Introduction
HaloStats (“we”, “our”, or “us”) operates an AI-powered football predictions platform available at halostats.com. This Privacy Policy explains what personal data we collect, how we use it, and what rights you have regarding your information.
By creating an account or using any part of our service, you confirm that you have read and understood this policy. If you do not agree with any part of it, please discontinue use of the platform.
We are committed to handling your personal data responsibly and in compliance with applicable data protection legislation, including the UK GDPR and the Data Protection Act 2018.
Information We Collect
We collect the following categories of data when you use HaloStats:
- Registration data — your full name and email address provided when creating an account.
- Usage data — pages visited, predictions viewed, features used, and time spent on the platform. This helps us improve the product.
- Device & browser information — IP address, browser type, operating system, and referring URLs collected automatically when you access the platform.
- Communications — any messages you send us via email or our contact form, including support requests.
- Subscription status — which plan you hold and your billing history, managed through Stripe.
We do not collect sensitive personal data such as racial or ethnic origin, political opinions, health information, or biometric identifiers.
Account Data
When you register for a HaloStats account, we collect and store your full name and email address. This information is used to:
- Authenticate your identity when you log in
- Manage your subscription and access permissions
- Deliver prediction content and product updates relevant to your plan
- Send transactional emails including receipts, password resets, and account alerts
Your account data is retained for as long as your account remains active. You may request deletion of your account and associated data at any time by contacting us. Upon deletion, your personal data will be removed from our active systems within 30 days, subject to any legal retention obligations.
Payment Processing
All payment processing on HaloStats is handled by Stripe, Inc., a PCI-DSS compliant payment provider. We do not store, log, or have access to your full card number, CVV, or any raw payment credentials.
When you subscribe to a plan, Stripe securely collects and processes your payment details directly. We receive only a tokenised reference and your billing status from Stripe.
Stripe’s handling of your payment data is governed by their own Privacy Policy, available at stripe.com/privacy. We recommend reviewing it to understand how your payment information is managed.
We retain records of subscription transactions (plan type, date, amount) for accounting and legal compliance purposes. These records do not include full payment details.
Data Storage & Security
Your personal data is stored on secure cloud infrastructure with encryption applied both at rest and in transit. We use industry-standard TLS/SSL protocols to protect data transmitted between your browser and our servers.
Access to personal data within our systems is restricted to authorised personnel only, on a need-to-know basis. We maintain access logs and conduct regular security reviews.
While we implement robust security measures, no system is completely immune to risk. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware, as required by law.
Data is stored within the United Kingdom and European Economic Area. Where data is transferred outside these regions, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
Your Rights
Under applicable data protection law, you have the following rights regarding your personal data:
- Right of access — you can request a copy of the personal data we hold about you.
- Right to rectification — you can ask us to correct inaccurate or incomplete data.
- Right to erasure — you can request deletion of your personal data, subject to certain legal exceptions.
- Right to restrict processing — you can ask us to limit how we use your data in certain circumstances.
- Right to data portability — you can request your data in a structured, machine-readable format.
- Right to object — you can object to processing based on legitimate interests or for direct marketing purposes.
- Rights related to automated decisions — you have the right not to be subject to solely automated decision-making that significantly affects you.
To exercise any of these rights, please contact us at the address listed in the Contact Information section below. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your data is being handled unlawfully.
Third-Party Services
HaloStats integrates with a limited set of third-party services to operate the platform. Each provider is subject to their own privacy policy and data handling standards.
- Stripe — payment processing and subscription management. Data processed: billing details, transaction history.
- Cloud hosting provider — infrastructure and data storage. Data processed: all platform data within encrypted, access-controlled environments.
- Analytics provider — anonymised usage analytics to measure platform performance and user experience. Data processed: aggregated behavioural data with no personal identifiers.
We do not sell, trade, or rent your personal data to third parties. We do not use your data for advertising targeting or share it with data brokers.
Any third-party service we engage is required to handle data in compliance with applicable data protection law and is bound by a data processing agreement where legally required.
Contact Information
If you have any questions, concerns, or requests relating to this Privacy Policy or how we handle your personal data, please contact us:
We aim to respond to all privacy-related enquiries within 5 business days. For formal data subject access requests, we will respond within the statutory 30-day period.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. The “Last updated” date at the top of this page will always indicate when the most recent revision was made.
For material changes — those that significantly affect how we handle your personal data — we will notify registered users via email at least 14 days before the change takes effect. Continued use of the platform after that date constitutes acceptance of the revised policy.
We encourage you to review this policy periodically to stay informed about how we protect your information. Archived versions of previous policies are available on request.
Questions about this policy? Contact us at privacy@halostats.com