Privacy Policy
Last updated: July 18, 2026
1. Introduction
SmartBet Lab ("we," "our," or "us") provides a sports betting tracking and analytics platform at smartbetlab.io. This policy describes, plainly and accurately, what data we collect, what we do with it, who processes it on our behalf, and the controls you have, including one-click export and one-click permanent deletion of everything.
If you do not agree with this policy, please do not use the service.
2. Information We Collect
Account information
- Your email address (used for passwordless sign-in links) and optional name and avatar
- Your preferences: language, currency, timezone, odds format, notification and bankroll settings
- We never collect or store a password. Sign-in is by magic link to your email
Betting data you bring
- Bets you sync via the browser extension, add manually, import from CSV, or scan from a slip photo
- Strategies, notes and bankroll transactions you create
- Analytics computed from the above (ROI, CLV, Sharp Score, tilt signals)
Payment information
- Payments are processed by Stripe. Card numbers never touch our servers. We store only your subscription plan, status and invoice history
Optional community data
- A public profile (handle, display name, bio) and leaderboard participation exist only if you explicitly opt in; public surfaces show scores and percentages, never currency amounts
Technical information
- Our own visit counter for public pages stores the page path, referrer domain and campaign tag only: no IP address, no device fingerprint, no user identity
- Standard server and error logs (which can include IP addresses) are kept transiently by our hosting and error-monitoring providers for security and debugging
- Messages you send through the contact form
3. How We Use Your Information
- To run the product: compute your analytics, settle your bets, send the reports you enabled
- To process subscriptions and apply the features of your plan
- To power the AI features you invoke, using your own betting record as context
- To respond when you contact support
- To keep the service secure and prevent abuse (rate limiting, error monitoring)
- To measure, in aggregate and anonymously, which public pages are visited
We do not sell your data, show ads, or use your data for advertising. We never share your betting data with bookmakers.
4. Services That Process Data for Us
We rely on a small set of established providers, each receiving only what its job requires:
- Supabase: database and authentication; our database is hosted in the European Union
- Vercel: application hosting and delivery
- Stripe: payment processing and tax handling
- Resend: transactional email (sign-in links, reports you enabled)
- Upstash: rate limiting and caching
- Sentry: error monitoring, so failures get fixed
- OpenAI: powers the optional AI features (coach, analyst, slip reader); relevant parts of your betting record are sent only when you use those features, under API terms that do not permit training on your data
- The Odds API: supplies market odds to us; none of your data is sent to it
Beyond these processors, we disclose information only with your consent, to comply with legal obligations, or to protect our rights and users' safety.
5. Data Security
- All traffic is encrypted in transit (TLS); the database is encrypted at rest by our provider
- Passwordless sign-in means there is no password database to steal
- Database row-level security ensures each account can only ever read its own rows
- The sync extension uses a revocable, import-only token, never your bookmaker credentials
- Encrypted database backups are taken weekly and expire automatically after 90 days
No system is perfectly secure, but we have designed the service so the most damaging classes of breach (password leaks, bookmaker credential theft), are structurally impossible, because we never hold those secrets at all.
6. Your Rights and Controls
The two rights that matter most are self-serve, no email, no waiting:
- Export: Settings → Account & Data → download a complete JSON file of everything we store about you, any time, on any plan
- Deletion: Settings → Account & Data → permanently delete your account. This cancels any paid subscription immediately, erases all your data and removes your login. It is instant and irreversible
You can also correct your details in Settings at any time. For anything else. Restriction, objection, or questions about this policy. Reach us via the contact page and we will respond as required by applicable law (including the GDPR where it applies).
7. Cookies
We use a small number of first-party cookies, all functional:
- Session cookies: keep you signed in (essential)
- Language cookie: remembers your chosen language
- Attribution cookies: remember how you first arrived (e.g. from a referral link or campaign) so referrals can be credited; they expire automatically
We use no third-party advertising or tracking cookies of any kind.
8. Data Retention
- Your data is retained while your account exists and is erased when you delete it
- Encrypted backups expire automatically within 90 days of being taken
- Anonymous public-page visit records are trimmed after 180 days
- Provider-side logs (hosting, error monitoring, email delivery) expire on those providers' standard short schedules
- Invoice records held by Stripe persist as required by financial regulations
9. International Transfers
Our primary database is hosted in the European Union. Some providers listed in section 4 process data in other jurisdictions (including the United States) under recognized safeguards such as Standard Contractual Clauses.
10. Age Requirement
SmartBet Lab is strictly for adults aged 18 or older (or the legal gambling age in your jurisdiction, if higher). We do not knowingly collect information from anyone under 18; if we become aware of such an account, we will delete it.
11. Browser Extension
The SmartBet Lab Chrome extension exists for one purpose: importing your own betting records from your bookmaker accounts into your SmartBet Lab account, at your request.
- What it reads: bet-history, bet-detail and bet-confirmation pages on supported bookmaker sites (the exact sites are always visible in the extension's install prompt and in the in-app supported list). Only to extract your bets (selection, odds, stake, result, receipt number).
- What it sends: the extracted bets to your SmartBet Lab account, authenticated by a revocable token you create in Settings. Nothing is sent anywhere else, and nothing is sent without a connected token.
- What it never touches: your bookmaker username, password, payment details or cookies. You log in to your bookmaker normally; the extension has no access to your credentials.
- Diagnostics: if a page fails to parse, the extension may send a structure-only snippet (tag names and CSS classes with all text removed) so we can fix the parser. It contains no personal data.
- Optional capture contributions: the "contribute this page" button sends a snapshot of the current page only when you click it, after on-device sanitization (all digits masked, emails removed, forms and scripts stripped). It is used solely to build support for new bookmakers and is never shared.
- No tracking: the extension contains no analytics, no ads and no third-party code, and it does not monitor your browsing.
- Revocation: disconnect at any time by revoking the token in Settings → Extension, or by uninstalling the extension.
12. Changes to This Policy
When we change this policy materially, we will update the date at the top and notify you in the app or by email. Continued use after a change means you accept the updated policy.
13. Contact Us
Questions about this policy or your data: reach us through the contact page.