Preview notice, updated 23 September 2026. Public registration and paid membership remain closed. The operator’s registered identity, address and final legal retention schedule must be completed before launch.
For privacy questions or requests, contact contact@betassist.app. This notice describes the website’s current architecture and the account service being prepared for launch.
The services we use
| Provider | Information handled | Purpose |
|---|---|---|
| OpenAI Sites and Cloudflare | Website requests and technical request information; account email, consent records, encrypted sign-in sessions, membership/payment references and saved selections in the application database. | Host and protect the website, run its server and store application data. Passwords pass through the server to Supabase over encrypted connections; we do not store them in our application database or application logs. |
| Supabase | Email, password verification data, email confirmation/reset records, authenticator factors and authentication activity. The selected authentication project is in Ireland (eu-west-1). | Verify identities, manage passwords, confirm email addresses and provide two-factor authentication. Supabase is the authentication service; the website’s main application database is Cloudflare D1. |
| Stripe | Payment details entered on Stripe’s pages, billing information, payment and subscription activity, and an account reference linking membership to BetAssist. | Checkout, recurring payments, cancellation, invoices, refunds and fraud prevention. BetAssist receives payment references and status, not full card details. Current integration uses Stripe’s test environment. |
| Amazon Web Services (AWS) | Recipient email addresses and verification/reset message content through SES; delivery information; encrypted application backups in S3; service status/error categories for monitoring and operational alerts. | Send essential account emails, recover the application after failures and alert the team to service problems. These BetAssist AWS resources are in London (eu-west-2). Application backups exclude authentication sessions and provider access/refresh tokens. |
| Microsoft 365 | Support and privacy emails sent to the business, their attachments, and delivery metadata. | The domain’s published mail routing uses Microsoft 365. It handles incoming business email; any additional forwarding arrangements and mailbox retention will be confirmed before launch. |
| GoDaddy | Domain registration and DNS information and technical data associated with domain services. | Manage the betassist.app domain. It is not the website’s account database or payment processor. |
Information you provide
Accounts use an email address, password, adult-age declaration and agreement to the terms. Authenticator setup adds a second factor. Saved selections contain the list name, selected lines and their recorded assessments. Do not put sensitive personal information into list names. This website has no customer file-upload feature.
If you email support, your message and attachments also pass through the mail services used by you and the business. The domain’s incoming mail routes through Microsoft 365. Additional forwarding and final mailbox retention arrangements will be documented before launch.
Why we process it
Account, membership and saved-selection processing is needed to provide the service you request. Abuse prevention, essential monitoring and recovery support the legitimate interest of running a secure service. Financial records may be needed for accounting, disputes and applicable legal obligations. We do not currently use customer data for advertising, sell it, or provide it to a betting operator. Optional marketing would require a separate choice and an updated notice.
Cookies, local drafts and cached screens
An essential HttpOnly cookie holds a random session identifier. Provider tokens remain encrypted on the server and are not stored in browser local storage. Sessions expire after 30 days at most, or seven days without activity. Temporary recovery and authenticator setup sessions last ten minutes.
The browser can remember board filters in the current tab and store queued selection IDs, list names and assessment fingerprints on this device. Drafts expire after seven days and are cleared when the site next reads them. These drafts are tied to the signed-in account and are sent only after connection and access checks succeed. Signing out, resetting your password or deleting your account clears BetAssist’s local drafts. Other people using the same unlocked browser may be able to inspect device storage. Payment and account-security actions are not queued offline.
Previously displayed rows may remain on screen while an update loads or the connection is unavailable. Their original check times remain visible. The site does not present cached information as a new price check, and does not store a full paid board for offline browsing.
Cancellation and account deletion
Use Cancel subscription in My account to stop renewal while retaining access through the paid period. Use Delete my account to end the subscription immediately, delete the Supabase sign-in, revoke website sessions, and remove the application profile and saved selections. Deletion requires password and authenticator confirmation. It does not automatically issue a refund or remove records we must keep for an existing dispute or legal obligation.
We retain minimal payment references and a deletion receipt to prevent old processing or restored data from reopening a deleted account. Encrypted backups are for recovery and expire under the storage lifecycle; current archives expire after 35 days, with noncurrent versions retained for a further 35 days. Deleted account access must not be restored with a backup. The final accounting and support retention periods depend on the registered operator’s obligations and will be published before launch.
Security and international processing
Controls include verified email, required two-factor sign-in, access checks, request limits, encryption, secure cookies and payment-notification signature checks. Request logging is limited to operational identifiers and error categories rather than passwords, message bodies or authentication tokens.
The selected regions above do not mean every provider operation stays in those countries. Global delivery networks, support and subprocessors may handle information elsewhere. Applicable provider contracts, subprocessors and transfer safeguards will be reviewed for the registered operator before launch. We do not claim that all processing is UK-only or EU-only.
Your choices and rights
You can ask for access, correction, erasure, restriction, portability, or object to processing where applicable. Contact us using the address above; we may need to verify your identity, and legal exceptions can affect a request. You can also raise a concern with your applicable data protection authority. A parent or guardian concerned about an under-18 account should contact support.
Provider information: OpenAI, Cloudflare, Supabase, Stripe, AWS, Microsoft, and GoDaddy.