Legal

Privacy Policy

Last updated: 7/29/2026

This Privacy Policy explains how Legendars ("Legendars", "we", "us", "our") collects, uses, discloses, retains, and protects personal information when you use our website, mobile and progressive web applications, and skill contest platform (collectively, the "Service"). It also describes your rights under applicable data protection laws, including the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), Brazil's Lei Geral de Proteção de Dados ("LGPD"), Canada's PIPEDA, and other applicable laws. This page is maintained by Legendars and is not an independent certification.

1

Controller and Contact

Data controller (GDPR / UK GDPR): Legendars, contact: privacy@legendars.com. Postal address available on written request.

Where we act as a controller, we determine the purposes and means of processing your personal data. Where we act as a processor for a partner (for example, a co-branded sponsored contest), that partner's privacy notice governs and this policy supplements it.

EU representative (Art. 27 GDPR) and UK representative (Art. 27 UK GDPR): to be appointed prior to targeting or offering paid Contests to EU or UK residents; until appointed, please contact privacy@legendars.com and we will route your request appropriately.

Data Protection Officer: dpo@legendars.com. We appoint a DPO where required by law or where the scale of monitoring justifies it.

2

Personal Data We Collect

Account data: email address, display name, hashed password credentials (handled by our authentication provider), preferred jurisdiction, and communication preferences.

Contest activity: Entries, predictions, wallet ledger entries, scores, ranks, prize payouts, and AMOE submissions tied to your account.

Eligibility and integrity data: attested age and jurisdiction, geolocation signals (approximate IP-based location, and, where permitted, device location for enforcement), sanctions and self-exclusion screening results, and fraud signals (device fingerprint, velocity, and integrity checks).

Payment and identity data (KYC): collected and held by our regulated exchange and payments partners under their own privacy notices and legal bases. Legendars typically receives only a token, status flag, and minimum identifiers required to credit or debit $CIPE.

Technical data: IP address, device and browser type, operating system, language, referrer URL, timestamps, session identifiers, cookie identifiers, crash and diagnostic logs.

Communications: support tickets, chat, and emails you send us, plus records of notices we send you.

We do not knowingly collect special categories of data (racial or ethnic origin, political opinions, religion, trade union membership, genetic or biometric data, health data, sex life or sexual orientation) and we ask that you do not submit them. We do not process criminal offence data other than sanctions screening flags where legally required.

3

How We Use Personal Data and Legal Bases (GDPR / UK GDPR Art. 6)

PurposeLegal basis
Create and administer your account; provide and operate the Service; run Contests; settle Prize Pools; process $CIPE credits and debitsPerformance of a contract (Art. 6(1)(b))
Verify eligibility, enforce jurisdictional restrictions, screen sanctions and self-exclusion listsLegal obligation (Art. 6(1)(c)); legitimate interests in preventing fraud and unlawful use (Art. 6(1)(f))
Detect, prevent, and investigate fraud, collusion, abuse, and security incidentsLegitimate interests (Art. 6(1)(f))
Security, logging, integrity, and platform administrationLegitimate interests (Art. 6(1)(f))
Transactional communications (verification, receipts, security notices, legal updates)Performance of a contract; legal obligation
Marketing communications and optional product updatesConsent (Art. 6(1)(a)), which you can withdraw at any time
Non-essential analytics and product researchConsent where required by ePrivacy / PECR; otherwise legitimate interests
Compliance with tax, accounting, AML, and other legal obligationsLegal obligation (Art. 6(1)(c))
Establish, exercise, or defend legal claimsLegitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we conduct a balancing test and you have the right to object as described in Section 8.

4

Automated Decision-Making and Profiling

Contest scoring is deterministic and formulaic; it is not "solely automated decision-making producing legal or similarly significant effects" within the meaning of GDPR Article 22. We use automated rules for fraud, sanctions, eligibility, and geolocation checks; these can cause an Entry to be blocked, voided, or a payout to be held pending review. You may request human review of any such decision by writing to privacy@legendars.com; a qualified person will re-examine the decision and you may contest it.

5

Sharing and Recipients

We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising as defined by the CCPA/CPRA. We disclose limited personal data to the following categories of recipients:

  • Cloud backend and database provider for authentication, database, storage, and serverless compute.
  • Email delivery provider for transactional messages.
  • Exchange and payments partner(s) for $CIPE on-ramp and off-ramp, KYC, and settlement.
  • Fraud, geolocation, sanctions, and identity screening providers for integrity and compliance.
  • Analytics and error monitoring providers configured to minimize personal data.
  • Professional advisers (auditors, lawyers, accountants) under duties of confidentiality.
  • Government, regulators, and law enforcement where required by law, valid legal process, or to protect the rights, safety, and property of users, Legendars, or the public.
  • A successor entity in connection with a merger, acquisition, reorganization, or sale of assets, subject to equivalent privacy commitments.

A current list of key subprocessors is available on request at privacy@legendars.com. We will provide reasonable prior notice of material changes to our subprocessors where required.

We do not share user prediction data with sportsbooks or third-party wagering operators for their independent use.

6

International Data Transfers

Legendars is based in the United States. Your personal data may be transferred to and processed in the United States and other countries where our service providers operate. Some of these countries may not provide the same level of data protection as your home country.

For transfers of personal data out of the European Economic Area, United Kingdom, or Switzerland, we rely on one or more of the following safeguards, as applicable: (a) an adequacy decision of the European Commission or the UK Government; (b) the EU Standard Contractual Clauses (Commission Decision 2021/914) with any additional supplementary measures identified in a Transfer Impact Assessment; (c) the UK International Data Transfer Addendum or the UK International Data Transfer Agreement; and (d) certification under the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. Data Privacy Framework, where our recipients are certified. You may request a copy of the relevant safeguards by contacting privacy@legendars.com; commercial terms may be redacted.

7

Retention

We retain personal data only for as long as necessary for the purposes described in this policy, then delete or anonymize it, unless a longer retention period is required or permitted by law.

  • Account records: for the life of the account and up to 24 months after closure, then deleted or anonymized.
  • Contest entries, scores, and payouts (wallet ledger): append-only for the life of the ledger, to preserve integrity, auditability, and dispute history. Personal identifiers may be pseudonymized after account closure.
  • KYC and AML records: as required by applicable financial-crime law (typically 5 to 7 years after the last transaction), held primarily by our regulated partners.
  • Tax and accounting records: as required by applicable tax law (typically 7 years).
  • Security and access logs: up to 12 months, longer if needed to investigate an incident.
  • Marketing consents: until withdrawn, plus a short record of withdrawal to honor your choice.
8

Your Rights (GDPR, UK GDPR, and Others)

Subject to conditions and exceptions under applicable law, you have the following rights:

  • Access a copy of the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure ("right to be forgotten") where legal grounds apply.
  • Restriction of processing in specified situations.
  • Portability of data you provided to us, in a structured, commonly used, machine-readable format.
  • Objection to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
  • Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see Section 4).
  • Lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ico.org.uk). In the EU, it is your national data protection authority. In Brazil, the ANPD.

To exercise your rights, email privacy@legendars.com from the address on your account. We will respond within 30 days (or one month under GDPR/UK GDPR), extendable by up to two additional months for complex requests. We may need to verify your identity before acting. Where you use an authorized agent, we may require proof of authority.

9

California Residents (CCPA / CPRA)

In the 12 months preceding this policy, we may have collected the categories of personal information described in Section 2 (identifiers, commercial information, internet or other electronic network activity, geolocation data, inferences, and, via partners, financial and government-issued identifiers for KYC). We use this information for the business and commercial purposes described in Section 3, and disclose it to the categories of recipients described in Section 5. We do not sell personal information and do not share it for cross-context behavioral advertising. We do not knowingly collect the personal information of consumers under 16.

California residents have the right to know, delete, correct, and to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and to non-discrimination for exercising these rights. To submit a request, email privacy@legendars.com. Authorized agents may submit requests with written authorization and verification of the consumer's identity.

10

Other Jurisdictions

Brazil (LGPD): we process personal data on the legal bases in Art. 7 LGPD analogous to those in Section 3, and honor data subject rights under Art. 18. Requests: privacy@legendars.com.

Canada (PIPEDA): we obtain consent as required, provide access and correction rights, and are accountable for personal information under our control. Complaints may be directed to the Office of the Privacy Commissioner of Canada.

Other U.S. state privacy laws (including CO, CT, VA, UT, TX, OR): we honor comparable rights of access, correction, deletion, portability, and opt-out of targeted advertising and sales, where applicable. We do not engage in targeted advertising or sales of personal data.

11

Cookies and Similar Technologies

We use strictly necessary cookies and local storage to keep you signed in, remember preferences, provide security, and enable contest entry. Where required by law (including the EU ePrivacy Directive and UK PECR), we request consent before setting non-essential cookies, and you can withdraw consent at any time through the in-app cookie settings. A detailed cookie table (name, purpose, duration, provider) is maintained in the in-app cookie settings and updated as our stack evolves. Disabling required cookies may break sign-in and Contest entry.

We honor the Global Privacy Control (GPC) signal where applicable.

12

Security

We implement technical and organizational measures appropriate to the risk, including encryption in transit (HTTPS/TLS), encryption at rest for the primary database, role-based access controls, row-level security policies on user data, principle-of-least-privilege for staff, audit logging, secrets management, secure software development practices, third-party dependency review, and vendor security due diligence. No system is perfectly secure. You play a role by protecting your credentials and using a strong, unique password; report suspected security issues to security@legendars.com.

13

Data Breach Notification

If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by GDPR Art. 33. Where the breach is likely to result in a high risk, we will notify affected users without undue delay, as required by GDPR Art. 34. We maintain an internal incident response plan and keep records of breaches in accordance with law.

14

Children

The Service is directed exclusively to adults. We do not knowingly collect personal data from anyone under 18 (and, where GDPR applies, we do not knowingly process the data of a child under the age of digital consent in that Member State without verifiable parental consent). If you believe a minor has provided us information, contact privacy@legendars.com and we will delete it.

15

Third-Party Links and Integrations

The Service may link to third-party sites, including exchange partners and licensed operator partners. Those sites have their own privacy practices, and we are not responsible for their content or handling of your data. Review their notices before providing personal data.

16

Do Not Track and Global Privacy Signals

Some browsers offer "Do Not Track" signals. There is no industry-standard interpretation of DNT. We honor the Global Privacy Control (GPC) as an opt-out signal for sale/sharing to the extent required by applicable law.

17

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted here with a new "Last updated" date and, where appropriate, notified in-app or by email. Prior versions are available on request.

18

Contact and Complaints

Privacy requests: privacy@legendars.com. DPO: dpo@legendars.com. Security: security@legendars.com.

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. UK residents may contact the Information Commissioner's Office (ico.org.uk).