Last updated 4 August 2026. This policy describes what Lottery Pool actually does with your information.
πͺπΈ Leer un resumen en espaΓ±ol
Lottery Pool is operated by BuiltStack. For anything in this policy, including a request to see or delete your data, write to support@builtstack.app.
The table below is the complete list. If something is not in it, we do not collect it.
| What | Why we need it | How long we keep it |
|---|---|---|
| Email address | This is how you sign in β we email you a one-time code instead of using passwords. We also use it to send you records of pools you are in. | Until you delete your account. |
| Display name | So other members of your pool can see who is who. | Until you delete your account or leave the pool. |
| Mobile number (optional) | Only if you ask for text message receipts. You can use the whole app without giving us one. | Until you remove it or delete your account. If you reply STOP, we keep the number on a do-not-text list so we honour that. |
| The US state you live in | Different states set different minimum ages and different rules. We ask you; we do not detect it. | Until you delete your account. |
| Pool records β pool names, who is in them, agreed contributions, ticket numbers, and the splits we calculate | This is the product. It is the shared record your group relies on. | Until the pool is deleted or you delete your account. |
| Ticket photographs (optional) | So a group can see the actual ticket rather than take someone's word for it. | See section 6 β read this one. |
| Your consent record β which statements you agreed to, the exact wording, and when | Because you agreed to specific things about age and about how the app works, and both of us should be able to see exactly what was said. | Kept as a legal record, including after account deletion. |
| Your time zone | To show draw times in your local time. Your browser reports it; no permission is involved and it is not a location. | Until you delete your account. |
| Subscription status | To know which features your account has. Stripe holds the payment details; we hold only the status and identifiers. | Kept as a financial record for as long as tax law requires. |
| Sign-in codes and session records | To keep you signed in and to let you sign out everywhere. | Codes expire in minutes. Sessions expire after 30 days or when you sign out. |
Some corner shops display a Lottery Pool code. If you scan one, we record that a scan happened, which shop's code it was, and a one-way scrambled fingerprint of the network address it came from. That fingerprint is used to spot fraudulent scan volume. It cannot be turned back into your address, and it is not linked to your account.
These are design decisions, not omissions:
We do not sell your personal information, and we do not share it for anyone else's advertising. We use a small number of service providers who process data strictly on our instructions:
| Provider | What they receive | What for |
|---|---|---|
| Cloudflare | Everything, as our hosting provider β the database, the stored photographs, and the traffic itself. | Running the Service. |
| Resend | Your email address and the content of emails we send you. | Delivering sign-in codes, invitations, and receipts. |
| Twilio | Your mobile number and message text β only if you opted into texts. | Delivering text receipts. |
| Stripe | Your payment details and email β only if you subscribe. | Taking subscription payments. Stripe is the controller of your card data under its own privacy policy. |
| Cloudflare Workers AI | A photograph of a handwritten member list, if you use that feature. | Reading the names and amounts off the page so you do not have to type them. We ask it to ignore phone numbers. |
We also fetch published winning numbers from official state lottery data feeds. That request is outbound only β it contains nothing about you.
Beyond those providers, we disclose personal information only where we are legally required to, where it is necessary to protect someone's safety or our legal rights, or in connection with a merger or sale of the business β in which case we will tell you before your information becomes subject to a different policy.
Members of a pool can see each other's display names, agreed contributions, whether a contribution has been marked paid, and any ticket photographs added to that pool. They cannot see your email address or your mobile number.
A pool organiser can generate a shareable receipt link. Anyone holding that link can view that pool's record without signing in β so treat it as you would a photograph of the ledger, and only share it with people who should see it.
If you opt in to text receipts, message frequency varies with your pool activity. Message and data rates may apply. Reply STOP to any message to stop them, or HELP for help. Opting out of texts does not affect anything else about your account. We never share your mobile number with anyone for their own marketing.
A photograph belongs to the pool it was added to rather than to the person who uploaded it, because it is the whole group's record of what the group holds. That decides what happens to it:
To have a specific photograph removed at any other time, email support@builtstack.app and we will delete it within 30 days.
A lottery ticket is a bearer instrument and its barcode is visible in a photograph. Only upload a photograph of a ticket your group actually holds, and only share the pool with people you trust.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities as required by law.
Wherever you live, you can ask us to:
Email support@builtstack.app and we will respond within 30 days at the latest. We will not charge you, and we will not treat you differently for asking.
Under the California Consumer Privacy Act you have the rights listed above, plus the right to know the categories of personal information collected, the purposes, and the categories of third parties they are disclosed to β all of which are set out in sections 2 and 4 of this policy.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. There is therefore no "Do Not Sell or Share My Personal Information" action for you to take, but if that ever changes we will provide one and tell you first.
You may use an authorised agent to make a request on your behalf; we will ask for proof of their authority.
Deleting your account removes your email address, display name, mobile number, declared state, and your membership of pools. Two things intentionally survive:
Pools you organised that still have other members in them are not destroyed when you leave, because they are those members' records too. Your personal details are removed from them.
The Service is not intended for and is not directed to anyone below the minimum lottery age in their state β 18 in most, 21 in some. We do not knowingly collect personal information from children. If you believe a child has given us information, contact support@builtstack.app and we will delete it and close the account.
The Service is operated from the United States and intended for users in the United States. Your information is stored and processed on infrastructure operated by our providers, which may include locations outside your state.
We use a single essential cookie to keep you signed in. That is the whole of it. There are no advertising cookies, no analytics cookies, and no third-party trackers, which is why the app has no cookie banner asking you to accept any.
If we change this policy materially, we will tell you by email or in the app before the change takes effect, and update the date at the top of this page.
Questions, requests, or complaints about privacy: support@builtstack.app. If you are not satisfied with our response, you may complain to your state Attorney General or, in California, to the California Privacy Protection Agency.