Privacy Policy
GreenSlips is a sports-betting research and analytics tool. It is not a sportsbook: we do not accept, place, or facilitate wagers, and we never handle your betting funds. This policy explains what personal data we collect when you use the GreenSlips website, web app, and mobile apps (together, the “Service”), why we collect it, who we share it with, how long we keep it, and the rights you have over it.
GreenSlips LLC, a Florida limited liability company, trading as GreenSlips
7901 4th St N, Ste 300, St. Petersburg, FL 33702, United States
Privacy contact: privacy@greenslips.pro
GreenSlips LLC is established in the United States and has no establishment in the UK or EU. We have not yet appointed a UK representative (Article 27 UK GDPR) or an EU representative (Article 27 GDPR); we intend to do so as our UK and EU user base grows and will publish their details here. Until then, UK and EU data subjects and supervisory authorities can contact us directly at privacy@greenslips.pro, and we will respond as if a representative had been appointed.
Contents
- Summary
- Data we collect
- Data we do not collect
- How and why we use data
- Who we share data with
- International transfers
- How long we keep data
- Security
- Your rights (UK, EU and worldwide)
- US state privacy rights (including California)
- Age limit and children
- Cookies and local storage
- App store disclosures
- Changes to this policy
- Contact and complaints
1. Summary
- We collect the minimum needed to run an account: your email address, your name (if your sign-in provider supplies one), and an account identifier.
- We store your app preferences (theme, default views, filters, pane layout) so they follow you between devices.
- We do not sell personal data, we do not share it for advertising, we show no ads, and we do not track you across other companies’ apps or websites.
- We collect no location data, no contacts, no payment card data (the beta is free), and no device advertising identifiers.
- You can export your data and delete your account yourself, inside the app, at any time.
- Our servers are hosted in the United Kingdom (Microsoft Azure, UK South). Some service providers are in the United States; transfers are protected by Standard Contractual Clauses and the UK Addendum.
2. Data we collect
2.1 Account data (from your sign-in)
Sign-in is handled by Auth0 (an Okta company). When you create an account or sign in, we receive and store a reference to:
- Email address — used to identify your account, to send account-service messages (for example the confirmation that your account was deleted, or the link to your data export), and to let you change your email or reset your password.
- Name (if provided by you or your sign-in provider) — shown to you in the app’s profile area only.
- Account identifier (the Auth0 subject ID, a random string) — the only key our own systems use to attach data to you. Our database holds no name, email, or password; those live only with Auth0.
Sign in with Apple and Google sign-in, where offered, pass us the same items. With Sign in with Apple you can choose to hide your real email address; Apple then gives us a relay address instead.
2.2 Preferences and app activity synced to your account
To make the app consistent across your devices we store: theme, default base unit and market scope, default slate view, last tab opened, avatar colour, pane widths, and your saved directory and terminal-board filters. These are settings, not a record of what you bet. Your bet slip is stored only on your device; when you ask the app to grade a slip, the legs are sent to our server to compute the grade and are not stored there afterwards.
2.3 Technical and security data
- Server logs: when your device talks to our servers we process the IP address, request path, timestamps, and user-agent string for security, abuse prevention, and debugging. Logs are retained for 30 days.
- Rate-limit and session state: short-lived entries keyed by your account identifier (expiring within seconds to 24 hours) that enforce fair-use limits and, after you delete your account, block any tokens issued before deletion.
- Authentication tokens: stored on your device in the platform’s secure store (Keychain on iOS, Keystore on Android, DPAPI on Windows, session storage in the browser) so you stay signed in.
2.4 Crash and diagnostic data (not yet enabled)
We plan to add crash reporting and performance monitoring (Sentry) to the apps. Until it is switched on, no crash or diagnostic data leaves your device. When it is enabled, this section will describe exactly what is sent (typically: the error, stack trace, app version, device model and OS version, and your account identifier so that we can find and delete your reports on request). We will update this policy and the app-store privacy labels before enabling it.
2.5 Support correspondence
If you email us, we keep the correspondence for as long as needed to resolve your request and for a reasonable period afterwards to evidence what was agreed.
3. Data we do not collect
- No precise or approximate location. The app never asks for location permission and does not geo-fence.
- No payment or card details. The beta is free. If we later add paid features, payments will be processed by Apple, Google, or Stripe under their own terms, and we will update this policy before launch.
- No contacts, photos, microphone, camera, health, or fitness data.
- No advertising identifiers (IDFA / GAID), no ad networks, no cross-app tracking, no third-party analytics SDKs.
- No wagering records. We never know whether you placed a bet, with whom, or for how much.
- No sensitive (special category) data, and nothing from anyone under 18 knowingly (see section 11).
4. How and why we use data
| Purpose | Data used | Legal basis (UK GDPR / GDPR) |
|---|---|---|
| Creating and operating your account; signing you in; syncing preferences | Account data, preferences, tokens | Performance of our contract with you (the Terms of Service) |
| Sending account-service emails (deletion confirmation, data-export link, email change, password reset) | Email address | Contract; legal obligation (responding to rights requests) |
| Keeping the Service secure, preventing abuse, enforcing fair-use limits | Server logs, rate-limit state, account identifier | Legitimate interests (security and integrity of the Service), balanced against your rights |
| Fixing bugs and improving reliability (when crash reporting is enabled) | Crash and diagnostic data | Legitimate interests; consent where local law requires it, with an in-app opt-out |
| Complying with law, and establishing or defending legal claims | Whatever is relevant | Legal obligation; legitimate interests |
| Keeping evidence that we honoured a deletion or export request | A one-way hash of your account identifier and the request timestamps | Legal obligation (accountability under Article 5(2)) |
We do not use your data for marketing (we send no marketing email), for profiling that produces legal or similarly significant effects, or for automated decision-making about you. The app’s projections are about players and games, not about you.
5. Who we share data with
We share personal data only with service providers (“processors”) that we need to run the Service, each bound by a data-processing agreement, and only for the purpose stated. We do not sell personal data and do not share it for cross-context behavioural advertising.
| Provider | What they do for us | Data | Location |
|---|---|---|---|
| Auth0 (Okta, Inc.) | Sign-in, account security, password and email management | Email, name, password (hashed), sign-in metadata | United States |
| Microsoft Azure | Hosting, database, cache, key vault, storage of data-export bundles, and sending account-service emails (Azure Communication Services) | All server-side data; email address and message content | United Kingdom (UK South); email service data location set per Microsoft’s regional options |
| Sentry (Functional Software, Inc.) | Crash and performance reporting — not yet enabled | Crash and diagnostic data, account identifier | United States |
| Apple, Google, Stripe | Payment processing — not used in the free beta; listed because the integration exists in our code and will be activated only with paid features, after this policy is updated | None today | United States / EU |
Our sports-data providers (BallDontLie and The Odds API) supply statistics and odds to us. We send them no personal data.
We may also disclose data where the law requires it, to protect the rights, safety, or property of GreenSlips or others, or as part of a merger, acquisition, or sale of assets (in which case we will tell you before your data becomes subject to a different privacy policy).
6. International transfers
Our primary users are in the United Kingdom and the European Economic Area, and our servers are in the United Kingdom. Some providers listed above are in the United States. When personal data leaves the UK or EEA we rely on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum (or the UK International Data Transfer Agreement), plus technical safeguards: TLS 1.2+ in transit, encryption at rest, and scoped access credentials. You can ask us for a copy of the relevant clauses using the contact details below.
7. How long we keep data
| Data | Retention |
|---|---|
| Account data held by Auth0; preferences | Until you delete your account (in-app), after which they are deleted |
| Data-export bundle | Deleted when you delete your account, and in any case automatically after 8 days |
| Deletion and export request records | Kept indefinitely as evidence, but anonymised: the account identifier is replaced by a one-way hash that cannot be turned back into your identity |
| Rate-limit and post-deletion token-block entries | Expire automatically within 24 hours |
| Server logs | 30 days |
| Background-job records that reference your account identifier | Expire with the job system’s retention window (days) |
| Data on your own device (preferences cache, bet slip, tokens) | Cleared when you sign out or delete your account; otherwise until you uninstall |
8. Security
We protect data with encryption in transit (TLS 1.2+) and at rest, private networking between our services, short-lived access tokens, least-privilege credentials, and secrets held in a managed key vault. Passwords are never visible to us; Auth0 stores them hashed. No system is perfectly secure, so if we learn of a breach that is likely to put your rights at risk we will notify the relevant regulator within 72 hours and tell you without undue delay, as the law requires. To report a security concern, email security@greenslips.pro.
9. Your rights (UK, EU and worldwide)
If you are in the UK or the EEA you have the rights below under the UK GDPR / GDPR. We extend the same rights to everyone, wherever you live, unless local law prevents it.
| Right | How to exercise it |
|---|---|
| Access and portability — get a copy of your data in a machine-readable format | In the app: Profile → Security & Billing → “Export my data”. We email you a secure download link (one request per 24 hours). Or email us. |
| Erasure — delete your account and data | In the app: Profile → Security & Billing → “Delete account”. Deletion runs immediately; you receive a confirmation email. Or email us and we will run it for you. |
| Rectification — correct inaccurate data | Change your email in-app (Security & Billing); reset your password from the same screen; edit preferences anywhere in the app. For anything else, email us. |
| Objection and restriction | Email us. Because we do no marketing or profiling, the main use you can object to is diagnostics, which you can also switch off in the app once it exists. |
| Withdraw consent | Where we rely on consent (for example crash reporting in some countries), you can withdraw it in the app’s settings at any time; withdrawal does not affect earlier processing. |
| Not be subject to solely automated decisions | Not applicable — we make no such decisions about you. |
| Complain to a regulator | UK: Information Commissioner’s Office, ico.org.uk/make-a-complaint, 0303 123 1113. EEA: your national data-protection authority (list at edpb.europa.eu). We would appreciate the chance to help first. |
We answer requests within one month (extendable by two months for complex requests, in which case we will tell you). We may ask you to confirm you control the account’s email address before acting. There is no charge unless a request is manifestly unfounded or excessive.
10. US state privacy rights (including California)
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana or another US state with a consumer privacy law, you may have the right to know what personal information we collect and how we use and disclose it, to access and correct it, to delete it, to obtain a portable copy, and to opt out of the sale of personal information, of its sharing for targeted advertising, and of profiling that produces legal or similarly significant effects. You also have the right not to be discriminated against for exercising these rights. We honour all of these rights for all US residents, whether or not a particular law applies to us.
We do not sell personal information, do not share it for cross-context behavioural advertising, do not use or disclose sensitive personal information, and do not knowingly collect personal information from anyone under 18. We have not done so in the preceding 12 months. Because we do not sell or share, there is nothing to opt out of; we nevertheless treat browser Global Privacy Control signals as a valid opt-out request.
California notice at collection. In the last 12 months we collected these categories of personal information (as defined in the CCPA): identifiers (email, name, account ID, IP address); internet or other electronic activity (server logs, app preferences); and, when enabled, diagnostic information. Sources: you, your sign-in provider, and your device. Purposes: section 4. Disclosed to service providers: section 5. Retention: section 7. We do not collect the other CCPA categories.
To exercise these rights, use the in-app tools in section 9 or email privacy@greenslips.pro. You may use an authorised agent; we will ask for proof of authority and will verify the request through your account email. If we deny a request you may appeal by replying to our decision email with the word “Appeal”.
11. Age limit and children
GreenSlips is for adults only: you must be at least 18, or older where the law of your location sets a higher age for sports betting (for example 21 in most US states). We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, email privacy@greenslips.pro and we will delete it.
12. Cookies and local storage
The GreenSlips website and web app set no advertising or analytics cookies. The web app keeps your sign-in tokens and a cache of your preferences in your browser’s session and local storage, which are strictly necessary to run the app and are cleared when you sign out. Auth0 sets its own strictly necessary cookies on its sign-in pages to complete login securely; see Okta’s privacy policy. Because we use only strictly necessary storage, no cookie consent banner is required under the UK PECR or the EU ePrivacy rules.
13. App store disclosures
The Apple App Store “App Privacy” label and the Google Play “Data safety” section for GreenSlips are derived from the same data inventory as this policy. In summary: data collected and linked to you — email, name, user ID, app preferences (and, when enabled, crash and diagnostic data); no data used to track you; no data shared with third parties for their own purposes; encrypted in transit; deletable in-app.
14. Changes to this policy
We will update this policy when our practices change — for example when crash reporting is enabled or paid features launch. The version number and dates at the top tell you which version you are reading. For material changes we will give notice in the app or by email at least 14 days before they take effect, except where a change is required sooner by law.
15. Contact and complaints
Privacy questions and requests: privacy@greenslips.pro
General support: support@greenslips.pro · Support page
Post: GreenSlips LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702, United States
See also our Terms of Service and Responsible Gambling page.