StrikeLockStrikeLock
HomeCompetitionsPredictionsNewsCountries
Champions League

StrikeLock — decision support, not betting advice.

Football data provided by API-Football and Highlightly.

Privacy PolicyTerms of Service
  • Home
  • Leagues
  • Tips
  • News
  • Nations

Privacy Policy

Last updated: July 27, 2026

1. Who we are

StrikeLock (“we,” “our,” or “us”) operates the website at www.strikelock.team and the StrikeLock football intelligence platform. Our servers are hosted in the United Arab Emirates. We are the controller responsible for your personal data.

For privacy-related inquiries, you can reach our privacy contact at strikelock@proton.me.

2. What personal data we collect

We collect and process the following categories of personal data, along with whether providing each category is required to use the corresponding feature.

Data categoryCollected whenRequired / Optional
Account data (name, email, avatar URL)Sign in via OAuth or EmailRequired for account features
Authentication identifiers (user ID, session tokens)Sign in and session maintenanceRequired for account use
Chat messages and conversation dataUse of the Copilot chat featureRequired for chat features
MFA credentials (TOTP seeds, passkey public keys)Enabling two-factor authentication or passkeysOptional
Technical usage data (IP address, browser type)Visiting any pageAutomatic (necessary for the Service)

3. Purposes and legal basis for processing

We process your personal data for the following purposes and on the following lawful bases:

  • Providing the StrikeLock service — delivering football data, predictions, chat intelligence, and user accounts. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
  • Authentication and security — verifying your identity, maintaining sessions, enforcing rate limits, and protecting against unauthorized access. Legal basis: legitimate interests (GDPR Art. 6(1)(f)).
  • Chat intelligence — processing your messages to provide AI-powered football analysis. Legal basis: your consent (GDPR Art. 6(1)(a)).
  • Service improvement — aggregated, anonymized analytics to understand platform usage. Legal basis: legitimate interests (GDPR Art. 6(1)(f)). No personal data is used for this purpose.

We do not use your personal data for direct marketing, nor do we sell or rent your personal data to any third party. We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you (GDPR Art. 22).

4. Classes of persons to whom data may be transferred

We may transfer your personal data to the following classes of persons (GDPR Art. 28):

  • Cloud service providers — Supabase, Inc. (USA), which hosts our database and authentication infrastructure. Supabase is contractually bound to process your data only on our instructions and to implement appropriate security measures.
  • AI service providers — The large language model provider you choose when using our BYOK (Bring Your Own Key) chat feature. Your API key is encrypted at rest (AES-256-GCM) and never stored in plaintext; we do not share it with any third party. Chat messages are transmitted to your chosen provider to fulfill your requests.
  • Football data providers — API-Football and Highlightly. No personal data is shared with these providers; they supply football data to us only.
  • Legal and regulatory authorities — where required by applicable law, court order, or governmental regulation.

5. International data transfers

Your personal data may be transferred to and processed in countries outside your jurisdiction, including the United Arab Emirates (where our servers are hosted) and the United States (where Supabase servers are located). Where such transfers occur, we ensure appropriate safeguards are in place, including contractual clauses and technical measures, to protect your data in accordance with applicable law (GDPR Arts. 44–49).

6. Data retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected (GDPR Art. 5(1)(e)):

Data categoryRetention period
Account data and profileDuration of account + 30 days after deletion request
Chat messages and conversations30 days from last message in the session
Authentication tokens and session dataSession duration (cookies) + 7 days (revocation denylist)
Server logs and IP addresses30 days (rotated automatically)

When personal data is no longer required, we take all practicable steps to erase it (GDPR Art. 17). Anonymized or aggregated data derived from personal data may be retained indefinitely for analytical purposes, as it can no longer identify you.

7. Data security

We implement technical and organizational measures to protect your personal data against unauthorized or accidental access, processing, erasure, loss, or use (GDPR Art. 32). These measures include:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Row-Level Security (RLS) on our database, ensuring you can only access your own data
  • Multi-factor authentication for administrative access
  • Immutable, read-only container filesystems for all production services
  • Regular security reviews and dependency vulnerability scanning
  • Data processors contractually bound to equivalent security standards

8. Cookies and similar technologies

We use only essential cookies necessary for the operation of the StrikeLock platform:

  • Session cookie (Supabase) — maintains your authenticated session. Expires when you close your browser or sign out. Strictly necessary for account functionality.
  • Theme preference (localStorage) — remembers your light/dark mode choice. Not a cookie; stored locally in your browser.

We do not use tracking cookies, analytics cookies, advertising cookies, or any third-party tracking technology. We do not use personal data for direct marketing.

9. Your data subject rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

RightGDPR
Right of accessArt. 15
Right to rectificationArt. 16
Right to erasureArt. 17
Right to restrict processingArt. 18
Right to data portabilityArt. 20
Right to objectArt. 21
Right to withdraw consentArt. 7(3)

To exercise any of these rights, contact us at strikelock@proton.me. We will respond within 30 days. If we refuse a request, we will provide written reasons.

10. California privacy rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you the right to:

  • Know what personal information we collect, use, and disclose (see Section 2).
  • Delete personal information we hold about you, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information.
  • Not be discriminated against for exercising these rights.

We do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information for any purpose beyond providing the Service. To exercise your CCPA/CPRA rights, contact us at strikelock@proton.me.

11. Children’s privacy

StrikeLock is not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction, which may be up to 16 under GDPR Art. 8). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will take steps to delete it.

12. Complaints

If you believe your data privacy rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority:

  • European Union / EEA: The data protection authority in your EU member state of residence. A list is available at edpb.europa.eu.
  • California:The California Attorney General’s office, or the California Privacy Protection Agency (CPPA).
  • Other jurisdictions: Contact your local data protection authority. We will cooperate fully with any regulatory investigation.

You may also seek compensation through civil action for damage caused by a contravention of applicable data protection laws (GDPR Art. 82).

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified via a prominent notice on our website or by email to registered users. The date at the top of this page indicates when it was last revised. Continued use of StrikeLock after changes constitutes acceptance of the updated policy.

14. Contact

For any questions about this Privacy Policy or to exercise your data subject rights, contact us at:

Email: strikelock@proton.me
Website: www.strikelock.team