Privacy Policy
Last updated: 8 May 2026
1. What we collect
- Account data: email address (required for magic-link auth), optional name.
- Usage data: API requests (endpoint, timestamp, response code) — used for rate-limit enforcement and abuse detection. Not used for tracking or marketing.
- Billing data: processed by our third-party Merchant of Record. We receive your purchase status and a customer-id; we never see card numbers.
- Webhook configuration: URLs and HMAC secrets you configure. We store these to deliver events.
2. What we don't collect
- No analytics scripts on app pages (Google Analytics, Hotjar, Mixpanel, etc. are not used).
- No tracking cookies. Only a technical server-side session cookie and a bot-mitigation cookie are used.
- No third-party advertising trackers.
3. Operator data
The data we expose to subscribers is about online operators (companies/brands) — not about end-users of those operators. We do not collect, process, or expose personal data of players.
4. Sub-processors
| Service | Purpose | Data shared |
| Payment processor (Merchant of Record) | Payment processing | email, billing address |
| Email delivery provider | Transactional email (magic-link, account notifications) | email |
| CDN & security provider | CDN, DDoS protection | IP, request metadata |
5. Data retention
- Account data: retained while your account exists; deleted within 30 days of an account-deletion request.
- Usage logs: retained for a limited period for abuse detection, then aggregated.
- Magic-link tokens: short-lived, deleted after use.
6. Your rights (GDPR / CCPA)
- Access: request a copy of your data.
- Correction: request edits to inaccurate data.
- Deletion: request account deletion (subject to legal retention requirements).
- Portability: data export available on request.
- Objection: object to processing of your data (we may then be unable to provide the Service).
Email team@dataglass.pro with the subject "GDPR request" for any of the above.
7. Security
- HTTPS everywhere.
- API keys stored hashed, never in plaintext.
- Magic-link tokens hashed, short-lived, one-time use.
- Database access restricted to the application service account.
- Backups encrypted.
8. International transfers
Application servers are located in the Middle East (UAE). By using the Service, you consent to transfer of your data to this region for processing. Sub-processors operate in the EU and US; standard contractual clauses apply where required.
9. Changes
Material changes notified via email at least 14 days before effective date.
10. Contact
team@dataglass.pro