Privacy notice
What we collect when you play a campaign, why, who sees it, and how long we keep it.
Two different roles
Each campaign is run by an organiser — a business, an organisation, or an individual. They decide what the promotion is and they receive the entries. We provide the software and store the data on their behalf.
An organiser can only ever see participants in their own campaigns. They cannot see anything from anyone else's.
What we collect when you play
Details you type in
Your name, and an email address or phone number. This is how the organiser reaches you if you win.
Your location — only if you share it
Location is only collected if you grant permission in your browser, and only after a screen that explains why it's being asked. It is used to confirm regional eligibility and to show the organiser the general area participants joined from. It is never inferred from your IP address and presented as though you shared it.
Most campaigns store an approximate position, rounded to about 100 metres. A campaign can request precise coordinates only where exact position genuinely matters, such as entry to a physical venue — you're told which applies before you decide. Precise coordinates are encrypted and deleted after 7 days.
Some campaigns require location to enter. Those say so clearly up front. If you decline, you simply can't take part in that promotion, and nothing further is collected.
Technical details your browser sends
IP address, browser and version, operating system, device type, screen size, preferred language, time zone, whether the device has a touchscreen, the page that referred you, and the campaign link you used. Where our network provider supplies it, an approximate country.
We use these for security, fraud prevention and campaign analytics. Your IP address is stored encrypted and matched only as a one-way hash for rate limiting.
What we never collect
- Your contacts, files or photos
- Your camera or microphone
- Wi-Fi network details or other apps on your device
- Device identifiers beyond what a browser normally exposes
- Fingerprinting designed to re-identify you across sites or work around your privacy settings
How long we keep it
- Precise location: 7 days, always — regardless of what the organiser chose.
- Your contact details: the organiser picks 7, 30, 90 or 180 days. After that your record is anonymised: your name, contact details and location are removed.
- Prize results and claim codes:kept, so a claim code you're holding keeps working and the organiser has a record of what was awarded. These stay linked to an anonymised record.
- Aggregated statistics: 12 months.
- Security audit logs: 12 months.
Deletion runs automatically on a schedule — it isn't something we do only when asked.
Asking us to delete your information
You can ask for your details to be removed before the retention period ends. Contact the campaign organiser, or reach us through the report a problem page with your claim code or the email address you entered.
If you had a winning result we'll keep the award record so the prize can still be honoured, but we'll remove your identifying details.
How it's protected
Traffic is served over HTTPS. Passwords are hashed with Argon2id. Precise coordinates and IP addresses are encrypted at rest. Session cookies are HTTP-only, so page scripts can't read them. Sensitive endpoints are rate limited, and administrative changes are written to an audit log.