Draft — requires attorney review. This document is not yet in force as written.
Privacy Policy
Version legal-2026-09-23-draft · Effective date: [Effective date not yet configured — launch blocker]
This policy explains what [Legal entity not yet configured — launch blocker] collects when you use Rift, why, who processes it for us, how long we keep it, and what you can ask us to do with it. Rift does not sell personal information and does not run third-party advertising or analytics scripts.
1. What we collect
- Account and identity. Your email address and name as held by our sign-in provider (Clerk), the invitation you accepted, your member role, when you joined and when you were last seen. Sign-in passwords and verification codes are handled by Clerk, not stored by Rift.
- Preferences. The sports, bet types, price range, favourite teams, saved filters and alert rules you choose. These are kept in a cookie on your device (
rift.prefs,rift.filters) and, when you are signed in, in our database (member_preferences) so they follow you between devices. - Your journal. Positions and picks you track (the pick, price, book, model and market probabilities as they stood, your units and notes, and how they settled), and your bankroll unit settings. Rift records units, never amounts of money.
- Notifications. If you turn on push notifications, your browser's push subscription endpoint and your notification settings.
- Product events. Named events such as "viewed the board" or "started checkout", stored in
product_eventswith a random identifier generated in your browser (rift.visitorin local storage). They contain no email, member id, IP address or payment detail. - Security records. An audit trail of sign-in refusals and administrative actions, which may include a one-way hash of an IP address and your browser's user-agent string; and rate-limit counters.
- Billing. If you subscribe: your payment provider customer and subscription identifiers, plan, billing period, trial and renewal dates, subscription state, amounts and dates of invoices, refunds and disputes, a one-way hash of your payment method's provider fingerprint (used only to enforce one free trial per card), promo codes you redeemed, your cancellation reason and feedback if you chose to give them, the confirmation shown to you at signup, and the billing emails queued to you. Your card number, expiry and security code go directly to Stripe; Rift never receives or stores them.
- Age and terms confirmations. That you confirmed the minimum age and accepted the billing terms, when, and under which policy version. We do not collect your date of birth.
- Referrals. Your referral code; for people who joined through your link, that a referral exists and its status (not their identity, which is not shown to you); service credits you earned. A referral cookie (
rift.ref) remembers a referral link you opened for up to 30 days. - Ask Rift assistant. Messages you send to the assistant are processed to produce an answer. Rift does not store conversation transcripts. Do not include sensitive personal information in assistant messages.
2. Cookies and local storage
- Sign-in session cookies set by Clerk, needed to keep you signed in.
rift.prefsandrift.filters: your view preferences.rift.ref: a referral link you opened (attribution only).- Local storage:
rift.visitor(random id),rift.first_seenandrift.firsts(which first-time events have fired).
There are no advertising or cross-site tracking cookies.
3. Why we use it
- To provide the service you asked for: your account, your preferences, your journal, your plan.
- To bill you, prevent trial, promo and referral abuse, and handle refunds and disputes.
- To keep Rift secure and to understand, in aggregate, which parts of the product are used.
- To send the service messages you need (trial reminders, cancellation confirmations) and, unless you opt out, at most one message after you cancel.
- To meet legal, tax and accounting obligations.
4. Who processes it for us
- Vercel - hosting and request logs.
- Supabase - database (United States).
- Clerk - sign-in and identity.
- Stripe - payments, when you subscribe. Stripe acts under its own privacy policy for card data.
- An email delivery provider, when one is configured, to send billing messages.
We do not sell or rent personal information, or share it for cross-context behavioural advertising.
5. How long we keep it
- Account, preferences, journal and referral records: while your account exists. Downgrading or cancelling never deletes them.
- Billing, invoice, refund and dispute records: as long as tax and accounting law requires (commonly up to 7 years), even after account deletion.
- Product events and security logs: kept only as long as needed for their purpose. [Drafting note: set specific periods.]
6. Your choices and rights
- Access, correct, or export your data; delete your account and personal data (billing records we are legally required to keep are retained, restricted to that purpose).
- Turn off push notifications, clear the preference cookies, or opt out of the post-cancellation message from your account page.
- Depending on where you live (for example California or the EU/UK), you may have further rights, including to object or to complain to a regulator.
To make a request, email [Legal contact not yet configured — launch blocker] or [Support email not yet configured — launch blocker]. We will verify the request comes from the account holder.
7. Children
Rift is not for anyone under the minimum age and we do not knowingly collect their information.
8. Security
Data is encrypted in transit; database tables are closed to public access and read only by Rift's server. No method is perfectly secure; we will notify you of a breach affecting you as the law requires.
9. Contact
[Legal entity not yet configured — launch blocker], [Address not yet configured — launch blocker]. Privacy contact: [Legal contact not yet configured — launch blocker].