Privacy Policy
Last updated: January 2026
1. Information We Collect
We collect information you provide directly to us, including:
- Account information (email, username, password)
- Profile information (display name, avatar)
- Financial information (wallet balances, transaction history)
- Trading activity (orders, positions, trade history)
- Communications (support requests, feedback)
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send technical notices and support messages
- Respond to your comments and questions
- Detect and prevent fraud and abuse
- Comply with legal obligations
3. Information Sharing
We do not sell your personal information. We may share your information with third parties only in the following circumstances: with your consent, to comply with legal obligations, to protect our rights and safety, or with service providers who assist in our operations.
4. Data Security
We implement industry-standard security measures to protect your personal information. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
5. Your Rights
You have the right to access, correct, or delete your personal information. You can manage your account settings or contact us to exercise these rights.
6. Cookies
We use cookies and similar technologies to collect information about your browsing activities and to personalize your experience. You can control cookies through your browser settings.
7. GDPR Compliance (European Users)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional rights and information apply to you under the General Data Protection Regulation (GDPR):
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide our prediction market services, execute trades, and manage your account
- Legitimate Interests: Processing for fraud prevention, security, service improvement, and direct marketing (where permitted)
- Legal Obligation: Processing required to comply with anti-money laundering (AML), know your customer (KYC), and tax reporting requirements
- Consent: Processing based on your explicit consent, such as marketing communications and optional analytics
Your GDPR Rights
Under GDPR, you have the following rights:
- Right of Access: Request a copy of all personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Right to Restrict Processing: Request limitation of how we process your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or direct marketing
- Right to Withdraw Consent: Withdraw consent at any time without affecting prior lawful processing
Data Protection Authority
You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights. For EEA residents, you can find your local authority at the European Data Protection Board website.
Data Protection Officer
For GDPR-related inquiries, you may contact our Data Protection Officer at dpo@predictbet.pro
8. CCPA/California Privacy Rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Your California Rights
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you
- Right to Delete: Request deletion of your personal information, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of the sale or sharing of your personal information (we do not sell personal information)
- Right to Limit Use: Limit the use and disclosure of sensitive personal information
- Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights
Categories of Personal Information Collected
In the past 12 months, we have collected the following categories of personal information:
- Identifiers: Email address, username, IP address, device identifiers
- Financial Information: Wallet addresses, transaction history, trading activity
- Internet Activity: Browsing history on our platform, search queries, interaction with our services
- Geolocation Data: Approximate location based on IP address
- Inferences: Predictions about your preferences and trading behavior
No Sale of Personal Information
We do not sell your personal information to third parties. We have not sold personal information in the preceding 12 months.
Submitting Requests
To exercise your California privacy rights, submit a verifiable consumer request through your account settings or by contacting us. We will verify your identity using the email address associated with your account. You may designate an authorized agent to make a request on your behalf.
Response Timing
We will respond to verifiable requests within 45 days. If we require more time, we will inform you of the reason and extension period (up to 90 days total).
9. Data Retention Periods
We retain your personal information for specific periods based on the type of data and our legal obligations:
Retention Schedule
- Account Information: Retained for the duration of your account plus 7 years after account closure (for regulatory compliance)
- Transaction Records: Retained for 7 years after the transaction date (tax and AML requirements)
- Trading History: Retained for 7 years after market resolution for regulatory reporting
- KYC Documents: Retained for 5 years after the end of the business relationship
- Communication Records: Support tickets and correspondence retained for 3 years
- Security Logs: IP addresses and access logs retained for 2 years
- Marketing Preferences: Retained until you withdraw consent or delete your account
- Cookie Data: Session cookies deleted on browser close; persistent cookies retained up to 1 year
Data Deletion
When retention periods expire, we securely delete or anonymize your data. If you request account deletion, we will delete personal data within 30 days, except where retention is required by law. Anonymized data may be retained for statistical analysis.
10. Third-Party Service Providers
We work with trusted third-party service providers to operate our platform. These providers process your data only on our behalf and under strict contractual obligations:
Our Service Providers
- Supabase (Database and Authentication): Stores account data, user authentication, and application data. Based in the United States with SOC 2 Type II certification.
- Vercel (Hosting): Hosts our web application and handles request routing. SOC 2 Type II compliant with global edge network.
- Polygon Network (Blockchain): Processes USDC cryptocurrency transactions. Decentralized public blockchain.
- Resend (Email): Sends transactional emails including verification, notifications, and account alerts.
- The Odds API (Sports Data): Provides real-time sports odds and game data. No personal user data is shared.
- Anthropic (AI Services): Powers AI-assisted features. Query data is processed but not stored for training.
Provider Obligations
All service providers are bound by data processing agreements (DPAs) that require them to: process data only according to our instructions, implement appropriate security measures, assist with data subject requests, notify us of any data breaches, and delete or return data upon termination of services.
11. International Data Transfers
Your personal data may be transferred to and processed in countries outside your country of residence. We implement appropriate safeguards for these transfers:
Transfer Mechanisms
- Standard Contractual Clauses (SCCs): We use EU-approved SCCs for transfers to countries without an adequacy decision
- Adequacy Decisions: Where available, we rely on European Commission adequacy decisions
- Supplementary Measures: Additional technical and organizational measures including encryption and access controls
Countries of Processing
Your data may be processed in the United States (primary servers), European Union (edge locations), and other locations where our service providers operate. Regardless of location, we ensure equivalent protection of your data.
Technical Safeguards
- All data in transit is encrypted using TLS 1.3
- Data at rest is encrypted using AES-256
- Access to personal data is restricted to authorized personnel only
- Regular security audits and penetration testing
Obtain a Copy
You may request a copy of the Standard Contractual Clauses or other transfer mechanisms by contacting our Data Protection Officer.
12. Data Breach Notification
We take data security seriously and have procedures in place to handle personal data breaches:
Breach Detection
We employ continuous monitoring, intrusion detection systems, and security audits to identify potential breaches. Our security team investigates any suspicious activity immediately.
Notification Procedures
- Regulatory Authorities: We will notify relevant data protection authorities within 72 hours of becoming aware of a breach that poses a risk to individuals' rights and freedoms
- Affected Users: We will notify you directly without undue delay if a breach is likely to result in high risk to your rights and freedoms
- Notification Content: Breach notifications will include the nature of the breach, likely consequences, measures taken to address it, and contact information for further inquiries
Our Response
In the event of a breach, we will:
- Immediately contain the breach and assess its scope
- Investigate the root cause and implement remediation measures
- Document the breach, its effects, and our response
- Review and strengthen security measures to prevent recurrence
- Cooperate fully with regulatory investigations
Recommended User Actions
If notified of a breach affecting your account, we recommend: changing your password immediately, enabling two-factor authentication if not already active, monitoring your account for unauthorized activity, and being vigilant about potential phishing attempts.
13. Children's Privacy
Our services are not intended for children, and we do not knowingly collect personal information from minors:
Age Requirement
You must be at least 18 years old (or the age of majority in your jurisdiction) to use PredictBet Pro. By creating an account, you represent and warrant that you meet this age requirement.
No Collection from Children
We do not knowingly collect, use, or disclose personal information from anyone under 18 years of age. Our KYC verification process includes age verification to prevent minors from accessing our services.
Parent/Guardian Notice
If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately. We will take steps to delete such information from our servers.
Discovery of Minor's Data
If we discover that we have inadvertently collected personal information from a child under 18, we will: immediately suspend the account, delete all associated personal data, and notify the parent or guardian if possible.
COPPA Compliance
In compliance with the Children's Online Privacy Protection Act (COPPA), we do not collect personal information from children under 13 under any circumstances. Users between 13-17 are also prohibited from using our prediction market services.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at support@predictbet.pro
For GDPR-specific inquiries, contact our Data Protection Officer at dpo@predictbet.pro
Mailing Address
PredictBet Pro, Attn: Privacy Team
We aim to respond to all privacy inquiries within 30 days.