Privacy Policy
Last updated:
This policy explains how Axia Signals Group LLC (trading as SportSignals) collects, uses, shares and protects personal data when you use SportSignals.com, its subdomains (including the billing portal at pay.sportsignals.com), our emails, alerts and related services (together, the "Service").
Who is responsible (the "controller"): Axia Signals Group LLC, 500 Paterson Plank Rd, STE 31016, Union City, NJ 07087, USA.
Privacy contact: privacy@axiasignalsgroup.com (you can also use support@sportsignals.com).
This policy is part of how we operate the Service alongside our Terms and Conditions and Data Deletion page.
At a glance
- We collect the data you give us (account, preferences, tracked bets, messages), data collected automatically (device, usage, approximate location) and subscription billing data. Your full card details never touch our servers; they go directly to our payment provider.
- If our separately controlled Reach prospect-discovery workflow is enabled, we may also review limited information from public Instagram profiles and public interactions. Reach never sends a direct message, follows or unfollows automatically, and SportSignals does not supply an Instagram password, session or cookie to the collection provider.
- We use your data to run the Service, process subscriptions, send the emails you have asked for, keep the Service safe, meet legal duties and improve what we build.
- We do not sell your personal data for money. We share it with the service providers who run our infrastructure, and we pass a random click identifier (not your name or contact details) to affiliate networks when you click out to a bookmaker.
- You have real rights over your data, including access, correction, deletion and objection to marketing. UK and EEA users have UK GDPR/GDPR rights; users in a growing number of US states have state privacy rights, including opting out of targeted advertising. See Sections 10 to 12.
- Questions or requests: privacy@axiasignalsgroup.com, or use the self-service options in Account Settings and our Data Deletion page.
1. Who this policy covers
This policy covers visitors to the Service, registered users, SportSignals+ subscribers, people who receive our emails or contact us, and people whose public Instagram profile or public interaction data may be reviewed through our separately controlled Reach prospect-discovery workflow. It does not cover third-party websites and services you reach from the Service (including bookmakers); they have their own privacy policies, and we encourage you to read them.
2. What we collect
Data you provide:
- Account data: email address, name (if provided), password (stored only as a secure hash by our authentication provider), and sign-in method (email, or a third-party login such as Google, Apple or Facebook, from which we receive your name, email and profile identifier).
- Profile and preferences: favourite leagues and teams, odds format, alert rules, quiet hours, notification and newsletter preferences.
- Tool data you enter: tracked prices and bets, watchlists, notes and settings you save in our tools. This can reveal information about your betting activity; we treat it as private to your account and never publish it.
- Communications: messages you send us by email or contact form, survey responses, and cancellation feedback.
- Optional connections: if you turn on browser push notifications, we store the subscription your browser issues (an endpoint address and the keys needed to encrypt a message to it) so we can deliver the alerts you asked for. You can turn push off in your account settings or your browser at any time.
Data collected automatically:
- Usage data: pages viewed, features and tools used, interactions, referral URLs, and clicks on outbound links (including affiliate "clickout" events, recorded against a random click identifier).
- Device and technical data: IP address, browser type and version, operating system, device type, screen size, language, and coarse performance/diagnostic data.
- Approximate location: we derive your country from your IP address on each request, to show the correct legal, responsible gambling and content variant for your region (for example 18+/UK helplines vs 21+/US helplines). We use the country value at request time and do not build a location history.
- Cookies and similar technologies: see Section 6.
Data from our billing provider: when you subscribe, our payment provider shares with us your subscription status, plan, billing dates, amounts, the payment method type and its last digits and expiry (never the full card number), and invoice/receipt records.
Limited public social profile data for Reach: if Reach is enabled after the required compliance review, we may obtain a public Instagram handle, display name, biography, public profile and post URLs, public account and engagement counts, business category, verification and private-account status, language and country signals, recent-post timing and the fact that an account made a public comment on an approved public post. We record which approved public source led to the observation and when. We do not target or infer special category data or information indicating that somebody is a child. If incidental public-source data reveals either, we use it only to exclude the profile and start the deletion workflow. The provider dataset can temporarily contain public comment text, a public profile-image URL and incidental contact or sensitive context present in a public biography. SportSignals does not import the comment text or profile image into its database, but a biography is copied for the restricted human review and can contain incidental information until it is identified and scrubbed or deleted. We do not obtain direct messages or private-profile content, and SportSignals does not supply an Instagram password, session or cookie to the collection provider. Reach uses the permitted data only to prepare an internal list for human review. It does not automatically contact, follow, unfollow or message anybody.
Data from third parties and public sources: conversion reports from affiliate networks (tied to the random click identifier, not your name), sign-in data from third-party login providers you choose to use, technical data from our infrastructure providers (for example security and delivery logs), and, where Reach is enabled, the public Instagram profiles and public posts described above. Reach public-profile data may be collected for us by approved Apify actors and checked manually against the public Instagram profile. We identify Instagram as the public source because we did not obtain this information from the person directly.
We do not ask for, target or infer special category data (such as health information) or data about children. Public-source material can contain incidental information of this kind; where identified, we use it only to exclude the profile from the operator worklist and start the deletion workflow. Please do not include sensitive information in messages to us.
3. What we use data for, and our legal bases
Where UK GDPR or EU GDPR applies, we need a legal basis for each use. In summary:
| What we do | Data involved | Legal basis |
|---|---|---|
| Provide the Service: accounts, preferences, tools, saved data, content delivery | Account, profile, tool data, technical | Performance of a contract |
| Run SportSignals+ subscriptions: checkout, billing, trials, reminders, pauses, cancellations, refunds | Account, billing | Performance of a contract; legal obligation (tax, accounting) |
| Send service emails: receipts, trial and renewal reminders, security and policy notices | Account, billing | Performance of a contract; legal obligation |
| Send marketing emails: newsletters, free picks, product news | Account, preferences | Consent, or (for similar-services messages to existing users) legitimate interests with an opt-out in every email |
| Show region-appropriate compliance content (age gates, helplines) | Approximate location | Legitimate interests; legal obligation |
| Measure and improve the Service: analytics, feature usage, funnel and performance measurement | Usage, technical | Legitimate interests (and consent where required for cookies) |
| Operate affiliate links and measure clickouts and commissions | Clickout events, click identifiers | Legitimate interests (funding a free service) |
| Prepare a limited Reach prospect-review list from public Instagram profile and interaction data | Public handle, profile and post references, public profile signals, source and observation records | Legitimate interests, but only after a documented purpose, necessity and balancing assessment confirms that this basis is appropriate; the processing remains disabled otherwise |
| Keep the Service safe: security, fraud and abuse prevention, trial-abuse and account-sharing detection, enforcing our Terms | Account, usage, technical, billing | Legitimate interests; legal obligation |
| Comply with law: tax, accounting, responding to lawful requests, establishing or defending legal claims | As relevant | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we balance our interests against your rights, and you can object (Section 10). Where we rely on consent, you can withdraw it at any time without affecting past processing.
4. Marketing emails
You choose whether to receive marketing from us (newsletters, free picks, product and offer news). Every marketing email includes a one-click unsubscribe, and you can also manage email preferences in Account Settings. Unsubscribing from marketing does not stop service emails we have to send (such as billing receipts, renewal reminders and security notices). We do not share your email address with third parties for their own marketing.
Reach does not send emails, texts or social-media direct messages and does not perform automated Instagram actions. A human operator may choose to open and follow a public profile after review. Any later direct marketing communication requires its own lawful basis and must follow the separate marketing rules that apply to that channel.
5. Sharing your data
We share personal data only as described here:
- Service providers (processors) acting on our instructions: hosting, content delivery and site analytics (Vercel), database, authentication and file storage (Supabase), subscription billing (OpenPay, an Airwallex company) and Airwallex, which processes your card data directly, transactional and marketing email delivery (Amazon Web Services, through Amazon SES, with Mailgun as a fallback), product analytics (Google, through Google Analytics), and error monitoring and diagnostics (Sentry, which records a small sample of browsing sessions to help us reproduce faults). Each provider is bound by contract to protect your data and use it only to provide services to us.
- Public-data processing provider for Reach: if Reach is enabled, Apify Technologies s.r.o. runs the specific, reviewed data-processing jobs on our instructions. We use a restricted credential and limit the data, run size, cost and retention. If a separately approved community-built actor is used, its creator may also be able to process the minimum actor input and output needed for that job; we do not approve such an actor without a separate privacy, permissions and transfer review.
- Affiliate networks and bookmaker partners: when you click an affiliate link we pass a random click identifier so the partner can attribute any sign-up and pay us commission. This identifier does not contain your name, email or account details. Networks report conversions back against the same identifier. What you then do on a bookmaker's site is governed by that bookmaker's privacy policy.
- Professional advisers: lawyers, accountants, auditors and insurers, under confidentiality duties, where reasonably necessary.
- Authorities and legal process: where required by law, or where reasonably necessary to establish, exercise or defend legal claims, enforce our Terms, or protect the rights, safety or property of users, the public or SportSignals.
- Business transfers: if we go through a merger, acquisition, financing, reorganisation or sale of assets, data may be transferred as part of that transaction, under this policy's protections.
We do not sell personal data for money. Some US laws define "sale" or "sharing" broadly enough to cover certain online advertising cookies; Section 11 explains your opt-out rights and how we honour them.
6. Cookies and similar technologies
We use cookies, local storage and similar technologies in four groups:
- Essential: sign-in sessions, security, load balancing, remembering consent choices, operating checkout. These are required for the Service to work and cannot be switched off.
- Functional: remembering preferences such as odds format and region.
- Analytics: understanding how the Service is used so we can improve it (for example page views, feature usage and funnel measurement, through Google Analytics and Vercel Analytics).
- Advertising and affiliate measurement: where used, capping how often promotions are shown and measuring the performance of partner placements. Our advertising is primarily contextual (based on the page, not on tracking you across other websites). Counting clicks on outbound partner links happens on our own servers as part of operating the link (Section 5) and does not depend on these cookies.
Where the law requires consent for non-essential cookies (as in the UK and EEA), we ask for it and you can change your choice at any time via the cookie settings link in the site footer. You can also control cookies in your browser settings; blocking essential cookies may break parts of the Service. Where US state law gives you the right to opt out of targeted advertising, we honour opt-out preference signals such as Global Privacy Control (GPC) in supported browsers.
7. International transfers
We are a US company, and the Service is operated from the United States with infrastructure and providers in the US, UK and EEA. If you use the Service from the UK or EEA, your personal data will be transferred to and processed in the United States and other countries whose laws differ from yours. Where we transfer UK or EEA personal data internationally, we use appropriate safeguards: the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, transfers to countries covered by adequacy decisions or regulations, and providers certified under the EU-US Data Privacy Framework (and its UK Extension) where applicable. For Reach, this review also covers Apify and any separately approved community-actor creator before that actor is used. You can ask us at privacy@axiasignalsgroup.com for more information about the safeguards used.
8. How long we keep data
We keep personal data only as long as needed for the purposes above:
- Account and profile data: for as long as your account exists. If you delete your account, we delete or anonymise this data within 30 days from live systems and within 90 days from backups, as described on our Data Deletion page.
- Tool data (tracked bets, watchlists, alerts): with your account, deleted on the same schedule.
- Billing and transaction records: up to 7 years after the transaction, as required for tax, accounting and audit.
- Support and complaint correspondence: up to 24 months after resolution, longer if needed for a legal claim.
- Marketing suppression: if you unsubscribe, we keep your email on a suppression list so we do not contact you again.
- Analytics: held in identifiable form no longer than needed, then aggregated or anonymised; anonymised statistics may be kept indefinitely.
- Clickout records: kept as long as needed to reconcile commissions and detect fraud, then aggregated.
- Reach discovered-prospect and observation data: raw handles, biographies and other readable fields about a discovered prospect are scheduled for deletion no later than 30 days from the relevant observation. A valid objection or deletion request, explicit youth evidence or another exclusion starts the earlier deletion workflow. Provider storage is also due for deletion within the applicable period. A failed provider deletion remains isolated in an audited recovery state and is manually requeued until a verified provider receipt is recorded; it is not returned to the operator worklist. Approved public source-account references are kept only while the source remains approved and necessary, and are deleted when that approval or need ends. We may keep a one-way keyed suppression token for as long as needed to honour an objection or deletion and prevent the same handle being imported again. The token does not reveal the handle and is not used for marketing. Minimised, pseudonymised operational and audit records are kept only for the documented legal, security and accountability period.
Where deletion is requested but law requires retention (for example tax records or data relevant to a dispute), we keep the minimum required, isolate it, and delete it when the requirement ends.
9. How we protect data
We use technical and organisational measures appropriate to the risk: encryption in transit (TLS), encrypted storage with our infrastructure providers, row-level access controls in our database, least-privilege internal access, separate production credentials, webhook signature verification for billing events, and logging. Full payment card data is handled only by our PCI DSS compliant payment providers and never reaches our servers. No internet service can promise perfect security, but if a breach affects your data we will notify you and regulators where the law requires.
10. Your rights: UK and EEA
If you are in the UK or EEA, you have the right to:
- Access the personal data we hold about you, and receive a copy;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten") in the circumstances set out in law, and via the self-service deletion described on our Data Deletion page;
- Restrict processing in certain circumstances;
- Portability: receive data you provided in a structured, commonly used, machine-readable format;
- Object to processing based on legitimate interests, and to direct marketing at any time (marketing objections are always honoured);
- Withdraw consent at any time, where processing is based on consent;
- Not be subject to solely automated decisions with legal or similarly significant effects (we do not make such decisions about you).
To exercise these rights, use Account Settings, the Data Deletion page, or email privacy@axiasignalsgroup.com. If you do not have a SportSignals account and your request concerns Reach, include the public Instagram handle and profile URL concerned. We may ask for reasonable evidence that the request relates to you, but we will never ask for your Instagram password, session or cookie. We will respond within one month (extendable by two months for complex requests, with an explanation). Exercising rights is free, unless a request is manifestly unfounded or excessive.
You also have the right to complain to us directly, which we encourage as the fastest route: email privacy@axiasignalsgroup.com and we will acknowledge within 2 business days. You can additionally complain to your supervisory authority: in the UK, the Information Commissioner (ico.org.uk); in the EEA, your national data protection authority.
11. Your rights: US states
If you live in a US state with a comprehensive privacy law (as of 2026 this includes California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia), you may have the right, subject to that law's conditions and thresholds, to:
- Know and access the personal data we process about you, and obtain a copy in a portable format;
- Correct inaccurate personal data;
- Delete personal data we hold about you;
- Opt out of the "sale" of personal data, "sharing"/processing for targeted advertising, and profiling in furtherance of decisions with legal or similarly significant effects (we do not conduct such profiling);
- Non-discrimination: we will not deny you the Service, charge different prices or reduce quality because you exercised a privacy right.
How to exercise these rights: email privacy@axiasignalsgroup.com with the subject "Privacy request", or use Account Settings and the Data Deletion page. We normally verify an account request by confirming control of the account email. If you do not have a SportSignals account and your request concerns Reach, include the public Instagram handle and profile URL concerned; we may ask for reasonable evidence that the request relates to you, but never for your Instagram password, session or cookie. We respond within 45 days, extendable once by 45 days where reasonably necessary. Authorised agents may submit requests where your state allows; we will verify the agent's authority and your identity.
Opt-out of targeted advertising / "sale" / "sharing": we do not sell personal data for money. To the extent advertising or affiliate cookies are treated as "sharing" or a "sale" under your state's law, you can opt out via the cookie settings link in the site footer, and we honour the Global Privacy Control (GPC) browser signal as a valid opt-out request in states that require it.
Appeals: if we decline your request, we will explain why, and you may appeal by replying with the subject "Privacy appeal". We will respond to appeals within the period your state's law requires (generally 45 to 60 days). If your appeal is denied, you may contact your state Attorney General; in California, the California Privacy Protection Agency.
California notice at collection (summary): we collect the following categories of personal information as described in Section 2: identifiers (including names, email and IP addresses, account identifiers and, where Reach is enabled, public social handles and profile identifiers), customer records (subscription and billing records, excluding full card numbers), commercial information (subscription history and clickout events), internet or network activity (usage and device data and limited public post or comment provenance), approximate (country-level) geolocation, and inferences including service preferences and, where Reach is enabled, limited region, adult-or-business suitability and internal review-priority signals. We collect them for the purposes in Section 3, retain them per Section 8, and disclose them to the categories of recipients in Section 5. Apart from account log-in credentials used solely to provide the account, Reach is designed not to target, infer or use sensitive personal information. Public-source material can incidentally contain sensitive context; if identified, it is isolated and placed into the deletion workflow rather than used for a purpose the CCPA treats as requiring a right to limit. Reach does not target children, but public-source material can initially include a profile belonging to a child before it is identified and excluded (Section 13). We do not knowingly sell or share the personal information of consumers under 16.
12. Rights everywhere else
Wherever you live, you can access and update your account data in Account Settings, download your data, delete your account via the Data Deletion page, unsubscribe from marketing, and contact us with any privacy question or request at privacy@axiasignalsgroup.com. We extend the spirit of the rights above to all users where practicable.
13. Children
The Service is for adults. You must be 18 or older to use it, and we do not knowingly permit anyone under 18 to use it. Reach does not target children, but public-source material can initially include a profile belonging to a child. Explicit youth evidence excludes the profile from the operator worklist and starts the deletion workflow, and an account with unknown age does not enter that worklist unless a human reviewer records an approved adult or business-account signal. Reach does not use appearance to infer age. If you believe a person under 18 has an account or has appeared in Reach, contact privacy@axiasignalsgroup.com and we will isolate the data, complete the deletion workflow and prevent re-import.
14. Automated decision-making
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Our sports prediction model analyses sporting events and bookmaker prices, not you. Automated processes we do use on personal data are limited to things like routing the right regional content, metering free allowances, detecting fraud and abuse (a person reviews before we suspend or close an account on that basis; automated checks may limit promotional eligibility, for example one free trial per person), and personalising content within the Service. If Reach is enabled, it may score limited public profile and interaction signals to prioritise a human suitability-review queue. A profile with unknown suitability may be reviewed there, but cannot enter the operator worklist or trigger an action unless a human records approved adult or business-account evidence. The score never contacts a person or performs an Instagram action.
15. Do Not Track and opt-out signals
We honour the Global Privacy Control signal as described in Sections 6 and 11. Because there is no common industry standard for legacy "Do Not Track" browser signals, we do not respond to them; GPC and our cookie settings are the reliable controls.
16. Changes to this policy
We may update this policy from time to time. The "Last updated" date shows the current version. If we make material changes, we will notify you (by email if you have an account, or by a notice on the Service) before they take effect. Earlier versions are available on request.
17. Contact us
Axia Signals Group LLC (SportSignals) 500 Paterson Plank Rd, STE 31016, Union City, NJ 07087, USA Privacy requests: privacy@axiasignalsgroup.com Support: support@sportsignals.com · General: hello@sportsignals.com
