Privacy Policy
Last updated August 5, 2026
InPlayGuru is operated by Super Números - Estatística na Nuvem, Lda, a company registered in Portugal ("InPlayGuru", "we", "us"). We are the data controller for the personal data described below. This policy covers the website https://inplayguru.com, our Telegram bots and channels, and everything else we run under the InPlayGuru name (together, the "Service").
If anything here is unclear, or you want to exercise any of your rights, write to support@inplayguru.com.
The short version
- We collect only what the Service needs to run: your account details, your Telegram identifiers if you connect them, your subscription status, and security logs.
- Payments are handled by Paddle. Card numbers never reach our servers.
- No advertising networks, no tracking pixels, no third-party audience analytics: usage stats run cookie-free on our own servers. We never sell personal data.
- Marketing email is strictly opt-in, and every message contains an unsubscribe link.
- You can download a copy of your data, or permanently delete your account, at any time from your Account page.
1. The data we collect
Account data
When you register we store your name, email address and password. The password is kept only as a one-way hash: we could not read it even if we wanted to. Your browser also tells us your timezone and preferred language during sign-up, so match times and text display correctly. Your marketing email choice (an unchecked box at sign-up) is stored with its date and source.
Telegram data, only if you connect it
Linking Telegram stores your chat id, Telegram user id, and, for group chats, the chat title and type. When alerts are sent, we keep a per-message delivery record (which pick, which chat, delivered or failed, and when) so we can show you your delivery history and debug problems. If you configure a custom bot, its token is stored encrypted.
Chats with our bots before you have an account
If you message one of our Telegram bots without being registered, we store what Telegram hands us: your
Telegram id, username, first name and language, plus which campaign brought you and how the conversation went.
We use it to send a short series of getting-started messages. Send /stop at any time to end them.
If you never create an account, this data is deleted at most 24 months after your last interaction.
Payments
Checkout and billing run entirely on Paddle, our merchant of record. Your card or bank details go directly to Paddle and never touch our servers. From Paddle we receive and keep your subscription plan and status, order ids, amounts, taxes and receipt links.
Support conversations
When you contact support we keep the conversation, including whatever details you chose to include, so we have context if you write again.
Security and technical data
Each registration and sign-in records your IP address and browser identifier. We use these to protect accounts and to stop free-trial abuse, and delete them after 24 months. Our servers also keep routine technical logs (requests, errors) for up to 90 days. If you arrived through a campaign link or a referral, we store that code with your account so we know which of our efforts work.
Usage analytics, without identifying you
We measure how the Service is used with Umami, an analytics tool that runs entirely on our own servers. It records page visits, interactions with product features (for example, starting checkout or saving a scanner layout), page performance timings, and technical context: browser and device type, country, referrer, and the campaign that brought you. Our servers add similar events for service milestones that happen off the page, such as an onboarding message being sent. For signed-in members, sessions carry broad account attributes (such as whether the plan is paid) so we can compare how groups of plans use the Service.
What analytics never receives: your name, email or anything you type, the content of your notes or strategies, Telegram identifiers, or any persistent identifier for you. It sets no cookies, stores nothing in your browser, and identifying parts of page addresses are stripped before recording. There are no session recordings and no heatmaps, and none of this data leaves our infrastructure.
Integrations you set up
If you use developer features we store what you configure: your webhook URL and your API key.
What we never collect
- No precise location, no contact lists, no access to your device beyond the pages you open.
- No card or bank numbers (Paddle holds those).
- No social media logins and no data bought from data brokers.
2. How we use it
Every purpose ties to one of the legal bases the GDPR defines:
| What we do | Legal basis |
|---|---|
| Run your account and deliver picks and alerts on the site, Telegram, email and any webhooks you configure | Contract |
| Charge subscriptions, handle refunds, keep billing records | Contract, then legal obligation for the records |
| Answer support requests | Contract |
| Send service messages: verification, expiry notices, changes to terms | Contract and legitimate interest |
| Send marketing email | Consent, withdrawable at any time |
| Send occasional product news and offers to your linked Telegram | Legitimate interest; opt out by sending /stop or unlinking Telegram |
| Help you get started when you message our bot before registering | Legitimate interest; /stop ends it |
| Keep the Service secure and prevent free-trial abuse | Legitimate interest |
| Measure which campaigns and referrals bring users | Legitimate interest |
| Understand how the Service is used and how it performs, through cookie-free analytics on our own servers | Legitimate interest |
| Comply with the law when it applies to us | Legal obligation |
3. Automated checks
One automated decision is worth naming: free trials are limited to one per person, and automated checks (for example, several accounts arriving from the same connection) can restrict a trial. These checks never affect paid access and carry no legal effects. If one gets it wrong, email us and a human will review it.
4. Who receives your data
We never sell personal data and we show no third-party advertising. Data reaches only the service providers below, each bound by a contract that limits them to working for us:
| Provider | What they do | What they receive |
|---|---|---|
| Paddle | Merchant of record: runs checkout, charges you, issues invoices | The payment details you enter at checkout, your email, your subscription history |
| ProfitWell / Paddle Retain | Subscription analytics and recovery of failed payments | Your email address and subscription status |
| Amazon Web Services | Sends our email and stores our backups (EU region) | Recipient addresses and message content; backup archives |
| Migadu | Hosts our support mailbox | Email you send to our support address |
| Freshworks (Freshdesk) | Runs our help desk | Your name, email and whatever your ticket contains |
| Telegram | Delivers bot and channel messages | Your chat id and the content of your alerts |
| OVH | Hosts our servers in the European Union | Service data lives on their machines |
| Cloudflare | Shields the site and speeds up delivery | Your IP address and connection metadata, in transit |
A few pages load small images (for example weather icons) directly from their providers, and some images inside marketing emails are hosted by the tools that build them. In both cases the host sees the standard request data any image load reveals (IP address, browser) and nothing more.
Our sports data suppliers send match data to us; nothing about you flows back to them. Usage statistics never leave our infrastructure either: our analytics (Umami) are self-hosted on our own servers.
Beyond that, we disclose personal data only if the law requires it (a court order, for example), or as part of a sale or restructuring of the business, in which case this policy continues to apply to it.
5. International transfers
Our servers run in the European Union. Some of the providers above process data in other countries; where that happens outside the EEA, the transfer rests on safeguards the GDPR recognizes, such as adequacy decisions (including the EU-US Data Privacy Framework) and Standard Contractual Clauses.
6. How long we keep data
| Data | Kept for |
|---|---|
| Your account, strategies, settings and Telegram links | Until you delete your account, or earlier for long-inactive accounts (see below) |
| Alert delivery records | While your account exists |
| Sign-in security logs (IP address, browser) | 24 months |
| Server and error logs | Up to 90 days on live systems, then only inside backup archives that expire on a rolling schedule |
| Billing and tax records | Up to 10 years, as Portuguese tax law requires |
| Bot chats that never became an account | At most 24 months after the last interaction |
| Support tickets | Kept in our help desk for context; deleted on request |
Inactive accounts are cleaned up as well: if your account has no active subscription and stays unused for an extended period, we may disable and eventually delete its content (strategies, settings, alert history) or the account itself, following the inactivity rules in our Terms of Use.
Deleting your account removes the record itself immediately, along with your strategies, settings, Telegram identifiers, delivery logs, events, API keys and sign-in history. It is not a deactivation, and it cannot be undone. Two things outlive it: billing records we are legally required to keep, and log lines and backups that age out on the schedules above.
7. Your rights, and where the tools live
- Access and portability: your Account page has an Export Personal Data button that downloads everything we hold on you as machine-readable JSON, including your profile, settings, strategies, billing history, sign-in history and Telegram delivery history.
- Rectification: edit your details on the Account page, or ask us to correct anything.
- Erasure: the Account page has a Delete Account section. It works immediately and permanently. You can also just ask us.
- Restriction and objection: email us and we will stop the processing you object to, unless a legal obligation stands in the way.
- Withdrawing consent: every marketing email carries an unsubscribe link that is
honored automatically; the same switch lives on your Account page. For Telegram, send
/stopto a bot or unlink Telegram in your settings.
We answer rights requests within one month. If you are not happy with our answer, you can complain to the Portuguese supervisory authority, the CNPD (cnpd.pt), or to your local EEA data protection authority.
8. Cookies
We set only the cookies the Service cannot work without: your sign-in session, a security token for forms, and your preferences. No advertising cookies and no third-party audience tracking, which is why you see no cookie banner here. The full inventory, including the few partner cookies that can appear when you open checkout or the support widget, is in our Cookie Policy.
9. Age requirement
The Service is intended for adults. You must be at least 18 to register, as our Terms of Use also state. We do not knowingly hold data on anyone younger; if you believe we do, tell us and we will delete the account.
10. How we protect data
All traffic runs over TLS. Passwords are stored as one-way hashes. Particularly sensitive values, such as custom bot tokens, are encrypted at rest. Access to production data is limited to the people who operate the Service. If a breach ever puts your rights at risk, we will notify you and the supervisory authority within the deadlines the GDPR sets.
11. Do Not Track signals
We do not build browsing profiles, so there is nothing for Do Not Track or Global Privacy Control signals to switch off. Every visitor gets that treatment by default.
12. Changes to this policy
When this policy changes, the date at the top changes with it. If a change is material, we will announce it by email or with a notice on the site before it takes effect.
13. Contact
Super Números - Estatística na Nuvem, Lda, trading as InPlayGuru.
Email: support@inplayguru.com