Privacy policy
Last updated 26 August 2026
This notice explains what EdgeLab21 collects, why it is used, who receives it, how long it is retained and the choices available to you.
1. Controller and contact
EdgeLab21 controls the personal data described in this notice. Signed-in users can submit privacy requests and questions through the authenticated contact form. Replies are sent to the verified Google account email used to sign in. If a data-protection representative or officer is appointed, this notice will be updated.
2. Data we obtain from you and your use
We process account name and sign-in identifier; Google identity identifiers; consent records; membership and support information, including the verified account email and message you submit; saved game rules, count and bankroll settings; user-entered roulette observations; referral codes and attribution; affiliate status, account-holder name, verified payout email, preferred payout currency, commission and payout records; administrative actions; and technical security records such as session tokens stored as one-way hashes, webhook receipts, request timing, errors and audit events. If you accept measurement, we also process pseudonymous information about visited pages, approximate location, device and browser type, traffic source, interactions such as scrolls and outbound clicks, OpenAI ad-click attribution, checkout starts and confirmed subscription events. We do not ask you to provide casino account credentials, wagering histories or special-category data.
3. Data from Google, OpenAI and Stripe
Google supplies the verified email, name and stable account identifier needed for sign-in. If you separately accept measurement, Google Analytics processes website usage information for the EdgeLab21 property and the OpenAI Ads Measurement Pixel processes ad-attribution and conversion events for the EdgeLab21 pixel. Google Analytics is not supplied with your EdgeLab21 account email or name. OpenAI conversion events contain the selected membership plan and a deduplication identifier, not payment-card or game data, and opt out of future user-level personalisation. If automatic advanced matching is enabled, supported identifiers are normalised and hashed in the browser before transmission; raw identifiers are not sent through that feature. Stripe supplies customer, checkout, subscription, invoice, refund, dispute, connected-account and transfer identifiers and statuses. EdgeLab21 does not receive or store complete payment-card numbers or card security codes. Referral bank details are collected directly by Wise through its secure email payment link. EdgeLab21 stores payout preferences and transfer reconciliation records.
4. Purposes and legal bases
We use identity, settings and membership data to perform our contract and provide the service; payment, tax and accounting data to perform the contract and comply with legal obligations; security, fraud, abuse and reliability data for our legitimate interests in protecting users and the service; referral and payout data to perform programme terms and meet tax, sanctions and verification obligations; and Google Analytics and OpenAI Ads measurement only with your consent to measure traffic, attribute conversions, understand content usage and improve usability. We do not sell personal data or use optional measurement data for third-party behavioural advertising.
5. Required data
A verified email, authentication identifier, membership record and required billing data are necessary to create and supply a paid account. If you do not provide them, we cannot provide membership. Optional game settings and observations can be omitted or cleared without closing the account.
6. Recipients and processors
Personal data is disclosed only as needed to Google for authentication and, with measurement consent, website measurement; OpenAI for consent-based advertising attribution and conversion measurement; Stripe for membership payments; Wise for referral batch payments, including the recipient name, verified email, chosen currency and payment amount; Hostinger for application and database hosting; professional advisers; and authorities where legally required. Service providers act under contractual and security obligations. Affiliate referrers receive aggregate attribution and commission information, not the referred member’s payment credentials.
7. International transfers
Our service providers may process data in the United Kingdom, the EEA, the United States or other service locations. Where required, transfers rely on an applicable adequacy decision, contractual safeguards such as standard contractual clauses, or another lawful transfer mechanism. You may request information about applicable safeguards through the contact form.
8. Retention
OAuth transaction data expires after about 20 minutes and authentication sessions after 30 days unless ended sooner. Account settings and user-entered observations are kept while the account remains active or until cleared. Google Analytics cookies are configured for no more than 395 days; Google Analytics event-level retention is controlled within the EdgeLab21 property. The OpenAI attribution cookie and optional measurement data are retained according to the applicable OpenAI Ads controls and can be removed sooner through Cookie settings. Support, security and failed-event records are retained only as long as reasonably necessary for investigation and reliability. Subscription, invoice, consent, referral, commission, payout, tax and audit records may be retained for up to 10 years where required for accounting, disputes, fraud prevention or legal claims. Data is deleted or anonymised when no longer needed.
9. Cookies and local storage
We use secure, HTTP-only cookies for authentication and OAuth security. Browser-language and measurement-consent preferences can be stored locally on your device. Google Analytics _ga cookies and the OpenAI Ads __oppref attribution cookie are optional and their scripts load only after you accept measurement. You can refuse or withdraw consent without losing access to EdgeLab21. Details are in the Cookie and storage notice.
10. Automated processing
Strategy, risk and roulette outputs are generated automatically from settings and observations, but they do not make legal or similarly significant decisions about you. Automated security and fraud signals may temporarily restrict an action; material account decisions are subject to human review on request.
11. Security
Measures include encrypted HTTPS transport, secure and HTTP-only session cookies, one-way token hashing, server-side access checks, least-privilege credentials, signed webhooks, payment idempotency, database constraints, immutable financial records and administrative audit logs. No internet service can promise absolute security. Please report suspected misuse promptly.
12. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability and may withdraw consent where processing relies on consent. Rights can be limited by identity verification, other people’s rights and mandatory record-retention duties. Submit requests through the contact form. We will respond within the period required by applicable law.
13. Complaints
Please contact us first. Where UK or EEA data-protection law applies, you may also complain to the ICO or the supervisory authority where you live, work or believe an infringement occurred. Other jurisdictions may provide a local supervisory authority.
14. Children
The service is for adults and is not directed to children. We do not knowingly create accounts for anyone under 18. Contact us if you believe a minor has provided personal data.
15. Changes
We will update this notice when data use, providers or legal requirements materially change and will notify registered users when appropriate. Version: 2026-08-26.