1. Who we are and how to contact us
BetFlux LLC is a Massachusetts, United States-based company providing sports data and analytics. This policy describes personal information handled through betflux.ai, our accounts, APIs, downloads, waitlists, and support channels. BetFlux LLC is the controller of customer and visitor information described here: we decide why and how it is used.
For privacy questions, access or deletion requests, or concerns about a provider, email legal@betflux.ai with the subject “Privacy request.” Our Terms of Service cover use of the Services.
This notice concerns our visitors and customers. Sports and market datasets are a separate part of our product. Do not send us sensitive personal information or information about other people that is unnecessary for support or your account.
2. Information we collect
- Account and identity information: email address, name, profile image, authentication-provider identifier, account creation and onboarding records, and preferences. A sign-in provider may supply profile information you authorize it to share.
- Billing and subscription information: plan, subscription status, customer and transaction identifiers, invoices, billing address, and tax information where needed. Payment card details are submitted directly to Stripe; our application does not store full card numbers or card security codes.
- API and service usage: API key identifiers and hashes, request times and endpoints, downloads, quota and rate-limit counters, and diagnostic events.
- Browser and device information: IP address, browser and device characteristics, referring pages, pages visited, interactions, and cookie or similar identifiers, depending on your preferences and the features used. IP addresses may indicate an approximate location.
- Communications: waitlist email and signup source, marketing preferences, support messages and attachments you choose to send, and email delivery or interaction information where enabled.
Sources include you, your browser or API client, sign-in providers you choose, payment and communication providers, and our operational systems. We do not need your sportsbook passwords, wagering account balances, government ID documents, or precise device location to provide the standard Services.
Account credentials and certain billing details are necessary to provide account access and paid features. If you do not provide required information, we may be unable to supply those features. Optional marketing consent is not a condition of access.
3. How and why we use information
Where the EU or UK GDPR applies, we rely on the following legal bases, as appropriate to each activity:
- Contract: create and authenticate your account, deliver requested data and downloads, administer your plan and payments, and respond to service requests.
- Legitimate interests: secure and maintain the Services, prevent fraud and abuse, enforce usage limits, investigate errors, measure basic service performance, and resolve disputes. We consider the impact on your privacy and do not rely on this basis where your rights override those interests or consent is legally required.
- Consent: optional analytics storage and identified analytics, advertising technologies, and promotional communications where consent is required. You can withdraw consent without affecting processing that was lawful before withdrawal.
- Legal obligations: tax and accounting records, valid legal requests, and handling privacy rights.
Service messages, such as security or billing notices, may be necessary even if you opt out of promotional email. We do not use customer information to make solely automated decisions with legal or similarly significant effects. Automated quota and security controls may restrict access; contact us if you believe a restriction is mistaken.
4. Customer data subprocessors and providers
The providers below support customer-facing operations. They receive information relevant to their function, not every category listed in this policy. “Subprocessor” applies when a provider assists us in processing data on a customer’s behalf; for our own account administration, these vendors may instead be our processors. Some providers, particularly payment providers, also act as independent controllers for their own legal or fraud-prevention purposes.
| Provider | Purpose | Personal information | Processing locations |
|---|---|---|---|
| Amazon Web Services (AWS) | Application and authentication hosting, operational databases, backups, and infrastructure logs. | Account and authentication records, contact details, subscription references, and technical logs. | United States; global support and infrastructure. |
| Cloudflare | Website and API delivery, network security, storage, and edge processing. | IP addresses, request metadata, API identifiers, usage information, and data transmitted through the service. | Global edge network, including the United States. |
| Stripe | Payments, subscriptions, invoices, tax calculation, and fraud prevention. | Contact and billing details, payment information submitted directly to Stripe, account identifiers, and transaction records. | United States and other countries in Stripe’s processing network. |
| PostHog | Website and product analytics, including cookieless measurement and consent-based identified analytics. | Page views, interaction events, device and browser information, and identifiers or profile properties when identified analytics is enabled. | United States analytics service; international support may apply. |
| Courier | Waitlist and communication preference management and notification delivery orchestration. | Names, email addresses, profile identifiers, signup source, list memberships, and communication preferences. | United States; provider support and delivery networks may be international. |
| Postmark (ActiveCampaign) | Transactional email delivery, such as welcome and account messages. | Sender and recipient addresses, message content, delivery status, and email interaction metadata where enabled. | United States; international support may apply. |
| Grafana Labs / Grafana Cloud | Service monitoring, diagnostic logs, metrics, and traces. | Technical events, request and account identifiers where included in diagnostics, and performance information. | Hosted service region and international support locations. |
Processing locations describe service footprints, not a promise of exclusive data residency. Provider support teams and their own subprocessors may operate in additional countries. Contact us for information about a particular processing arrangement.
Production authentication uses self-hosted Logto on our hosting infrastructure. Use of that software alone does not mean that customer account data is sent to Logto Cloud.
We update this list as our providers change. If a separate data processing agreement applies to your organization, its notice and objection provisions govern subprocessor changes. Contact us before submitting personal data for processing on your organization’s behalf so we can determine whether a separate agreement is needed.
7. How long we keep information
We retain user personal information while your account or relationship with us is active and for no more than one year after it becomes inactive, unless a longer period is required by law. Activity includes using your account or API, maintaining an active subscription, or communicating with us about an ongoing service request. Information may be deleted sooner when it is no longer needed or in response to a valid deletion request.
- Account and subscription records: while providing the account and for up to one year after inactivity, subject to legally required retention.
- Billing and tax records: for the applicable statutory recordkeeping period and any unresolved audit or payment dispute.
- Support and communications: for handling the request or subscription and related follow-up, within the one-year inactivity limit. Where legally necessary, limited suppression records may remain so we can honor an unsubscribe request.
- Technical and analytics records: for troubleshooting, security investigations, usage accounting, and service analysis, with shorter operational or provider retention periods where applicable and no longer than one year after inactivity.
- Backups: removed through the backup lifecycle within the same retention limit, except for records we are legally required to preserve.
We retain personal information only as long as necessary for these purposes, then delete or de-identify it. Contact us for a retention assessment or deletion request relating to your account. Closing an account does not necessarily require immediate deletion of tax, security, or dispute records.
8. Security and international processing
We use safeguards appropriate to the Services, including access controls, protected connections, and hashed API keys. No storage or transmission method is completely secure. Protect your credentials, revoke exposed API keys, and contact us promptly about suspected unauthorized access.
BetFlux operates in the United States, and our providers may process information in the United States and other countries with different privacy laws. Where a restricted international transfer is subject to the GDPR, UK GDPR, or Swiss law, an applicable lawful transfer mechanism is required, such as an adequacy decision or appropriate contractual safeguards. Contact legal@betflux.ai to ask which safeguards apply to your information and how to obtain a copy. This policy is not itself a transfer agreement or a claim of certification under a privacy framework.
9. Your privacy rights
Depending on where you live and which laws apply, you may request access to your information, correction, deletion, a portable copy, or restriction of processing. You may withdraw consent and complain to a privacy regulator. These rights can be subject to lawful exceptions.
Right to object: where we rely on legitimate interests, you may object based on your situation. You may object to direct marketing at any time.
Send requests to legal@betflux.ai. Tell us the right you wish to exercise and the email associated with your account. Do not send passwords, full payment details, or identity documents unless we specifically request a proportionate verification method. We may verify identity and authority before disclosing or deleting information. An authorized agent may submit a request subject to applicable verification requirements.
We respond within the timeframe required by applicable law, generally one month for GDPR requests and 45 days for applicable US state access, correction, or deletion requests. If a permitted extension is needed, we will explain it. Opt-out requests follow the shorter deadlines that apply to them. We will not unlawfully discriminate or retaliate against you for exercising your rights.
If we deny a request, you may ask us to review the decision by emailing “Privacy appeal.” We will explain the outcome and any further complaint options required by law. You can complain directly to your local authority, including an EEA supervisory authority, the UK Information Commissioner, or the Swiss Federal Data Protection and Information Commissioner.
10. California and other US state notices
Where applicable, state privacy laws give you rights to know or access, correct, delete, and obtain a copy of personal information, and to opt out of sale, sharing, targeted advertising, or certain profiling. The collection and provider sections above describe the categories, sources, purposes, and recipients of information handled by the Services, including identifiers, commercial information, internet activity, and approximate location derived from network information.
To opt out of browser-based advertising disclosures, turn off Marketing in Cookie preferences. You may also email legal@betflux.ai with “Do not sell or share my personal information.” This choice does not require a paid account. If you use more than one browser or device, make the choice on each. Contact us if you need help applying an opt-out preference signal such as Global Privacy Control; this notice does not represent that the current site automatically recognizes every browser signal.
We do not use sensitive personal information to infer characteristics about you or knowingly sell or share the personal information of people under 16. We do not use customer information for profiling that produces legal or similarly significant effects. Our Services are intended only for adults aged 21 and older.
11. Children and age restrictions
The Services are not directed to people under 21, and we do not knowingly collect personal information from children under 13 or the applicable age of digital consent. If you believe a child has provided information, contact legal@betflux.ai so we can investigate and take appropriate action, including deletion where required.
12. Changes to this policy
We update this policy when our practices or obligations change and revise the date above. For material changes, we will provide additional notice where required, such as through the Services or email. Where a new use requires consent, we will request it before that use.
Questions about this policy or our customer data providers can be sent to legal@betflux.ai.