Sweeps Lobby

Privacy Policy

Last updated

[YOUR LEGAL ENTITY NAME] is the controller of personal data collected through Sweeps Lobby. This policy explains what we hold and why. It describes the system as it is actually built, not as a generic template.

1. What we collect

At registration: email address, username, a hashed password, date of birth, state of residence, and optionally a phone number and referral code.

Automatically: the IP address and user agent at signup and at each login, login counts and timestamps. We use these for fraud prevention and eligibility checks.

When you transact: a full ledger of every coin movement, purchase requests, and redemption requests.

When you verify identity: the document type and document number you supply, and the outcome of the review.

We do not store card numbers. We do not run advertising trackers or sell data to data brokers.

2. Why we use it

To operate your account and maintain an accurate balance. To confirm you meet the minimum age and are in a state where we can operate. To detect and prevent fraud, multi-accounting and promotion abuse. To meet legal and record-keeping obligations. To respond when you contact support.

Marketing email is sent only if you opted in, and every message contains a one-click unsubscribe.

3. How passwords are handled

Passwords are hashed with scrypt using a unique per-user salt and are never stored or logged in plain text. We cannot see your password and cannot tell it to you — a reset is the only route.

4. Who we share it with

Game system operators receive only what is necessary to create and maintain your account on their platform.

Payment and payout providers receive what they need to process a transaction.

Law enforcement or regulators where we are legally required to disclose.

We do not sell personal data.

5. How long we keep it

Account and transaction records are kept for the life of the account and then for the period required by applicable financial and gaming record-keeping rules.

Identity verification records are kept only as long as required for that purpose, then deleted.

Login attempt logs are kept for a short rolling period for security purposes.

6. Your rights

You can request a copy of your data, ask us to correct it, ask us to delete it where we are not required to keep it, and object to marketing at any time. Write to support@example.com and we will respond within the period required by applicable law.

Depending on your state you may have additional rights, including the right not to be discriminated against for exercising them. Deleting your account does not remove records we are legally obliged to retain.

7. Cookies

We set one essential cookie to keep you signed in. It is httpOnly, same-site, and is deleted when you sign out. Without it the service cannot work, so it is not subject to consent.

Any analytics added later will be disclosed here before it is switched on.