Privacy Policy
This policy explains how MatchPool collects, uses, and protects your personal information.
1. Information We Collect
Personal Information
When you create an account, we collect:
- Username (publicly displayed on leaderboards)
- Email address (for account verification and notifications)
- First and last name (optional, kept private)
- Date of birth (for age verification, kept private)
- Password (stored securely using one-way hashing)
Account Activity Data
- Match predictions (tips) and scores
- Group memberships and competition history
- Terms acceptance records and timestamps
Payment Information
Payment card details are collected and processed exclusively by Stripe. MatchPool never stores, processes, or has access to your full card number, CVV, or other sensitive payment details. We only store:
- Stripe customer ID and payment session references
- Payment amounts, dates, and status
- Card type and last four digits (provided by Stripe for your reference)
Usage Data
- IP address and approximate location (for geo-compliance)
- Browser type and device information
- Pages visited and features used
- Login timestamps and session information
2. How We Use Your Data
We use your information to:
- Provide and operate the MatchPool prediction competition
- Create and manage your account
- Process payments and distribute prizes
- Verify your age and eligibility
- Enforce responsible gaming limits and self-exclusion periods
- Send account-related notifications (activation, password reset, payment confirmations)
- Display your username on public leaderboards and group standings
- Detect and prevent fraud, abuse, and multi-accounting
- Comply with legal and regulatory requirements
- Improve the Service based on usage patterns
We do not sell your personal information to third parties.
3. Third-Party Services
MatchPool integrates with the following third-party services:
Stripe — Payment Processing
Processes all payments and prize payouts. Stripe receives your payment card details directly and is PCI-DSS Level 1 certified.
Stripe Privacy PolicyCloudflare Turnstile — Bot Protection
Used during registration to prevent automated account creation. Cloudflare may collect IP address and browser information.
Cloudflare Privacy PolicyEmail Delivery Service — Transactional Email (United States, operated by Google)
Account verification emails, password resets, and payment notifications are delivered via a Google email service. Your email address is shared with Google for delivery purposes.
Google Privacy PolicyError Monitoring Service — Application Diagnostics (United States)
We use a third-party error monitoring service to detect and diagnose technical errors. This service may receive technical data including IP addresses and error context, but not payment information.
4. Data Retention
- Account data: Retained for the lifetime of your account plus 30 days after deletion
- Payment records: Retained for 7 years for financial and tax compliance
- Competition history: Retained for the lifetime of your account (tips, scores, leaderboard positions)
- Responsible gaming records: Self-exclusion and spending limit history retained for 5 years
- Usage logs: Automatically purged after 90 days
5. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Update or correct inaccurate personal information through your profile settings
- Deletion: Request deletion of your account and associated personal data
- Data Portability: Request your data in a machine-readable format
- Objection: Object to processing of your data for specific purposes
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
Note: Some data cannot be deleted if required for legal compliance (e.g., payment records for tax purposes) or if you have active entries in paid competitions.
6. Cookies
MatchPool uses the following cookies:
- Session cookie: Essential for keeping you logged in (expires when you close your browser or after inactivity)
- CSRF token: Essential security cookie that protects against cross-site request forgery attacks
- Language preference: Remembers your selected language
We do not use advertising or tracking cookies. We do not use third-party analytics services that track individual users.
7. Children's Privacy
MatchPool is not intended for anyone under 18 years of age. We do not knowingly collect personal information from anyone under 18. If we discover that we have collected information from a minor, we will delete that information immediately and terminate the associated account.
If you believe a minor has created an account, please contact us immediately at [email protected].
8. Security
We implement the following security measures to protect your data:
- All data transmitted over HTTPS (TLS encryption)
- Passwords stored using industry-standard one-way hashing (PBKDF2)
- CSRF protection on all forms
- Payment data handled exclusively by Stripe (PCI-DSS Level 1)
- Regular security scanning and dependency updates
- Bot protection via Cloudflare Turnstile during registration
While we take reasonable measures to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
9. International Transfers
MatchPool is operated from Australia and hosted on cloud infrastructure in the United States. Your data may be processed in regions outside your country of residence. By using the Service, you consent to the transfer of your information to these locations.
Our third-party service providers (including Stripe, Google, and Cloudflare) may also process data in the United States, European Union, and other jurisdictions according to their own privacy policies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the version number and effective date at the top of this page
- Notify registered users by email of material changes
- Post a prominent notice on the Service
Continued use of the Service after changes are posted constitutes acceptance of the revised policy.
11. Contact
If you have questions about this Privacy Policy or how we handle your data, please contact us: