Data protection

Tychefy Privacy Policy

This policy explains how the platform processes personal data, on what legal bases such processing rests, and which safeguards and rights may apply when you use the service.

Last updated: 04/09/2026

This Privacy Policy explains how we process personal data when you use the Tychefy platform (the “Service”). Where the General Data Protection Regulation (GDPR) applies, processing is carried out in accordance with the principles of lawfulness, transparency, data minimisation, and security. In Cyprus, processing is also subject to Law 125(I)/2018 on the protection of natural persons with regard to the processing of personal data.

1. Data controller and contact details

The data controller for the operation of Tychefy is Acrossmedia241 LTD, registered at Kyriakou Matsi 3, 3040, Limassol, Cyprus with registration number HE 290075, VAT number CY10290075L For privacy-related matters, data protection requests, or questions about this Policy, please contact customers@tychefy.com.

2. Categories of data

  • Account and identification data: email address, user identifier, and authentication-related data handled through an identity provider, such as Clerk.
  • Billing and entitlement data: subscription status, one-time purchase records, transaction identifiers, and payment event records. For Shortlist Packs we additionally keep a ledger of shortlists granted and consumed, including the model and the official draw each shortlist relates to. That ledger is what determines your remaining balance, and it is also the record used to calculate any refund apportioned by shortlists consumed under Section 9 of the Terms; it is therefore retained for as long as necessary to substantiate the transaction. We do not store full card details, which are handled by the payment provider, such as Stripe.
  • Technical and operational data: IP address, where it appears in logs, user-agent, timestamps, application errors, and diagnostic information used for security and reliability purposes.
  • Usage data and user inputs: inputs that you submit, such as recent draw information or joker number values, as well as operational history files that you update through the Service.

3. Purposes of processing and legal bases

  • Provision of the Service (Article 6(1)(b) GDPR): account creation and management, access to platform features, and presentation of outputs.
  • Legitimate interests (Article 6(1)(f) GDPR): security, prevention of misuse, troubleshooting, and improvement of service reliability.
  • Legal obligation (Article 6(1)(c) GDPR): accounting, tax, and related compliance obligations where required.
  • Consent (Article 6(1)(a) GDPR): non-essential cookies and analytics, where consent is required by applicable law.

4. Cookies and similar technologies

We use technically necessary cookies and similar storage technologies for authentication, session continuity, security, and basic service operation. We also store the user’s cookie-banner choice locally in the browser in order to remember that preference on the same device and browser.

Where we use advertising or measurement technologies, this is described in the section “Advertising audiences and measurement on third-party platforms”, and any required consent is obtained beforehand.

Cookies and similar storage that are not strictly necessary for the operation of the Service are placed only after your consent, in accordance with the Regulation of Electronic Communications and Postal Services Law of 2004 (Law 112(I)/2004), which implements Directive 2002/58/EC in Cyprus, read together with the GDPR. You can review or change your choice at any time through the cookie settings on the site.

5. Recipients and service providers

The Service relies on third-party providers for infrastructure and operational functionality, including Vercel for hosting and deployment, Clerk for authentication and identity services, and Stripe for payment processing and subscription-related billing events. For conversion measurement, as described in Section 4, event data are also transmitted to Google (Google Analytics 4) and Meta Platforms (Conversions API). With marketing consent, the Yahoo DSP pixel also measures page visits, shortlist builds, unlock clicks, checkout starts and confirmed payments. If enhanced matching is enabled, a signed-in user’s verified email is trimmed, lowercased and SHA-256 hashed before it is passed to Yahoo. No plaintext email or phone number is sent by this integration.

Depending on the relevant processing activity, such providers may act as processors on our behalf or, for limited parts of their own service operation, as independent controllers under their own legal documentation. Where required, appropriate contractual and transfer safeguards are applied.

6. Transfers outside the EEA

Where personal data are transferred outside the European Economic Area, appropriate safeguards, such as an adequacy decision of the European Commission (including the EU-US Data Privacy Framework, Commission Implementing Decision (EU) 2023/1795) or Standard Contractual Clauses, are applied where required.

7. Advertising audiences and measurement on third-party platforms

In addition to the conversion measurement described above, we may use certain personal data to create and manage advertising audiences on third-party advertising platforms, in particular Meta Platforms (Facebook and Instagram) and Google.

Specifically, we may upload a limited set of customer identifiers, such as email addresses, to Meta and Google in a hashed or pseudonymised form, so that these platforms can match them against existing accounts and allow us to show or withhold advertising to existing customers, and to create lookalike or similar audiences in order to reach new people whose characteristics resemble those of our existing customers.

We may also use website and app interaction data collected through advertising technologies, such as the Meta pixel and Google tags, where applicable consent has been obtained, to build audiences of visitors for remarketing and measurement purposes.

Where this processing requires consent under applicable law, such consent is obtained before the relevant data are used for these purposes, and you may withdraw it at any time. Where this processing is based on our legitimate interests (Article 6(1)(f) GDPR) in promoting the Service and reaching relevant audiences, you have the right to object to such processing at any time, including for direct-marketing purposes, in which case we will cease using your data for those purposes.

The identifiers we upload are transmitted in hashed form, and we do not transmit full payment-card details. Depending on the activity, Meta and Google may act as our processors or as independent controllers under their own legal terms. Appropriate contractual and international-transfer safeguards are applied where required, as described in Sections 5 and 6.

You can exercise your rights, including objection and withdrawal of consent, by contactingcustomers@tychefy.com. You may also adjust advertising preferences directly with the relevant platform through its own settings.

8. Retention period

We retain personal data only for as long as necessary for the purposes described in Section 3. The periods below apply to each category.

  • Saved model runs: each account retains the six most recent runs per game page. Older runs are deleted automatically by a scheduled process.
  • Measurement and checkout data: individual events are deleted after two days, having first been consolidated into daily aggregate totals that contain no user identifiers.
  • Payment event ledger: thirty days. This record exists solely to prevent a payment provider webhook from being processed twice.
  • Account data: retained for as long as the account is active. Deletion of an account is immediate and permanent.
  • Accounting and tax records: six years, as required by Cypriot tax legislation and the Companies Law. This obligation prevails over a request for erasure, in accordance with Article 17(3)(b) of the GDPR, and we will tell you where that is the reason a request cannot be met in full.

Where data must be kept beyond these periods to resolve a security incident or to establish, exercise, or defend a legal claim, retention is limited to what that purpose requires.

9. Security

We implement technical and organisational measures, including access controls, encryption in transit, event logging, and limitation of privileges. No method of transmission or storage can, however, guarantee absolute security.

10. Data subject rights

Depending on the applicable legal framework, you may exercise rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may also lodge a complaint with the competent supervisory authority. In Cyprus, this is the Commissioner for Personal Data Protection (www.dataprotection.gov.cy); if you reside in another Member State of the European Union, you may also contact the supervisory authority of your place of residence.

Where processing is based on your consent, you may withdraw that consent at any time, and withdrawal is as straightforward as giving it. Withdrawal does not affect the lawfulness of processing carried out before it. For the cookies and measurement technologies described in Sections 4 and 7, you may change or withdraw your choice at any time through the cookie settings available on the site.

11. Automated decision-making

The Service generates probabilistic outputs for the purpose of supporting the organisation of selections and is not intended to produce legal effects or otherwise bind you. The final decision on whether and how to use any output remains exclusively your own.

12. Minors

The Service is not intended for minors. If we become aware that data relating to a minor have been collected, we will take steps to restrict processing or delete the relevant data.

13. Changes to this Policy

We may update this Privacy Policy from time to time. The current version will be published on this page together with the updated effective date.