Privacy Policy (Draft)
Status: Draft for legal review — not published
Product: SignalScore World Cup / SignalScore Pro
Effective date: May 25, 2026
Last updated: May 25, 2026
Important: This is a working draft, not legal advice. Have a qualified attorney review before launch.
1. Overview
Klondike Enterprises Group LLC ("SignalScore," "we," "us," or "our") operates SignalScore World Cup and related services (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website, use the demo dashboard, create an account, make predictions, or purchase a plan.
By using the Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Service.
2. Information We Collect
2.1 Information you provide
| Category | Examples |
|---|---|
| Account information | Name, email address, username, password (stored hashed), profile preferences, display name for leaderboards |
| Predictions and reputation | Match selections (Home Win / Draw / Away Win), timestamps, accuracy stats, streaks, tier rank |
| Communications | Support messages, feedback, waitlist sign-ups, survey responses |
| Payment-related information | Billing name, billing address, last four digits of payment card (full card data is handled by Stripe — we do not store full PAN) |
2.2 Information collected automatically
| Category | Examples |
|---|---|
| Device and usage data | IP address, browser type, operating system, pages viewed, referring URL, session duration, click paths |
| Local storage (demo/current) | Predictions may be stored in your browser via localStorage before cloud account sync is available |
| Log and security data | Server logs, error reports, authentication events, abuse prevention signals |
2.3 Information from third parties
| Source | Examples |
|---|---|
| Stripe (payment processing) | Transaction status, subscription ID, customer ID, invoice metadata, payment method type |
| Analytics providers | Aggregated usage metrics (if enabled) |
| Email provider | Delivery status, bounces, and engagement events for transactional email |
We do not sell your personal information for money.
3. Account Information
When account registration is available, we use account information to:
- ▸Authenticate you and secure your session
- ▸Display your predictor profile, reputation, and leaderboard position
- ▸Associate predictions and subscription status with your account
- ▸Communicate account-related notices
Public vs. private data: Leaderboard display names and prediction stats may be visible to other users. Your legal name and email address are not displayed publicly unless you choose to share them.
Demo note: In the current prototype, some prediction data may exist only in browser local storage and is not synced to our servers until accounts and backend persistence launch.
Account deletion: You may request account deletion when available. Deletion is subject to legal, tax, and billing record retention requirements described in Section 8.
4. Payment Processing via Stripe
Paid plans — WORLD CUP PASS ($19.95 one-time) and SIGNALSCORE PRO ($24.95/month) — are processed by Stripe, Inc., our third-party payment processor.
When you purchase a plan:
- ▸Payment card data is entered on Stripe's hosted checkout or PCI-compliant payment fields
- ▸Stripe processes the transaction and notifies us of payment status
- ▸We receive subscription status, Stripe customer ID, transaction metadata, and limited billing details — not full card numbers
Stripe's handling of payment data is governed by Stripe's Privacy Policy. We encourage you to review it.
We use payment information to:
- ▸Fulfill your purchase and grant plan access
- ▸Manage subscription renewals, cancellations, and refunds
- ▸Prevent fraud and resolve billing disputes
- ▸Meet tax and accounting obligations
5. Analytics and Cookies
Cookies and similar technologies
We may use cookies, local storage, and similar technologies to operate and improve the Service:
| Type | Purpose |
|---|---|
| Essential | Authentication, session management, security, checkout completion |
| Functional | User preferences (e.g., onboarding state, UI settings) |
| Analytics | Aggregated usage measurement (e.g., page views, feature adoption) |
You can control cookies through your browser settings. Disabling essential cookies may limit core functionality, including login and checkout.
Analytics
If analytics are enabled in production, we may use a provider such as Vercel Analytics, Plausible, or Google Analytics (vendor TBD at launch). Analytics data is generally aggregated and not intended to personally identify you unless combined with account data.
Demo note: The current prototype may use minimal or no third-party analytics. This policy describes planned production behavior.
We do not use your prediction history to place bets or wagers on your behalf.
6. Communications and Emails
We may contact you by email or in-app notice for:
| Type | Examples |
|---|---|
| Transactional | Account verification, password reset, purchase receipts, subscription renewals, cancellation confirmations |
| Service | Material changes to Terms or Privacy Policy, security alerts, feature availability |
| Marketing | Product updates, launch announcements, promotional offers — only with your consent |
Opt-out: Marketing emails include an unsubscribe link. You may opt out of marketing at any time. Transactional emails related to an active account or subscription may still be sent as necessary to provide the Service.
7. How We Use Information
We use collected information to:
- ▸Provide and improve the Service (signals, predictions, leaderboards, reputation)
- ▸Process WORLD CUP PASS and SIGNALSCORE PRO purchases
- ▸Authenticate accounts and prevent fraud, abuse, and policy violations
- ▸Send transactional and (with consent) marketing communications
- ▸Analyze product usage, diagnose bugs, and improve performance
- ▸Comply with legal obligations and enforce our Terms of Service
8. Data Storage and Security
Storage and retention
| Data type | Retention approach |
|---|---|
| Account data | Retained while your account is active; deleted or anonymized upon verified deletion request, subject to legal holds |
| Billing records | Retained per tax and accounting requirements (typically up to 7 years — confirm with your CPA) |
| Server logs | Typically 30–90 days unless needed for security investigations |
| Local demo data | Remains on your device until you clear browser storage |
Data may be stored and processed in the United States or other countries where our service providers operate.
Security measures
We use reasonable administrative, technical, and organizational safeguards, including:
- ▸HTTPS encryption in transit
- ▸Hashed password storage (when accounts launch)
- ▸Access controls and least-privilege practices
- ▸Vendor security review for payment and hosting providers
No method of transmission or storage is 100% secure. Report security concerns to klondikesteve@gmail.com.
9. Sharing and Disclosure
We may share information with service providers who process data on our behalf:
| Vendor type | Purpose |
|---|---|
| Stripe | Payment processing and subscription management |
| Hosting (e.g., Vercel) | Application hosting and delivery |
| Email (e.g., Resend, Postmark, SendGrid) | Transactional and marketing email delivery |
| Analytics (if enabled) | Aggregated usage measurement |
We require vendors to process data only for contracted purposes and in accordance with applicable privacy laws.
We may also disclose information when required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale with appropriate notice where required.
10. User Rights
Depending on your location, you may have rights to:
- ▸Access the personal information we hold about you
- ▸Correct inaccurate information
- ▸Delete your account and associated data (subject to legal retention)
- ▸Export your data in a portable format
- ▸Object to or restrict certain processing activities
- ▸Withdraw consent for marketing communications
To submit a privacy request, contact klondikesteve@gmail.com. We will verify your identity before fulfilling requests.
California residents (CCPA/CPRA): Additional rights may apply, including the right to know, delete, and opt out of certain sharing. We do not sell personal information for money.
EU/UK residents (GDPR): Additional rights may apply once we finalize our GDPR posture, including data portability and the right to lodge a complaint with a supervisory authority.
11. Children
The Service is not directed to children under 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact klondikesteve@gmail.com and we will take appropriate steps to delete it.
12. International Users
If you access the Service from outside the United States, your information may be transferred to and processed in the US or other countries where our providers operate. By using the Service, you consent to such transfers where permitted by law.
13. Policy Updates
We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect the most recent revision. Material changes may be communicated by email or a prominent notice on the Service.
Continued use after an update becomes effective constitutes acknowledgment of the revised policy.
14. Contact
Klondike Enterprises Group LLC
Privacy requests: klondikesteve@gmail.com
Support: klondikesteve@gmail.com
Security: klondikesteve@gmail.com
Pre-launch checklist
- ▸ Confirm analytics vendor and update cookie section
- ▸ Attorney review (CCPA / GDPR if applicable)
- ▸ Link from site footer alongside Terms of Service and Refund Policy
- ▸ Document Stripe DPA and subprocessor list