Scope & Acceptance
This Privacy Policy describes how BookieSlip, Inc. ("BookieSlip," "we," "us," or "our") collects, uses, shares, and protects personal information about you when you use our website, mobile apps, APIs, and related services (the "Services").
We are a Delaware corporation. The Services are operated from the United States and are intended for U.S. residents 21 years of age or older. By using the Services, you consent to the practices described in this Policy.
This Policy is incorporated by reference into our Terms of Use, House Rules, and Sweepstakes Rules. If you do not agree with this Policy, do not access or use the Services.
Categories of Information We Collect
We collect the following categories of personal information, organized per California Civil Code § 1798.140 with examples specific to the Services.
| Category (CCPA bucket) | Examples we collect |
|---|---|
| A. Identifiers | Legal name, postal address, email address, telephone number, date of birth, Account username, IP address, device identifier, advertising identifier (IDFA/AAID), Account UID, Social Security Number (last 4 or full where required for tax reporting). |
| B. Customer records (Cal. Civ. Code § 1798.80) | Government-issued photo ID image, address proof (utility bill, bank statement), payment-method token (provided by Stripe), redemption shipping address, W-9 information. |
| C. Commercial / wagering activity | Bets placed, amounts wagered, settlement outcomes, parlay legs, picks viewed, picks tailed, Prize Coin redemptions, subscription tier, promo usage. |
| D. Internet and network activity | Pages viewed, features used, search and filter history, click and tap interactions, session duration, referring URL, error logs, crash reports. |
| E. Geolocation | Coarse location derived from IP address, and where you grant permission, precise GPS-level location at the time of wager acceptance or redemption. |
| F. Audio / visual | Selfie photo or short video submitted for ID verification, which is used solely for one-time biometric matching. Support call recordings if you opt in. |
| G. Professional / employment | Not collected, except if you apply for a job with us. |
| H. Education information | Not collected. |
| I. Inferences | Wagering pattern signals used to detect fraud, multi-accounting, syndicate play, and to model your responsible-gaming profile; preferences inferred from your activity for product personalization. |
| J. Sensitive PI (CPRA § 1798.140(ae)) | Government identification numbers (SSN, driver's license), financial-account access credentials (handled by Stripe — see Section 8), precise geolocation (when opted-in), Account login credentials, biometric information processed for identity verification. |
We do not collect. We do not collect racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, health data, sexual orientation or sex-life data, or any other sensitive category outside what is listed above.
Sources of Information
We obtain personal information from three categories of sources.
| Source | What we receive |
|---|---|
| Directly from you | Information you enter at registration, in Account Settings, when submitting an AMOE postcard, when uploading KYC documents, when contacting support, when posting User Content, or when responding to a survey. |
| Automatic from your device | IP address, device and browser information, advertising identifiers, cookies and SDK identifiers, interaction telemetry, error and crash reports, network performance signals. |
| Third parties | Identity-verification vendors (image, ID-document validation, watchlist screening), geolocation vendors, fraud-prevention vendors, payment processor (Stripe), sports data providers (Sportradar, SportsDataIO) for non-personal scoring and stats, advertising and marketing partners (when you click their ads or sign up via their referrals), and government or law-enforcement sources where lawful. |
How We Use Information
We use personal information for the following business purposes.
- Operate the Services. Create and manage your Account; accept wagers and grade outcomes per the House Rules; process redemptions; deliver subscription benefits.
- Verify your identity and age. Confirm you are 21+ and a U.S. resident outside Restricted States, including by biometric ID-to-selfie matching (Section 9).
- Process payments and tax reporting. Charge subscription fees and bundle purchases via Stripe; issue Form 1099-MISC where required.
- Detect and prevent fraud. Multi-accounting detection, syndicate-pattern analysis, AML-style controls, sanctions screening, VPN and geo-spoofing detection, dispute and chargeback investigation.
- Personalize the Services. Recommend picks and games, surface relevant social content, tailor the home dashboard. We do not engage in solely automated decision-making that produces legal or similarly significant effects on you.
- Communicate with you. Send transactional emails, SMS notifications you opt in to, push notifications, in-product banners, and (with consent) marketing communications.
- Improve the Services. Analyze usage to fix bugs, ship new features, and improve our models; conduct A/B testing.
- Comply with law. Respond to subpoenas, court orders, lawful regulatory requests, and tax obligations; cooperate with law-enforcement as required.
- Enforce these terms. Investigate violations of the Terms, House Rules, or Privacy Policy; enforce or defend our legal rights.
- Corporate transactions. In the event of a merger, acquisition, financing, or sale of assets, transfer information to a successor entity subject to this Policy (or one substantially similar).
What we do not do. We do not sell your personal information for money. We do not "share" your personal information for cross-context behavioral advertising without an explicit opt-in or unless required by Applicable Law. We do not train our or any third party's AI models on your User Content or chat messages (see Section 12). We do not use your data for any purpose materially different from the list above without prior notice and, where required, your consent.
Sharing & Disclosure
We disclose personal information only to the categories of recipients listed below and only for the purposes set forth in Section 4.
| Recipient category | Detail and named vendors |
|---|---|
| Affiliates and subsidiaries | Entities under common control with BookieSlip, for the same purposes set forth in this Policy and under the same protections. |
| Cloud hosting & storage | Amazon Web Services (AWS) — application hosting, encrypted storage of KYC documents, log retention. Data is stored in AWS U.S. regions. |
| Payment processing | Stripe, Inc. — handles all payment card data. We do not receive or store full card numbers, expiration, or CVC. See Section 8. |
| Identity verification (KYC) & biometrics | Our third-party identity-verification provider performs document validation and biometric ID-to-selfie matching. See Section 9 for biometric handling. The current vendor's name and privacy policy are available on request from privacy@bookieslip.com. |
| Geolocation & VPN detection | Our third-party geolocation and VPN-detection provider confirms you are physically located in a permitted state at the time of any Prize Coin transaction. The current vendor's name and privacy policy are available on request from privacy@bookieslip.com. |
| Sports data providers | Sportradar, SportsDataIO — supply event schedules, scores, stats. We send no personal information to these providers; they send us non-personal data only. |
| Communications & messaging | Resend (transactional email), Twilio (SMS), Apple Push Notification Service, Firebase Cloud Messaging (push). Recipient lists are configured by you in Account Settings. |
| AI / chat | Anthropic, PBC (Claude API) — processes chat messages you send in our chat surfaces. We have a Data Processing Agreement that prohibits Anthropic from training models on our customer data. Messages are retained per Anthropic's zero-retention policy for API users. See Section 12. |
| Analytics & error monitoring | Sentry — application error monitoring (PII-minimized where possible). We do not currently embed Google Analytics, Meta Pixel, or other third-party advertising trackers on logged-in surfaces. |
| Professional advisors | Attorneys, accountants, auditors, and tax advisors under confidentiality obligations. |
| Regulators and government | State Attorneys General, the IRS, FinCEN-equivalent processes where applicable, and any court of competent jurisdiction; only as required by Applicable Law or to assert or defend our legal rights. |
| Law enforcement | Pursuant to lawful subpoena, warrant, or other court order, or where we have a good-faith belief that disclosure is necessary to prevent imminent harm. |
| Corporate transactions | A successor entity in connection with a merger, acquisition, reorganization, financing, or sale of assets, subject to the protections of this Policy or a comparable replacement. |
Every service provider listed above is bound by a written contract that limits their use of personal information to the specific purposes for which we share it, requires appropriate technical and organizational safeguards, and prohibits secondary uses (including selling or sharing for advertising).
Cookies, SDKs & Tracking
We use cookies, local storage, mobile SDKs, and similar technologies to operate the Services, remember your preferences, and detect fraud.
| Category | Purpose and examples |
|---|---|
| Strictly necessary | Authentication tokens (JWT in localStorage), session cookies, CSRF tokens, anti-fraud signals. Cannot be disabled without breaking the Services. |
| Preferences | Tier preference, sport filter selections, dark-mode setting, last-viewed pick. Stored in localStorage. |
| Security and fraud | Device fingerprint and IP signals used by the rate limiter, the velocity controller, and the VPN-detection vendor. |
| Performance and crash reporting | Sentry SDK collects crash reports and performance traces, with PII scrubbed where possible. |
| Analytics | First-party analytics beacon to /api/analytics/vitals collects page-view and feature-usage events. No third-party advertising trackers on logged-in surfaces. |
Controls. You can clear cookies and local storage from your browser at any time. Doing so will sign you out and reset your preferences. You can opt out of non-strictly-necessary analytics via your Account Settings or by submitting a Do Not Sell or Share request (Section 6).
Payment Information & Stripe
All payment-card data is handled by Stripe, Inc., a PCI DSS Level 1 certified service provider. BookieSlip never receives, stores, or processes your full card number or CVC.
| What we receive from Stripe | Detail |
|---|---|
| Tokenized payment method | Card brand, last 4 digits, expiry month/year, and country of issue — used to display your saved payment method. |
| Transaction status | Success, failure, decline reason, chargeback notifications. |
| Customer email | We pass your verified Account email to Stripe so they can email receipts. |
| Billing address (where collected) | Postal code, country, and (where required by state tax law) full billing address. |
Stripe's processing of your information is governed by its own privacy policy, available at stripe.com/privacy. Stripe is the controller of payment-card data; BookieSlip is the controller of the identity and transaction metadata associated with your Account.
Identity Verification & Biometric Data
To redeem Prize Coins, you must complete identity verification. This involves a biometric comparison of your government-issued photo ID and a selfie you submit. This section is provided in compliance with the Illinois Biometric Information Privacy Act (740 ILCS 14, "BIPA"), the Texas Capture or Use of Biometric Identifier Act (Texas Bus. & Com. Code § 503.001, "CUBI"), the Washington My Health My Data Act (where applicable), and analogous state law.
| Element | Disclosure |
|---|---|
| What is collected | An image of your government-issued photo ID; a selfie photo or short video; a mathematical representation (face geometry / face template) derived from the selfie and the ID photo for one-time matching. |
| Specific purpose | Identity verification, fraud prevention, age verification (21+), AML and sanctions screening, and Restricted-State enforcement. No other purpose. |
| Length of term | Biometric templates are retained until the earlier of: (a) completion of the verification, plus a brief audit window not to exceed 90 days; or (b) three (3) years following your last interaction with the verification vendor or with the Services. ID document images are retained for five (5) years following Account closure to comply with industry-standard recordkeeping (per 31 C.F.R. § 1010.430 conventions). |
| Destruction schedule | At the end of the retention window, biometric templates are permanently destroyed and ID images are deleted from active and backup storage according to a documented destruction policy. |
| Recipients | Our third-party identity-verification provider is the processor that runs the document-to-selfie comparison and securely returns a yes/no result to BookieSlip. The current vendor's name and contractual retention window are disclosed on request from privacy@bookieslip.com. We do not share biometric data with advertising partners, law-enforcement (except under lawful court order, subpoena, or similar legal process), or any other third party. |
| Consent | Before any biometric collection, you are presented with a standalone consent screen describing the items above and asked to actively check a box stating "I consent to the collection and use of biometric information as described." You may revoke consent by emailing privacy@bookieslip.com; revocation prevents future redemption but does not affect bets already placed. |
| Sale prohibition | We do not, and will not, sell, lease, trade, or otherwise profit from biometric data. |
You may decline to provide biometric information. If you do, you will not be able to complete identity verification or redeem Prize Coins, but you may continue to use other parts of the Services. We do not condition non-redemption access on biometric consent.
Geolocation Data
We collect location information to confirm you are in a permitted U.S. state. Precise geolocation is treated as Sensitive Personal Information and is used only for the limited purposes set out below.
| Type | Detail |
|---|---|
| Coarse location (IP-based) | Approximate city or state derived from your IP address. Collected automatically when you access the Services. Used for Restricted-State enforcement at sign-in. |
| Precise geolocation (GPS) | Lat/long from your device's GPS, accurate to within roughly 1,750 feet. Collected only at the moment of wager acceptance or redemption, and only after you grant the OS-level permission. Required to verify presence in a permitted state. |
| Network-derived location | Wi-Fi and cellular signal data when used by the geolocation vendor to corroborate the IP and GPS readings. |
| Retention | Precise location is retained for 12 months alongside the corresponding bet or redemption record, then anonymized. Coarse IP-derived signals are retained for 30 days for security purposes. |
| Sharing | Shared only with our geolocation vendor for the limited purpose of state-presence verification. Not shared with advertising partners. Not sold. |
| Your control | You may revoke precise-location permission in your device settings at any time; future wagers and redemptions will be paused until you re-grant. |
| VA SB 338 (eff. July 1, 2026) | We do not sell precise geolocation of Virginia residents. This is a flat policy that exceeds what VA SB 338 requires. |
Marketing, Email & SMS
We send transactional communications about your Account and, with your consent, marketing communications by email and SMS.
Transactional. Receipts, security alerts, identity-verification updates, bet-settlement notifications, redemption status, and policy changes. These are required to operate the Services and are sent regardless of your marketing preferences.
Marketing email. Newsletters, promotions, feature announcements. You may opt out from any marketing email via the unsubscribe link in the footer, or in Account Settings → Notifications. Opt-out is honored within 10 business days.
SMS / TCPA. If you opt in to SMS programs (e.g., "Prime Time" alerts), you consent to receive recurring autodialed text messages from BookieSlip at the verified phone number. Programs disclose their frequency cap (Prime Time: up to 1 message per day) and their TCPA-required terms at the opt-in screen. Message and data rates from your carrier may apply. Reply STOP to unsubscribe; HELP for assistance. Carriers are not liable for delayed or undelivered messages. Phone numbers and consent timestamps are stored encrypted and retained for at least four years to support TCPA compliance evidence.
No sharing of mobile numbers. Mobile numbers and SMS consent records are collected only to operate the SMS programs you opt in to. Mobile numbers are not shared with third parties or affiliates for marketing or promotional purposes. We do not sell, rent, or share mobile opt-in data with third parties under any circumstances. Twilio acts as our SMS message-delivery processor under a written data-processing agreement and is contractually prohibited from using your number for any purpose other than delivering the messages you opted in to receive.
Push notifications. Controlled by your operating system. You can revoke permission in device settings.
All marketing, SMS, and push preferences are managed in one place: Account → Notifications. Changes apply within minutes.
AI Features & Chat Data
The Services include AI-powered features — pick recommendations, chat personas, and terminal-style analysis. This section explains how the AI features use your data.
| Topic | Detail |
|---|---|
| Underlying model | We use Anthropic's Claude API (Anthropic, PBC) and may use other large-language-model APIs in the future. We do not host our own foundation model. |
| What we send | Your chat message content, the persona configuration you've selected, recent pick context, and bet-history snippets relevant to the conversation. We send no payment data, no Social Security Number, no government ID, and no geolocation to the AI vendor. |
| Training | Our agreement with Anthropic prohibits use of customer data for model training. We will not opt in to any training program without first updating this Policy and giving you notice and a choice. |
| Retention by Anthropic | Anthropic processes API requests under its zero-retention policy for API customers. Anthropic's standard 30-day operational logging for trust-and-safety review applies; beyond that, content is not retained. |
| Retention by us | Chat transcripts are stored in your Account for 12 months to enable conversation history, then deleted. You may delete your transcripts at any time from the chat surface. |
| Hallucinations | AI features can produce inaccurate or fabricated content. Picks, projections, and analysis are for informational and entertainment purposes only. See our Terms of Use, Section 14. |
Data Retention
We retain personal information only as long as needed for the purposes described in this Policy. The table below shows the retention windows by data class.
| Data class | Retention period |
|---|---|
| Account profile (name, email, address) | For the life of the Account, plus five (5) years after closure for fraud, regulatory, and tax record-keeping. |
| KYC documents (ID, proof of address) | Five (5) years after Account closure (consistent with 31 C.F.R. § 1010.430 industry practice). |
| Biometric templates | Up to 90 days after verification completion, or 3 years after last interaction, whichever is earlier (per BIPA § 15(a) and Section 9). |
| Wager and settlement records | Seven (7) years for IRS and AML-style recordkeeping. |
| Subscription / billing records | Seven (7) years (IRS standard). |
| Tax records (W-9, 1099-MISC) | Seven (7) years per IRS § 6501. |
| Precise geolocation | 12 months alongside the corresponding bet/redemption; then anonymized. |
| Marketing preferences and consent timestamps | Until you withdraw consent, plus four (4) years for TCPA/CAN-SPAM compliance evidence. |
| Support tickets and call recordings | Three (3) years from last interaction. |
| Server logs, security telemetry, error reports | 12–24 months for security and performance analysis; longer where retained for an active investigation. |
| Cookies and local storage | Session-scoped or up to 13 months for preferences, unless cleared earlier by you. |
| Backups | Encrypted snapshots are retained for 90 days for disaster recovery; backup data is purged when the active record's retention period ends (a deletion request flows to backups within 90 days of the production deletion). |
Legal hold. Where we are subject to a litigation hold, subpoena, or regulatory inquiry, we may retain relevant data beyond the standard windows above until the matter is resolved.
Anonymization. Where we retain data beyond the active windows for analytics or model evaluation, the data is anonymized so that it cannot reasonably be linked to you.
Your Privacy Rights
You have rights under U.S. state privacy laws, exercised through a single privacy request portal. Where state laws differ, we apply the stricter standard to all U.S. residents wherever practical.
| Right | What it means |
|---|---|
| Right to know / access | Confirm whether we process your personal information and obtain a copy of what we hold and how we've used and shared it. |
| Right to delete | Request deletion of your personal information, subject to retention exceptions (legal hold, tax/AML, security, dispute defense). |
| Right to correct | Request correction of inaccurate personal information. |
| Right to portability | Receive a copy of your personal information in a portable, machine-readable format. Use Account → Data Export for a self-serve flow. |
| Right to opt out of sale or sharing | Opt out of any sale or share for cross-context behavioral advertising. See Section 6. |
| Right to opt out of targeted advertising | Same as above. We currently do not engage in targeted advertising; this right is preserved for any future feature. |
| Right to opt out of profiling | Opt out of automated profiling that produces legal or similarly significant effects. We do not currently engage in such profiling. |
| Right to limit use of sensitive PI | Restrict our use of Sensitive PI to the necessary-services list in 11 C.C.R. § 7027(m). |
| Right to appeal | If we deny a request, you may appeal within 60 days. We respond within 45 days of receipt of the appeal. |
| Right to non-discrimination | We do not discriminate against you for exercising any right under this Policy. Subscription pricing is not adjusted based on exercise of a privacy right. |
How to submit a request. Use the request form linked from Section 21 — Contact or email privacy@bookieslip.com. We respond within 45 days of receipt (extendable once by an additional 45 days with notice).
Verification. Before fulfilling an access, deletion, correction, or portability request, we verify your identity by confirming control of the verified Account email and (for sensitive requests) by matching a recent transaction identifier or by re-verifying KYC. We do not collect more information for verification than we already hold.
Authorized agents. You may use an authorized agent. We require written authorization signed by you (or a power of attorney) before acting on agent submissions, except where a GPC signal is in use for opt-out of sale/sharing.
California Notice (CCPA / CPRA)
This section provides additional disclosures required of California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA/CPRA").
Categories collected. See Section 2. In the preceding 12 months we have collected categories A, B, C, D, E, F, I, and J as defined in that section. We have not collected categories G or H.
Sources. See Section 3.
Business and commercial purposes. See Section 4.
Categories disclosed. In the preceding 12 months we have disclosed categories A, B, C, D, E, and J to the recipient categories described in Section 5.
Sale and sharing. We have not sold personal information in the preceding 12 months. We have not shared personal information for cross-context behavioral advertising in the preceding 12 months. See Section 6.
Sensitive PI. We use Sensitive PI only for purposes enumerated in 11 C.C.R. § 7027(m): performing the Service, security, anti-fraud, identity verification, brief storage and processing, ensuring physical safety, and maintaining product or service quality. You may exercise the right to limit by following the footer link "Limit the Use of My Sensitive Personal Information."
Your rights. California residents may exercise the rights in Section 14 plus the following: right to know specific pieces of personal information collected; right to know categories of third parties to whom we disclose; right to opt out of sale and sharing; right to limit use of Sensitive PI; right to non-discrimination (no different price or service for exercising rights); right to delete; right to correct; right to portability.
Shine the Light (Cal. Civ. Code § 1798.83). California residents may once per year request the categories of personal information we disclosed to third parties for those third parties' direct-marketing purposes during the prior calendar year. We do not currently disclose personal information for third-party direct-marketing purposes; if that changes, this section will be updated.
GPC. We honor the Global Privacy Control browser signal as a valid opt-out of sale and sharing. The signal is honored at the browser level and persists for the session.
Authorized agents. Authorized agent submissions are accepted with written authorization. No agent is required if you submit a GPC signal yourself.
Minors. California residents under 16 may not have their personal information sold or shared without opt-in consent (or, for those under 13, parental consent). We do not knowingly collect personal information of minors under 21. See Section 17.
Metrics. We will publish annual CCPA request-handling metrics on this page where required by 11 C.C.R. § 7102.
Other State Notices
This section provides additional disclosures required of residents of other U.S. states with comprehensive privacy laws. The universal rights in Section 14 apply across these states; the table below highlights state-specific points.
| State | Key rights and notes |
|---|---|
| Virginia (VCDPA) | Access, deletion, correction, portability, opt-out of sale, opt-out of targeted advertising, opt-out of profiling with significant effects, appeal. We do not sell precise geolocation of Virginia residents (per VA SB 338, effective July 1, 2026). |
| Colorado (CPA) | Same rights as Virginia, plus mandatory GPC honoring. Appeal window is 60 days; we respond within 45 days. |
| Connecticut (CTDPA) | Same rights as Colorado. Data Protection Assessments performed for high-risk processing per CTDPA § 8. |
| Utah (UCPA) | Access, deletion, portability, opt-out of sale, opt-out of targeted advertising. No correction right. No appeal mechanism mandated. |
| Texas (TDPSA) | Access, deletion, correction, portability, opt-out of sale, opt-out of targeted advertising, opt-out of profiling, appeal. We honor GPC for Texas residents. |
| Oregon (OCPA) | Universal rights plus a right to obtain a list of specific third parties to whom we have disclosed personal information. |
| Montana (MCDPA) | Universal rights. DPAs required for high-risk processing as of June 1, 2026. |
| New Jersey (NJDPA) | Universal rights. Stricter treatment of minors 13–17 — opt-in for targeted advertising. |
| Delaware (DPDPA) | Universal rights. We honor GPC. |
| Minnesota (MCDPA) | Universal rights plus right to receive a list of specific third parties. |
| New Hampshire | Universal rights. We honor GPC. |
| Rhode Island | Universal rights. |
| Tennessee (TIPA) | Universal rights. We maintain a written privacy program aligned with NIST Privacy Framework as a safe harbor. |
| Indiana / Iowa / Maryland / Kentucky | Universal rights with state-specific addenda; submit via the same privacy request portal. |
| Florida (FDBR) | Applies only to operators meeting the $1B revenue + digital ad threshold. BookieSlip is currently below threshold; we extend universal rights to Florida residents as a courtesy. |
| New York (SHIELD Act) | Security and breach-notification regime. See Sections 18 and 19. |
| Illinois (BIPA) | Biometric-specific rights and disclosures. See Section 9. |
| Washington (My Health My Data) | If you reside in WA, our use of consumer health data is governed by MHMDA. We do not knowingly collect consumer health data. |
How to exercise. Use the same portal described in Section 14. We will handle your request under the standard most favorable to you when state rights overlap.
Children & COPPA
BookieSlip is not directed to children. The Services require a minimum age of 21. We do not knowingly collect personal information from anyone under 21.
COPPA (under 13). Consistent with the federal Children's Online Privacy Protection Act and the FTC's COPPA Rule amendments effective April 22, 2026, we do not knowingly collect personal information from children under 13. If we learn we have inadvertently collected such information, we will delete it promptly.
Minors 13–20. Although the Services are not open to anyone under 21, if you believe a minor under 21 has provided us with personal information, please contact us at privacy@bookieslip.com so we can investigate and remove the information.
State minor protections. Where state law (California, Colorado, Connecticut, Delaware, Minnesota, Montana, New Hampshire, New Jersey, Oregon) imposes opt-in or opt-out protections for residents under various ages (typically 13–17), we apply the higher standard.
If you are a parent or legal guardian and believe a minor in your care has registered for BookieSlip, contact privacy@bookieslip.com. We will close the Account and delete personal information without delay.
Information Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, and destruction. No system is perfectly secure; we describe our program transparently below.
| Control | Detail |
|---|---|
| Encryption in transit | TLS 1.2+ for all client-server communication. HSTS enforced on production domains. |
| Encryption at rest | AES-256 for KYC documents, biometric metadata, and database backups. Stored in AWS KMS-encrypted S3 and RDS. |
| Authentication | Bcrypt-hashed passwords (work factor ≥ 12). JWT access + refresh tokens with short access TTL and proactive refresh. Optional multi-factor authentication on supported flows. |
| Access controls | Role-based access control with least privilege. KYC + biometric data is accessible only to a named Compliance/AML team under audit logging. |
| Network security | VPC isolation, security groups limiting ingress, WAF, rate limiting, bot detection, and per-account velocity controls. |
| Vendor security | All processors are bound by written Data Processing Agreements with SOC 2 / ISO 27001 or equivalent attestations where applicable. |
| Vulnerability management | Dependency scanning in CI, regular third-party penetration tests, responsible-disclosure email at security@bookieslip.com. |
| Logging and monitoring | Centralized log aggregation, anomaly detection, retained 12–24 months. Suspicious-event alerting routed to on-call. |
| Disaster recovery | Encrypted backups retained 90 days. Tested restoration procedures. |
| Personnel | Background-checked employees; required security and privacy training; written confidentiality obligations. |
Your role in security. Choose a unique, strong password. Enable available second factors. Sign out of shared devices. Never share your Account credentials. Report any suspected unauthorized access to security@bookieslip.com immediately.
Data Breach Notification
In the event of a security breach affecting your personal information, we will notify you and applicable regulators as required by Applicable Law.
| Jurisdiction / law | Notification commitment |
|---|---|
| California (Civ. Code § 1798.82; SB 446 in 2026) | Consumer notice within 30 days of confirming the breach. Attorney General notice within 15 days after consumer notice if more than 500 California residents are affected. |
| Texas (TDPSA) | Notice within 60 days; notice to consumer reporting agencies if more than 10,000 Texas residents are affected. |
| New York (SHIELD Act) | Notice without unreasonable delay. AG, DOS, and State Police where required. |
| Colorado / Florida / Washington | Notice within 30 days of confirmation. |
| Connecticut / Delaware / Louisiana / Texas | Notice within 60 days of confirmation. |
| Oregon / Tennessee / Rhode Island | Notice within 45 days of confirmation. |
| Other states | Notice in accordance with the jurisdiction's breach-notification statute; in the absence of a specific deadline, we commit to notice within 60 days. |
Content of notice. Description of the incident, categories of personal information affected, date or estimated date of the incident, mitigation steps, recommended consumer actions, and a contact channel to ask follow-up questions.
Substitute notice. If individual notice is impracticable due to volume or lack of contact information, we will provide substitute notice as permitted by statute (typically a prominent website notice and notice to major statewide media).
Vendor breaches. Our Data Processing Agreements require service providers to notify us promptly (within 24–72 hours) of any security incident involving our customer data. We will roll up the regulatory and consumer notice obligations and respond on the timeline above.
International Data Transfers
BookieSlip operates exclusively in the United States. The Services are not offered to residents of the European Economic Area, the United Kingdom, Switzerland, or other foreign jurisdictions.
Personal information is stored on servers located in the United States. Some processors may have parent companies or sub-processors located outside the U.S. (e.g., support-team operations or engineering teams), and access to data may occur from those locations under written Data Processing Agreements that mirror U.S. protections. Where such access occurs from the EEA or UK, the processor is bound to the European Commission's Standard Contractual Clauses (2021) and any applicable UK or Swiss addenda.
If you access the Services from outside the United States, you do so on your own initiative and at your own risk, and your information will be processed in the United States subject to U.S. law.
Accessing the Services from outside the United States, or from a Restricted State, is prohibited by our Terms of Use. Repeated attempts may result in Account suspension.
Changes, Contact & Privacy Officer
We update this Policy as our practices evolve and as the law changes. Material changes are communicated by email and an in-product banner at least 30 days before they take effect.
Material vs. non-material. Material changes include any expansion of the categories of personal information collected, new categories of recipients, additional purposes that go beyond the list in Section 4, changes to retention windows, changes to your rights or to the request portal, and any change to AI training, sale, or sharing posture. Non-material changes (typo fixes, clarifying examples, restructured prose) take effect on posting.
Version that governs you. The version of this Policy in effect at the time of any collection or use governs that collection or use. Historical versions are archived and provided on request.
Contact.
| Topic | Channel |
|---|---|
| Privacy requests (access, deletion, correction, portability, opt-out, appeal) | privacy@bookieslip.com — or use the request form linked from this page. |
| Privacy Officer | Email privacy@bookieslip.com with subject "Attn: Privacy Officer." Email correspondence to the Privacy Officer satisfies any writing or signature requirement under the federal E-SIGN Act, 15 U.S.C. § 7001, and applicable state UETA equivalents. If you require a physical mailing address for service of a privacy request or appeal, request it via the same email and we will provide the address of our registered agent in the State of Delaware. |
| Security incident or vulnerability | security@bookieslip.com |
| DMCA notices | dmca@bookieslip.com |
| Legal notices | legal@bookieslip.ai |
| General support | support@bookieslip.com |
| CCPA / state privacy requests | All California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other state privacy requests are accepted at privacy@bookieslip.com and via the request form linked from this page. A dedicated toll-free request line will be added if and when our California consumer count exceeds the threshold under 11 C.C.R. § 7020 requiring offline submission methods. |
Cross-references. See also our Terms of Use, House Rules, Sweepstakes Rules, and Account & Data Deletion page.