Legal

Privacy Policy

We take your privacy seriously. This policy explains what data we collect, why we collect it, and what rights you have under the GDPR.

Last updated: April 9, 2026

1. Who we are

BetsPlug ("we", "us", "our") is an AI-driven sports analytics platform operated from the Netherlands. We are the data controller for the personal information described in this policy. You can reach us at support@betsplug.com.

2. What data we collect

We only collect the data we genuinely need to operate the service, bill your subscription and improve our product.

Account data

  • Name and email address (when you create an account)
  • Country of residence (for tax and compliance reasons)
  • Hashed password (we never store your password in plain text)
  • Subscription tier and plan history

Payment data

  • Payment is handled by Stripe and PayPal. We never see or store your full card number, CVC or bank details - these go directly to our payment processors.
  • We do store the last four digits of your card, the card brand, and a tokenised reference so we can show your saved method and process recurring charges.

Usage data

  • Pages visited, features used, predictions viewed
  • Device type, browser, approximate location (city level, derived from IP)
  • Anonymised performance metrics (load time, errors)

3. Why we collect it

  1. To deliver the service - your account, predictions, notifications, customer support.
  2. To process payments - recurring subscription billing via Stripe and PayPal.
  3. To improve the product - anonymised analytics on which features get used so we know what to build next.
  4. To meet legal obligations - tax records, fraud prevention, regulatory requests.

4. Who we share it with

We share data only with carefully selected processors who help us run BetsPlug. Each of them is bound by a data processing agreement.

  • Stripe & PayPal - payment processing
  • Vercel - hosting and edge delivery (data center in Frankfurt, EU)
  • Cloudflare - DDoS protection and CDN
  • Sendgrid / Postmark - transactional email (account confirmations, receipts)

We never sell your personal data to advertisers or data brokers. Full stop.

5. How long we keep it

  • Account data: as long as your account is active, plus 30 days after deletion.
  • Billing records: 7 years (legally required by Dutch tax law).
  • Usage analytics: anonymised after 90 days.
  • Server logs: 30 days.

6. Your rights under the GDPR

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Export your data in a portable format
  • Object to processing or restrict it
  • File a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens)

To exercise any of these rights, email support@betsplug.com. We will respond within 30 days.

7. Security

We use TLS encryption for all data in transit, encrypted storage at rest, hashed passwords (bcrypt), and strict role-based access controls. We are PCI DSS compliant via our payment processors. If we ever experience a data breach affecting your account, we will notify you and the relevant authority within 72 hours, as required by the GDPR.

8. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date at the top and, for material changes, notify you by email.

9. Contact

Questions about this policy or your data? Email us at support@betsplug.com.