Privacy policy
⚠️ IASHARK IS NOT A BETTING SITE: NO BETS ARE TAKEN ON THIS SITE. OUR ANALYSES ARE STATISTICAL ESTIMATES WITH NO GUARANTEE OF ANY OUTCOME.
GAMBLING INVOLVES RISKS: DEBT AND ADDICTION. NEED HELP? CONTACT A HELP SERVICE IN YOUR COUNTRY OR GAMBLING THERAPY (FREE, ONLINE): GAMBLINGTHERAPY.ORG.
FOR ADULTS AGED 18 AND OVER ONLY.
1. Data controller
IASHARK (sole trader, registered office in Paris, France) is the controller of the personal data collected through the iashark.com website. Contact: contact@iashark.com.
IASHARK has not appointed a data protection officer; any request relating to your data can be sent to the address above.
2. Data we collect
We only collect the data needed to run the service:
- Account data — email address, password (handled by our authentication provider and never stored in plain text), plan (free or Pro), creation and update dates.
- Preferences (optional) — display name, favourite leagues, language, time zone, notification preferences, management settings (daily exposure, stop threshold) and starting bankroll entered voluntarily in the Tools area. This data remains private and is never shared.
- Decision journal (Pro subscribers, optional) — the entries you record: match, market, odds, estimated probability, stake, status and result.
- Subscription — customer identifier at our payment provider, subscription status and plan, end date of the billing period, payment events. Bank card data is processed exclusively by Stripe and is never stored by IASHARK.
- Internal journey measurement — random session identifier, page viewed, language, type of step (visit, sign-up, opening checkout…) and, if you are logged in, your account identifier.
- Audience measurement — pages visited, length and sequence of visits, technical information about your device and browser, and approximate location, via Google Analytics, which loads as soon as you arrive on the site; you can object at any time from the Cookie policy.
- Security — IP address used to limit abusive login attempts, and technical logs kept by our hosting providers.
- Correspondence — the content of the messages you send us.
We do not collect any sensitive data. We do not sell any data to third parties.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and managing your account, access to analyses and tools | Performance of the contract (Art. 6(1)(b)) |
| Managing the subscription, payment, invoicing | Performance of the contract (Art. 6(1)(b)) and legal accounting obligations (Art. 6(1)(c)) |
| Saving your preferences and your journal | Performance of the contract (Art. 6(1)(b)) |
| Security of the service, prevention of fraud and abusive logins | Legitimate interest (Art. 6(1)(f)) |
| Internal journey measurement to improve the service | Legitimate interest (Art. 6(1)(f)) |
| Audience measurement via Google Analytics | Legitimate interests (Art. 6(1)(f)); you can object at any time |
| Responding to your requests and complaints | Performance of the contract or legitimate interest |
4. Recipients and processors
Your data is accessible to the publisher and its technical providers, within the limits of their tasks:
- Supabase — database, authentication and server functions; data hosted in the European Union (Paris region).
- Stripe — payment and subscription management; Stripe also acts as a separate controller for certain purposes of its own (fraud prevention, regulatory obligations).
- Netlify — website hosting and technical logs.
- Google Ireland Limited — Google Analytics (audience measurement), unless you have objected.
- Providers of technical resources — fonts (Google Fonts), a technical library (jsDelivr) and team logo images (API-SPORTS): when these resources load, your IP address is transmitted to them.
Your data may also be disclosed to public authorities where required by law.
5. Transfers outside the European Union
Some providers (in particular Netlify, Stripe, Google and Supabase, companies headquartered outside the European Union) may process data outside the European Economic Area, particularly in the United States. These transfers are covered by the European Commission's adequacy decision on the EU–US Data Privacy Framework where the recipient is certified under it, or otherwise by the standard contractual clauses adopted by the European Commission.
6. Retention periods
- Account data, preferences and journal — for as long as the account is used; if you subscribed, up to one year after the subscription ends, unless you delete your account earlier. Deleting the account erases the account and the data linked to it.
- Subscription and payment data — managed and retained by Stripe under its own rules; accounting records are kept for the legally required period.
- Internal journey measurement — for as long as needed for the statistical analysis of the service; the link to your account is removed when your account is deleted.
- Google Analytics — according to the retention period set in Google Analytics (2 or 14 months for user-level and event-level data).
- Correspondence — for as long as needed to handle your request.
7. Your rights
Under the GDPR and the French Data Protection Act (loi Informatique et Libertés), you have the following rights:
- Access — obtain a copy of the data we hold about you;
- Rectification — correct inaccurate data;
- Erasure — request the deletion of your data;
- Restriction — request that processing be temporarily suspended;
- Portability — receive your data in a structured, machine-readable format;
- Objection — object to processing based on legitimate interest;
- Withdrawal of consent — at any time, for processing based on consent;
- Post-mortem instructions — under French law, set instructions regarding what happens to your data after your death.
From the "My account" page, you can export your data (JSON file) and delete your account at any time.
To exercise your rights, write to contact@iashark.com. We reply within one month, which may be extended under the conditions laid down by the GDPR.
You can lodge a complaint with the French data protection authority, the CNIL (cnil.fr), or with the data protection authority of your country of residence.
8. Automated decisions
IASHARK's statistical models concern football matches, not people. No decision producing legal effects concerning you is made solely on the basis of automated processing.
9. Security
Your data is stored with Supabase (encrypted infrastructure, SOC 2 certified), with access controls restricting each user to their own data. Payments are processed by Stripe, a certified PCI DSS Level 1 service provider. We never have access to your bank card details.
10. Minors
The service is reserved for people aged 18 and over. If we learn that an account has been created by a minor, we delete it.
11. Cookies
Details of the cookies and similar technologies used are set out in our Cookie policy.
12. Changes and contact
This policy may be updated; the date of the last update appears at the top of the page. For any question about the protection of your data: contact@iashark.com.