This Privacy Policy explains how [COMPANY LEGAL NAME] ("we", "us") collects, uses, and protects your personal information when you use ReplayLab Pro (the "Service"). We are the data controller. Contact: [PRIVACY EMAIL].
| Category | Examples | Why |
|---|---|---|
| Account | Name, email address, mobile number (optional), password (stored only as a secure hash) | Create and secure your account; sign you in; send verification and password-reset codes |
| Sign-in provider | If you use Google Sign-In: your Google email and name | Let you sign in with Google |
| Usage & activity | Practice sessions, logins, actions, timestamps | Run the Service, show your dashboard/history, prevent abuse |
| Technical / log | IP address, browser/device info, cookies | Security, session management, diagnostics |
| Billing (Pro) | Subscription status; payment is handled by our processor | Provide paid features. We do not store full card details |
All trading balances and results are virtual and are not financial account data.
Where required (e.g. under GDPR/UK GDPR), we rely on: performance of a contract (running your account), legitimate interests (security, improving the Service), consent (where asked, e.g. marketing), and legal obligation. You can withdraw consent at any time.
We use a small number of cookies that are strictly necessary to keep you signed in and secure (for example a session cookie). We [do / do not] use analytics or advertising cookies. You can control cookies in your browser, but disabling essential cookies will break sign-in.
We do not sell your personal information. We share it only with service providers who help us run the Service, under contract, including:
We may also disclose information if required by law or to protect our rights, users, or the Service.
We keep your account data while your account is active and for a reasonable period afterward as needed for legal, security, and record-keeping purposes, then delete or anonymise it. One-time codes expire quickly. Retention specifics: [YOUR RETENTION PERIODS].
We use technical and organisational measures to protect your data, including hashed passwords, encrypted transport (HTTPS), access controls, and restricted database access. No system is perfectly secure, but we work to protect your information and will notify you of a breach where required by law.
Depending on where you live, you may have the right to access, correct, delete, or export your data, object to or restrict certain processing, and withdraw consent. To exercise these rights, contact [PRIVACY EMAIL]; we will respond within the time the law requires. You may also complain to your local data-protection authority.
The Service is not directed to children under [18], and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
Your data may be processed in countries other than yours. Where required, we use appropriate safeguards (such as standard contractual clauses) for such transfers.
We may update this policy. We will post the new version here and, for material changes, notify you by [email / in-app notice].
[COMPANY LEGAL NAME], [ADDRESS] · [PRIVACY EMAIL] · [Data Protection Officer / representative, if applicable].