In short
- RADIAL TECHNOLOGY SOLUTIONS LTD is responsible for your data (section 1).
- We do not sell your personal data, and we do not pass it to anyone so that they can market to you. We run no advertising or analytics tags, and no advertising or analytics company receives anything about you.
- You can download your data and erase your account yourself, from your account page (section 13).
- Some things are built but switched off, and we say so: behavioural capture (section 9), marketing email, text messages and referral rewards.
- Where we have not yet fixed how long we keep something, we say that too, rather than guess (sections 11 and 12).
1 · Who we are
Comp Hub is a trading name of RADIAL TECHNOLOGY SOLUTIONS LTD,
a company registered in England and Wales, company number 16743244,
whose registered office is 83 Parsonage Lane, Bishop's Stortford, England, CM23 5BA. That company operates this platform and is the
data controller: it decides why and how your personal data is used. Its registration with the Information
Commissioner's Office is [ICO REGISTRATION NUMBER — OPERATOR TO SUPPLY].
To ask a privacy question or use any right in section 13, email
support@comphub.localhost
or use the contact form.
You can also do most things yourself from your account.
2 · Where your data comes from
- From you: when you register, enter, play, claim a prize, post a free entry, sign up for an alert or write to us.
- From your device and how you use the site: cookies, your IP address and browser details, and a record of what you do (sections 7, 8 and 10).
- From our own staff, who record things about your account: a free postal entry arriving, a prize winner's age and identity check, a prize being sent or paid, correspondence with you.
We do not receive data about you from social networks, credit reference agencies, data brokers
or advertisers. There is no social sign-in on this platform.
3 · What we do with your data
For each activity: what we hold, why, our legal basis under UK GDPR, how long we keep it, and who
receives it. "Legitimate interests" means we have weighed our interest against your rights and
believe the balance is fair; you can object (section 13).
Your account and age check
- What we hold
- Your name, email address, date of birth and password (stored only as a one-way hash, never in readable form). If you give one, your phone number. The version of the terms you accepted and when. Whether we have asked you about marketing. A random reference number for your account, used to link records without your name. If you arrived through a share link, invitation card or campaign link, the code or campaign tags attached to it. Your display name and whether your profile is public (public is off unless you switch it on), and whether you have opted in to being seen by crew mates.
- Why
- To create and run your account, to confirm you are over 18, to keep the account secure, and to contact you about it. Your date of birth is used for two things only: to check your age, and to give you a birthday gift of coins at some point in your birthday month (see "Streaks, daily visits and gifts" below) — not on the exact day, on purpose: it keeps our permanent record from being able to reveal your date of birth from when a gift was given. The date you give at sign-up is what you declare; the platform does not check it against a document.
- Legal basis
- Contract (running your account). Legal obligation and legitimate interests (confirming you are an adult). Legitimate interests (account security, and the birthday gift). Consent, where you tick a marketing box.
- How long
- While your account is open. If you never verify your email and do nothing else, the account is deleted automatically after 7 days by default. When you erase your account, the identifying fields are removed (section 13).
- Shared with
- The email delivery provider that sends you your verification and account emails (section 6).
Signing in and security
- What we hold
- A session record while you are signed in (session identifier, IP address, browser details, last activity), password-reset links, and a "remember me" cookie if you tick that box. Each sign-in and sign-out is also written to the event record (section 8). Our staff sign in with two-step verification; members do not have it.
- Why
- To keep you signed in and to protect your account.
- Legal basis
- Contract; legitimate interests (security).
- How long
- Sessions expire after 120 minutes of inactivity and are cleared automatically. Password-reset links expire after 60 minutes. The event-record entries are permanent (section 8).
- Shared with
- Nobody.
Streaks, daily visits and gifts
- What we hold
- Once a day, when you visit while signed in, the platform records that you visited, updates your streak and its milestones, and checks whether a gift is due: a daily gift of coins, a welcome gift when you join, and a birthday gift once during the month the date of birth you gave falls in (never the exact day, so the record of it cannot reveal your date of birth). Each gift is an entry in your coin ledger with its source and an expiry date. This is separate from behavioural capture in section 9.
- Why
- To run streaks and gifts, and to show you your progress.
- Legal basis
- Contract (the features you use) and legitimate interests.
- How long
- No automatic deletion is set. These records survive erasure of your account carrying only your opaque account number (section 13).
- Shared with
- Nobody. Your streak is visible to others only where a public profile, a crew or the streak lists described under "Winners boards" show it.
Your cookie and privacy choices
- What we hold
- Each choice you make on the cookie banner or in your preferences: analytics yes or no, marketing yes or no, when, which version of the wording, and the IP address and browser details at that moment. If you are signed in the record is tied to your account. If you are not, it is tied to your session identifier, unless you already hold a choice cookie, in which case no identifier is stored. A browser privacy signal (Global Privacy Control, or "Do Not Track") is treated as a refusal of both, and we then do not show the banner.
- Why
- To honour your choice and to be able to show what you chose.
- Legal basis
- Legal obligation (we must be able to demonstrate consent) and legitimate interests.
- How long
- No automatic deletion is set. Records that belong to an account lose their IP address, browser details and identifier when you erase the account. Records from visitors who never made an account are not linked to a name, but they do hold an IP address and browser details, which could identify a person, and they are not yet on a deletion schedule; erasure cannot reach them because nothing ties them to an account.
- Shared with
- Nobody.
Entries, orders, coins and refunds
- What we hold
- For each order: the competition, how many entries, the ticket numbers, the totals, the status, the terms version you accepted, and your analytics and marketing cookie choices at the time. For the coin ledger: every credit and spend on your balance, its type, where it came from and when. For refunds: the reason, the amount and which member of staff made it. An order or account can be flagged for review after a refund or chargeback.
- Card payments
- The checkout is not yet connected to a payment provider, so no card payment is taken today. The platform has no field for a card number and stores none. When a provider is connected we will name it here before it takes any payment.
- Why
- To run competitions, allocate tickets, keep your coin balance accurate, process refunds, keep proper financial records and prevent abuse.
- Legal basis
- Contract; legal obligation (financial records); legitimate interests (fraud and abuse prevention).
- How long
- No automatic deletion is set. When you erase your account these records stay, but they carry only your opaque account number and no name, email or other identifying detail (section 13).
- Shared with
- Nobody today. A payment provider will be added to this list when one is connected.
Free postal entries
- What we hold
- You send us a card that gives your full name, the email address on your account, your date of birth, the competition and any skill-question answer. Our staff use the email address to find your account and record that the entry arrived: the date received, who processed it, any note they add, the terms version and your answer choice. The platform does not store the name and date of birth from the card in their own fields. We email you a confirmation. A postal entry needs an account; there is no route for someone without one.
- Why
- To give you a real ticket in the draw, on the same footing as a paid entry.
- Legal basis
- Contract (you asked to enter); legal obligation (a free route is a condition of running these draws).
- How long
- The entry record has no automatic deletion. It is anonymised when you erase your account. We have not yet fixed how long the physical cards are kept.
- Shared with
- The email delivery provider (for the confirmation).
Draws and arcade plays
- What we hold
- For each draw: the winner, the random seed and commitment used, a published list of ticket numbers each paired with a scrambled holder reference (scrambled with a secret value we do not publish, so the list does not show who holds a ticket), and which two members of staff ran it. For each entrant, a win or loss record. For each arcade play, win or lose: the outcome, the prize type and value, the coins staked and any coins returned, the time, and a code that proves the outcome was fixed before you played.
- Why
- To run the draws and games, show you your history, pay wins, and prove the results were fair.
- Legal basis
- Contract; legitimate interests (proving fairness and handling disputes).
- How long
- No automatic deletion is set. These records survive erasure of your account carrying only your opaque account number (section 13).
- Shared with
- The published draw list is public, in the scrambled form described above. Otherwise nobody.
Winning a draw prize: claims, identity check and publication
- What we hold
- When you claim: your full name, contact email, phone number, your delivery address (only if you take the item rather than cash), your prize choice and any notes. Before any draw prize is paid or sent, a member of staff checks the winner's age and identity. The platform records only that the check was done, when and by whom; it does not store copies of documents. We also record dispatch, the payment reference and staff notes.
- Why
- To deliver or pay the prize, confirm the winner is eligible, and prevent fraud.
- Legal basis
- Contract; legal obligation; legitimate interests (fraud prevention).
- Publication
- A draw winner is shown publicly as "Anonymous winner" unless they agree otherwise. If they agree, we publish the name on their account. We do not currently publish a winner's location or photo. Agreement is recorded by our staff against the prize; there is no tick-box for it on the claim form. The lawful basis for publishing is consent, and you can withdraw it by contacting us; erasing your account turns the published name back into "Anonymous winner".
- How long
- No automatic deletion is set. Claim and fulfilment records are anonymised when you erase your account.
- Shared with
- The email delivery provider (for your winner notice). Any delivery courier will be added to this list; the platform does not yet connect to one.
Cash prizes and your bank details
- What we hold
- The first time you win an instant cash prize in the arcade we ask for the name on your bank account, the sort code and the account number. They are stored encrypted, one set per member, and replaced if you give new ones. For a draw cash prize our staff make a manual bank transfer and record a payment reference. No payment service is connected, so nothing is paid automatically.
- Why
- To pay you what you have won.
- Legal basis
- Contract.
- How long
- While your account is open, so a later win pays you without asking again. If you erase your account we delete them: straight away if nothing is still being paid out to you, or the moment that payment finishes if one is, so a payment already on its way to you is never left with nowhere to go (section 13).
- Shared with
- Nobody; no payment provider is connected.
Winners boards, profiles and crews
- What is shown
- The winners page shows recent and top arcade wins and the members who have had the most coins back, with how many they earned in the last 30 days and their current streak. These lists do not check whether you have made your profile public. They show your display name if you have set one, and otherwise the name on your account; an erased account shows as "A member". Other lists, such as the streak lists on the home and club pages, do check that your profile is public. A profile page and a link to it exist only if you make your profile public. If you join a crew, the crew's page lists its members by display name with their streaks. Scouting, which shows your display name and standing to crew members, works only if you opt in. Public profile and scouting are off by default; joining a crew is your choice.
- Why
- To show that results are real and to run the community features.
- Legal basis
- Legitimate interests for the winners page; consent for a public profile and for scouting.
- How long
- Shown while the underlying record exists. Erasing your account removes the name from what is shown.
- Shared with
- Anyone who visits the page; these pages are public.
Email and text messages
- Service emails
- We send emails that are part of running your account: verifying your address, resetting a password, a welcome message, entry and postal-entry confirmations, draw results, a winner notice with your claim link, a notice of an instant cash win, and a notice if a competition you entered is cancelled. We also send a reminder when coins you hold are about to expire, and some messages about games you have already played, such as when a machine you played changes or reopens. We treat those as service messages, so they do not depend on marketing consent and do not carry an unsubscribe link. The legal basis is contract for the first group and legitimate interests for the second. Anonymised accounts receive nothing.
- Marketing email: switched off
- We do not send marketing email today. You can tick a box at registration, at onboarding or in your account, or leave your address on the "upcoming" page, and we then keep your address, your choice, the source and the date (and, on the "upcoming" page only, your IP address) so that we can when marketing starts. One tick counts as consent; there is no confirmation email. You can switch it off any time in your consents, and an address that has unsubscribed is not re-added. Legal basis: consent.
- Launch alerts
- If you ask to be told when a competition opens, we keep your email address, the competition and your IP address, and send one email when it opens.
- Text messages
- No text message provider is connected, so no text message is sent. If you give a mobile number, it is held on your account so that we can alert you to a prize you have won. Today an attempted text, with the number and message, is written to our technical log instead of being sent (section 10).
- Tracking in email
- Our emails contain no tracking pixel and no tracked links. Images are loaded from our own servers, which can see the address the request came from.
- How long
- No automatic deletion is set for marketing preferences or launch alerts; they are deleted when you erase your account. We keep a record that a message was sent (its type and your account reference), not its contents.
- Shared with
- The email delivery provider, which handles your address, your first name where the message uses it, and the message itself (section 6).
Safer play
- What we hold
- Self-exclusion. If you exclude yourself we record it and its end date on your account, and it stops you entering. An active exclusion cannot be shortened.
Signs of harm. Every minute the platform reads the event record (section 8) for each real member who has done something new, and for any member whose level is already above green, and works out five indicators: how often you buy in a session, chasing after a loss, chasing across sessions, how fast your balance is falling per turn, and how long a session has lasted. For each it stores a green, amber or red level and the last few items behind it. Authorised staff can view the levels in our internal analysis pages. Staff receive alarm emails that contain a count, never a name. We do not use these levels to restrict your account, to decide what you are offered or to nudge you, and nothing in the platform takes an action about you because of them.
- Why
- To help members stay in control and to spot problem play.
- Legal basis
- Legitimate interests (protecting members from harm), and contract for a self-exclusion you asked for.
- How long
- No automatic deletion is set. The harm levels are deleted when you erase your account.
- Shared with
- Nobody.
Preventing fraud, abuse and bots
- What we hold
- The sign-up form uses a hidden field and a timing check to spot automated submissions; nothing is stored from them. We can also switch on a Cloudflare Turnstile check on the sign-up, complaint and basket forms. When it is on, your browser contacts Cloudflare and we send Cloudflare the check result together with your IP address. Requests to some endpoints are rate-limited using your IP address and the random cf cookie (section 7); that key is held briefly by the rate limiter, and the start of it, which includes your IP address, can be written to our log when a request is refused for arriving too fast. Refunds, chargebacks and payout checks can flag an account or payment for a member of staff to look at; a flag on its own blocks nothing.
- Legal basis
- Legitimate interests (keeping the platform secure and fair).
- How long
- Flags stay on the order or account record. We do not keep the bot-check inputs.
- Shared with
- Cloudflare, only when Turnstile is switched on. Cloudflare is a United States company (section 6).
Share links, invitation cards and campaign links
- What we hold
- When you follow a member's share link we set a cookie called loop_ref for 30 days, before you have made any cookie choice. It holds which link you came from. We also write a record of the visit with a device code (a scrambled form of your IP address and browser, see section 8). If your browser sends a privacy signal we set nothing and record nothing. The referral rewards are switched off, so at present nothing is credited to anyone and the cookie is not used to give a reward. If you arrive from a founder invitation card we keep its code in a cookie for up to a year and on your account when you register, so we can match you to the invitation. Campaign tags on a link you follow are kept on your account at registration.
- Why
- To understand how people arrive and, when the reward features are on, to credit the person who invited you.
- Legal basis
- Legitimate interests.
- How long
- The cookies expire as stated. The visit records have no automatic deletion and are anonymised when you erase your account, apart from the permanent event record (section 8).
- Shared with
- Nobody.
The holdout group
- What we do
- When you register, the platform randomly places you in a "holdout" group or a "treated" group, so that in future we can measure whether a new feature helps members. Nothing on the platform differs between the two groups today. The group is written to the event record of your registration, not to your account, and the code that reads it can only report totals for groups of 20 or more. The event record row does also carry your account number, so someone with direct access to the database could see which group a person was in; we do not read it that way.
- Legal basis
- Legitimate interests (finding out whether our features work and are safe).
- How long
- Permanent, as part of the event record (section 8).
Contacting us and complaints
- What we hold
- If you use the contact form: your name, email address, subject and message, and your account number if you are signed in. Our staff can also record correspondence with a member.
- Why and legal basis
- To answer you and handle complaints. Legitimate interests and, where a complaint concerns a contract, contract.
- How long
- No automatic deletion is set. These records are anonymised when you erase your account.
- Shared with
- Nobody, except Cloudflare's check on the form if it is switched on. The form sends no acknowledgement email.
Records of what our staff do
- What we hold
- An audit log of staff actions: who did what, to which record, the staff member's IP address and, for changes, the before and after values, which can include a member's details. Staff reading a member's record is logged too. When an account is erased we log that it happened against the opaque account number or, for someone without an account, an unsalted one-way hash of their email address, with no IP address. That hash is still personal data: anyone holding the address can compute it and check for a match.
- Why and legal basis
- Accountability, security and dispute handling. Legitimate interests and legal obligation.
- How long
- No automatic deletion is set. The audit log is deliberately kept when you erase your account, so that we can show what was done and by whom.
4 · Automated decisions
We do not make decisions about you that have a legal or similarly significant effect solely by
automated means. Draws and instant-win outcomes are random and are not chosen by reference to
who you are. Some checks run automatically and flag things for a person, and a person decides
(sections on fraud and safer play above).
5 · Under 18s
This platform is for people aged 18 and over. We ask for your date of
birth when you register and refuse those who declare themselves younger. We do not knowingly
collect data about children.
6 · Who receives your data
- Service providers acting on our instructions: ZeptoMail, who sends the emails described throughout this notice, our hosting and database providers, and Cloudflare for the bot check where it is switched on. They may use your data only to provide their service to us.
- The public, in the ways described under draws, winners and the winners boards.
- Our own staff, who can see the records they need for their job. Their access to a member's record is logged.
- Advisers, regulators, courts and the police, where the law requires or allows it.
- A buyer of the business: if we sold the whole business, your data would pass to the buyer, which would have to use it as described here. We would not sell the member dataset on its own.
We do not sell personal data. We do not share member-level data with anyone so that they can market
to you or for their own purposes. There are no advertising or analytics tags on the site, no advertising
network receives anything about you, and the retired tracking pixels and server-to-server ad transmitters no longer exist.
Hosting and database providers not yet named. This draft does not yet name
those, or say in which countries each processes your data, because that is still being settled and we will
not guess. Cloudflare is a United States company. Before a provider outside the UK handles your data we will
confirm the legal safeguard for the transfer and record it here.
7 · Cookies and similar storage
You can change your choices at any time from the Cookie policy page.
These are the cookies the platform sets:
- The session cookie (named after the site, ending -session) and XSRF-TOKEN (necessary): keep you signed in and protect forms. Set for every visitor. The session lasts 120 minutes of inactivity.
- ww_consent (necessary): remembers your cookie choices. One year.
- cf: a random value set on your first visit, unless your browser sends a privacy signal. No consent is asked for it. Today it is used only to help rate-limit requests (section 3, fraud and abuse) and is not saved in any of our databases. It exists to seed the statistical measurement in section 9, which is switched off. HttpOnly, 90 days.
- sq: set only if you accept analytics. A random reference, encrypted, 180 days. If you register, we copy it onto your account. Nothing else reads it and no guest browsing journey is recorded (section 9). It is removed if you refuse analytics.
- loop_ref: set when you follow a share link (section 3). 30 days.
- founder_code: set when you follow a founder invitation link. Up to one year, and removed when you register.
- remember_web_…: only if you tick "remember me" when signing in. It stays until you sign out or it expires.
The arcade also remembers your sound setting and whether you have played in your browser's own storage;
neither leaves your device.
8 · The event record, which is permanent
The platform keeps a permanent, append-only record of significant events: registering, signing in
and out, your cookie choice, an entry, a purchase, an arcade play, a win, a claim, a self-exclusion, a share
link visit, an email being sent (its type, a scrambled digest of the address and the subject line) and
a signed-in member looking at the winners page. Each event carries your account number, the time,
any amount involved, your cookie choices at that moment, a scrambled form of your session and a
device code, which is a scramble of your IP address and browser details.
Why: to prove that results were fair, to investigate disputes and fraud,
and to measure how the platform performs, including the safer-play indicators above.
Legal basis: legitimate interests.
How long, and what erasure does to it: the record is permanent by design and cannot be
edited or deleted, so erasing your account does not remove it. What erasure does is cut the link to your
name: after it, the events carry an account number that no longer belongs to any identifiable person. The
device code is a different matter. Someone who already held your IP address and browser details could
recompute it, so we do not call it anonymous, and it remains after erasure. We have put this question to counsel.
9 · Behavioural capture: built, and switched off
The recording described in this section is not stored today. The only things that do run are the diagnostic items listed at the end of this section. We have built a system that records
how people use the site, so that we can see what works and protect members. It is switched off and can only be
switched on by a deliberate change to the code. Before it is switched on we will update this section. The parts
of the system that do run today are stated at the end. It has three layers, each on a different legal basis, and
each treats a refusal differently.
Layer 1 · Statistical measurement of all visitors
What: a fixed list of about fifteen events with no free text, such as a page being viewed,
a session starting, a competition being viewed (by category and price band only), a cookie choice being made and a count of visitors whose browser sent a privacy signal.
No IP address is stored. Each event carries a token made from the random cf cookie and a secret
that changes every day, so the token cannot be followed from one day to the next and cannot be linked to an account.
Why: counts, to improve the service. How long: the day's rows and secret are
designed to be destroyed within about two days; only counts are kept, and counts small enough to point at a person are not published.
Who: nobody outside us. Basis: this runs without asking consent, relying on the
statistical-purposes exception in the cookie rules, which allows it where the data is used only for statistics on our own service and does not leave our
control, and on legitimate interests under UK GDPR.
How to object. A Global Privacy Control or "Do Not Track" signal stops the cf cookie
being set, so the visit would be counted without any token. You can also email us to object. A switch on the site itself that stops even the counting is not built yet.
Layer 2 · Signed-in members
What: while you are signed in, a record of what you do on the site: entering a page, how long a view stayed in front of you,
leaving a page, and timings such as how long you hesitated. It also records which prize, machine or card you were looking at. Each event is linked to your
member reference and carries your cookie choices at that moment. The plan for this layer also lists further events, such as watching a reveal, switching machine and
reading to a depth; the browser code that sends them today emits only the first three kinds. No IP address is stored.
Why: to understand how members use the platform and to improve it. It is not used to choose what you are shown, to time offers to you or to nudge you,
and no member-facing part of the platform reads it.
Basis and refusal: legitimate interests, not consent. It is conditional on your having accepted the current terms.
Refusing analytics on the cookie banner does not currently stop this layer; the banner choice is recorded beside each event but does not switch it off.
There is no per-member switch for this layer in your account or anywhere in the platform yet, so before it is switched on we will build a way to honour an objection, and you will be able to object by emailing us. Erasing your account deletes these records that are tied to your member reference.
How long: events are first held in a buffer and moved to analysis tables; the buffer is emptied 14 days after the move. The period for the analysis tables is not set: a 14-month figure is written into our settings, but nothing enforces it.
Who: nobody outside us.
Layer 3 · Consented guest journeys: not built
This layer would follow a visitor's whole journey before they register, on their consent. It does not exist: the recording endpoint refuses its events. Today, if you accept
analytics on the cookie banner, the only effect is the sq cookie in section 7, which we copy onto your account if you register and
otherwise do not use. If you refuse analytics, that cookie is removed.
What runs today, even with capture switched off. The recording endpoint receives messages from the site's code. When it refuses one (for example a malformed message)
it keeps the raw message for 30 days to find faults; no IP address is kept with it. It also keeps a daily count of how many messages it discarded, by event name, with nothing about a person. The
safer-play indicators in section 3 run today, but they read the event record in section 8, not this system. The cf cookie is set today, as section 7 says.
Nothing in this system is sold, shared with an advertiser or sent to a third party.
10 · Technical logs
Our servers keep technical logs to diagnose faults. They can include IP addresses, the address or phone number of a message the platform
tried to send, and error details. The main application log is not rotated automatically. Queued and failed jobs, such as an email that could not be sent,
contain the recipient and are kept until we clear them. Failed jobs are deleted if you erase your account and are otherwise not cleared automatically. Legal basis: legitimate interests (keeping the service working and secure).
11 · How long we keep things: the summary
Deleted automatically today:
- An unverified account with no activity: 7 days by default.
- Sessions: 120 minutes of inactivity. Password-reset links: 60 minutes.
- Capture: refused messages after 30 days; the buffer 14 days after it is processed; the daily statistical rows and secrets within about two days (switched off, section 9).
Everything else has no automatic deletion. It is kept until you erase your account, in the form
set out in section 13, or until we delete it by hand. We have not yet set fixed periods for orders, the coin ledger, draw and play records, winner records, postal entries,
consent records, complaints, staff correspondence, the audit log, marketing preferences, launch alerts or the safer-play levels, and we will not state a period we have not set.
Where the law requires us to keep financial or draw records for a set time, that requirement takes precedence over a request to delete them.
12 · What this draft does not yet settle
- The names and countries of our email delivery, hosting and database providers, and the transfer safeguard for each.
- Fixed retention periods for the records listed above.
- Whether the bot check is switched on for the live site.
- The payment provider, once one is connected.
- The legal-basis analysis, which is for counsel.
13 · Your rights, erasure and export
- See and download your data. From your account you can download a file of the data the platform holds about you, including records that survive erasure, in a machine-readable format. It leaves out passwords and secret keys, and some technical fields: device codes, the before-and-after values in the staff log, session and queue contents, and draw seeds. If you want those, ask us. This is also your right to portability.
- Correct it. Edit your name and email on your profile page, or contact us for anything else.
- Erase your account. From your account page, with your password, and it takes effect at once. Your name, email address, phone number, date of birth, campaign tags, display name, referral and invitation codes and two-step keys are removed from your account, and it is locked. Your sessions, reset links, safer-play levels and behavioural-capture records tied to your member reference are deleted. Winner claims, prize records, postal entries, consent records, complaints, correspondence and your marketing and launch-alert records are deleted or anonymised. The engine checks its own work and reports if anything remains.
- What stays after erasure. The anonymised account row, so that the records that point at it still make sense. Orders, tickets, the coin ledger, draw and play records, refunds and referral records, carrying only your opaque account number. The permanent event record, including the device codes and a record that the erasure happened, which carries your account number and the device code of the request (section 8). The audit log, including a second record that the erasure happened (section 3). Payment-notification payloads and queued jobs, which are not scrubbed. Your bank details, only if a payment to you is still in progress — deleted the moment it finishes (section 3). For someone with no account, erasure by email is handled by our staff.
- Also: to restrict processing or to object to processing that relies on legitimate interests (including behavioural capture for signed-in members and the safer-play indicators), contact us. To withdraw consent given for marketing email or a public profile, use your consents and profile pages, or contact us.
- We answer within one month. We may need to check who you are first. If you have no account, email us.
- Complain. You can complain to the Information Commissioner's Office at ico.org.uk. We would like the chance to put things right first.
14 · What we keep when an account is erased
When you erase your account, we keep one small record so that a self-exclusion, a spending
limit, a per-person entry limit or a one-off welcome gift cannot be shed simply by erasing
and signing up again. It holds no name, no address, and no link back to the account you
erased.
- What we keep
- A one-way, keyed hash of your email address — keyed so that only we can test an address against it, using a secret kept apart from the record itself — and only the smallest marker each purpose below needs: the end date of a self-exclusion, or that it has no end date; how many tickets you held in a draw still open when you erased; and whether the one-off welcome gift had already been given. We do not yet have a ban feature, so nothing is kept for one. We do not keep any identity document details at a cash payout — we record only that a check happened, when, and which member of staff did it (section 8) — so there is nothing of that kind to hash here either.
- Why
- To keep a self-exclusion or spending limit in force if you sign up again; to keep the per-person limit on draw entries honest across accounts; and to stop the welcome grant being claimed more than once.
- Legal basis
- Our intended basis, which counsel is still reviewing: legal obligation, for keeping a self-exclusion or spending limit in force (responsible play); and legitimate interests, for preventing fraud and abuse (the draw limit and the welcome grant).
- A hash is still personal data
- A hash is not anonymous. Anyone who can test an email address against it can tell whether it matches, and we keep it precisely so that we can do that when someone signs up again. We treat it as personal data, and the rights in section 13 apply to it.
- How long
- A self-exclusion marker is kept for as long as the exclusion itself lasts — indefinitely, if you set it that way. The draw-limit and welcome-gift markers are kept for twelve months from when you erased, whichever way the self-exclusion marker goes, and are then cleared. Once nothing is left to keep, the whole record is deleted.
- Shared with
- Nobody.