Effective: 2026-05-21
Who we are
The ZINGO World Cup Predictor (the "Service") is operated by ZINGO ("we", "us", "our"), reachable at info@zingo.buzz. We are the data controller for personal data processed through this Service.
What we collect
When you create an account or use the Service, we may collect:
- Account data — your email address, display name, and (optionally) your Instagram handle.
- Authentication data — encrypted password (we never see plaintext), session tokens.
- Predictions & gameplay — your match score predictions, ZINGO Zone player picks, league memberships, team names within leagues, timestamps.
- Technical data — minimal IP address and user-agent information collected by our hosting providers (Netlify, Supabase) for security and abuse prevention.
We do not use advertising cookies, behavioural tracking, or third-party analytics that build profiles.
Why we use it
- To operate the Service — store and display your predictions, leaderboards, leagues.
- To authenticate you and keep your account secure.
- To send transactional emails: signup confirmation, password recovery, and match-reminder emails sent roughly 2 hours before a match kicks off if you haven't predicted it yet. You can turn off reminder emails any time from your profile page.
- To debug, investigate abuse, and improve the Service.
Legal basis (UK / EU users)
We process your data under the following GDPR / UK GDPR legal bases:
- Contract — to provide you the Service you signed up for.
- Legitimate interest — to keep the Service secure, prevent fraud, and improve features.
- Consent — where required (e.g. optional Instagram handle, opt-in emails).
Who we share it with
We use a small set of trusted infrastructure providers:
- Supabase (database + authentication) — hosted in the EU (Ireland, eu-west-1).
- Netlify (static hosting + CDN).
- Resend (transactional email delivery — receives your email address and the email content to send signup/password/reminder messages on our behalf). US-based.
- flagcdn.com (country flag images served to your browser).
We do not sell your data. We will only disclose data if legally compelled.
International transfers
Data may be processed outside your country — Netlify's CDN serves traffic globally, and Resend processes email sending in the United States. Where applicable, transfers are made under standard contractual clauses or equivalent safeguards.
Retention
Account and prediction data is retained for as long as your account is active and for a reasonable period afterwards for record-keeping. You can request deletion at any time (see "Your rights" below).
Your rights
Under UK GDPR / EU GDPR (and similar US state laws where applicable) you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Request deletion ("right to be forgotten").
- Receive a copy of your data in a portable format.
- Object to, or restrict, certain processing.
- Lodge a complaint with your national data protection authority (e.g. ICO in the UK, DPC in Ireland).
To exercise any of these, email info@zingo.buzz. We will respond within 30 days.
Cookies
We only set cookies and local-storage entries strictly necessary for the Service — primarily your authentication session. We do not use advertising or third-party tracking cookies.
Children
The Service is intended for users aged 13 and over. If you are under 13 (or under 16 in some EU jurisdictions), please do not create an account.
Changes to this policy
We may update this policy. Material changes will be highlighted on this page with an updated effective date.
Contact
Questions about this policy or your data? Email info@zingo.buzz.
