Privacy Policy

Last Updated: 12/5/2025

Welcome to Awardable! Awardable values your privacy and the protection of your personal data. This privacy policy describes what information we collect from you, how we collect it, how we use it, how we obtain your consent, how long we keep it in our databases and, if necessary, with whom we share it.

By using the platform and services, you are accepting the practices described in this privacy policy. Your use of the platform is also subject to our terms and conditions.

GENERAL INFORMATION

The personal data of users that are collected and processed through:

Will be under the responsibility and in charge of:

HOW WE OBTAIN YOUR CONSENT

When you use the platform, register as a user, create a profile, purchase a subscription, use the functionalities available on the platform, create an award, accept an award, create a group, join a group, create a tournament, join a tournament, contact us through our contact information and provide us with personal information to communicate with you, you consent to our collection, storage and use of your information under the terms set out in this privacy policy.

TYPES OF INFORMATION COLLECTED

The information we collect from our users helps us to continually improve the user experience on the platform. These are the types of information we collect:

Information You Provide to Us

You provide information when you use the platform, register as a user, create a profile, purchase a subscription, use the functionalities available on the platform, create an award, accept an award, create a group, join a group, create a tournament, join a tournament, contact us through our contact details. You may provide us with the following information:

  • First and last name
  • Organization/Team name
  • Date of birth
  • Profile photo
  • Email
  • Phone

Information Collected Automatically

As you browse our website, certain usage data is automatically collected. These include technical information such as the IP address of your device, the type and version of your browser, the specific pages you visit on our website, the date and time of your access, the amount of time you spend on those pages, and other diagnostically relevant data.

In the case of access via mobile devices, we also collect information specific to these devices. This may include the type of mobile device used, its unique identifier, the IP address of the device, the mobile operating system and the type of mobile browser, along with other identifiers and diagnostic data.

Authentication Services (Clerk)

We use Clerk, a third-party authentication service, to manage user accounts and authentication. Clerk may collect and process the following information:

  • Email address and password (encrypted)
  • Name and profile information
  • OAuth provider data (if you sign in with Google or other providers)
  • Session tokens and authentication cookies
  • Device and browser information
  • IP addresses and login timestamps

When registering or logging in to our platform via Google or other OAuth providers, users allow us to access their basic profile information, such as name, email and profile picture. This process is governed by both Clerk's and the OAuth provider's privacy policies. We do not collect or store passwords for OAuth accounts. By using these login methods, users consent to the sharing of this information between our platform, Clerk, and external authentication services.

Clerk's privacy policy can be found at: https://clerk.com/legal/privacy

User Content

Awardable collects and processes user content, which includes data and information entered on our platform, solely for the provision and improvement of our services. We are committed to maintaining the confidentiality and security of this content, and will not share it with third parties except as required by law or for the operation of the service.

Payment Information

Your credit card or payment card details will be processed by the payment processors available on the platform, who will process and store your data securely and for the sole purpose of processing subscription payments. Awardable reserves the right to engage any available payment processor.

Contact Information

We may access some personal information about the user, such as name and email address, when the user or any third party communicates with us through our contact information. Personal information provided through our contact information is not stored on any Awardable server and will be stored on the respective server of our email service.

HOW LONG WE KEEP YOUR DATA

Personal data provided by users through the platform will be retained for the time necessary to provide the functionalities available on the platform, fulfill the legitimate purposes described in this policy or until the user closes the user account or requests the deletion of their data. Awardable may retain personal data for a longer period provided that the user has consented to such processing. Once the retention period has expired, the personal data will be deleted.

HOW WE USE YOUR INFORMATION

In general, we use the information we collect primarily to provide, maintain, protect and improve our platform. We use personal information as described below:

  • Facilitate registration for our users
  • Facilitate the creation of awards
  • Facilitate the creation of groups
  • Facilitate the creation of tournaments
  • Facilitate the inclusion of sponsors in awards and profile
  • Facilitate acceptance of user-created awards
  • Provide our subscriptions
  • Process subscription payments
  • Provide the functionalities available on the platform
  • Understand and improve your experience using our platform
  • Respond to your comments or questions through our support team
  • Send you related information, including confirmations, invoices, technical notices, updates, security alerts, and support and administrative messages
  • Send you notifications and relevant information about Awardable
  • Awardable marketing purposes
  • Process user requests related to the exercise of their rights over their personal data
  • Link or combine your information with other data we obtain from third parties to help us understand your needs and provide you with better service
  • Protect, investigate and deter fraudulent, unauthorized or illegal activities

HOW WE SHARE INFORMATION

Information about our users is an important part of our business, and we are not in the business of selling it to third parties. We share customer information only as described below:

Third-Party Suppliers

We use third party services to perform certain functions on our platform. Some of these functions and services include: website creation and hosting, payment processing, registration and login, sending emails, and tracking and analyzing data on the platform. These third-party services may have access to personal information needed to perform their functions, but may not use that information for other purposes.

Email Communications

By providing us with your email address, you consent and agree that we may send relevant content, notifications and information to your email address. If you wish to stop receiving communications from Awardable, you may unsubscribe at any time by using the "unsubscribe" option available in the same emails or by sending your request through our contact information.

Business Transfers

In the event Awardable creates, merges with, or is acquired by another entity, your information will likely be transferred. Awardable will send you an email or post a prominent notice on our platform before your information becomes subject to another privacy policy.

Protection of Awardable and Others

We release personal information when we believe release is appropriate to comply with the law, enforce or apply our terms and conditions and other agreements, or protect the rights, property, or safety of Awardable, our users, or others.

Anonymous Information

Awardable uses anonymous browsing information collected automatically by our servers primarily to help us administer and improve the platform. We may also use aggregated anonymous information to provide information about the platform to potential business partners and other unaffiliated entities. This information is not personally identifiable.

DATA BREACH NOTIFICATIONS

In the event of a security breach that compromises the confidentiality of the personal data of our users, Awardable undertakes to notify those affected in a timely manner. This notification will be made through the means of contact that have been provided by the user on our platform. We will take all reasonable measures to protect the information and remedy any situation that compromises the security of your data.

INTERNATIONAL DATA TRANSFER

By using our platform, you agree that your personal data may be transferred and processed outside the United States, where data protection laws may differ. Awardable is committed to taking the necessary steps to ensure that your data is treated in accordance with applicable privacy standards and is adequately protected during any international transfer.

COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar tracking technologies to track activity on our platform and store certain information. Cookies are files with a small amount of data that may include an anonymous unique identifier.

Types of Cookies We Use

  • Essential Cookies: Required for authentication and core platform functionality (Clerk session cookies)
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand how users interact with our platform

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service. For more information about cookies and how to manage them, please visit our Cookie Policy.

SESSION MANAGEMENT

When you log in to our platform, we create a secure session using Clerk's authentication system. This session is maintained through encrypted cookies and tokens. Sessions may expire after a period of inactivity for security purposes, requiring you to log in again.

We implement the following session security measures:

  • Secure, HTTP-only cookies
  • Session token encryption
  • Automatic session expiration
  • IP address validation
  • Device fingerprinting for suspicious activity detection

DATA PROCESSING AND STORAGE

Your data is processed and stored using the following infrastructure:

Supabase (Database)

We use Supabase, a PostgreSQL-based database service, to store your profile information, awards, tournament data, and other user-generated content. Supabase stores data in secure data centers and implements industry-standard encryption both in transit and at rest. Supabase's infrastructure is hosted on AWS (Amazon Web Services).

Vercel (Hosting)

Our application is hosted on Vercel's global edge network, which automatically distributes your requests to the nearest server for optimal performance. Vercel may process request metadata including IP addresses, request headers, and performance metrics.

Data Location

Your data may be processed and stored in the United States and other countries where our service providers operate. By using our Service, you consent to the transfer of your information to these countries, which may have different data protection laws than your country of residence.

PROTECTION OF YOUR INFORMATION

We grant access to your personal information only to those outside persons or services that have a legitimate need to know it and in accordance with our privacy policy. We adhere to industry-recognized security standards to protect your personal information, both during transmission and in storage.

Security Measures

  • HTTPS/TLS encryption for all data in transit
  • Encrypted storage of sensitive data at rest
  • Regular security audits and vulnerability assessments
  • Access controls and authentication via Clerk
  • Secure payment processing through PCI DSS compliant Stripe
  • Database access restrictions and role-based permissions
  • Automated backups and disaster recovery procedures
  • Monitoring for suspicious activity and unauthorized access

However, it is important to note that no method of transmission over the Internet or electronic storage is foolproof and 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

We undertake not to sell, distribute or transfer your personal data to unauthorized third parties, unless we have your explicit consent or are required by law to do so.

USER RIGHTS

Users who provide information through our platform, as data subjects, have the right to access, rectify, download or delete their information, as well as to restrict and oppose certain processing of their information. These rights are described below:

  • Access and Portability: To access and know what information is stored on our servers, you can send us your request through our contact information
  • Rectification, Restriction, Limitation and Deletion: You may also rectify, restrict, limit or delete much of your information
  • Right to be Informed: Users will be informed, upon request, about what data we collect, how it is used, how long it is kept and whether it is shared with third parties
  • Object: Where we process your data based on our legitimate interests, you may object to this processing in certain circumstances
  • Withdraw Consent: Where you have previously given your consent, you have the right to withdraw your consent to the processing and storage of your information at any time
  • Complaint: If you wish to lodge a complaint about our use of your information, you have the right to do so with your local supervisory authority
  • Rights Related to Automated Decision-Making: Users may request that we provide them with a copy of the automated processing activities we conduct

Users may exercise all of these rights by contacting us via the contact information. The request to exercise their rights will be attended and answered within a maximum period of 10 working days.

PROTECTION OF CHILDREN'S ONLINE PRIVACY

We comply with national and international data protection regulations regarding the protection of children's personal data. We do not collect any information from children under the age of 13. If we become aware that a child under the age of 13 has provided us with personal information, we will take immediate steps to delete such information.

CALIFORNIA PRIVACY RIGHTS

If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA) and California's "Shine the Light" law.

CCPA Rights

  • Right to Know: You can request information about the personal data we collect, use, and disclose
  • Right to Delete: You can request deletion of your personal information
  • Right to Opt-Out: We do not sell your personal information to third parties
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

Shine the Light Law

California Civil Code Section 1798.83 permits California residents to request certain information about disclosure of personal information to third parties for direct marketing purposes. We do not share your personal information with third parties for their direct marketing purposes.

To exercise any of these rights, please contact us at privacy@awardable.io or support@awardable.io.

MARKETING COMMUNICATIONS

We may send you marketing communications about Awardable products, features, promotions, and updates. You can opt out of receiving marketing emails at any time by:

  • Clicking the "unsubscribe" link in any marketing email
  • Updating your email preferences in your account settings
  • Contacting us at support@awardable.io

Please note that even if you opt out of marketing communications, we will still send you transactional emails related to your account, such as purchase confirmations, password resets, and important service updates.

THIRD-PARTY SERVICES

Our platform integrates with and relies on the following third-party services. Each service has its own privacy policy governing the collection and use of your information:

Clerk (Authentication)

Manages user authentication, accounts, and sessions. Collects email, password (encrypted), profile data, and authentication tokens.
Privacy Policy: https://clerk.com/legal/privacy

Stripe (Payment Processing)

Processes subscription payments. Collects payment card information, billing details, and transaction data.
Privacy Policy: https://stripe.com/privacy

Supabase (Database)

Stores user data, awards, tournaments, and platform content. Hosted on AWS infrastructure.
Privacy Policy: https://supabase.com/privacy

Vercel (Hosting)

Hosts our application and processes requests. May collect request metadata, IP addresses, and performance data.
Privacy Policy: https://vercel.com/legal/privacy-policy

Except as expressly included in this privacy policy, this document addresses only the use and disclosure of information Awardable collects from you. If you disclose your information to others, different rules may apply to their use or disclosure of the information you disclose to them. Awardable does not control the privacy policies of third parties, and you are subject to the privacy policies of those third parties where applicable.

CHANGES TO PRIVACY POLICY

We reserve the right to change our privacy policy at any time. Changes will be promptly notified to our users and posted on the website. Your continued use of our website and services following these changes constitutes acceptance of the changes.

CONTACT INFORMATION

If you have questions or concerns about these terms, please contact us:

Awardable
support@awardable.io