Privacy Policy

Last updated: May 2026

1. Information We Collect

When you create an account and use the Platform, we collect:

  • First name and email address
  • Country of residence
  • Hashed password (we never store plain-text passwords)
  • Spin history, points balance, level, and achievement progress
  • Prize redemption records
  • IP address (via hosting logs, used for rate limiting and security)

We do not collect or store payment information. We do not collect sensitive personal information such as government IDs or financial account numbers.

2. How We Use Your Information

  • To create and manage your account
  • To operate the daily spin game and track prize history
  • To send transactional emails (account welcome, spin reminders, prize notifications)
  • To enforce our Terms of Service and prevent fraud
  • To improve and maintain the Platform
  • To comply with applicable laws and regulations

We do not sell your personal information to third parties.

3. Data Storage & Security

  • Your data is stored in a hosted PostgreSQL database with encryption at rest
  • Passwords are hashed using bcrypt with a minimum of 12 salt rounds
  • Sessions use secure, HttpOnly JWT cookies
  • We use rate limiting to protect against brute-force attacks
  • While we take reasonable steps to protect your data, no system is 100% secure. In the event of a data breach, we will notify affected users as required by applicable law

4. Cookies

We use one secure, HttpOnly authentication cookie strictly for session management. We do not use third-party tracking cookies, advertising cookies, or analytics cookies. If you disable cookies, you will not be able to log in to the Platform.

5. Third-Party Service Providers

We share data with the following service providers only to the extent necessary to operate the Platform:

  • Supabase / PostgreSQL — database hosting
  • Vercel — web hosting (server logs may include IP addresses)
  • Resend — transactional email delivery (your email address is shared for sending)
  • Upstash — rate limiting (IP-based, not stored persistently)
  • Affiliate partners — when you click an affiliate link, the partner's own privacy policy applies to any data collected on their site

6. Email Communications

By creating an account, you consent to receive transactional emails related to your account (welcome email, prize notifications, spin reminders). You may opt out of non-essential marketing emails at any time by clicking "unsubscribe" in any email or contacting us at hello@jackpotjerseys.com. We comply with the US CAN-SPAM Act and Australian Spam Act 2003.

7. Your Rights — All Users

Regardless of your location, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your account and associated personal data
  • Withdraw consent for email communications at any time

To exercise these rights, contact us at hello@jackpotjerseys.com. We will respond within 30 days.

8. Australian Privacy Act

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If you are an Australian resident and believe we have breached the APPs, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

9. California Residents — CCPA Rights

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights:

  • Right to Know — you may request details about the categories and specific pieces of personal information we have collected about you
  • Right to Delete — you may request deletion of your personal information, subject to certain exceptions
  • Right to Opt-Out — we do not sell personal information, so there is nothing to opt out of
  • Right to Non-Discrimination — we will not discriminate against you for exercising your CCPA rights

To submit a CCPA request, email us at hello@jackpotjerseys.com with "CCPA Request" in the subject line.

10. Children's Privacy

The Platform is not directed to children under the age of 18. We do not knowingly collect personal information from anyone under 18. If we discover we have collected data from a minor, we will delete it immediately. If you believe a minor has created an account, contact us at hello@jackpotjerseys.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised date. Material changes will be communicated via email where required by law. Continued use of the Platform after changes are posted constitutes your acceptance of the updated policy.

12. Contact

For any privacy-related questions or requests, contact us at hello@jackpotjerseys.com or via our contact page.