Last updated: November 2025
Privacy Policy
This policy explains what personal data xRaffle ("we", "us") processes, why, and the choices you have. It applies to xraffle.dev and any subdomains we operate.
Data we collect
- Account data: your name, email address, and hashed password (or the identifier returned by Google if you sign in with Google).
- Raffle data: the public X (Twitter) post URLs you submit, the participants returned by the X API for those posts, the filters you configure, and the winners you draw.
- Billing data: subscription status and payment metadata provided by our payment processor. We never receive or store card numbers or wallet keys.
- Technical data: IP address, user agent, and basic request logs used to operate the service and prevent abuse.
How we use it
- To provide the dashboard, run raffles, and publish audit pages.
- To authenticate you and secure your account.
- To bill you and handle subscription changes.
- To respond to support requests.
- To detect abuse, fraud, or violations of our terms.
We do not sell personal data and we do not use it to train advertising profiles.
Legal bases (GDPR)
- Contract: to deliver the service you signed up for.
- Legitimate interest: security, abuse prevention, and product analytics limited to aggregate usage.
- Legal obligation: tax and accounting records.
- Consent: optional cookies and marketing email, both of which you can withdraw at any time.
Sharing and subprocessors
We share limited data with vetted service providers that help us run xRaffle: Appwrite (authentication, database, and function hosting), our payment processor for subscription billing, X (Twitter) for fetching public post engagement, and email delivery providers. Each receives only what it needs to perform its role.
Public audit pages
When you publish a raffle audit page, the tweet URL, participant handles, and the drawn winner become publicly viewable at a shareable URL. Do not run raffles with private data you do not want to appear on a public page.
Retention
Account data is kept for as long as your account is active. Raffle records are kept while the account exists so audit pages stay reachable. When you delete your account we remove personal data within 30 days, except records we must keep for legal reasons (for example invoices).
Your rights
You can request access, correction, deletion, portability, or restriction of your data by emailing support@raffle.dev. You also have the right to lodge a complaint with your local data protection authority. See our GDPR page for more detail.
Security
Traffic is encrypted with TLS. Passwords are stored hashed by our authentication provider. Access to production systems is limited to the people who need it. No online service can guarantee absolute security, but we work to keep this one appropriate to the data it holds.
Changes
We may update this policy as the product evolves. Material changes will be announced in-app or by email before they take effect.