Privacy Policy

Last updated · 2 September 2026

This policy explains what personal information SportQuanta collects, why we collect it, who we share it with, and the choices you have.

Draft — this document is pending review by counsel and is not yet binding.

1. Who we are

SportQuanta operates from 30N Gould Street, #47580, Sheridan, WY 82801, United States. For the purposes of the GDPR we are the data controller for the information described here. Our contact address for privacy matters is [email protected].

2. Information we collect

  • Account information — name, work email, organization name, and password credentials, provided when you register.
  • Billing information — plan, billing country, and tax identifiers. Card details are collected and stored by our payment processor, not by us.
  • API usage data — API key identifier, endpoints called, timestamps, response codes, request volume, and IP address. We need this to enforce quotas, bill accurately, and investigate abuse.
  • Contact submissions — the name, email, company, topic, and message you send through the contact form on this site.
  • Site analytics — pages viewed, referrer, approximate location derived from IP, device and browser type.
  • Support correspondence — the content of emails and messages you send us.

3. Cookies and analytics

This site sets a first-party cookie named saas-kit-landing-locale, which remembers whether you are reading in English or Korean. It is strictly necessary for that preference and stores no identifier.

We use Google Analytics 4 (measurement ID G-65YFK3NQH7) to understand aggregate traffic. Google sets its own cookies and processes that data under its own terms; see policies.google.com/privacy. You can opt out with Google's browser add-on or by blocking analytics cookies in your browser.

The application at user.sportquanta.com sets session cookies that are strictly necessary to keep you signed in.

4. How we use information

  • to provide, operate, and secure the API and the dashboard;
  • to authenticate users and enforce plan quotas and rate limits;
  • to bill subscriptions and administer trials;
  • to respond to support requests and contact-form submissions;
  • to detect, investigate, and prevent abuse, fraud, and security incidents;
  • to measure and improve the site and the product in aggregate;
  • to send service notices, and — only with your consent — product updates.

5. Legal bases (EEA and UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the service you signed up for); legitimate interests (securing the service, preventing abuse, understanding aggregate usage); consent (analytics cookies and marketing email, which you can withdraw at any time); and legal obligation (tax and accounting records).

6. Sharing and disclosure

We do not sell personal information. We share it only with:

  • infrastructure and hosting providers that run the service on our behalf;
  • our payment processor, for subscription billing;
  • Google Analytics, for aggregate site measurement;
  • the workspace tool that receives contact-form submissions so our team can reply;
  • professional advisers, and authorities where we are legally required to disclose;
  • an acquirer, in the event of a merger or sale, subject to this policy continuing to apply.

7. Retention

Account records are kept for as long as the account is active and for up to 24 months afterwards. API request logs are kept for up to 13 months for billing, capacity, and abuse investigation. Billing records are kept for the period required by tax law, typically 7 years. Contact-form submissions are kept for up to 24 months. We delete or anonymize data once these periods end.

8. Security

All traffic is encrypted in transit with TLS. Credentials are hashed, API keys are stored as hashes and shown in full only once at creation, and access to production systems is restricted and logged. No system is perfectly secure; if a breach affects your personal data we will notify you and any relevant regulator as the law requires.

9. International transfers

We operate in more than one region and our providers may process data outside your country, including in the United States. Where personal data leaves the EEA, the UK, or Korea, we rely on Standard Contractual Clauses or another lawful transfer mechanism.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal information, to object to processing based on legitimate interests, and to withdraw consent. Under Korean law (PIPA) you may also request suspension of processing. Under the CCPA/CPRA, California residents may request access and deletion and may opt out of any sharing for cross-context behavioural advertising — we do not sell personal information.

To exercise any of these, email [email protected]. We will respond within the period the applicable law allows, and will ask for enough information to verify your identity. You may also complain to your local supervisory authority.

11. Marketing

We send product and marketing email only with your consent, and every such message carries an unsubscribe link. Service notices — billing, security, and material changes to the API — are sent to all customers and cannot be unsubscribed from while the account is active.

12. Children

The service is intended for businesses and is not directed at anyone under 18. We do not knowingly collect personal information from children; if we learn we have, we delete it.

13. Changes to this policy

We may update this policy. Material changes will be announced by email or in the dashboard before they take effect, and the “last updated” date above always reflects the current version.

14. Contact

Privacy questions and rights requests: [email protected], or through the contact form on this site.

This document is published in English and Korean. If the two versions differ, the English version governs.

Privacy Policy · sportquanta