Privacy policy
How we collect, use and protect your information
This policy is effective from Sep 21, 2026.
What we collect
Account details: your email address or phone number, display name, password (stored only as an irreversible hash — we never see the original), and the timestamp of your age confirmation at sign-up.
Preferences: interface language, time zone, theme, default sport and competition, notification channels.
Activity: reading history, bookmarks, the teams and competitions you follow, the picks you track, and the content you have unlocked.
Transactions: each order’s amount, currency, payment channel, channel reference and refund details, plus every points movement and its expiry.
Security data: a device summary derived from your browser and operating system, the sign-in IP address, and when each session was created and last active. This is what lets you recognise and sign out an unfamiliar login under Settings › Sessions and devices.
How we use it
To run the service: decide what you may read, settle points and membership periods, show your tracked picks and record, and render the interface the way you set it.
To notify you: order results, refund results, points and membership expiry reminders, and site announcements.
To keep things safe: sign-in rate limiting (five failures on one identifier within 15 minutes locks it briefly), spotting unusual logins, and debugging.
We do not sell your personal data, and the site carries no third-party advertising or behavioural analytics.
Third parties
Payment channels take the payment once you place an order. We do not store card numbers or any other payment credential — an order holds only the amount, currency, channel and channel reference.
Email and SMS providers: once the site enables a channel, your address or number is used to send verification codes, reset links and reminders. Nothing is sent, or passed on, while a channel is disabled.
The data sources and model services we use to produce an analysis receive match data only — never any user’s personal information.
We do not currently use any third-party error-monitoring service.
How we protect it
Third-party API keys and the credentials for payment and notification channels are stored encrypted; sessions use signed tokens; passwords are stored only as hashes.
You can review every sign-in and sign other devices out at any time under Settings › Sessions and devices.
How long we keep it
Sign-in records — the device, IP address and activity times — are stored with your session, which expires after 30 days by default. Your reading history is kept so that you can pick up where you left off in your workspace.
Account details, orders, the points ledger, membership periods and unlock records are kept for as long as your account exists — otherwise what you bought and any points you have not spent would disappear. Where the law requires a longer retention, that requirement applies.
When you close your account we erase the records associated with it.
Your choices
Under Settings you can change your display name, language, time zone, theme, default sport and competition and notification channels, change your password, and sign other devices out.
Exporting your data and closing your account have no self-service route yet; email hello@deepball.demo and we will handle it manually.
Before acting on such a request we verify your identity through the phone number or email address registered on your account.
Minors
This service is for people aged 18 and over, confirmed at sign-up. If we find that an account belongs to a minor we will disable it.
Cross-border transfers
Some of the third-party services we rely on — payment channels and model services among them — are located outside the country. Related information is therefore transferred abroad and stored and processed there.
Changes to this policy
An update to this policy takes effect on the day it is published. We do not notify you separately, so please check this page from time to time.
Contact us
Questions about your personal data can go to hello@deepball.demo.