
Privacy Policy
1. Who does this apply to?
- Organizers: The people who create accounts to run raffles. (For your account data, MyRifa is the “data controller”.)
- Participants: The people who fill out public forms to enter raffles. (For your entry data, the Organizer is the “data controller,” and MyRifa is just the “processor” acting on their behalf.)
2. What data do we collect?
If you are an Organizer:
- The basics: Your email, your securely hashed password, and the tokens used to verify your account or reset your password.
- Audit logs: Metadata about the actions you take while logged in (e.g. creating, publishing, or deleting a raffle) so we can keep the platform running smoothly and investigate problems.
If you are a Participant:
- Entry info: Your email (so we can prevent duplicate entries and the organizer can contact you if you win), plus any extra questions the organizer decided to put on their form.
- Consent: Timestamps and checkboxes showing you agreed to enter.
- Views: Anonymous counts of how many times a form was viewed — we don’t tie these to who viewed it.
Automatically (for everyone): We collect basic web request metadata like IP addresses and timestamps to stop abuse, prevent spam, and keep the site secure. We never attach your IP address to your actual raffle entry.
3. Why do we process your data?
We only use your data for three reasons:
- To make the app work: To let organizers run raffles, let participants enter them, and allow data exports. (Legal basis: Contract / Legitimate Interest)
- To keep it secure: To stop bots and prevent abuse on the platform. (Legal basis: Legitimate Interest)
- For marketing: Only if a specific raffle requires it and you explicitly click a button giving your consent. (Legal basis: Consent)
4. Who sees your data?
We don’t sell your data. Here is exactly who gets to see it:
- Organizers: Get to see the entry data for their own raffles so they can pick a winner.
- Our Subprocessors:
- Hosting: MyRifa is locally hosted on private infrastructure that we own and manage directly — not a third-party cloud host.
- System email: A trusted transactional-email provider we use to send account verification and password-reset emails.
- Payments: Paddle is our payment provider and merchant of record for paid plans. If you subscribe, Paddle collects your name, email, billing address, and payment details to process the charge and handle tax — MyRifa never sees or stores your card number. Paddle is never involved in participant entries.
- Monitoring: Grafana Cloud, which receives technical performance data (error rates, page load times, request traces) so we can keep the app running reliably. Emails, phone numbers, passwords, and tokens are actively stripped out of this data before it’s sent — it’s for diagnosing problems, not identifying you.
- The Law: We will disclose data if we are legally required to do so by law enforcement.
5. How long do we keep it?
- Organizers: We keep your data for as long as your account is active.
- Participants: Our policy is to delete or fully anonymize your entries 18 months after a raffle ends (configurable via
ENTRY_RETENTION_MONTHS). This runs automatically on a schedule — it isn’t a manual or aspirational process.
6. How do we keep it safe?
We take security seriously:
- Encryption: Passwords are hashed using cutting-edge security (argon2id). All data travels across the web securely via HTTPS.
- Access Control: Participant entry data is strictly locked down so it can only be seen by the organizer who ran that specific raffle and our authorized system admins.
7. Your Data Rights
Depending on where you live, you have the right to access, correct, delete, restrict, or export your personal data.
- Participants: Because the Organizer controls your entry data, please reach out to them first with any requests.
- Organizers (or if you just need extra help): Shoot us an email anytime at [email protected].