What We Collect
- Account info: name, email, hashed password, role (buyer/capper).
- Capper profile: bio, sports, subscription price (visible to other users).
- Purchase data: handled by Stripe — they store the card details, not us. We only store the transaction record (amount, pick, date).
- Usage data: picks you've unlocked, subscriptions, gift sender/recipient pairs, affiliate clicks.
- Email engagement: Resend (our email provider) processes the digest emails we send you.
What We Do With It
- Run the marketplace — show you picks, process purchases, deliver unlocks.
- Send the Sharp of the Day digest to subscribed users (unsubscribe anytime).
- Track affiliate clicks so we know which sportsbook partnerships drive traffic (aggregate, not per-user reporting to affiliates).
- Improve the product based on aggregate behavior (e.g., which sports filters are popular).
What We DON'T Do
- We do not sell your data to advertisers.
- We do not share your email with cappers or other users.
- We do not see or store your credit card — Stripe handles that.
- We do not share your data with sportsbooks. When you click a "Tail this pick" affiliate link, only the affiliate's own tracking applies (subject to their privacy policy).
Third Parties We Use
- Stripe — payment processing. stripe.com/privacy
- Resend — transactional email. resend.com/privacy
- MongoDB — encrypted database hosting for our records.
- PrizePicks / Betr / Novig — third-party sportsbooks linked via affiliate buttons. They are separate businesses with their own terms and privacy policies.
Cookies & Local Storage
We use browser localStorage to store your login token (so you stay signed in) and basic UI preferences. We do not use third-party tracking cookies. Stripe and our affiliate partners may set their own cookies when you visit their sites.
Your Rights
- Access: request a copy of your data anytime.
- Deletion: request account + data deletion — we'll remove your personal data within 30 days (transaction records may be retained for tax/legal compliance, but anonymized).
- Email opt-out: every digest email includes an unsubscribe link. One click → done.
- CCPA / GDPR: if you're in California or the EU, you have additional rights to your data — email us and we'll handle within the legal timeframe.
Security
Passwords are hashed with bcrypt (industry standard). Connections are HTTPS-encrypted. Stripe handles payment data per PCI-DSS Level 1 standards. We don't store card numbers on our servers. No security system is 100% bulletproof — if there's a breach we'll notify affected users.
Children
PrimeStatLab is for users 21+ only. We do not knowingly collect data from anyone under 21.
Changes
We may update this policy. Material changes will be announced via email + a notice on the site.
This policy applies to the PrimeStatLab marketplace specifically and supplements any general privacy policy on primestatlab.com.