privacy policy · v1.0 draft

How we handle data.

iGamingInbox is a competitive email-intelligence platform. We receive promotional emails that gambling operators send to subscription mailboxes we control, redact personal information at the point of ingestion, and present the redacted material to business customers for competitive analysis. This notice explains what we process, on what legal basis, who processes it for us, and your rights.

Last updated: July 2026 · Controller: iGamingInbox, London, United Kingdom (a limited company will be incorporated before first paid onboarding; this notice will be updated with its details) · Contact: privacy@igaminginbox.com

Who we are

iGamingInbox is operated by an individual founder based in London, United Kingdom. A legal entity will be incorporated before the first paying customer is onboarded.

Contact: privacy@igaminginbox.com

What we collect — and what we don't

From honeypot inboxes (the emails we monitor)

We capture:

  • The email subject line
  • The email body (text + HTML), after PII redaction (see below)
  • The sender address (operator domain)
  • The send timestamp
  • The Message-ID header (for de-duplication)

We do not store:

  • The honeypot Gmail address itself (replaced with `[honeypot]` token)
  • Player greeting names (Jordan, Mr Smith, etc. — replaced with `[Player]`)
  • Personalised bonus codes (replaced with `[CODE]`)
  • Tracking-pixel URLs or session-token query strings (replaced with `[redacted]`)
  • Account balances or personal financial data (regex-stripped from body)
  • Phone numbers (replaced with `[phone]`)
  • The IMAP password for any honeypot Gmail (stored as Vercel environment variables, never written to DB)

From you (our customers and prospects)

If you hold a beta account, request a demo, or contact us:

Cookies and local storage

We do not use advertising or analytics cookies, and we do not run third-party trackers. We use browser local storage for strictly necessary purposes only: keeping you signed in (authentication tokens) and remembering interface preferences (e.g. theme). These are not shared with third parties.

Our pages load fonts and libraries from content-delivery networks (Google Fonts, jsDelivr, Tailwind CDN). When your browser fetches those assets, the CDN necessarily receives your IP address and user-agent as part of the request. We do not send them anything else. If we add product analytics in future, we will use a privacy-respecting, cookieless provider and update this notice first.

Our lawful bases (UK GDPR, Article 6)

We do not sell personal data, we do not use it for advertising, and we do not carry out automated decision-making that produces legal or similarly significant effects on individuals.

How redaction works

All email content passes through a redaction function at the moment of ingestion, before any data is written to our database. Our systems never store an unredacted copy: the unredacted version exists in our processing pipeline only transiently and is discarded after parsing. (The original message also remains in the receiving mailbox itself, as with any email account; those mailboxes are access-controlled, used solely as capture infrastructure, and are not part of the product.)

The redaction covers:

We preserve all the competitive intel value — bonus amounts, wagering requirements, game names, operator names, campaign copy, CTA destinations (minus tracking) — without the personal data.

Residual data. Redaction is automated and continuously improved, but no automated system is perfect. If you believe personal data relating to you appears anywhere in the platform, email privacy@igaminginbox.com and we will review and remove or further redact it promptly — normally within 5 working days, and in any event within the statutory one month.

Where it's stored, and who processes it for us

Data at rest — email records, screenshots, operator data and customer accounts — lives in a managed PostgreSQL database and storage hosted by Supabase in London (eu-west-2). Mailbox credentials are held as encrypted environment variables, never written to the database, never exposed to the frontend, and never logged.

We use a small number of sub-processors, each receiving only what its function requires:

International transfers. Some sub-processors are US companies, so limited processing occurs outside the UK/EEA. Where that happens we rely on the providers' standard safeguards (UK IDTA / EU Standard Contractual Clauses, and the UK–US Data Bridge / EU–US Data Privacy Framework where the provider is certified). Importantly, content leaving our environment for rendering or AI analysis has already been redacted.

How long we keep it

Redacted promotional emails are retained indefinitely for the purpose of building a historical competitive intelligence archive. This is the core utility of the product — historical depth matters for trend analysis.

Customer account data is retained for the duration of your subscription plus 12 months (to allow re-activation). On verified deletion request, your account data is deleted within 30 days.

Operator-side data (emails captured from honeypots) is not associated with any individual customer and is not subject to individual-deletion requests from operators.

Security

All traffic is encrypted in transit (TLS). Database access is governed by row-level security: signed-out visitors can read only a limited recent window, account holders read via authenticated sessions, and write operations from our pipeline use segregated service credentials. Secrets (mailbox credentials, API keys, admin tokens) live in the hosting platform's encrypted environment configuration and are never present in client-side code or the database. Access to production systems is limited to the founder.

Your rights (under UK GDPR)

You have the right to:

To exercise any of these rights, email privacy@igaminginbox.com. We respond within one calendar month, as the law requires, and may need to verify your identity first. If you're unhappy with our response you can complain to the UK Information Commissioner's Office (ico.org.uk).

Changes to this policy

We will update this page when our practices change. The version number and date at the top of this page reflect the most recent revision. Material changes will be communicated to active customers via email.

A note on this draft

This Privacy Policy is a working draft pending review by a UK SaaS / privacy lawyer before our first paying customer is onboarded. The principles outlined here (redact-on-ingest, no unredacted content stored, UK-hosted data at rest, UK GDPR rights respected) are foundational and will not change in subsequent revisions — but legal phrasing may be tightened.

If you have any concerns about our data handling, please contact us directly. We are open to scrutiny on this — the whole product is built around the principle that competitive intel should never come at the cost of personal data leakage.