then 30 days |
|---|---|
| Billing and invoices | 7 years — required by tax law |
| Support messages | 24 months |
| Usage analytics | 14 months, aggregated after 3 |
| Published picks | Permanently — they are the public record and are not personal data once the analyst is identified only by their public name |
Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object to processing, or take it elsewhere in a portable format. Write from your account email and we respond within 30 days, usually much sooner.
Deleting your account is permanent. It removes your subscription history and cannot be undone — export anything you need first.
If you think we have handled your data badly, tell us first so we can fix it. You also have the right to complain to the data protection authority for the territory this demo names, or to the supervisory authority where you live.
Security and transfers
Data is encrypted in transit and at rest, access is limited to staff who need it, and administrative access is logged. We test the settlement and payment paths before every release.
Our infrastructure is hosted in the EU. Where a processor transfers data outside the EEA, that transfer relies on Standard Contractual Clauses.
If a breach ever affects your data, we will notify you and the regulator within the deadlines the GDPR sets, and tell you exactly what was exposed.
Under-18s and changes
The service is not for anyone under 18. We do not knowingly collect data from minors, and we delete any account we discover belongs to one.
We may update this policy. Material changes are announced on the site and by email at least 14 days before they take effect, with a summary of what changed.
Data requests and privacy questions go straight to our data protection contact — not to a ticket queue. Write from your account email so we can identify you.