Privacy Policy
Effective: [[EFFECTIVE_DATE]] · Controller: [[COMPANY_LEGAL_NAME]]
Introduction
This Privacy Policy explains how we collect, use, share, and protect personal information when you use Rallypot (the "Service"): a peer-to-peer prediction contest platform where users pay a buy-in, contribute to a shared prize pool, and may deposit, hold, and withdraw real money. It applies to the Rallypot mobile app and website.
1. Who We Are & How to Contact Us
The data controller responsible for your personal information is [[COMPANY_LEGAL_NAME]], [[COMPANY_ADDRESS]]. For privacy questions or to exercise your rights, contact us at [[PRIVACY_EMAIL]].
If you are in the EU or UK, our representative / data protection contact is [[EU_UK_REPRESENTATIVE]]. [[ATTORNEY: confirm whether an Art. 27 representative or DPO is required.]]
2. Data We Collect
We collect the following categories of personal information:
- Account information: your name, email address, password (stored hashed), date of birth, and any username.
- Identity / KYC data: government-issued ID documents, a photograph or selfie, and verification results, collected through our verification provider (Didit). See Section 6.
- Financial and banking data: deposit/withdrawal amounts, transaction history, account balance, and bank-linking details processed through our payment provider (Trustly). We do not store full bank credentials ourselves.
- Location data: device GPS coordinates used to confirm you are in a permitted jurisdiction, and the resulting state/region.
- Contest activity: the contests you enter, predictions you submit, outcomes, winnings, and your wallet/ledger history.
- Device and usage data: IP address, device and OS identifiers, app version, push-notification tokens, log/timestamp data, and diagnostics.
- Communications: emails and messages you exchange with us, and your notification preferences.
3. How We Use Your Data
- Operate the Service: create your account, run contests, form prize pools, and settle results.
- Verify identity and eligibility: perform KYC, confirm age, and confirm your location/jurisdiction.
- Process payments: handle deposits, withdrawals, balances, and related records.
- Prevent fraud and abuse: detect multi-accounting, collusion, money laundering, and prohibited conduct.
- Comply with law: meet anti-money-laundering, tax, record-keeping, and other legal obligations.
- Communicate with you: send transactional emails and, if you opt in, push notifications.
- Improve and secure the Service: diagnostics, analytics, and safeguarding our systems.
4. Legal Bases for Processing (GDPR/UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases under Article 6:
- Performance of a contract (Art. 6(1)(b)): to provide the Service you request, including running contests and processing payments.
- Legal obligation (Art. 6(1)(c)): to meet KYC/AML, tax, and record-keeping requirements.
- Legitimate interests (Art. 6(1)(f)): to prevent fraud, secure the Service, and improve our products, balanced against your rights.
- Consent (Art. 6(1)(a)): for optional push notifications and any processing that requires consent; you may withdraw consent at any time.
Where we process special-category data (such as biometric data used in identity verification), we rely on an additional Article 9 condition where required.
[[ATTORNEY: confirm applicability of GDPR/UK GDPR, the correct Art. 6 bases per purpose, and the Art. 9 condition for any biometric/identity processing.]]
6. Sensitive Data & Identity (KYC)
To meet legal obligations and prevent fraud, we (through Didit) collect and verify identity information, which may include government-issued ID images and a selfie or biometric facial match. This information is used to confirm your identity and eligibility, is transmitted securely, and is retained as described in Section 7 ([[KYC_RETENTION_PERIOD]]). We restrict internal access to identity data and store related artifacts in access-controlled storage.
[[ATTORNEY: confirm KYC data-handling, biometric-data notice/consent requirements (e.g. BIPA and similar state laws), and the retention/destruction schedule for identity documents and biometric identifiers.]]
7. Data Retention
We keep personal information only as long as needed for the purposes described, then delete or anonymize it. Financial and identity records are retained longer where required by anti-money-laundering, tax, and other legal obligations. Our retention schedule by category: [[RETENTION_PERIODS]]; identity / KYC records: [[KYC_RETENTION_PERIOD]].
[[ATTORNEY: confirm retention periods, including statutory minimums for AML/financial and tax records, and maximums for biometric/identity data.]]
8. Security
We use technical and organizational safeguards including encryption in transit (TLS), encryption at rest, role-based access controls, and database-level row security. No method of transmission or storage is perfectly secure. If a breach affecting your personal information occurs, we will notify you and regulators as required by applicable law.
9. International Data Transfers
We operate the Service from, and store data in, the United States. Our sub-processors may process data in the United States and elsewhere. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data-protection laws than your country. [[ATTORNEY: confirm transfer mechanisms (e.g. SCCs, UK IDTA, adequacy) and any required transfer-impact disclosures for EU/UK users.]]
10. Children
The Service is not directed to, and we do not knowingly collect personal information from, anyone under [[MIN_AGE]]. If you believe someone under that age has provided us information, contact [[PRIVACY_EMAIL]] and we will delete it.
11. Your Privacy Rights (CCPA/CPRA & GDPR/UK)
Depending on where you live, you may have some or all of the following rights:
California (CCPA/CPRA): the right to know/access the personal information we collect, use, and disclose; the right to delete; the right to correct; the right to opt out of the "sale" or "sharing" of personal information; the right to limit use of sensitive personal information; and the right not to receive discriminatory treatment for exercising your rights.
Do Not Sell or Share: We do not sell your personal information for money. [[ATTORNEY: confirm whether any disclosure constitutes a "sale" or "sharing" (including for cross-context behavioral advertising or analytics) under CCPA/CPRA, and add an opt-out mechanism if so.]]
EU / UK (GDPR / UK GDPR): the right to access; rectification; erasure; restriction of processing; data portability; objection to processing based on legitimate interests; and withdrawal of consent. You also have the right to lodge a complaint with your supervisory authority.
To exercise any right, contact [[PRIVACY_EMAIL]]. We will verify your request and respond within the time required by applicable law. You may use an authorized agent where permitted.
13. Changes & Effective Date
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service or by email. The effective date below reflects the latest version. Effective date: [[EFFECTIVE_DATE]].
