Privacy notice

Last updated 2026-10-01. Two kinds of person's data passes through here: the operator who pays us, and the entrant who never will. This notice covers both, because an entrant deserves to know what a raffle tool kept about them.

What we collect

From a Telegram sign-in we get your Telegram id, first and last name, your username if you have one, and the time the login was signed. That is the whole identity: there is no email field, no password and no profile to fill in, because the product does not need them.

For entrants, we store the Telegram id, the entry, the ticket number, the per-entry random contribution used by the draw, the reference code, and whatever the operator's payment review kept: a reference string and a screenshot.

For payment profiles, we store the handles and addresses you enter — Venmo username, cashtag, PayPal handle, Zelle email or phone, crypto receiving address. These are shown to entrants for the express purpose of paying you, and nothing else.

For billing, Stripe stores your card. We store a customer id, a subscription id, invoice numbers and amounts. We never see or store card numbers.

What we do not collect

  • Your entrants' payment credentials. There is no field for them.
  • Reading of your group's chat. The bot sees the messages it posts and the button presses made on them, not your group's conversation.
  • Trackers. There is no analytics script, no advertising pixel, and no third-party font or CDN: the CSS and JS on this site are served by our own container.
  • A copy of your entrants' money. We are not a payment intermediary, so there is no balance to hold and nothing to lose.

Who can see an entrant's payment

This is the question we get most, so it has its own heading. Other group members see that someone entered, and how many people have paid. They do not see who paid, how much, to which handle, with which transaction reference, or a screenshot of anything. Payment detail travels only in the private message between the entrant and the bot, and the operator's review happens there.

The dashboard repeats that rule: it lists a reference code and an amount for review, and links to the DM where the screenshot lives. It does not paste entrants' payment evidence into a web page.

What a public proof page shows

For a finished raffle, the verification page publishes the entry list in hashed form, each entry's random contribution, the seeds, the pick log and the winners. Entry identifiers are opaque uuids, not names — but winners are shown with the Telegram display name we hold for them, because announcing who won is the entire point of a prize draw and a host cannot pay an anonymous uuid.

If you were a winner and would rather be shown by id only, tell the host. We will add a per-promotion setting; until then, publishing a winner's name is the host's call and ours.

How long, and why

Payment screenshots are kept for a dispute window and then deleted; raffle banners are deleted a few days after the winner post that referenced them. The delete-by date is set on the row when the file is created rather than guessed later, because "delete everything older than a week" would have destroyed a screenshot the day a chargeback needed it, and keeping it a day longer than necessary would have been a different kind of failure. Licence, entry and audit rows are kept while the account exists: they are the record that a draw was honest, and deleting them would destroy the thing the product is for.

For operators, processing is necessary to perform the contract you bought. For entrants, the host is the controller and we are their processor: an entrant's request about their data should go to the host who ran the raffle, and we will help them answer it. We disclose data to Stripe (billing), to Telegram (the bot platform) and to our hosting provider. We do not sell data and we do not ad-match anything to anyone.

Your entrants' data sits in the same Postgres container as everything else, in the region you deployed it to. If you self-host, that statement becomes literal and you are also the one holding the keys.

Cookies

One functional cookie: a signed session, containing your Telegram id, an optional tenant id, whether you are platform staff, and a CSRF token. It is HttpOnly, SameSite=Lax, Secure where HTTPS is configured, and it expires after twelve hours. There is a second short-lived cookie for the login form's CSRF token and a third for a one-message notice. No advertising, analytics or preference cookies exist on this site.

Your rights, and the practical version

Access, correction, deletion and portability apply to both kinds of person. Practically: an operator can export any raffle's entries as CSV and delete their account; an entrant can ask a host to remove them, and voiding an entry keeps the seat's history because a deleted entry in a finished draw would mean the published proof no longer reproduces — the tension between erasure and an audit trail is real, and we resolve it in favour of the trail while marking the row voided.

Contact: the support address in your dashboard, or reply to the bot's DM.