Privacy Policy
Last updated: 11 June 2026
This policy explains what personal data WC2026 Predictor collects, why we collect it, how we use it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Jump to section
1. Who We Are
WC2026 Predictor is operated as an independent prediction game at itsonlyagameson.com. We are the data controller for personal information collected through this website.
If you have any questions about this policy or how we handle your data, contact us at: [email protected]
2. What Personal Data We Collect
We collect the following categories of personal data:
- Account data: Your display name (nickname), email address, and chosen favourite team when you register.
- Payment data: When you pay the £3 entry fee, Stripe processes your card details directly. We store only the Stripe session ID and payment intent ID — never your raw card number, CVV, or full card details.
- Prediction & game data: Your score predictions, quiz answers, mini-game selections, and creative challenge submissions.
- Usage data: Pages visited, actions taken within the app, and approximate session timing — used to improve the service.
- Charity vote: Which charity you voted for (linked to your account, visible only to administrators).
- Communications: Any messages you send us via email or feedback forms.
3. How We Use Your Data
We use your personal data for the following purposes and legal bases:
| Purpose | Legal Basis (UK GDPR) |
|---|---|
| Providing the prediction game and leaderboard | Performance of a contract (Art. 6(1)(b)) |
| Processing your £3 entry payment via Stripe | Performance of a contract (Art. 6(1)(b)) |
| Sending account-related emails (e.g. password reset) | Performance of a contract (Art. 6(1)(b)) |
| Calculating and displaying scores and rankings | Performance of a contract (Art. 6(1)(b)) |
| Administering the charity vote and donation | Legitimate interests (Art. 6(1)(f)) |
| Preventing fraud and abuse | Legitimate interests (Art. 6(1)(f)) |
| Improving the service and fixing bugs | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
We do not sell your personal data to third parties. We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
4. Third Parties We Share Data With
We share limited data with the following trusted third-party processors:
- Stripe (stripe.com): Payment processing. Stripe is PCI-DSS Level 1 certified. Your card data goes directly to Stripe — we never see it. Stripe's privacy policy: stripe.com/gb/privacy
- GoDaddy / Airo (godaddy.com): Hosting and infrastructure. Our application runs on GoDaddy's Airo platform.
- football-data.org: Live World Cup 2026 fixture and result data. No personal data is shared with this service.
All processors are contractually bound to handle your data only on our instructions and in accordance with applicable data protection law.
5. How Long We Keep Your Data
- Account data: Retained for the duration of your account. You may delete your account at any time from your Profile page.
- Payment records: Retained for 7 years to comply with UK financial record-keeping obligations.
- Game data (predictions, quiz, mini-games): Retained for the duration of the competition and up to 12 months after it ends for audit and prize verification purposes.
- Usage/log data: Retained for up to 90 days.
6. Your Rights Under UK GDPR
As a UK resident you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Ask us to correct inaccurate or incomplete data.
- Right to erasure: Ask us to delete your data ("right to be forgotten"). You can also delete your account directly from your Profile page.
- Right to restriction: Ask us to restrict processing of your data in certain circumstances.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).
8. Security
We implement appropriate technical and organisational measures to protect your personal data, including HTTPS encryption in transit, hashed passwords (bcrypt), HTTP security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy), rate limiting on sensitive endpoints, and server-side validation of all user inputs. Payment data is handled exclusively by Stripe and never stored on our servers.
9. Children
This service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us at [email protected] and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes will be communicated via a notice on the homepage. Continued use of the service after changes constitutes acceptance of the updated policy.
Questions about your data?
We're happy to help. Email us and we'll respond within 30 days.
[email protected]