Privacy Policy

Last updated: May 2026

This Privacy Policy explains how EV Lighthouse Limited (“EV Lighthouse”, “we”, “our”, “us”) collects, uses, stores, and protects your personal data when you use our website, application, and services (collectively, the “Service”). By using the Service, you agree to the practices described in this Privacy Policy.

We are committed to complying with the Personal Data (Privacy) Ordinance (PDPO) of Hong Kong and, where applicable, the General Data Protection Regulation (GDPR) of the European Union.

1. Information we collect

1.1 Account information

  • Email address
  • Password (hashed and salted)

1.2 Poker data

You may upload or input poker-related data, including:

  • Hand history information
  • Game results
  • Performance metrics
  • Derived statistics

We do not store the original hand history files you upload, only the parsed and structured data extracted from them.

1.3 Usage & analytics data

We collect anonymized or pseudonymized analytics data, including:

  • Device type
  • Browser type
  • Pages visited
  • Time spent on the Service
  • General usage patterns

We use privacy-focused analytics tools as well as standard web analytics tools.

1.4 Payment information

Payments are processed by third-party payment processors. We do not store your full payment card details. We may receive limited payment metadata such as subscription status, billing history, and last 4 digits of card (if provided by processor).

1.5 Cookies & tracking technologies

We use cookies and similar technologies for:

  • Authentication
  • Security
  • Analytics
  • Service functionality

You may disable cookies in your browser, but some features may not function properly.

2. How we use your information

We use your information to:

  • Provide and operate the Service
  • Process subscriptions and payments
  • Analyze usage and improve the Service
  • Communicate product updates and important notices
  • Ensure security and prevent fraud
  • Comply with legal obligations

We do not sell your personal data.

3. Legal bases for processing (GDPR)

Where GDPR applies, we process personal data under the following legal bases:

  • Contract: To provide the Service you signed up for
  • Legitimate Interests: To improve the Service, prevent abuse, and analyze usage
  • Consent: For optional analytics and marketing communications
  • Legal Obligation: For tax, accounting, and compliance requirements

4. Data storage & international transfers

Your data may be stored and processed across multiple regions, including Asia (e.g., Seoul), the European Union, and the United States. This depends on the infrastructure used for hosting, databases, analytics, and content delivery.

We use reputable third-party service providers that implement industry-standard security measures and, where required, appropriate safeguards for international data transfers (such as Standard Contractual Clauses).

5. How we share your information

5.1 Service providers (data processors)

We use third-party providers for:

  • Hosting and database services
  • Content delivery and security
  • Analytics
  • Payment processing
  • Error monitoring

We do not name these providers explicitly in this policy, but all are contractually required to protect your data.

5.2 Legal compliance

We may disclose information if required by law, court order, or government authority.

5.3 Business transfers

If EV Lighthouse is involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction.

6. Data retention

We retain personal data only as long as necessary for the purposes described in this policy.

  • Account data: retained while your account is active
  • Poker Data: retained until you delete it or close your account
  • Backups: may persist for up to 90 days after deletion
  • Legal/financial records: retained for the period required by law

7. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion (“right to be forgotten”)
  • Request data export (“data portability”)
  • Object to certain processing
  • Withdraw consent (where applicable)

To exercise these rights, contact us at [email protected]. We may need to verify your identity before processing your request.

8. Marketing communications

We may send occasional product updates or announcements. You can opt out at any time by clicking “unsubscribe” in the email or by contacting us directly.

We do not send spam or third-party marketing.

9. Security

We implement industry-standard security measures, including:

  • Encryption in transit
  • Secure password hashing
  • Access controls
  • Firewalls and DDoS protection
  • Regular monitoring

However, no system is completely secure. You use the Service at your own risk.

10. Children's privacy

The Service is intended for adults aged 18 and above. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, contact us immediately.

11. Changes to this privacy policy

We may update this Privacy Policy from time to time. If changes are material, we will notify you via email or through the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact us

If you have questions about this Privacy Policy or your data, please contact us at [email protected].