Draft status
Publication blocker: controller name, postal address, registration details, privacy contact inbox, and processor paperwork still need founder/legal confirmation.
This policy is a launch draft for legal review. It should not be published as final until Lottiq's controller identity, postal address, registration details, privacy inbox, data-processing paperwork, and transfer wording are confirmed.
Plain-language summary: Lottiq is a lottery statistics tool, not a gambling service. We collect your email, account settings, selected lottery, jurisdiction, saved combinations, ticket history you enter, subscription status, and limited technical data so the product works. Payments are handled through Stripe. Analytics are cookieless through Plausible. Error monitoring uses Sentry with personal-data scrubbing. You can request access, correction, or deletion of your data. This draft is not publication-ready until the controller details and privacy contact are complete.
Controller details
Until those details are complete, this page must stay in draft state. Do not imply that the privacy inbox exists until it has been created.
Lottiq is designed as a data-minimised statistics and entertainment service. We collect what we need to run accounts, subscriptions, saved analysis, support, security, and product measurement. We do not sell personal data, run advertising, or build advertising profiles.
1. What this policy covers
This policy explains how Lottiq handles personal data when you visit lottiq.app, create an account, complete onboarding, use Reader, start the 48-hour Analyst trial, subscribe to Analyst or Strategist, receive transactional emails or draw reminders, use saved combinations or ticket history, or contact Lottiq support.
2. What Lottiq is not
Lottiq is a statistics and information tool. It is not a lottery operator, gambling operator, ticket retailer, payment intermediary for lottery play, syndicate manager, or money-handling service. Lottiq does not sell tickets, process stakes, hold lottery funds, pay lottery prizes, monitor self-exclusion status, or collect official gambling-operator records.
3. Data we collect
We collect account and product data: email address, locale, jurisdiction, selected lottery, onboarding answers, plan state, account settings, saved combinations, ticket history you enter, push-notification preference where you opt in, Stripe customer and subscription IDs, and technical security records. We also receive Stripe subscription status, Resend delivery metadata for transactional email, Plausible aggregate analytics, and Sentry error events after personal-data scrubbing.
4. Data we do not collect
We do not store payment-card numbers, official lottery tickets, prize claims, official betting records, gambling spend, self-exclusion status, health data, political opinions, religious beliefs, biometric data, advertising profiles, or personal data bought from data brokers. Plausible does not receive Lottiq user IDs or email addresses from us.
5. Legal bases
For users covered by GDPR, UK GDPR, Swiss data protection law, or similar rules, we use contract necessity for the account, onboarding, saved workspace, trial, subscription, transactional email, and billing flows. We use legitimate interests for service security, abuse prevention, debugging, error monitoring, product measurement, and responsible-play localisation. We use consent for optional push notifications and any future optional email subscriptions. We use legal obligation for records that must be retained for tax, accounting, fraud-prevention, dispute, or compliance reasons.
6. How we use data
We use personal data to authenticate you, keep your account secure, remember your language and jurisdiction, show the right lottery workspace, save combinations and ticket history, provide Reader, Analyst, Strategist, trial, and subscription access, process billing through Stripe, send transactional emails through Resend, send optional draw reminders where enabled, respond to support, prevent abuse, fix errors, and understand aggregate product usage.
7. Service providers
Lottiq uses a small processor set: Supabase for authentication and database hosting; Vercel for hosting, serverless functions, and request handling; Stripe for checkout, billing, customer portal, subscription state, invoices, and payment processing; Resend for transactional email; Plausible for cookieless analytics; Sentry for error monitoring with personal-data scrubbing; and Google only if Google sign-in is enabled and used. Processor contracts and transfer mechanisms must be confirmed before publication.
8. International transfers
Lottiq uses European infrastructure where available, including the Supabase project configured in an EU region. Some providers may process data outside the European Economic Area, the United Kingdom, or Switzerland. Before final publication, Lottiq must confirm each provider's applicable safeguard, such as a data-processing agreement, standard contractual clauses, an adequacy mechanism, or another lawful transfer basis. This draft does not claim that any specific transfer certification or processor agreement has been completed.
9. Retention
Account data is kept while your account is active. Account records may be retained for up to 30 days after deletion for security, support, and deletion verification. Saved combinations, ticket history, locale, jurisdiction, and preferences are kept until you delete them or delete the account. Billing records may be retained for up to 7 years where legal, tax, accounting, fraud-prevention, or dispute rules require it. Server and security logs are kept for 30 to 90 days. Internal Stripe webhook logs are planned for 90-day retention. Plausible analytics is aggregate and cookieless. Sentry retention follows the configured Sentry project settings.
10. Your rights
Where privacy law applies, you may request access to your personal data, obtain a copy of it, correct inaccurate data, delete personal data, restrict or object to certain processing, withdraw consent where processing is based on consent, and lodge a complaint with your supervisory authority. Some rights are not absolute; limited records may be retained for billing, tax, security, fraud-prevention, dispute, or legal reasons.
11. Data access and deletion
You can request access to your personal data, a portable copy where the right applies, correction, restriction, objection, or deletion by contacting support@lottiq.app from your account email. We may ask for information needed to verify your identity and understand the request. We aim to respond without undue delay and, where GDPR applies, within one month unless the request is complex or another lawful extension applies. Account deletion is available directly in the product and removes or anonymises Lottiq product data that is no longer needed, while preserving limited records that must remain for legal, accounting, security, fraud-prevention, or dispute reasons.
12. Cookies and tracking
Lottiq does not use advertising cookies, retargeting pixels, third-party ad networks, or behavioural advertising tools. Plausible Analytics is cookieless and aggregate. Strictly necessary session cookies may be used to keep the app secure and signed in. These necessary cookies are not used for advertising.
13. Children and minors
Lottiq is for adults only. You must be at least 18 years old, or older if your local rules require it. We do not intentionally provide accounts to minors. If Lottiq learns that a minor has created an account, the account should be suspended and the related data deleted unless a limited legal record must be retained.
14. Responsible-gambling data
Lottiq may show responsible-play resources based on your selected jurisdiction. Clicking an external resource does not share your Lottiq account data with that organisation. Lottiq does not profile users for problem gambling behaviour, does not receive self-exclusion lists, and does not share user data with lottery operators or gambling regulators unless required by a valid legal obligation.
15. Security
Lottiq uses access controls, provider security controls, row-level security where applicable, restricted service-role access, logging minimisation, and personal-data scrubbing for error monitoring. No online service is risk-free, but Lottiq is built to collect less data than a gambling service because it does not process ticket purchases, lottery stakes, or lottery funds.
16. Changes to this policy
We may update this policy when the product, providers, legal requirements, markets, or data practices change. Material changes should be communicated clearly before they take effect where required. Re-consent should be requested only when a change affects processing that depends on consent.
17. Future markets
Lottiq's launch policy is GDPR, UK GDPR, and Swiss-law first. If Lottiq opens additional markets such as the United States, Canada, Australia, Japan, Italy, Germany, Portugal, or the Netherlands, local addenda may be added before or at market launch. Those addenda should not be treated as active until the relevant market and legal review are ready.
Provider overview
Retention overview
Legal-basis overview
Contact
Users may contact their local data protection authority. For the current European launch, likely authorities include the AEPD in Spain, CNIL in France, ICO in the United Kingdom, FDPIC in Switzerland, and other national authorities depending on the user's residence. Lead-authority wording must be confirmed by legal review.
Product or account question? Contact support@lottiq.app.