This Privacy Policy describes how IABET LLC (“IABET,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you use the IABET mobile application and website (the “Service”). This policy applies to all users worldwide and addresses requirements under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other applicable privacy laws.
1. Information We Collect
Information You Provide:
- Account information: name, email address, and authentication credentials (via Google or Apple Sign-In)
- Profile preferences: language, timezone, odds format, notification preferences
- Support communications: messages you send to our support team
- Referral codes: when you share or use a referral code
Information Collected Automatically:
- Device information: device type, operating system, app version, unique device identifiers
- Usage data: pages viewed, features used, predictions followed, session duration, interaction patterns
- Log data: IP address (hashed and anonymized), timestamps, error reports
- Subscription data: plan tier, purchase history, billing status (processed by App Stores)
Information from Third Parties:
- Authentication providers: Google or Apple provide your name, email, and profile photo when you sign in
- Payment processors: Apple App Store and Google Play provide subscription status (we do not receive or store payment card details)
2. How We Use Your Information
We use your information for the following purposes:
- Provide the Service: deliver personalized predictions, manage your account, process subscriptions
- Improve the Service: analyze usage patterns, identify bugs, optimize AI models, develop new features
- Communications: send prediction alerts, account notifications, and service updates (with your consent for marketing)
- Security: detect fraud, prevent abuse, protect against unauthorized access
- Legal compliance: comply with applicable laws, regulations, and legal processes
We never sell your personal information to third parties.
3. Third-Party Services
We share data with the following categories of service providers, strictly for the purposes described:
| Provider | Purpose | Data Shared |
|---|---|---|
| Clerk | Authentication | Email, name, auth tokens |
| Supabase | Database hosting | Account data, predictions |
| RevenueCat | Subscription management | User ID, subscription status |
| Segment | Analytics routing | Anonymized usage events |
| PostHog | Product analytics | Anonymized usage events |
| Sentry | Error monitoring | Error reports, device info |
| OneSignal | Push notifications | Device token, user ID |
| Resend | Transactional email | Email address, name |
All service providers are contractually obligated to protect your data and use it only for the specified purposes.
4. International Data Transfers
Your data may be transferred to and processed in the United States, where our servers and service providers are located. For users in the European Economic Area (EEA) or other regions with data transfer restrictions, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection of your data.
5. Data Retention
- Account data: retained for the duration of your account, plus 30 days after deletion request
- Usage analytics: retained in anonymized form for up to 24 months
- Error logs: retained for 90 days
- Billing records: retained for 7 years as required by tax law
- Support communications: retained for 12 months after resolution
6. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: request a copy of the personal data we hold about you
- Rectification: correct inaccurate or incomplete data
- Deletion: request deletion of your personal data (available in-app via Account Info > Delete Account)
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Restriction: request restriction of processing under certain conditions
- Withdraw consent: withdraw consent at any time where processing is based on consent
- Do Not Sell (CCPA): we do not sell personal information. You may still submit a request at privacy@iabet.co
To exercise any of these rights, contact us at privacy@iabet.co. We will respond within 30 days (or 45 days for complex requests, with notice).
7. Legal Basis for Processing (GDPR)
For users in the EEA, we process your data under the following legal bases:
- Contract performance: to provide the Service you subscribed to
- Legitimate interests: to improve the Service, prevent fraud, and ensure security
- Consent: for marketing communications and optional analytics
- Legal obligation: to comply with applicable laws and regulations
8. Data Security
We implement industry-standard security measures to protect your data:
- All data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Authentication via OAuth 2.0 (Google, Apple) with secure token management
- IP addresses hashed with HMAC-SHA256 before storage
- Regular security audits and penetration testing
- Rate limiting, circuit breakers, and abuse detection
- Role-based access controls for internal systems
9. Children's Privacy
IABET is not intended for children under 18. We do not knowingly collect personal information from anyone under 18 years of age. If we learn that we have collected data from a child under 18, we will delete that information promptly. If you believe a child under 18 has provided us with personal data, please contact us at privacy@iabet.co.
10. Push Notifications
If you enable push notifications, we use your device token to send prediction alerts, account updates, and promotional content. You can disable notifications at any time through your device settings or the Notifications page in the app.
11. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via the app or email. The “Last updated” date at the top of this page indicates when this policy was last revised. Continued use of the Service after changes constitutes acceptance.
12. Contact
For privacy-related inquiries:
IABET LLC
Privacy Team
Email: privacy@iabet.co