CLEAR INFORMATION, BEFORE YOU ENTER
Privacy.
No real-money launch, legal approval or live postal-entry service is claimed.
Draft privacy notice — professional review required Version draft-v1, 3 October 2026. Use fictional information in this sandbox.
Controller: [OWNER LEGAL ENTITY], [ADDRESS], [PRIVACY CONTACT]. ICO registration/fee assessment: [OWNER TO COMPLETE]. This notice must be finalised before collecting real entrant data.
Current processing The sandbox stores account email, a salted scrypt password hash, self-declared name, date of birth, region and postcode; random participant and entry identifiers; orders and signed payment-event digests; raw postal intake and decisions; sessions; operational and audit records; selected-winner verification notes, fictional payout references and sandbox inbox messages. No card numbers or bank details are collected. Postal data is entered by operators from fictional training submissions. Provider events are sandbox events, not evidence of money received. IP-derived hashes are used for short-term login/registration rate limiting; they are not anonymous if linkable.
Purposes and draft lawful bases Proposed contract processing: accounts, accepted orders, entry administration, winner contact and prize fulfilment. Proposed legitimate interests: proportionate security, fraud prevention, audit and service support, subject to documented balancing. Legal obligation only where an identified applicable obligation requires retention/disclosure. Marketing would require a separately reviewed basis and applicable electronic-marketing consent; no marketing feature is implemented. Accepting terms does not create blanket data-protection consent. Do not collect more verification data than the reviewed process needs.
Sharing and international transfers Current processing is local to this deployment. No provider or marketing network receives data from the sandbox. Planned processors include [HOST], [APPROVED PAYMENT PROVIDER], [POSTAL PROCESSOR], [EMAIL/SUPPORT] and [VERIFICATION PROVIDER]; choose contracts, locations, safeguards and any transfer assessment before enabling them. Disclosure to regulators, advisers or courts must be limited to a valid purpose and basis. The developer does not invent controller/processor approvals.
Retention and protection Sessions expire after eight hours; logout or an operator password reset revokes sessions. The manager recovery/tick action deletes expired sessions and rate-limiter windows older than 24 hours. Automatic scheduling and wider privacy retention/pseudonymisation require further implementation. Draft live schedule for professional/accounting review: expire session rows daily; remove short-term authentication limiter data after 24 hours; delete ordinary support/intake material after [PERIOD]; retain necessary transaction/audit and winner evidence for [JUSTIFIED PERIOD]; expire backups after [PERIOD]. None of these unresolved periods should be presented as settled law. The database contains personal data in plaintext at rest; use encrypted host storage/backups, restricted access and tested deletion/pseudonymisation. Immutable evidence does not justify indefinite retention of identifying data.
Your rights Depending on the circumstances, you may request access, rectification, erasure, restriction, portability and object to processing; withdraw consent where consent is used. Contact [PRIVACY CONTACT]. Verify identity proportionately and respond within the applicable time requirements, considering exceptions lawfully. These processes are manual and unstaffed in the sandbox. You may complain to the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/ .
Winner evidence Public draw evidence exposes high-entropy entry tokens, counts, hashes, seed reveal, result and timestamps, not entrant names or contact details. This is data minimisation, not a guarantee of anonymity. A live winner-publication notice, ability to object or reduce publication and handling of legitimate regulatory requests still require review. No automated eligibility decision based on profiling is implemented; operators decide postal records, while the stated random process selects a token.
See cookie information for device storage. Controller identity, lawful bases, retention, processor arrangements and rights/incident procedures are real-money launch gates.