PRIVACY POLICY
Last updated: April 2026
Flip a Coin ("we," "us," or "our") is committed to protecting your personal data. This Privacy Policy explains what information we collect, why we collect it, how we use and safeguard it, and your rights regarding your data. This policy applies to all users of the Flip a Coin mobile application and website (the "Service").
1. INFORMATION WE COLLECT
Information You Provide
- Account data: Phone number (used for SMS-based OTP authentication), username, full name, and profile picture
- Identity verification (KYC): Government-issued ID, date of birth, and address β collected when required for withdrawals
- Payment data: Payment method details (processed by our PCI-compliant payment providers; we do not store full card numbers)
- Communications: Messages sent to our support team
Information Collected Automatically
- Device data: Device model, operating system, screen resolution, unique device identifiers
- Usage data: Game sessions, tap timestamps, scores, win/loss records, session duration
- Network data: IP address, connection type, approximate location (country/region level)
- App performance: Crash logs, error reports, and performance metrics
Information from Third Parties
We may receive information from payment processors (transaction status, fraud signals), app stores (installation data), and identity verification services (KYC results). We do not purchase data from data brokers.
2. HOW WE USE YOUR INFORMATION
We use your personal data for the following purposes:
- Service delivery: Operate the app, process game sessions, match players, calculate scores
- Payments: Process deposits, withdrawals, entry fees, and winnings
- Fair play: Detect and prevent cheating, fraud, and abuse using server-side validation
- Identity verification: Comply with KYC/AML requirements for real-money transactions
- Communication: Send SMS messages for OTP-based login and signup verification, deliver service updates, respond to support requests, and send push notifications about games and tournaments
- Improvement: Analyze usage patterns to improve game performance, fix bugs, and enhance user experience
- Legal compliance: Fulfill regulatory obligations including tax reporting and anti-money laundering
3. LEGAL BASIS FOR PROCESSING
Under the General Data Protection Regulation (GDPR) and similar legislation, we process your data based on the following legal grounds:
- Contract performance: Processing necessary to provide you with the Service (account management, game operations, payments)
- Legal obligation: Processing required by law (KYC, AML, tax reporting, age verification)
- Legitimate interests: Fraud prevention, security, service improvement, and analytics β balanced against your privacy rights
- Consent: Marketing communications and optional cookies β you may withdraw consent at any time
4. SHARING YOUR INFORMATION
We do not sell your personal data. We share data only in the following circumstances:
- Payment providers: Razorpay, Pay.nl, and Rapyd process your financial transactions
- KYC providers: Identity verification services validate your identity for regulatory compliance
- Cloud infrastructure: Our servers and databases are hosted on secure cloud platforms
- Analytics: Aggregated, anonymized data may be used for business analysis
- Legal requirements: We may disclose data when required by law, court order, or government request
- Business transfers: In the event of a merger, acquisition, or sale, user data may be transferred as part of the business assets
5. COOKIES & TRACKING TECHNOLOGIES
Our website uses cookies and similar technologies for:
- Essential cookies: Required for the website to function (session management, security)
- Analytics cookies: Help us understand how visitors use the website (page views, traffic sources)
You can manage cookie preferences through your browser settings. Blocking essential cookies may affect website functionality.
6. DATA RETENTION
We retain your personal data only as long as necessary for the purposes described in this policy:
- Active accounts: Data is retained for the duration of your account
- Closed accounts: Core account data is retained for up to 5 years after closure to comply with anti-money laundering regulations and to resolve potential disputes
- Game data: Game session records are retained for 3 years for dispute resolution and fair play auditing
- Financial records: Transaction records are retained for 7 years as required by tax and financial regulations
After the retention period expires, data is securely deleted or anonymized.
7. DATA SECURITY
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Secure authentication with OTP verification delivered via SMS
- Access controls limiting employee access to personal data on a need-to-know basis
- Regular security assessments and monitoring
- PCI-DSS compliant payment processing through certified providers
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We encourage you to keep your device and account credentials secure.
8. SMS/TEXT MESSAGING
FlipACoin uses SMS (Short Message Service) text messages solely for transactional authentication purposes. By providing your mobile phone number during account registration or login, you expressly consent to receive SMS messages from FlipACoin.
Types of SMS Messages
- One-time passcodes (OTP): Verification codes sent during login, account registration, password reset, and account verification
- Account security alerts: Notifications related to account deletion verification
Message Frequency & Rates
SMS messages are sent only in direct response to user-initiated requests (e.g., tapping "Get OTP"). We do not send marketing, promotional, or advertising messages via SMS. Message frequency varies based on your authentication activity. Standard message and data rates from your mobile carrier may apply.
Opt-Out
You may opt out of receiving SMS messages at any time by replying STOP to any message. You may also text HELP for assistance. Opting out of authentication SMS may prevent you from logging in to your account. For further assistance, contact support@flipacoin.com.
SMS Data
We do not share your phone number or SMS opt-in data with third parties for marketing purposes. Phone numbers are shared only with our SMS service provider (Twilio) for the sole purpose of delivering authentication messages.
9. INTERNATIONAL DATA TRANSFERS
Flip a Coin operates in multiple countries. Your data may be transferred to and processed in countries outside your country of residence, including countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or transfers to countries with an adequate level of data protection.
10. YOUR RIGHTS
Under GDPR and applicable data protection laws, you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Restriction: Request that we limit the processing of your data in certain circumstances
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests or for direct marketing
- Withdraw consent: Withdraw consent for processing based on consent at any time
To exercise any of these rights, contact us at support@flipacoin.com. We will respond within 30 days. You may also delete your account directly through the app β see our Delete Account page for instructions.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority (e.g., the Autoriteit Persoonsgegevens in the Netherlands).
11. CHILDREN'S PRIVACY
Flip a Coin is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a user under 18, we will take steps to delete that information promptly. If you believe a minor has created an account, please contact us immediately.
12. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via push notification, email, or in-app notice at least 14 days before taking effect. The "Last updated" date at the top of this page indicates when the policy was last revised.
13. CONTACT US
For privacy-related inquiries, data requests, or complaints:
- Email: support@flipacoin.com
- Website: flipacoin.com/support
We aim to respond to all privacy requests within 30 days of receipt.
See also: Terms of Service Β· Delete Account Β· Responsible Gaming