Last updated: ⟨ LAST UPDATED (PRIVACY) — NOT SET ⟩
This Privacy Policy explains how Gamzingo LLC collects, uses, shares and protects personal data when you use giveaways.com (the "Platform").
Data controller:
Gamzingo LLC
16192 Coastal Highway, Lewes, Delaware 19958, United States
Delaware file number: 10650438
Contact: privacy@giveaways.com
Gamzingo LLC operates the Platform and determines how your personal data is used.
Group companies. Gamzingo LLC is part of a group that includes Gamzingo Limited, a company registered in the Republic of Cyprus (registration number HE 492520, Georgiou Christoforou 8, 1st Floor, Strovolos, 2012, Nicosia, Cyprus), which carries out marketing activities. Where personal data is processed in the context of that establishment, or where we offer services to individuals in the European Economic Area, the EU General Data Protection Regulation (GDPR) applies and we process data accordingly. In those circumstances the relevant supervisory authority is the Office of the Commissioner for Personal Data Protection (Cyprus), or your local supervisory authority.
Residents of certain US states have additional rights, described in Section 9.
You give us:
| Data | When |
|---|---|
| Name, email address, password | Registration |
| Date of birth / age confirmation | Registration and verification |
| Postal address | Redemption, and Alternative Method of Entry |
| Identity documents and a facial image | Identity verification, when you request a redemption |
| Payment details | When you purchase Gold Coins (handled by our payment provider — we do not store card numbers) |
| Wallet address or payout details | When you request a redemption |
| Support messages | When you contact us |
| Marketing preferences | If you choose to subscribe |
We collect automatically:
| Data | Purpose |
|---|---|
| IP address | Location verification, fraud prevention, security |
| Approximate location (country and region, derived from IP) | Enforcing jurisdictional restrictions |
| Device, browser and operating system | Security, compatibility |
| Session records — sign-in times, device and IP | Account security and fraud detection |
| Gameplay records — games played, coin balances, transactions | Operating the Platform, prize determination, record-keeping |
| Cookies and similar technologies | See our Cookie Policy |
We do not knowingly collect data from anyone under 18. If we learn we have, we will delete it. See Section 11.
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and operating your account | Performance of a contract |
| Running games and determining outcomes | Performance of a contract |
| Processing Gold Coin purchases | Performance of a contract |
| Processing redemptions and verifying winners | Performance of a contract; legal obligation |
| Verifying identity and age | Legal obligation; legitimate interests |
| Enforcing jurisdictional restrictions | Legal obligation; legitimate interests |
| Preventing fraud, abuse and money laundering | Legitimate interests; legal obligation |
| Responsible play tools and interventions | Legitimate interests; legal obligation |
| Responding to support requests | Performance of a contract; legitimate interests |
| Marketing communications | Consent (which you may withdraw at any time) |
| Analytics and improving the Platform | Consent, where required; otherwise legitimate interests |
| Complying with legal, tax and regulatory obligations | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interest in operating a secure, lawful platform is not overridden by your rights.
We do not sell your personal data.
We share personal data with the following categories of recipient, only as necessary:
| Recipient | What they process | Where |
|---|---|---|
| Supabase — database, authentication and file storage | Account data, gameplay records, session records | United States |
| Vercel — application hosting | Request data, IP addresses | United States |
| Stripe — payment processing for Gold Coin purchases | Payment and transaction data | United States / EU |
| Shufti Pro — identity verification | Identity documents, facial image, verification result | EU / United Kingdom |
| Sentry — error monitoring | Technical error data | United States |
| Payment and payout providers | Redemption payout details | Varies by method |
| Professional advisers, auditors and insurers | As required | Varies |
| Regulators, law enforcement and courts | Where legally required | Varies |
A current list of processors is available on request from privacy@giveaways.com.
We may also disclose data in connection with a merger, acquisition or sale of assets, subject to equivalent protections.
Personal data is transferred outside the European Economic Area, principally to the United States. Where we do so, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, and where applicable the EU–US Data Privacy Framework. You may request a copy of the relevant safeguards from privacy@giveaways.com.
When you request a redemption, you must complete identity verification. This is carried out by Shufti Pro, our verification provider.
Your identity documents and facial image are submitted directly to Shufti Pro and are not stored on our systems. We receive and retain only a verification status, a reference number and a timestamp.
This means that if you ask us to delete your verification data, we will delete the record we hold and request deletion from Shufti Pro. Their retention of the underlying documents is governed by their own retention policy and applicable law.
| Data | Retention |
|---|---|
| Account and profile data | For the life of the account, then [X] years after closure |
| Transaction and gameplay records | [X] years, to meet financial, tax and anti-money-laundering obligations |
| Identity verification records (status and reference) | [X] years after the related redemption |
| Session and IP records | [X] months |
| Support correspondence | [X] years |
| Self-exclusion records | Retained for the period of exclusion and [X] years thereafter, so exclusions can be honoured |
| Marketing preferences and suppression records | Retained indefinitely, so opt-outs are honoured |
⚠️ [PENDING] — Retention periods must be set before publication. They are legal and operational decisions, not defaults, and they must be consistent with what the system actually does.
Where an account is closed but records must be retained for legal reasons, we restrict processing to that purpose only.
Where the GDPR applies to our processing of your data, you have the right to:
To exercise any right, contact privacy@giveaways.com. We will respond within one month, extendable by two further months for complex requests, and will tell you if an extension applies.
Limits on erasure. We may be unable to erase records we are legally required to keep — including transaction records, verification records and self-exclusion records. Where that applies, we will tell you which records are retained and why.
We use technical and organisational measures including encryption in transit, access controls, role-based administrative permissions, multi-factor authentication for staff accounts, audit logging of administrative actions, and monitoring for unauthorised access.
No system is completely secure. If a breach occurs which is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and, where the risk is high, notify you directly.
If you are a resident of California, Colorado, Connecticut, Virginia or another state with comprehensive privacy legislation, you may have the right to know what personal data we collect, to request deletion or correction, to opt out of "sales" or "sharing" and of targeted advertising, and not to be discriminated against for exercising these rights.
We do not sell personal data and do not share it for cross-context behavioural advertising.
To exercise these rights, contact privacy@giveaways.com. You may use an authorised agent, and we may take steps to verify their authority.
See our Cookie Policy for what we set, why, and how to control them. Non-essential cookies are set only with your consent.
The Platform is strictly for adults aged 18 or over (19 in Alabama and Nebraska). We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact privacy@giveaways.com and we will delete it.
We may update this Policy. Material changes will be notified to you, and the "last updated" date above will change.
Gamzingo LLC
16192 Coastal Highway, Lewes, Delaware 19958, United States
Delaware file number: 10650438
Privacy enquiries and data-subject requests: privacy@giveaways.com
Supervisory authority: Office of the Commissioner for Personal Data Protection, Cyprus — dataprotection.gov.cy
Open mystery boxes, win real products, and ship them or sell them back for Sweeps Coins.