Privacy Policy

Last updated: 15 April 2025

This Privacy Policy explains how Optana Limited (trading as RaffleHub), company number 16358985, (“RaffleHub”, “we”, “us”, or “our”) collects, uses, and protects personal data in connection with the RaffleHub platform and website at www.rafflehub.io & www.myrafflehub.co.uk.

We are the data controller for personal data collected through the RaffleHub platform. For questions about this policy, contact us at info@rafflehub.io.

1. Who this policy covers

This policy applies to:

  • Platform customers - businesses and individuals who sign up to use RaffleHub to operate their own competition websites (“tenants”).
  • Marketing site visitors - anyone who visits myrafflehub.co.uk.

This policy does not cover the personal data of end users (competition entrants) on tenant-operated competition websites. Each tenant is the data controller for their own customers’ data. If you are a competition entrant, please refer to the privacy policy of the competition operator whose site you entered on.

2. Data we collect

When you sign up to RaffleHub

  • Name and email address of the account holder
  • Company name
  • Account credentials (passwords are hashed and never stored in plain text)

When you subscribe (billing)

  • Billing address (collected by Stripe during checkout)
  • Payment method details (processed and stored by Stripe - we do not store card numbers)
  • Subscription and invoice history

Usage and technical data

  • Log data including IP address, browser type, pages visited, and timestamps
  • Platform usage data (competitions created, orders processed) used for billing and service improvement
  • Cookies - see Section 7

Communications

  • Emails and messages you send us (support, enquiries)

3. How we use your data

  • Providing the service - to operate your account, provision your tenant platform, and process your subscription billing
  • Billing - to calculate and collect the platform subscription fee and metered usage charges via Stripe
  • Communications - to send essential service notifications, billing alerts, and responses to your enquiries
  • Security - to detect and prevent abuse, fraud, and unauthorised access
  • Legal obligations - to comply with applicable law and respond to lawful requests
  • Service improvement - to understand how the platform is used and fix issues

We do not sell your personal data to third parties. We do not use your data for automated decision-making that produces legal effects.

4. Legal basis for processing (UK GDPR)

  • Contract - processing necessary to deliver the RaffleHub service you have subscribed to
  • Legitimate interests - security monitoring, fraud prevention, and service improvement
  • Legal obligation - where required by law
  • Consent - for optional marketing communications, if you have opted in

5. Third-party services

We share data with the following third parties only to the extent necessary to operate the platform:

  • Stripe - payment processing and subscription billing. Stripe is the data processor for all payment data. See Stripe’s Privacy Policy.
  • Supabase - database and authentication infrastructure. Data is stored within the EU.
  • Vercel - hosting and edge delivery. See Vercel’s Privacy Policy.

We do not transfer your personal data outside the UK or EEA without appropriate safeguards.

6. Data retention

  • Account data is retained for the duration of your subscription and for up to 7 years after account closure, to satisfy legal and financial record-keeping requirements.
  • Billing records are retained for 7 years to comply with HMRC requirements.
  • Support communications are retained for 2 years.
  • You may request earlier deletion subject to our legal obligations - see Section 8.

7. Cookies

The RaffleHub marketing site uses only essential cookies required for navigation and session management. We do not use advertising or tracking cookies on the marketing site.

The tenant admin portal uses session cookies for authentication. These are essential and cannot be disabled.

8. Your rights

Under UK GDPR you have the right to:

  • Access - request a copy of the personal data we hold about you
  • Rectification - request correction of inaccurate or incomplete data
  • Erasure - request deletion of your data, subject to our legal obligations
  • Restriction - request that we restrict processing of your data in certain circumstances
  • Portability - receive your data in a structured, machine-readable format
  • Objection - object to processing based on legitimate interests
  • Withdraw consent - where processing is based on consent, withdraw it at any time

To exercise any of these rights, email info@rafflehub.io. We will respond within one calendar month.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

9. Security

We implement appropriate technical and organisational measures to protect your personal data, including encrypted data storage, access controls, and server-side authentication enforcement. No payment card data touches our servers - all payment processing is handled by Stripe.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified to active customers by email. Continued use of the platform after the effective date of an updated policy constitutes acceptance of the changes.

11. Contact

For privacy-related enquiries: info@rafflehub.io
For general enquiries: info@rafflehub.io
Optana Limited, registered in England and Wales, company number 16358985.