Loading...
Loading...
Last updated: June 6, 2026
At PrediPick we take your privacy very seriously. This policy describes what personal data we collect, how we use it, with whom we share it and what rights you have over it. By using our site, you accept the practices described below.
PrediPick is an interactive sports prediction and simulation platform focused on the 2026 FIFA World Cup. The site is operated from Argentina and you can contact us at any time at hello@predipick.com for privacy-related matters.
We collect the following categories of data: • Account data: email address, full name and profile picture (when you sign in with Google or provide them when registering). • Usage data: your predictions, simulations, daily challenge answers, unlocked achievements, leagues you participate in, referrals you invite and general activity on the site. • Newsletter data: email address if you voluntarily subscribe. • Technical data: IP address, browser type and version, language, country of origin and access timestamps (automatically collected by Vercel and Supabase). • Technical cookies: cookies strictly necessary to keep your session active. We do not use advertising or tracking cookies.
We use your personal data exclusively to: • Create and maintain your user account. • Store and display your predictions, simulations, progress in daily challenges, achievements and ranking. • Allow your participation in leagues with other users and manage the referrals you invite. • Send you transactional communications: Magic Link sign-in emails, account confirmations and service-related notifications. • Send you the blog newsletter, only if you voluntarily subscribed. You can unsubscribe at any time from the footer of each email. • Improve the product through aggregated and anonymous usage analytics. • Prevent fraud, abuse and attacks (rate limiting, bot detection, account protection).
To operate PrediPick we share strictly necessary data with the following providers: • Supabase (United States): database, user authentication, image storage. Their servers may be in the US or EU. • Google OAuth: when you sign in with Google, we receive your email, name and profile picture. Google does not receive any data from PrediPick except for the authentication flow itself. • Vercel (United States): site hosting and global CDN. Receives your IP address and technical data from each request. • Zoho Mail (India / global): transactional email delivery (Magic Link) and newsletter. Receives your email address and, for newsletters, aggregated open metrics. • DeepSeek (China): only generic prompts are sent to generate blog post drafts when an administrator requests it. No user personal data is sent. • Pixabay and Unsplash: stock image downloads for blog posts. No personal data is shared. • flagcdn: flag icon service. No personal data is shared. • Upstash (optional): rate limiting with Redis. Temporarily stores anonymous counters associated with your IP to prevent abuse. All these providers have their own privacy policies and comply with international data protection standards.
PrediPick uses only strictly necessary technical cookies to keep your session active, managed by Supabase Auth. We do not use advertising tracking cookies, third-party cookies for commercial purposes, or behavioral analytics cookies. You can configure your browser to block or delete cookies, but this may prevent you from signing in correctly.
As a user, you have the following rights over your personal data: • Access: you can request a copy of all data we have about you. • Rectification: you can correct incorrect data from your profile or by requesting it via email. • Deletion: you can request the complete deletion of your account and all associated data at any time. • Portability: you can download your data in a structured and portable format (JSON). • Opposition and limitation: you can object to the processing of your data or request that it be limited in specific circumstances. • Withdrawal of consent: if processing is based on your consent, you can withdraw it at any time. To exercise any of these rights, write to us at hello@predipick.com and we will respond within a maximum of 30 calendar days.
We retain your personal data while your account is active. If you delete your account, all associated personal data is permanently deleted within a maximum of 30 days, except for data we must retain due to legal obligation (for example, tax or audit records) or to resolve pending disputes.
We implement reasonable technical and organizational measures to protect your data: • HTTPS/TLS encryption in transit between your browser and our servers. • Encryption at rest in the database and stored files. • Row Level Security (RLS) in Supabase: each user can only access their own data. • Restricted access to the administration panel, protected by authentication and role verification. • Passwords and tokens managed exclusively by Supabase Auth: we never store or have access to your password in plain text. • HTTP security headers (CSP, HSTS, X-Frame-Options) to prevent common attacks. Despite these measures, no system is 100% secure. If you detect a vulnerability, please contact us immediately at hello@predipick.com.
PrediPick is intended for users over 13 years of age. We do not intentionally collect personal data from children under 13. If a parent or guardian detects that a child under 13 has registered, please contact us at hello@predipick.com and we will delete the account and all associated data within 7 days.
We may update this privacy policy periodically to reflect changes in our practices, services or legal requirements. We will notify you by email or through a visible notice on the site if the changes are significant. The date of the last update always appears at the beginning of this page. We recommend reviewing it periodically.
For any questions, requests or complaints related to your privacy or the processing of your personal data, you can write to us at: 📧 hello@predipick.com We commit to responding within a maximum of 30 calendar days. If you consider that we have not adequately resolved your inquiry, you have the right to file a complaint with the data protection authority in your country.
This policy is written in Spanish and English. In case of discrepancy between versions, the Spanish version prevails.