01
Introduction
SnapStakes ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use the SnapStakes mobile application ("App"). This Privacy Policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
03
Data We Collect
3.1 Data You Provide
WHAT WE COLLECT
Phone number: Account verification and login
Display name: Identify you to other players
Photos and videos: Core gameplay (challenge submissions)
Payment information: Processed by Stripe. We do not store card details.
Identity verification: Collected by Stripe Connect for payouts (KYC)
3.2 Data We Collect Automatically
| Data Type | Purpose |
|---|---|
| Device information | App functionality and troubleshooting |
| Push notification token | Game notifications |
| Photo timestamp and GPS | Verify submissions are genuine |
| IP address | Security and fraud prevention |
| Voting patterns | Aggregated analysis of your voting history across Games to detect anomalous or abusive voting behaviour and enforce Voting Integrity clause in Terms of Service |
3.3 Cookies and Tracking
SnapStakes is a native mobile application. We do not use cookies, web beacons, or browser-based tracking technologies.
3.4 Data We Do NOT Collect
We do not store payment card details (handled entirely by Stripe). We do not access your contacts, call logs, or messages. We do not use cookies or web tracking technologies (the App is a native mobile application). We do not sell your personal data to third parties.
3.5 Third-Party Images in Challenge Submissions
Players may submit photos or videos that incidentally include other people (bystanders, friends, etc.). These images are processed as follows:
- Player responsibility: Players submitting content are responsible for ensuring they have the right to photograph any individuals depicted. Our Terms of Service require players not to submit content without appropriate consent.
- Legal basis: We process these images under Article 6(1)(f) UK GDPR (legitimate interests) for the purpose of operating the game. Our legitimate interest is providing the core gameplay experience.
- Visibility: Submitted images are visible only to other players in the same game (typically 2-10 people).
- Right to removal: If you appear in a photo submitted by another player and wish to have it removed, contact privacy@snapstakes.app with details about the game and image. We will review and respond within 7 days.
- Share cards: Winners may share a "winner card" showing their winning photo. Players consent to this potential public sharing when they submit content.
04
How We Use Your Data
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Provide and operate the App | Performance of contract (Art. 6(1)(b)) |
| Process payments and payouts | Performance of contract (Art. 6(1)(b)) |
| Verify identity for payouts | Legal obligation (Art. 6(1)(c)) |
| Send push notifications | Legitimate interest (Art. 6(1)(f)) |
| Prevent fraud and abuse | Legitimate interest (Art. 6(1)(f)) |
| Monitor voting patterns for abuse or manipulation | Legitimate interest (Art. 6(1)(f)) |
| Improve the App | Legitimate interest (Art. 6(1)(f)) |
05
Who We Share Your Data With
5.1 Other Players
Your display name and challenge submissions are visible to other players in your games. Your wallet balance, phone number, and payment details are never shared.
Your individual vote choices are anonymous - other players only see aggregate vote counts, never how you specifically voted. However, we may analyse voting patterns internally for the purpose of detecting anomalous or abusive behaviour (see Section 3.2). Individual votes are never disclosed to other players.
5.2 Service Providers
| Provider | Data Shared | Purpose |
|---|---|---|
| Stripe | Payment data, identity | Payments, KYC, payouts |
| Supabase | Account and game data | Database, authentication |
| Twilio | Phone number | SMS verification |
| Expo / Apple | Push token | Notifications |
06
International Data Transfers
Some service providers are based outside the UK. We ensure appropriate safeguards via UK adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules.
07
Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 6 months |
| Challenge submissions | Duration of game + 12 months |
| Transaction records | 7 years (UK financial regulations) |
| Push notification tokens | Until logout or uninstall |
08
Your Rights Under UK GDPR
You have the right to: access your data, rectify inaccuracies, request erasure, restrict processing, data portability, object to processing, withdraw consent, and lodge a complaint with the Information Commissioner's Office (ICO).
ICO: ico.org.uk · Phone: 0303 123 1113
To exercise your rights, contact support@snapstakes.app. We will respond within one month.
09
Data Security
We implement encryption in transit (TLS/HTTPS), encryption at rest, row-level database security, phone-based authentication with secure tokens, and PCI-DSS Level 1 compliant payment processing via Stripe.
10
Children's Privacy
IMPORTANT
The App is strictly for users aged 18 and over. We do not knowingly collect data from anyone under 18. If discovered, accounts will be immediately terminated and data deleted.
11
Changes to This Policy
We may update this policy from time to time. Material changes will be notified through the App. The "Last Updated" date indicates when the latest changes were made.