Privacy

Privacy Policy

Last updated: January 30, 2025

Privacy at a Glance

  • • We collect only what's necessary to provide the Service
  • • We NEVER sell your personal data
  • • No third-party tracking or advertising cookies
  • • Passwords are hashed; data encrypted in transit
  • • You can delete your account and data at any time

1. Information We Collect

  • Account Data: Email address, name, and profile picture (via Google OAuth or manual registration).
  • Usage Data: Pages visited, predictions viewed, community activity, and feature usage patterns. This data is collected via server-side analytics and is anonymized.
  • Payment Data: Processed securely by Paystack. We do NOT store card numbers, CVVs, or bank details on our servers.
  • Device Information: Browser type, operating system, IP address, and device identifiers — used solely for security and fraud prevention.

2. How We Use Your Data

  • To provide and maintain the Service (predictions, community features, dashboard).
  • To process subscriptions and manage your account.
  • To send transactional notifications about activity relevant to you (likes, comments, follows).
  • To improve prediction quality and platform performance via aggregated, anonymized analytics.
  • To detect and prevent fraud, abuse, and unauthorized access.

3. Data Sharing

We do NOT sell, rent, or trade your personal data. We share data only with these essential service providers:

  • Paystack: For secure payment processing (PCI DSS compliant).
  • Supabase: For database hosting (EU West region, SOC 2 compliant).
  • Vercel: For application hosting and edge delivery.
  • Google: Only if you use Google OAuth for authentication.
  • Sentry: For error monitoring and application stability (anonymized error data only).

We may disclose data if required by law, court order, or to protect the rights and safety of our users.

4. Data Security

We implement industry-standard security measures: passwords are hashed with bcrypt (12 rounds); all data in transit is encrypted via TLS 1.3; sessions use JWT tokens with secure expiration policies; API endpoints are rate-limited to prevent abuse; database connections are secured through Supabase's managed PostgreSQL infrastructure with connection pooling. While we strive to protect your data, no system is 100% secure and we cannot guarantee absolute security.

5. Cookies & Local Storage

We use essential cookies only for authentication (session tokens) and user preferences (theme, settings). We do NOT use third-party tracking cookies, advertising cookies, or analytics cookies. Local storage is used to cache user preferences for better performance. You can clear cookies and local storage at any time through your browser settings.

6. Your Rights

  • Access: View your data from your Dashboard at any time.
  • Correction: Update your profile, settings, and personal information at any time.
  • Deletion: Request complete account deletion from Dashboard settings or by contacting support. We will process deletion within 30 days.
  • Export: Contact us to request a portable copy of your personal data.
  • Objection: You may object to certain data processing activities by contacting support.

7. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If we learn that we have collected data from a user under 18, we will delete that data promptly. If you believe a minor has provided us with personal data, please contact us immediately.

8. International Data Transfers

Your data may be processed in locations outside your country of residence, including the European Union (Supabase), United States (Vercel), and other regions where our service providers operate. We ensure that all transfers comply with applicable data protection laws and that adequate safeguards are in place.

9. Data Retention

Account data is retained while your account is active. Upon account deletion, personal data is permanently removed within 30 days. Anonymized, aggregated prediction statistics (which cannot identify you) may be retained indefinitely for improving the Service. Payment records are retained as required by applicable tax and financial regulations.

10. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact

For privacy-related inquiries, data requests, or concerns, contact us at support@vantagegold.live. We aim to respond to all privacy requests within 14 business days.

This Privacy Policy is part of our Terms of Service. By using Vantage Gold, you consent to the data practices described herein.