Last Updated: August 29th, 2018
CryptoSports is the first Ethereum blockchain games that offers players to
engage in fantasy sports contests and other sports betting activities using
using certified ownership of real-world athlete tokens. CryptoSports™
was created by CryptoSports, Inc. (the "Company").
The Company is committed to protecting and respecting your privacy. This Privacy
Policy (this “Policy”) sets out how we collect and process personal information
about you when you visit our website at https://cryptosports.team, when you use our
mobile dapp, when you enter or create contests (“Contests”), when you trade
digital assets in our market ("Marketplace"), or when you otherwise do business
or make contact with us.
What information is collected?
The Company collects data to enable us to operate our website, Contests, and our digital
Marketplace (collectively, our "Services") effectively, and to provide you with the best user experiences. You provide
some of this data to us directly, such as when you register to use our Marketplace, subscribe
to a newsletter, respond to a survey, make an enquiry through our website, contact us for
support, or contact us as a prospective user, vendor, supplier, or consultant. We get some
of your data by recording how you interact with our website, Marketplace, and our Contests
by, for example, using technologies like cookies or local storage in your web browser.
We also obtain and process data in the context of making the Marketplace and Contests
available to you.
You have choices about the data we collect. When you are asked to provide personal data,
you may decline. But if you choose not to provide data that is necessary to enable us
to make the Marketplace or Contests available to you, you may not be able to interact
with our website. The data we collect depends on the context of your interactions with
the Company, and the choices you make (including your privacy settings). The data we
collect can include the following:
Email and Metamask Wallet Address. We may collect your email address and
your Metamask wallet address.
Device and Usage information. We may collect data about your device and
how you and your device interact with the Company and our Services. For example, we may
collect your interactions on our website, your feature usage patterns, location
data, and your interactions with us. We may also collect data about your device
and the network you use to connect to our Service; this may include data such as
your IP address, browser type, operating system, and referring URLs.
What do we use your information for?
We use the data we collect to operate our business, and to make the Services available
to you. This includes using the data to improve our Services, and to personalize your
experiences. We may also use the data to communicate with you to, among other
things, inform you about your account, provide security updates, and give you
information about the Service. We may also use the data to manage your email
subscriptions, improve the relevance and security of our website, respond to
user enquiries, send you periodic marketing communications about our Services,
and improve the relevance of our advertising.
We use data to provide the Services to you, to improve the Services, and to perform
essential business operations. This includes operating the Services, maintaining
and improving the performance of the Services, developing new features, conducting
research, and providing customer support. Examples of such uses include the following:
Providing our Services. We use data
to carry out your transactions with us and to make the Services available to you.
In certain cases, the Services may include personalized features and recommendations
to enhance your enjoyment, and automatically tailor your experience based on the
data we have about you.
Technical support. We use data to diagnose problems, and to provide customer
care and other support services.
Improving the Services. We use data to continually improve our website and our Services,
including system administration, system security, and adding new features or capabilities.
Business Operations. We use data to develop aggregate analyses and business
intelligence that enable us to operate, protect, make informed decisions, and report
on the performance of our business.
Promotions. We may use your data to administer contests, promotions, surveys,
or other site features.
Improving Advertising Campaigns. We may use your data to improve our advertising
campaigns, primarily in an effort to prevent targeting you with advertisement that are
not relevant to you.
Communications. We use data we collect to communicate with you, and to personalize
our communications with you. For example, we may contact you to discuss your account,
to remind you about features of the Services that are available for your use, to update you
about a support request, or to invite you to participate in a survey. Additionally, you
can sign up for email subscriptions, and choose whether you want to receive marketing
communications from us.
Sending Periodic Emails. We may use your data to send you periodic emails. Depending
on the marketing preferences you select on your privacy dashboard we may send you occasional
marketing emails about our Services, which you can unsubscribe from at any time using the
link provided in the message.
Generally. We use data to respond to your enquiries and requests relating to our
Services, to create and administer your account, and to provide us with information and
access to resources that you have requested from us. We also use data for general
business purposes, including, among other things, to improve customer service, to help
us improve the content and functionality of our Services, to better understand our users,
How do we protect your information?
We implement a variety of security measures to maintain the safety of your personal information when you enter, submit, or access your personal information. We offer the use of a secure server. All supplied sensitive information is transmitted via Secure Socket Layer (SSL) technology and then encrypted into our gateway providers database only to be accessible by those authorized with special access rights to such systems, and are required to keep the information confidential.
How do we ensure that our processing systems remain confidential, resilient, and available?
We implement a variety of measures to ensure that our processing systems remain confidential, resilient, and available. Specifically, we have implemented processes to help ensure high availability, business continuity, and prompt disaster recovery. We commit to maintaining strong physical and logical access controls, and conduct regular penetration testing to identify and address potential vulnerabilities.
High Availability. Every part of the Services utilizes properly-provisioned, redundant servers (e.g., multiple load balancers, web servers, replica databases) in case of failure. We take servers out of operation as part of regular maintenance, without impacting availability.
Business Continuity. We keep encrypted backups of data daily in multiple regions on the Amazon AWS cloud platform. While never expected, in the case of production data loss (i.e., primary data stores loss), we will restore organizational data from these backups.
Disaster Recovery. In the event of a region-wide outage, we will bring up a duplicate environment in a different AWS region. Our operations team has extensive experience performing full region migrations.
Physical Access Controls. CryptoSports hosted on Amazon Web Services ("AWS"). AWS data centers feature a layered security model, including extensive safeguards such as custom-designed electronic access cards, alarms, vehicle access barriers, perimeter fencing, metal detectors, and biometrics. According to the AWS Security Whitepaper: “AWS’s data centers are state of the art, utilizing innovative architectural and engineering approaches. Amazon has many years of experience in designing, constructing, and operating large-scale data centers. This experience has been applied to the AWS platform and infrastructure. AWS data centers are housed in nondescript facilities. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication a minimum of two times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff.” The Company's employees do not have physical access to Google or AWS data centers, servers, network equipment, or storage.
Logical Access Controls. the Company is the assigned administrator of its infrastructure on AWS, and only designated authorized Company operations team members have access to configure the infrastructure on an as-needed basis behind a two-factor authenticated virtual private network. Specific private keys are required for individual servers, and keys are stored in a secure and encrypted location.
Intrusion Detection and Prevention. Unusual network patterns or suspicious behavior are among the Company’s biggest concerns for infrastructure hosting and management. AWS’s intrusion detection and prevention systems (IDS/IPS) rely on both signature-based and algorithm-based security to help identify traffic patterns that are similar to known attack methods. IDS/IPS involves tightly controlling the size and make-up of the attack surface, employing intelligent detection controls at data entry points, and developing and deploying technologies that automatically remedy dangerous situations, as well as preventing known threats from accessing the system in the first place. We do not provide direct access to security event forensics, but we do provide access to our engineering and customer support teams during and after any unscheduled downtime.
Yes. Cookies are small files that a site or its service provider transfers to your computers hard drive through your Web browser (if you allow) that enables the sites or service providers systems to recognize your browser and capture and remember certain information. You can choose to disable cookies, but if you do, your ability to use or access certain parts of the Services or of our website may be affected.
You may refuse to accept cookies by activating the setting on your browser that allows you to refuse the setting of cookies. You can find information on popular browsers and how to adjust your cookie preferences at the following websites:
Our web pages may contain electronic images known as web beacons (also called single-pixel gifs) that we use to help deliver cookies on our websites, and to count users who have visited those websites. We may also include web beacons in our promotional email messages or newsletters, to determine whether and when you open and act on them.
In addition to placing web beacons on our own websites, we sometimes work with other companies to place our web beacons on their websites or in their advertisements. This helps us to develop statistics on how often clicking on an advertisement on a Company website results in a purchase or other action on the advertiser's website.
Finally, our Services may contain web beacons or similar technologies from third-party analytics providers that help us compile aggregated statistics about the effectiveness of our promotional campaigns or other operations. These technologies enable the analytics providers to set or read their own cookies or other identifiers on your device, through which they can collect information about your online activities across applications, websites or other products.
Do we disclose any information to outside parties?
We share your personal data with your consent, or as necessary to make the Services available to you. We also share your data with vendors working on our behalf; when required by law or to respond to legal process; to protect our customers; to protect lives; to maintain the security and integrity of our Services; and to protect our rights or our property.
We share your personal data with your consent, or as necessary to make the Services available to you. We also share personal data with vendors or agents working on our behalf for the purposes described in this Policy. For example, companies we have hired to provide cloud hosting services, off-site backups, and customer support may need access to personal data to provide those functions. In such cases, these companies are required to abide by our data privacy and security requirements and are not allowed to use personal data they receive from us for any other purpose. The current list of vendors that we use to help us make the Services available to you can be found here. We will update this list from time to time as the list of vendors changes. If you have questions or concerns about any of our vendors, feel free to contact us at email@example.com.
We may disclose your personal data as part of a corporate transaction such as a corporate sale, merger, reorganization, dissolution, or similar event. Finally, we will access, transfer, disclose, and/or preserve personal data, when we have a good faith belief that doing so is necessary to:
We may use and share aggregated non-personal information with third parties for marketing, advertising, and analytics purposes. We do not sell or trade your personal information to third parties.
comply with applicable law or respond to valid legal process, judicial orders, or subpoenas;
respond to requests from public or governmental authorities, including for national security or law enforcement purposes;
protect the vital interests of our users, customers, or other third parties (including, for example, to prevent spam or attempts to defraud users of our products, or to help prevent the loss of life or serious injury of anyone);
operate and maintain the security or integrity of our Services, including to prevent or stop an attack on our computer systems or networks;
protect the rights, interests or property of the Company or third parties;
prevent or investigate possible wrongdoing in connection with the Services; or
How to Access and Control Your Personal Data
You can view, access, edit, delete, or request a copy of your personal data for many aspects of the Services via your user dashboard. You can also make choices about the Company’s collection and use of your data. You can always choose whether you want to receive marketing communications from us. You can also opt out from receiving marketing communications from us by using the opt-out link on the communication, or by visiting your user dashboard.
- Data Access. You can access your personal data on your account’s user dashboard.
- Data Portability. You can request a copy of your personal data by submitting an email to us at firstname.lastname@example.org and including “Please send me a copy of my personal data” in the “Subject” line. The Company may verify your ability to access that email, then send you a digital export of the data we hold that is associated with your email address. We will use reasonable efforts to respond to your request within 14 days, but in all events within 30 days of our receipt of the request. The Company may be limited in its ability to send certain personal data to you (e.g., the identification of your Metamask wallet).
- Data Erasure. You can delete your personal data on your account’s user dashboard. Please be aware that we require certain information about you in order to make the Services available to you; this means that if you want to delete any of these critical pieces of personal data, you may be required to delete your entire profile and no longer be able to access or play the Services. Alternatively, you may request that the Company delete your personal data by submitting an email to us at email@example.com and including “Please delete my personal data” in the “Subject” line. The Company will verify your ability to access that email, then delete the personal data associated with your email address. We will use reasonable efforts to respond to your request within 14 days, but in all events within 30 days of our receipt of the request.
- Data Correction. You can modify your personal data on your account’s user dashboard. Note that since some of the data we collect is specific to you – for example, your Metamask wallet address – you may not be able to modify this data without needing to create a new user profile.
- Your Communications Preferences. You can choose whether you wish to receive marketing communications from us. If you receive marketing communications from us and would like to opt out, you can do so by following the directions in that communication. You can also make choices about your receipt of marketing communications by signing into your account, and viewing and managing your communication permissions in your account’s user dashboard, where you can update contact information, manage your contact preferences, opt out of email subscriptions, and choose whether to share your contact information with the Company and our partners. Alternatively, you can request that we withdraw consent to use your personal data by submitting an email to us at firstname.lastname@example.org and including “Please withdraw my consent for marketing communications” in the “Subject” line. The Company may verify your ability to access that email, then update our systems to remove your email address from the system we use to send marketing communications. We will use reasonable efforts to respond to your request within 14 days, but in all events within 30 days of our receipt of the request. Please note that these choices do not apply to mandatory communications that are part of the Services, or to surveys or other informational communications that have their own unsubscribe method.
Third Party Links
Occasionally, at our discretion, we may include or offer third party products or services on our website or through our Services. If you access other websites using the links provided, the operators of these websites may collect information from you that will be used by them in accordance with their privacy policies. These third party sites have separate and independent privacy policies. We, therefore, have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about these sites.
Where we Store and Process Personal Data; International Transfers
Personal data collected by the Company may be stored and processed in United States or in any other country where the Company or its affiliates, subsidiaries or service providers maintain facilities. The storage location(s) are chosen in order to operate efficiently, to improve performance, and to create redundancies in order to protect the data in the event of an outage or other problem. We take steps to ensure that the data we collect is processed according to the provisions of this Policy, and the requirements of applicable law wherever the data is located.
We transfer personal data from the European Economic Area and Switzerland to other countries, some of which have not been determined by the European Commission to have an adequate level of data protection. When we engage in such transfers, we use a variety of legal mechanisms, including contracts, to help ensure your rights and protections travel with your data. To learn more about the European Commission’s decisions on the adequacy of the protection of personal data in the countries where the Company processes personal data, please visit: ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.htm
We may retain your personal information as long as you continue to use the Services, have an account with us, or for as long as is necessary to fulfill the purposes outlined in this Policy. You can ask to close your account by contacting us as described above, and we will delete your personal information on request. We may, however, retain personal information for an additional period as is permitted or required under applicable laws, for legal, tax, or regulatory reasons, or for legitimate and lawful business purposes.
We will retain your personal data for as long as necessary to make the Services available to you, or for other essential purposes such as complying with our legal obligations, resolving disputes, and enforcing our agreements. Because these needs can vary for different types of data, actual retention periods can vary significantly. The criteria we use to determine the retention periods include:
How long is the personal data needed to make the Services available to you and/or operate our business? This includes such things such as maintaining and improving the performance of the Services, keeping our systems secure, and maintaining appropriate business and financial records. This is the general rule that establishes the baseline for most data retention periods.
Is there an automated control, such as in your user dashboard, that enables you to access and delete the personal data at any time? If there is not, a shortened data retention time will generally be adopted.
Is the personal data of a sensitive type? If so, a shortened retention time would generally be appropriate.
Has the user provided consent for a longer retention period? If so, we will retain the data in accordance with your consent.
Is the Company subject to a legal, contractual, or similar obligation to retain the data? Examples can include mandatory data retention laws in the applicable jurisdiction, government orders to preserve data relevant to an investigation, or data that must be retained for the purposes of litigation.
We will update this privacy statement when necessary to reflect customer feedback and changes to our Services. When we post changes to this statement, we will revise the "last updated" date at the top of the statement. If there are material changes to the statement or in how the Company will use your personal data, we will notify you either by prominently posting a notice of such changes before they take effect or by sending you a notification directly. We encourage you to periodically review this privacy statement to learn how the Company is protecting your information.
How to Contact Us
If you have a technical or support question, please send us an email at email@example.com. If you have a privacy concern, complaint, or a question for the Data Protection Officer of the Company, please contact us by sending us an email at firstname.lastname@example.org. We will respond to questions or concerns within 30 days. Unless otherwise stated, the Company is a data controller for personal data we collect through the Services subject to this statement. Our address is CryptoSports Inc., 44 Brookford Street, Cambridge, MA 02140.