Privacy policy
Last updated
Short version: the extension analyses pages inside your browser. Our servers receive hashes, hostnames, URL paths and numbers — never the text of a page, and never a screenshot.
Summary
- No page content. Page text, HTML and screenshots never leave your browser. Our API rejects any request field that is not on its specification.
- What is sent: hashed word fragments (n-gram hashes), link hostnames, link URL paths, numeric layout signals, and the URL of the page you scanned.
- Account: your email address, only if you sign in.
- Scan history: kept server-side with URL query strings removed. Anonymous snapshots are deleted after 30 days.
- No tracking: no analytics scripts, no advertising cookies, no third-party trackers on this site or in the extension.
- Providers: Stripe for payments (we never store card details) and Resend for transactional email.
Who we are
iGamingDetect is operated by [ENTITY — pending] ("we", "us"), the data controller for the processing described here. Contact details are at the end of this policy.
iGamingDetect is a competitive-intelligence tool for marketing teams. It is not a gambling service and does not process any wagering data.
What the extension sends
Brand detection runs entirely inside the extension. It only contacts our API at api.igamingdetect.com in these cases:
1. Downloading brand data and configuration
The extension fetches a hashed brand index and a scoring configuration. These requests carry no data about you or the page beyond standard HTTP headers.
2. Resolving ambiguous matches (POST /v1/resolve)
When a scan finds a name that could belong to more than one brand, the extension asks the API to disambiguate. The request contains, per detected block:
| Field | What it is | What it is not |
|---|---|---|
| n-gram hashes | 64-bit hashes of the matched brand name fragment | Not reversible to the text; not the surrounding sentence |
| hostnames | Hostnames of links inside the block (e.g. example.com) | Not the link's full URL, not the page's other links |
| URL paths | The path portion of those links (e.g. /go/brand) | Query strings are not used for matching |
| numeric signals | Block position, size, placement type, counts | No text, no images, no DOM |
| scan URL | The address of the page you scanned | Stored with the query string removed (see Scan history) |
Every request is validated against a fixed schema. A request carrying any other field is rejected with an error and nothing is stored.
3. Anonymous install token
On first contact the API issues a random identifier (a UUID) stored in the extension. It lets us apply the free-plan daily quota and attribute scans to an install. It contains no personal data and is not linked to a person unless you sign in and choose to connect the install to your account.
4. Reporting a missing brand (optional, signed-in only)
Signed-in users with a reviewer role can manually submit the name of a brand the extension failed to recognise. This is the only path by which a string from a page reaches our servers, it happens only when you press the button, and the submitted name is reviewed by a person before it enters the brand database.
What we never collect
- The text, HTML or DOM of any page you visit or scan
- Screenshots or images
- Your browsing history, open tabs, or pages you do not explicitly scan
- Form input, passwords or session cookies from other sites
- Precise location, device fingerprints, or advertising identifiers
The extension requests only the Chrome permissions activeTab, scripting, sidePanel and storage, plus network access to our own API host. It cannot read a page until you open the side panel on that tab and start a scan.
Account data
You can use the free plan without an account. If you sign in (required for Pro), we store:
- Email address — used to sign you in with one-time codes and to send transactional messages (sign-in codes, a one-time welcome message, receipts, service notices). We do not send marketing email.
- Display name — optional, set by you, shown only to you inside the product.
- Role and plan — free or Pro, and any internal reviewer role.
- Session and account tokens — stored as one-way hashes only. One-time sign-in codes expire after 10 minutes.
- Billing status — subscription state received from Stripe. We do not receive or store card numbers.
We do not use passwords, so we do not store any.
Scan history and snapshots
Each scan that contacts the API produces a snapshot: the install or account identifier, the page URL, a timestamp, and the ranked results (brand identifiers, scores and numeric signals). Snapshots contain no page content.
- Query strings are stripped from the URL before storage, so tracking parameters, session identifiers and search terms embedded in a URL are not retained.
- Anonymous snapshots (free plan, not signed in) are deleted 30 days after the scan.
- Account snapshots form your scan history and are kept while your account is active, so you can review past scans. They are deleted when you delete your account.
Data stored in your browser
The extension uses Chrome's local extension storage for: the hashed brand index and scoring configuration, a cache of your recent scan results (15 minutes, so re-scanning a page makes no API call), the anonymous install token, and your account token if you sign in. None of this is synced to Chrome's cloud storage, and uninstalling the extension removes it all.
Service providers
We use a small number of providers who process data on our behalf under contract:
| Provider | Purpose | Data |
|---|---|---|
| Stripe | Payment processing and subscription management | Email, billing details you enter on Stripe's hosted pages, subscription status. Card data is handled solely by Stripe and never touches our servers. |
| Resend | Transactional email delivery | Email address and the message content (sign-in codes, receipts, notices). |
| Cloudflare | Hosting of this website and network protection for our API | Standard connection metadata (IP address, request headers) processed transiently to serve and protect the service. |
We do not sell personal data and we do not share it with advertisers or data brokers.
Cookies and tracking
This marketing website sets no cookies and loads no analytics or advertising scripts. The signed-in area uses a single strictly necessary session cookie (igd_session, HttpOnly) that keeps you signed in for up to 30 days; it is not used for tracking. The extension does not use cookies.
Retention
| Data | Kept for |
|---|---|
| Anonymous scan snapshots | 30 days |
| Account scan history | Life of the account |
| Account (email, plan, tokens) | Until you delete the account |
| One-time sign-in codes | 10 minutes |
| Session cookie | 30 days, or until sign-out |
| Billing records | As required by tax and accounting law after the subscription ends |
| Server request logs | Short-lived operational logs, rotated automatically |
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to restrict or object to its processing, and to lodge a complaint with a supervisory authority. To exercise any of these, email us from the address on your account. We respond within 30 days.
Deleting your account removes your email, tokens and scan history. Billing records required by law are retained in anonymised or restricted form.
Where we rely on legal bases under the GDPR or UK GDPR: providing the service (contract) for accounts, scans and billing; legitimate interest for security, abuse prevention and the anonymous install quota; legal obligation for tax records.
Security
All traffic between the extension, this site and our API is encrypted with TLS. Tokens and sign-in codes are stored only as SHA-256 hashes. The API enforces its schema on every request and rejects unknown fields, which structurally prevents page content from being accepted even by mistake. Access to production systems is restricted to the people who operate the service.
Children
iGamingDetect is a business tool intended for adults working in marketing. It is not directed at anyone under 18 and we do not knowingly collect data from them.
Changes to this policy
We will post any changes on this page and update the date at the top. If a change materially reduces your rights or expands what we collect, we will notify account holders by email before it takes effect.
Contact
[ENTITY — pending]
Privacy enquiries: privacy@igamingdetect.com