Privacy Policy
Last updated: July 25, 2026 · Effective date: July 25, 2026
1. Who We Are
Data Controller: Winnzi, Belgium
Data Protection Officer: [To be appointed]
Email: dpo@winnzi.gg
2. What Data We Collect
2.1 Account and Authentication Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Email address | Account, communication | Contract (Art. 6(1)(b)) |
| Username | Identification, profile | Contract |
| Password (hashed) | Security | Contract |
| Game account username or identifier (self-reported by you) | Opponent matching, match-result verification | Contract |
| IP address | Security, fraud, geo-compliance | Legitimate interest |
2.2 Financial and Transaction Data
We record all deposits, withdrawals, competition entry fees, prize payments, and platform fees as immutable ledger entries. We do not store your full credit card number or CVV — payment card data is handled entirely by Stripe.
If you use the optional USDC feature, we also process the selected blockchain network, deposit and payout references, transaction status and hash, amounts, fees, timestamps, and your saved withdrawal address. Public blockchain transfers are inherently visible on the relevant network. We display withdrawal addresses in masked form where the complete address is not needed, but must provide the complete destination and transaction details to our crypto payment provider to perform your request. Winnzi does not ask for or store a wallet seed phrase or private key.
2.3 Identity Verification Data (KYC)
To comply with our anti-money laundering and know-your-customer obligations, and to prevent fraud on a competition platform with payments, we require identity verification before certain account actions — in particular, before you can make a withdrawal.
Identity verification is performed entirely by Stripe Identity. When you start verification, you are redirected to a Stripe-hosted flow where you submit a government ID and a selfie directly to Stripe. Stripe processes this data — including any biometric matching — as an independent controller, under its own privacy policy. Winnzi does not receive, view, or store your ID document images or biometric data at any point.
What Winnzi does receive and store is limited to:
- the verification result (verified / not verified),
- a Stripe session reference identifier, and
- the timestamp of verification.
| Data | Purpose | Legal Basis |
|---|---|---|
| Verification result (pass/fail) | Determine trust level, unlock withdrawals | Legal obligation (Art. 6(1)(c)) — AML/KYC compliance |
| Stripe session reference | Audit trail, dispute resolution | Legal obligation (Art. 6(1)(c)) |
| Phone number, email | Account identification, communication | Contract (Art. 6(1)(b)) |
Winnzi has one verification tier: unverified accounts may deposit and play up to platform limits but cannot withdraw; a successful Stripe Identity verification unlocks full withdrawal limits as set out in our Terms of Service. There is no separate biometric processing step performed by Winnzi itself. For information on how Stripe processes your ID and biometric data during verification, see Stripe's Privacy Policy.
3. Who We Share Your Data With
We share data with the following third-party processors under GDPR Article 28:
Stripe (Payment Processing & Identity Verification)
Transaction data, Stripe customer ID, and identity verification data. For identity verification, Stripe acts as an independent controller: we initiate a Stripe Identity session and receive back a verification result (verified/not verified) and a session reference. Stripe collects, stores, and processes the underlying government ID and biometric data directly — Winnzi never receives or stores your ID images or biometric data.
Stripe DPA · Stripe Privacy
NOWPayments (Optional USDC Processing)
When the USDC feature is enabled and you use it, NOWPayments receives the blockchain address, network, asset, amount, payment or payout reference, and related transaction metadata needed to process and monitor the transfer. It may also perform fraud, AML, sanctions, or compliance checks under its own terms and privacy policy.
NOWPayments Privacy Policy
Neon (Database Hosting)
All Platform data stored in PostgreSQL. Hosted in the EU.
Cloudflare (Infrastructure)
Web traffic data (IP addresses, request headers). CDN, DDoS protection.
Cloudflare GDPR
Railway (Application Hosting)
Application logs and runtime data. Hosted in the EU.
Upstash (Redis — Caching & Session Data)
Session tokens, rate-limiting counters, and cached lobby/match state. Data is transient. Hosted in the EU.
Vercel (Frontend Hosting & Analytics)
Web traffic and request data for the frontend application (IP addresses, request headers). We use Vercel Analytics to measure aggregate page usage; this does not use cookies or persistent identifiers and does not track you across sites.
Sentry (Error Monitoring)
Application error reports for debugging and reliability, on both our frontend and backend. Sentry is configured with sendDefaultPii: false and scrubbing that strips IP addresses, email addresses, cookies, authorization headers, and any field indicating a password, token, session identifier, or payment detail before an event leaves the application. Only sanitized error context is transmitted.
We may also disclose personal data to competent authorities where required by applicable law, or in connection with a merger/acquisition.
4. How Long We Keep Your Data
| Category | Retention | Reason |
|---|---|---|
| Account data | Account + 3 years | Legal claims |
| Financial transactions | 10 years | Belgian tax/AML law |
| ID verification documents | Account + 1 year | AML/KYC |
| Biometric data | Account + 1 year or consent withdrawal | Consent; GDPR minimization |
| Match data | Account + 3 years | Disputes |
| Replay files | 1 year | Disputes |
| Technical logs | 90 days | Security |
| Support communications | 3 years | Legal claims |
5. Your Rights Under GDPR
As a data subject, you have the following rights:
Right of Access (Art. 15)
Request a copy of all personal data we hold about you.
Right to Rectification (Art. 16)
Request correction of inaccurate data.
Right to Erasure (Art. 17)
Request deletion of your data. Exceptions apply (AML record-keeping, legal claims).
Right to Restriction (Art. 18)
Request that we limit how we process your data.
Right to Data Portability (Art. 20)
Receive your data in a machine-readable format (JSON/CSV).
Right to Object (Art. 21)
Object to processing based on legitimate interest.
Right to Withdraw Consent (Art. 7(3))
Withdraw consent at any time. Does not affect lawfulness of prior processing.
6. How to Exercise Your Rights
- Email: privacy@winnzi.gg
- Subject line: "GDPR Request — [Right]"
- Required: Your username, email, and description of the right you wish to exercise.
- Verification: We may verify your identity before processing.
- Response time: Within 30 days (extendable to 90 for complex requests).
- Cost: Free of charge (reasonable fee for manifestly unfounded requests).
Autorité de protection des données (APD)
Rue de la Presse 35, 1000 Bruxelles · +32 (0)2 274 48 00
autoriteprotectiondonnees.be
7. Cookies and Tracking
We use only strictly necessary cookies: session management, CSRF protection, and cookie consent preferences. We do not use third-party analytics (e.g., Google Analytics). If we introduce analytics in the future, we will update this policy and implement a consent banner.
Stripe's payment processing may set its own cookies during checkout — governed by Stripe's Cookie Policy.
8. International Data Transfers
Your data is primarily processed within the EEA. Where transfers outside the EEA occur, we rely on:
- EU Standard Contractual Clauses (SCCs)
- EU-U.S. Data Privacy Framework (Stripe participates)
- European Commission adequacy decisions
9. Data Security
- Encryption in transit (TLS 1.2+) and at rest (AES-256, bcrypt).
- Access controls — authorized personnel only, need-to-know basis.
- Payment card data handled entirely by Stripe (PCI-DSS Level 1 compliant).
- Incident response: GDPR Article 33 (72-hour authority notification) and Article 34 (data subject notification).
10. Children's Privacy
The Platform is not for users under 18. We do not knowingly collect data from children. If we discover we have collected data from a child, we will delete it promptly.
11. Automated Decision-Making
Trust level assignment and fraud detection involve some automated processing. Under GDPR Article 22, you have the right to human intervention, to express your point of view, and to contest automated decisions. Contact privacy@winnzi.gg.
12. Contact
- Email: privacy@winnzi.gg
- DPO: dpo@winnzi.gg (once appointed)
- Address: [To be completed with registered business address in Belgium]