Privacy Policy

Last updated: 15 August 2026

Draft template — not yet legally reviewed

This document is a working template prepared for Don Quack. It has not been reviewed by a qualified lawyer, and the highlighted fields still need real values. Do not treat it as final or as legal advice.

This policy explains what personal data Don Quack collects, why, and what rights you have over it. The data controller is [Legal entity name], [Registered address], contactable at [privacy email].

1. What we collect

Information you give us

  • Your email address, when you create an account. This is the only piece of personal information we ask for. We do not collect your name, address, date of birth, or phone number.
  • Messages you send us, if you contact support.

Information created by using the service

  • Sign-in records — hashed one-time codes, when they were issued and used, and the number of failed attempts. We store codes only in hashed form, never in plain text.
  • Your IP address, recorded in server logs and used to rate-limit sign-in requests. This is a security measure against brute-force and abuse.
  • Your forecast history — which fixtures you requested and what we returned, so you can see your history in the app.
  • Subscription and payment records — your plan, its status and dates, the amount, and the payment identifiers returned by our payment provider.
  • Language preference.

What we deliberately do not collect

We do not use analytics, advertising, tracking pixels, or third-party tracking cookies of any kind. We do not build advertising profiles, and we never sell your personal data.

Our fonts are served from our own servers rather than a font CDN, so loading a page on Don Quack does not reveal your IP address to any third party.

We also never see your payment credentials. Cryptocurrency payments are handled entirely by NOWPayments; no card number, wallet key, or seed phrase ever reaches our servers.

2. Cookies and local storage

Don Quack does not set advertising or analytics cookies, so there is no consent banner to click through.

We do store one item in your browser’s local storage: the session token that keeps you signed in for up to 30 days. It is strictly necessary to operate the service you asked for. Clearing your browser storage signs you out.

3. Why we use your data, and our legal basis

  • To run your account and deliver forecasts — necessary for performance of our contract with you (GDPR Art. 6(1)(b)).
  • To send one-time sign-in codes — performance of the contract (Art. 6(1)(b)).
  • To take payment and manage subscriptions — performance of the contract (Art. 6(1)(b)).
  • To send service emails, such as a notice before your subscription ends — performance of the contract, or our legitimate interest in keeping you informed (Art. 6(1)(b) and 6(1)(f)).
  • To rate-limit sign-ins and prevent abuse — our legitimate interest in keeping the service secure (Art. 6(1)(f)).
  • To meet tax and accounting obligations — compliance with a legal obligation (Art. 6(1)(c)).

We do not use your data for automated decision-making that produces legal or similarly significant effects for you. The forecasts themselves are generated from sports data, not from anything about you.

4. Who we share it with

We share the minimum necessary with service providers who process data on our behalf under contract:

  • Resend — sends your sign-in codes and service emails. Receives your email address.
  • NOWPayments — processes cryptocurrency payments. Receives an order reference and amount.
  • DigitalOcean — hosts our servers and database in [data centre region].
  • OpenAI — generates forecast commentary. Receives match data only; no personal data about you is sent.
  • Telegram — only if you choose to use our Telegram bot, in which case Telegram’s own privacy policy also applies.

We may also disclose data where legally required, or to establish or defend legal claims.

5. International transfers

Some providers are based outside the European Economic Area, principally in the United States. Where data is transferred outside the EEA we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision. [Confirm the transfer mechanism in place with each processor.]

6. How long we keep it

  • Account data — while your account exists, then deleted within [30] days of you closing it.
  • One-time codes — minutes; they expire and are purged shortly after use.
  • Server and rate-limit logs[90] days.
  • Forecast history — while your account exists.
  • Payment and invoice records — retained as long as tax law requires, typically [7] years, even after your account is closed.

7. Your rights

If you are in the EEA or UK you have the right to access your data, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent where we rely on it. Exercising these rights is free and we will respond within one month.

Write to [privacy email] from the address on your account. You also have the right to complain to your national data protection authority; ours is [Supervisory authority].

8. Security

Traffic is encrypted with TLS. Sign-in codes are stored hashed with a server-side secret. Access to production systems is restricted, and our internal services are not exposed directly to the internet.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a high risk to your rights, we will notify you and the relevant authority as the GDPR requires.

9. Children

Don Quack is for adults aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, contact [privacy email] and we will delete it.

10. Changes

We will update this policy as the service changes, and will revise the date at the top. If a change materially affects your rights we will tell you by email.

See also our Terms of Service.

Questions about this document? Contact us at legal@donquack.com.