Privacy
Privacy policy
Last updated: June 2026
This Privacy Policy explains what personal data The Lovable Game ("we", "us") collects when you use our website and prediction game (the "Service"), how we use it, who we share it with, and the rights you have. We aim to collect the minimum needed to run a fair, fun game.
01Who is the controller?
The Lovable Game is the data controller for personal data processed in connection with the Service. For any data protection request, contact privacy@bracket26.example.
02What we collect
- Account data: email address, display name, and (if you sign in with Google) your OAuth identifier and profile photo URL.
- Profile preferences: country, favourite team, language, marketing-email opt-in (all optional).
- Game data: your picks, scores, leaderboard position, referral relationships.
- Technical data: IP address, browser, device type, and basic error logs needed to keep the Service running securely.
- Communications: messages you send to support and any opt-in email engagement.
We do not knowingly collect data from anyone under 18.
03How we use your data
- To create your account and authenticate you (contract);
- To run the game: score picks, display leaderboards, deliver prizes (contract);
- To keep the Service secure and prevent fraud (legitimate interest);
- To send service emails like password resets or rule changes (legitimate interest / contract);
- To send marketing emails about The Lovable Game and tournaments — only with your opt-in consent;
- To comply with legal obligations (e.g. tax records for prize winners).
04Who we share with
We never sell or rent your personal data. We share limited data with carefully chosen processors who help us run the Service:
- Cloud hosting & database (EU region) for storing accounts, picks, and serving the app.
- Authentication providers (Google) if you choose social sign-in.
- Transactional email provider for sign-in links, password resets, and prize notifications.
- Error & uptime monitoring for diagnosing bugs and outages.
Each processor is bound by a data processing agreement. Where data leaves the EEA, we rely on the European Commission's Standard Contractual Clauses and supplementary measures.
05How long we keep it
Account and game data is kept for as long as your account is active. If you delete your account, we erase personal data within 30 days, except where we must keep limited records to comply with legal obligations or to defend legal claims (typically up to 6 years for accounting where prizes were issued). Aggregated, anonymised stats (e.g. "32% of players picked Brazil") may be retained indefinitely.
06Your rights
If you are in the EEA, the UK, or a comparable jurisdiction, you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict or object to certain processing;
- port your data to another service;
- withdraw consent for marketing at any time, with no effect on past processing;
- lodge a complaint with your local supervisory authority.
To exercise these rights, email privacy@bracket26.example. We respond within 30 days and may ask for proof of identity.
07Security
We use industry-standard safeguards: TLS in transit, encryption at rest, scoped database access, row-level security, and regular dependency audits. No system is 100% secure; we will notify you and the appropriate authority of a breach affecting your personal data within 72 hours of discovery, as required by law.
09Changes
We may update this policy occasionally. Material changes will be announced in-app or by email at least 14 days before they take effect.