Last updated: 6 June 2026 · Version 1.0
This Privacy Policy explains how SportSweeps (“we”, “us”), registered in Ireland, collects, uses and protects personal data when you use our fantasy-golf platform. We act as the data controller for personal data described below and are committed to compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR and the Irish Data Protection Act 2018.
Data Controller: SportSweeps, Ireland
Data Protection Contact: dpo@sportsweeps.io
Our trading name and registered entity may change as we formalise the company. The dpo@ address will remain the primary GDPR contact.
We deliberately collect the minimum data needed to run the product.
| User | What we store |
|---|---|
| Players | Full name, email address, hashed password, display name, pool entries (picks, tiebreakers), draft state, email preferences. |
| Club/society admins | Admin name, email, hashed password, society/group name, uploaded logo, billing subscription reference. |
| Payments | Card and bank details are handled entirely by Stripe / Revolut. We never see or store card numbers, CVVs or IBANs - we only keep a processor subscription ID to operate the service. |
| Technical | Session cookies, IP address (hashed for consent audit logs), browser user-agent string. |
We do not sell personal data. We share only what each processor strictly needs:
| Processor | Purpose | Location |
|---|---|---|
| MongoDB Atlas | Primary application database (accounts, pools, entries) | EEA region |
| Stripe | Subscription billing & payment processing | Ireland / USA (SCCs) |
| Revolut | Subscription billing & payment processing (EU societies) | Lithuania / Ireland |
| Resend | Transactional email delivery (confirmations, receipts, resets) | EU / USA (SCCs) |
| ESPN | Live tournament leaderboards (public data, no personal data sent) | USA |
| DataGolf | Golfer odds feed (public data, no personal data sent) | Canada |
Where a processor is located outside the EEA, transfers are protected by the European Commission's Standard Contractual Clauses (SCCs).
Under GDPR you have the right to:
SportSweeps uses only a small number of first-party cookies. Analytics and marketing cookies are off by default and only activated if you opt in. Full details are in our Cookie Policy.
Passwords are hashed with bcrypt. Traffic is TLS-encrypted end-to-end. Access to production data is restricted, audited, and limited to personnel with a clear operational need.
Our platform is intended for users aged 18 and over. We do not knowingly collect personal data from children under 16.
If we materially change this policy we will notify registered users by email and update the “Last updated” date above.
For any privacy question or to exercise a right above, email dpo@sportsweeps.io. We respond within 30 days.