Privacy Policy
pinnodds ("we", "us") provides a real-time sports odds data API at pinnodds.com. This policy explains what personal data we collect, why, how long we keep it, and your rights. We keep it short and literal — it describes what the service actually does.
1. Who is responsible
The data controller is the operator of pinnodds.com. Contact for any privacy matter: [email protected].
2. What we collect and why
| Data | When | Purpose · legal basis |
|---|---|---|
| Email address | Signup, key recovery, purchase, support | Create and operate your account, deliver your API key, send transactional emails (verification, receipts, expiry reminders). Contract. |
| API key (stored as a one-way hash), plan, expiry, usage counters (requests per day per key) | While your account exists | Authenticate requests, enforce plan limits, billing reconciliation. Contract. |
| Payment records: amount, currency, plan, provider transaction id, status | When you buy a plan | Fulfil the purchase, accounting, fraud prevention. We never see or store card numbers or crypto wallet keys — payments are processed by our providers (see §4). Contract · legal obligation. |
| Acquisition source (e.g. "google / organic", a referrer domain, or a campaign tag) captured on your first visit | First visit → attached at signup | Understand which channels bring customers. First-party only, stored in your browser's localStorage until you sign up. Legitimate interest. |
| Support conversations (chat widget, email, Telegram) | When you contact us | Answer you and improve documentation. Legitimate interest. |
| Server logs: IP address, request path, timestamp, user agent | Every request | Security, abuse prevention, per-IP rate limiting, debugging. Rotated on a short schedule. Legitimate interest. |
| Analytics & advertising cookies (Google Analytics, Microsoft Clarity, Google Ads, Meta) | Only after you accept cookies (EEA/UK); see the Cookie Policy | Understand site usage, session replays and heatmaps, measure ad campaigns. Consent. |
We do not sell personal data, and we do not use it for automated decision-making with legal effects.
3. Emails we send
Transactional: verification link, API key delivery and recovery, payment receipts, plan-expiry reminders, security notices. Occasional product announcements go to customers with an active or recent plan; every such email carries a one-click unsubscribe link (transactional messages required to run your account are not affected).
4. Processors and third parties
- Hosting — our servers in the EU; Cloudflare (CDN, DDoS protection, TLS) in front of them.
- Payments — NOWPayments (crypto checkout) and, when enabled, Stripe (card payments). Each processes your payment under its own privacy policy; we receive only the transaction outcome and reference.
- Email delivery — our SMTP provider, used solely to send the messages above.
- Analytics / ads (consent-gated in the EEA/UK) — Google Analytics 4, Google Ads, Microsoft Clarity, Meta Pixel. See the Cookie Policy for cookies, purposes and opt-out.
- Support chatbot — messages typed into the on-site assistant are processed by an AI provider to generate answers; do not paste secrets into it.
Some processors (Google, Microsoft, Meta, Stripe) are US companies; transfers rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses.
5. Retention
- Account and key data: for the life of the account, then deleted or anonymised within 90 days of deletion.
- Payment records: 10 years where required by tax and accounting law.
- Server logs: typically 30 days.
- Support conversations: up to 24 months.
- Analytics data: per each provider's retention (GA4 is set to 14 months).
6. Your rights
If you are in the EEA/UK you can access, correct, export or delete your data, restrict or object to processing, and withdraw consent at any time (withdrawal does not affect prior processing). Email [email protected] from the address on your account and we respond within 30 days. You may also complain to your local supervisory authority. To delete your account outright, email us — we remove the account and its key immediately and purge remaining data on the schedule above.
7. Security
API keys are stored hashed (SHA-256), never in plaintext; TLS everywhere; access to production systems is limited to the operator. No system is perfectly secure — if you suspect your key leaked, rotate it from the panel or contact us.
8. Children
The service is for adults (18+) and businesses. We do not knowingly collect data from minors.
9. Changes
We update this page when our practices change and adjust the date above. Material changes are announced by email to active customers.