Legal
Privacy Policy
What we collect, why we collect it, who we share it with, and how to get it deleted.
Last updated September 3, 2026
By using HAXIOM EDGE you consent to the collection and processing of your information as described in this policy. If you do not agree, do not use the Service.
1. Information we collect
You give us
- Account details — name, email address, and a password, which is stored only as a salted hash. We never see or store your password in plain text.
- Preferences — selected sport, watchlists, alert thresholds, time zone.
- Content you enter — wagers logged in the bet tracker, saved signals, and notes.
- Correspondence — messages you send us through the contact form or by email.
Collected automatically
- Authentication cookies, which keep you signed in. These are strictly necessary for the Service to function.
- Technical data — IP address, browser and device type, pages requested, and timestamps, recorded in server logs.
What we do not collect
- Card numbers. Payment details are entered directly with our payment processor and never reach our servers. We store only a processor reference, the card brand, and the last four digits.
- Government identification, biometrics, or precise location.
- Data from sportsbook accounts. We have no connection to any operator and cannot see your betting activity unless you enter it yourself.
2. How we use it
| Purpose | Basis |
|---|---|
| Operate your account and deliver the Service | Performance of a contract |
| Process payments and prevent fraud | Contract; legitimate interests |
| Send transactional email (confirmation, password reset, alerts you enable) | Contract; consent for alerts |
| Diagnose faults and secure the platform | Legitimate interests |
| Meet legal and regulatory obligations | Legal obligation |
We do not sell your personal information, and we do not share it with advertisers or data brokers.
3. Who processes your data
We use a small number of vendors to run the Service. Each processes data only on our instructions:
| Provider | Purpose |
|---|---|
| Supabase | Database and authentication |
| Vercel | Application hosting and delivery |
| Resend | Transactional email |
| Cloudflare | DNS |
| Payment processor | Subscription billing and card storage |
We may also disclose information where required by law, to enforce our Terms, or as part of a merger or acquisition — in which case you will be notified before your data becomes subject to a different policy.
4. Cookies
We use strictly necessary cookies only. They keep you signed in and maintain your session; without them the Service cannot work. We do not use advertising or cross-site tracking cookies. Blocking cookies will prevent you from signing in.
5. How long we keep it
- Account data — while your account is open, then deleted within 90 days of closure.
- Billing records — up to 7 years, as tax and accounting rules require.
- Server logs — typically 30 days.
- Anonymised, aggregated performance data — retained indefinitely. It cannot be linked back to you.
6. Your rights
Depending on where you live, you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data — name and email are editable from your account page.
- Delete your account and associated data.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent for optional emails at any time.
- Not be discriminated against for exercising any of these rights.
Exercise any of these through the contact form, choosing the Privacy topic. We respond within 30 days. Residents of the EEA and UK may also lodge a complaint with their supervisory authority.
7. Security
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Database access is governed by row-level security policies, so the tier of content your subscription covers is enforced by the database itself rather than by the interface. Passwords are hashed. Access to production systems is limited to those who need it.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
8. Children
The Service is restricted to adults aged 21 and over. We do not knowingly collect information from anyone under 21. If we learn that we have, we will delete it. If you believe a minor has given us information, contact the contact form.
9. International transfers
Our providers operate in the United States, so your data may be processed there. Where data moves out of the EEA or UK we rely on Standard Contractual Clauses or an equivalent safeguard.
10. Changes
We may update this policy. Material changes will be announced by email or in-product notice before they take effect, and the date above will change.
11. Contact
Send privacy enquiries through the contact form and choose the Privacy topic. Anything else goes through the same form.
