1Who is responsible for your data
VARstats is run by an individual developer, Merdan Allaberdiyev. For any question about your data: info@varstats.com.
2What we collect
Account: email address, nickname, interface language, and your password — stored only as a one-way hash. If you sign in with Google or Apple, we receive that provider’s account identifier and the email address it shares (Apple may share a private relay address).
Settings and use: favourite teams; if you connect the Telegram bot, your Telegram user ID and username, chat identifier, language and chosen notifications.
Technical data: IP address and browser or device details when you sign in and for active sessions, and a history of sign-in attempts — to protect accounts from password guessing.
Payments: plan, amount, date and the provider’s transaction number. We never receive or store card numbers or other payment details — the payment provider handles them.
Website: visit statistics through Yandex Metrica, including Session Replay (Webvisor: scrolling, clicks and pointer movement on the page), and through Google Analytics. For its own visit count, the site stores a random visitor identifier in your browser; if you are signed in, the visit is linked to your account. The mobile app does not use any of these tools.
Contact form: name, email address, message text and the sender’s IP address.
Errors: when something fails on our server, error details are sent to the Sentry monitoring service. Headers, cookies, request content and user details are removed before sending, but the error text itself may occasionally contain individual data.
3Why
To run your account and sign you in; to unlock access you have paid for and answer payment questions; to send service emails (email confirmation, password reset, receipts, end of trial) and occasional promotional emails — you can opt out by replying to one or writing to info@varstats.com; to protect the service from break-ins and abuse; to find and fix errors; and to understand which parts of the website are used.
We do not sell data or share it with advertising networks. We are not affiliated with any bookmaker: the website and the app contain no affiliate links or bookmaker advertising, we receive no money from bookmakers and pass nothing about you to them.
4Who receives data
Only those the service cannot work without, and only as much as needed: payment providers — Stripe (cards), NOWPayments (cryptocurrency), Apple, Google Play and RevenueCat (in-app purchases; RevenueCat receives your account identifier to link a purchase to it, plus device details and IP address); Google and Apple — when you sign in with them; Yandex and Google — website visit statistics; Sentry — error details; Telegram — bot messages, if you connected it; our email provider — to deliver emails; and the hosting provider whose servers run the service.
We may also disclose data where the law requires it.
5How long we keep it
Account data — for as long as the account exists. Sessions are deleted within a day after they expire. The sign-in attempt log, contact-form messages and payment providers’ notifications (which may include an email address) are kept to protect accounts, for accounting and for payment disputes.
When an account is deleted, its email and nickname are erased, while payment records are kept for accounting together with the providers’ notifications. On request to info@varstats.com we will delete these too, unless the law requires us to keep them.
6Your rights and account deletion
You can ask what data we hold about you, correct it, or delete it. To delete your account, use the app: Profile → “Delete account”, or email info@varstats.com. An account without payments is deleted completely; one with payments is anonymised. A subscription bought through the App Store or Google Play must be cancelled separately in the store settings. Full details: varstats.com/en/delete-account.
7Cookies
The website uses cookies to keep you signed in and remember your language, Yandex Metrica and Google Analytics cookies for statistics, and stores an identifier in your browser (localStorage) for counting visits. You can delete or block all of this in your browser settings; without the sign-in cookie the site cannot keep you signed in.
8Security
Connections are encrypted (HTTPS), passwords are stored only as hashes, and server access is restricted. In the app, sign-in data is kept in the device’s secure storage.
9Age
The service is intended for people aged 18 and over. We do not knowingly collect data from minors; if such data has reached us, contact us and we will delete it.
10Changes
We may update this policy; the date at the top shows the latest version. We will announce material changes on the website.
11Contact
info@varstats.com or the contact page on the website.
