PUNTERS REPUBLIC PRIVACY POLICY

Last Updated: 22 October 2025

Effective Date: 1 July 2025

Version: 2.0

INTRODUCTION

Punters Republic ("we", "us", "our", or "the Platform") is committed to protecting your privacy and handling your personal information responsibly and in accordance with applicable privacy laws.

This Privacy Policy explains:

  • What personal information we collect
  • How we collect, use, and disclose that information
  • Your rights regarding your personal information
  • How we protect your information
  • How to contact us about privacy matters

By using the Punters Republic platform (www.puntersrepublic.com), you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal information as described herein.

This Privacy Policy should be read in conjunction with our Terms and Conditions.

QUICK ACCESS TO YOUR PRIVACY RIGHTS

Your Rights at a Glance:

Access Your Data: Request a copy of all personal information we hold about you
Correct Your Data: Update or correct inaccurate information
Delete Your Data: Request permanent deletion of your account and associated data
Export Your Data: Download your data in a portable format
Control Visibility: Manage who can see your profile and competition activity
Opt-Out: Unsubscribe from non-essential communications

Exercise Your Rights:

Account Settings: Log in and visit your Privacy Settings dashboard
Written Request: Contact our Data Protection Officer (details in Section 14)

Table of Contents

1. INFORMATION WE COLLECT

We collect several types of information to provide and improve our services.

1.1 Personal Information You Provide

Registration Data:

  • Full name
  • Email address
  • Date of birth (to verify age eligibility)
  • Country of residence
  • Username (display name)
  • Password (stored as encrypted hash only)

Profile Information (Optional):

  • Profile picture or avatar
  • Favourite sports
  • Favourite teams/athletes
  • Tipping style preferences
  • Bio or personal description
  • Social media links (if you choose to provide)

Competition Data:

  • Event selections (predictions)
  • Double Down designation
  • Gimme designation
  • Substitution requests and history
  • Private league memberships
  • League creation and administration activities

Communication Data:

  • Emails you send to us
  • Support requests and correspondence
  • Feedback and survey responses
  • Posts, comments, and messages within the Platform

1.2 Information Automatically Collected

Usage Information:

  • Pages visited on the Platform
  • Features used and time spent
  • Clicks, navigation paths, and interactions
  • Competition participation patterns
  • Login dates and times
  • Device and browser information

Technical Information:

  • IP address
  • Browser type and version
  • Operating system
  • Device type (mobile, tablet, desktop)
  • Screen resolution
  • Language preferences
  • Referring website or source
  • Cookies and similar tracking technologies (see Section 10)

Location Information:

  • General geographic location based on IP address (city/country level)
  • We do NOT collect precise GPS location data

Performance and Analytics Data:

  • Competition statistics (points, rankings, accuracy)
  • Engagement metrics (logins, active participation)
  • Feature usage patterns
  • Error logs and diagnostic data

1.3 Information from Third Parties

Social Media Integration (If Applicable):

  • If you choose to link social media accounts, we may receive public profile information
  • This is entirely optional and controlled by you

Payment Processors (If Applicable for Future Features):

  • We do not currently process payments
  • If payment features are added, we will update this policy accordingly

2. HOW WE USE YOUR INFORMATION

We use your personal information for the following purposes:

2.1 Platform Operations and Service Delivery

Competition Administration:

  • Create and maintain your account
  • Process and record your event selections
  • Calculate scores using our scoring system
  • Maintain leaderboards (global and private leagues)
  • Process substitutions within permitted limits
  • Track Double Down and Gimme selections
  • Determine competition winners and rankings

Communication:

  • Send competition updates and results notifications
  • Provide important platform announcements
  • Respond to your inquiries and support requests
  • Send administrative messages (password resets, account security)
  • Notify you of rule changes or policy updates

Social Features:

  • Enable private league creation and participation
  • Display leaderboard information
  • Allow user interaction and community engagement
  • Facilitate friend connections and social sharing

2.2 Personalization and Enhancement

User Experience:

  • Customize your dashboard and interface
  • Remember your preferences and settings
  • Provide relevant content recommendations
  • Display personalized competition insights
  • Generate statistical analysis of your performance

Platform Improvement:

  • Analyze usage patterns to improve features
  • Identify and fix technical issues
  • Develop new features based on user behavior
  • Optimize platform performance and reliability
  • A/B testing of new features (anonymized)

2.3 Legal and Safety

Compliance:

  • Comply with legal obligations and regulations
  • Respond to legal requests and court orders
  • Enforce our Terms and Conditions
  • Protect against fraud, abuse, and security threats
  • Investigate violations of platform rules

Safety and Security:

  • Detect and prevent fraudulent activity
  • Monitor for multiple accounts or cheating
  • Protect the integrity of the competition
  • Secure user accounts and data
  • Prevent unauthorized access

2.4 Analytics and Research

Anonymized Analytics:

  • Generate aggregated statistics about platform usage
  • Identify trends in user behavior and preferences
  • Measure feature adoption and engagement
  • Create demographic reports (age ranges, countries)
  • Inform business decisions and strategy

Important: Analytics data is anonymized and cannot be used to identify individual users.

3. HOW WE SHARE YOUR INFORMATION

We do not sell your personal information to third parties. We share information only as described below:

3.1 Public Information

The following information is visible to other users of the Platform:

Always Public:

  • Your username/display name
  • Your leaderboard position and total points
  • Number of 1st, 2nd, and 3rd place finishes
  • Double Down and Gimme status (played/not played)
  • Substitutions used count (X/3)
  • Competition statistics and performance data
  • Posts and comments in public areas

Conditionally Public (Based on Your Privacy Settings):

  • Your full profile information
  • Your specific event selections (after event deadlines)
  • Your private league memberships
  • Your activity feed and history

Never Public Without Your Consent:

  • Your email address
  • Your date of birth
  • Your IP address
  • Your password or security information

3.2 Private League Participants

Within private leagues you join:

  • Your selections and performance are visible to other league members
  • League administrators can view league-specific analytics
  • You consent to this sharing by joining the league

3.3 Service Providers and Third Parties

We may share information with trusted service providers who assist us, including:

Technology and Infrastructure:

  • Hosting and cloud storage providers (e.g., Supabase, AWS)
  • Content delivery networks
  • Database management services
  • Analytics platforms (e.g., Google Analytics, anonymized)

Communications:

  • Email service providers for transactional and marketing emails
  • SMS providers (if we implement SMS notifications)

Security and Fraud Prevention:

  • Security monitoring services
  • Fraud detection tools

Legal and Professional Services:

  • Legal advisors and consultants
  • Accounting and audit firms
  • Insurance providers

Third-Party Requirements:

  • All service providers are contractually bound to protect your information
  • They may only use your data to provide services to us
  • They cannot use your data for their own purposes

3.4 Aggregated and Anonymized Data

We may share aggregated, anonymized data that cannot identify individual users:

  • Overall platform statistics and trends
  • General demographic information (age ranges, countries)
  • Popular predictions and betting patterns
  • Platform usage metrics
  • Research and academic purposes

3.5 Legal Requirements and Protection

We may disclose your information when required or permitted by law:

Legal Obligations:

  • Comply with valid legal processes (subpoenas, court orders, warrants)
  • Respond to government or regulatory requests
  • Cooperate with law enforcement investigations

Protection of Rights:

  • Enforce our Terms and Conditions
  • Protect our rights, property, and safety
  • Protect the rights and safety of our users
  • Prevent fraud, abuse, or illegal activity
  • Defend against legal claims

3.6 Business Transfers

If Punters Republic is involved in a merger, acquisition, sale of assets, or bankruptcy:

  • Your information may be transferred to the new entity
  • We will notify you before your information is transferred
  • The new entity will be bound by this Privacy Policy

4. YOUR PRIVACY RIGHTS

Under Australian privacy laws (Privacy Act 1988) and other applicable regulations, you have the following rights:

4.1 Right to Access (Australian Privacy Principle 12)

You have the right to request:

  • Confirmation that we hold personal information about you
  • Access to that personal information
  • Details about how we use and disclose your information

How to Exercise: Email legal@puntersrepublic.com with subject "Access Request"

Response Time: Within 30 days

Cost: Generally free; we may charge reasonable fees for extensive requests

4.2 Right to Correction (Australian Privacy Principle 13)

You have the right to:

  • Request correction of inaccurate or incomplete information
  • Update your personal details at any time
  • Add statements to your records if we disagree about accuracy

How to Exercise: Update information directly in Account Settings, or email legal@puntersrepublic.com

Response Time: Corrections made immediately or within 30 days for disputes

4.3 Right to Deletion (Erasure)

You have the right to request deletion of your personal information, subject to certain exceptions:

  • We may retain information required for legal compliance
  • We may retain anonymized competition data for historical records
  • We may retain information necessary for legitimate business interests

How to Exercise: Email legal@puntersrepublic.com with subject "Deletion Request"

Process:

  1. We will verify your identity
  2. Delete or anonymize your personal information
  3. Confirm deletion within 30 days
  4. Some data may be retained in backups for up to 90 days

Important: Deletion is permanent and cannot be undone. Your leaderboard positions and competition history will be removed.

4.4 Right to Data Portability

You have the right to receive your personal information in a structured, commonly used, and machine-readable format.

How to Exercise: Visit Account Settings > Export Data, or email legal@puntersrepublic.com

What You Receive:

  • JSON or CSV file containing your personal data
  • All competition selections and history
  • Profile information and preferences
  • Leaderboard statistics and performance data

Response Time: Immediate download or within 7 days for manual requests

4.5 Right to Object or Restrict Processing

You have the right to:

  • Object to certain types of data processing (e.g., marketing)
  • Request restriction of processing in certain circumstances
  • Withdraw consent where processing is based on consent

How to Exercise:

  • Unsubscribe links in emails for marketing objections
  • Account Settings for preference management
  • Email legal@puntersrepublic.com for formal objections

Limitations: We may need to continue processing for essential platform functions.

4.6 Right to Lodge a Complaint

If you believe we have breached Australian privacy laws, you have the right to complain to:

Office of the Australian Information Commissioner (OAIC)

We encourage you to contact us first so we can address your concerns.

5. PRIVACY CONTROLS AND SETTINGS

You can control your privacy through your Account Settings:

5.1 Profile Visibility

  • Public Profile: Anyone can view your profile information
  • Limited Profile: Only registered users can view your profile
  • Private Profile: Only private league members can view your profile

5.2 Competition Activity Visibility

  • Control who can see your event selections
  • Control who can see your substitution history
  • Manage private league visibility

5.3 Communication Preferences

  • Competition Updates: Results and leaderboard notifications (essential, cannot opt-out)
  • Platform News: New features and announcements (optional)
  • Marketing Communications: Promotions and offers (optional, currently none)
  • Email Frequency: Choose daily, weekly, or event-based digests

5.4 Social Interactions

  • Control who can send you friend requests
  • Manage comment and post permissions
  • Block or mute specific users

5.5 Data Sharing

  • Control whether your anonymized data is used for platform analytics
  • Opt-out of third-party analytics cookies (see Section 10)

Access Privacy Settings: Log in > Profile > Privacy Settings

6. DATA SECURITY

We implement industry-standard security measures to protect your information:

6.1 Technical Safeguards

Encryption:

  • All data transmitted between your device and our servers is encrypted using TLS 1.3
  • Passwords are hashed using bcrypt with salt (never stored in plain text)
  • Sensitive data is encrypted at rest using AES-256

Access Controls:

  • Role-based access controls limit employee access to personal data
  • Multi-factor authentication for administrative access
  • Regular access audits and reviews
  • Need-to-know principle enforced

Infrastructure Security:

  • Firewalls and intrusion detection systems
  • Regular security patches and updates
  • Distributed denial-of-service (DDoS) protection
  • Secure cloud hosting with reputable providers

Monitoring:

  • 24/7 security monitoring
  • Automated threat detection
  • Regular penetration testing
  • Incident response procedures

6.2 Organizational Safeguards

Policies and Training:

  • Employee confidentiality agreements
  • Security awareness training for all staff
  • Data handling procedures and protocols
  • Incident response and breach notification plans

Data Minimization:

  • We collect only necessary information
  • We retain data only as long as needed
  • Regular data audits and purging of unnecessary information

6.3 Your Responsibility

You are responsible for:

  • Keeping your password confidential
  • Using a strong, unique password
  • Logging out of shared devices
  • Reporting suspicious activity immediately

Security Best Practices:

  • Never share your account credentials
  • Enable two-factor authentication (if available)
  • Use a password manager
  • Be cautious of phishing attempts

6.4 Data Breach Notification

In the unlikely event of a data breach:

  • We will notify affected users within 72 hours of discovering the breach
  • We will notify the OAIC as required by law
  • We will provide information about the breach and steps to protect yourself
  • We will take immediate action to contain and remediate the breach

7. DATA RETENTION

7.1 Active Accounts

We retain your personal information for as long as your account is active and as necessary to provide services.

7.2 Retention Periods

Account Data:

  • Retained while your account is active
  • Retained for 12 months after account deletion (for dispute resolution and legal compliance)

Competition Data:

  • Historical competition results retained indefinitely in anonymized form
  • Your specific selections may be retained for up to 7 years for record-keeping

Communication Records:

  • Support correspondence retained for 3 years
  • Legal communications retained for 7 years

Technical Logs:

  • Server logs retained for 90 days
  • Security logs retained for 12 months
  • Analytics data retained indefinitely in anonymized form

Financial Records (If Applicable):

  • Payment records retained for 7 years (tax compliance)

7.3 Anonymization

After retention periods expire:

  • Personal identifiers are removed
  • Data is aggregated and anonymized
  • Anonymized data may be retained indefinitely for historical and analytical purposes

7.4 Legal Holds

We may retain information longer if required for:

  • Ongoing legal proceedings
  • Regulatory investigations
  • Compliance with court orders

8. INTERNATIONAL DATA TRANSFERS

8.1 Data Location

Your information may be processed and stored in:

  • Australia (primary data residency)
  • Singapore (for certain cloud services)
  • United States (for certain service providers)
  • European Union (for certain service providers)

8.2 Safeguards for International Transfers

When we transfer data internationally, we ensure:

  • Service providers are certified under recognized frameworks (e.g., Privacy Shield successors, Standard Contractual Clauses)
  • Adequate security measures are in place
  • Data protection agreements with all processors
  • Compliance with Australian cross-border privacy obligations (APP 8)

8.3 Your Consent

By using the Platform, you consent to the transfer of your information to countries that may have different data protection laws than Australia.

9. CHILDREN'S PRIVACY

9.1 Age Restriction

Punters Republic is not intended for, and may not be used by, anyone under the age of 18.

9.2 Verification

We require all users to confirm they are at least 18 years old during registration.

9.3 Parental Notice

If we become aware that we have collected personal information from someone under 18:

  • We will take steps to delete that information as quickly as possible
  • We will terminate the account
  • Parents or guardians who believe we have collected information from a minor should contact us immediately

9.4 Reporting

To report underage users: legal@puntersrepublic.com

10. COOKIES AND TRACKING TECHNOLOGIES

10.1 What Are Cookies?

Cookies are small text files stored on your device that help us provide and improve our services.

10.2 Types of Cookies We Use

Essential Cookies (Required):

  • Authentication and session management
  • Security and fraud prevention
  • Load balancing and performance
  • Remember your preferences

Cannot be disabled without losing functionality

Analytics Cookies (Optional):

  • Google Analytics (anonymized IP addresses)
  • Platform usage tracking
  • Feature adoption metrics
  • Performance monitoring

Can be disabled in Privacy Settings

Functional Cookies (Optional):

  • Remember your settings and preferences
  • Personalize content and recommendations
  • Save your dashboard layout

Can be disabled in Privacy Settings

10.3 Third-Party Cookies

We use the following third-party cookies:

  • Google Analytics: Website traffic analysis (anonymized)
  • Cloudflare: Security and performance optimization

Control Third-Party Cookies: Visit the third party's website to opt-out or use browser settings.

10.4 Managing Cookies

Browser Controls:

  • Chrome: Settings > Privacy and Security > Cookies
  • Firefox: Settings > Privacy & Security > Cookies and Site Data
  • Safari: Preferences > Privacy > Manage Website Data

Platform Controls:

Account Settings > Privacy > Cookie Preferences

Important: Disabling essential cookies will prevent you from logging in and using the Platform.

10.5 Do Not Track

We currently do not respond to "Do Not Track" browser signals, but you can control cookies as described above.

11. THIRD-PARTY LINKS AND SERVICES

11.1 External Links

The Platform may contain links to third-party websites, services, or content (e.g., news articles, social media).

Important:

  • We are not responsible for the privacy practices of third-party sites
  • This Privacy Policy does not apply to third-party sites
  • We encourage you to review their privacy policies

11.2 Social Media Integration

If we offer social media integration features:

  • Linking accounts is entirely optional
  • Review the social media platform's privacy policy
  • We only access information you explicitly permit

11.3 Embedded Content

Third-party embedded content (videos, widgets) may collect information about you:

  • These services have their own privacy policies
  • We do not control their data practices

12. MARKETING AND COMMUNICATIONS

12.1 Types of Communications

Transactional Communications (Cannot Opt-Out):

  • Account creation confirmations
  • Password reset requests
  • Security alerts
  • Competition results and scoring updates
  • Important platform announcements
  • Legal notices and policy changes

Promotional Communications (Can Opt-Out):

  • Platform news and feature announcements
  • Competition reminders and tips
  • User engagement campaigns
  • Surveys and feedback requests

12.2 Opting Out

Email Unsubscribe:

  • Click "Unsubscribe" link in any promotional email
  • Update preferences in Account Settings > Communication Preferences
  • Email legal@puntersrepublic.com to opt-out of all non-essential communications

Important: You cannot opt-out of transactional communications necessary for platform operation.

12.3 Marketing from Third Parties

We do not sell or share your information with third parties for their marketing purposes.

13. CHANGES TO THIS PRIVACY POLICY

13.1 Updates

We may update this Privacy Policy from time to time to reflect:

  • Changes in our practices
  • New features or services
  • Legal or regulatory requirements
  • User feedback

13.2 Notification of Material Changes

For significant changes:

  • We will notify registered users via email at least 30 days before changes take effect
  • We will display a prominent notice on the Platform
  • We will update the "Last Updated" date at the top of this policy

13.3 Your Acceptance

Continued use of the Platform after changes take effect constitutes acceptance of the updated Privacy Policy.

13.4 Previous Versions

We maintain an archive of previous Privacy Policy versions. Contact us to request previous versions.

14. CONTACT US

14.1 Privacy Officer

For privacy-related questions, concerns, or to exercise your rights:

Email: legal@puntersrepublic.com
Subject Line: Include relevant keywords (e.g., "Access Request", "Deletion Request", "Privacy Inquiry")

14.2 Data Protection Officer

For formal privacy complaints or data protection matters:

Email: legal@puntersrepublic.com
Attention: Data Protection Officer

14.3 General Inquiries

For general questions about the Platform:

Email: support@puntersrepublic.com
Website: www.puntersrepublic.com/support

14.4 Response Times

  • Privacy requests: Within 30 days
  • Data access/export: Within 7-30 days
  • General inquiries: Within 5 business days

14.5 Mailing Address

Punters Republic operates as a digital-only platform. For all correspondence, please use our email contacts above.

For formal legal notices, email: legal@puntersrepublic.com

15. COMPLIANCE AND REGULATORY INFORMATION

15.1 Applicable Laws

This Privacy Policy complies with:

  • Privacy Act 1988 (Cth) - Australian Privacy Principles (APPs)
  • Spam Act 2003 (Cth) - Electronic communications
  • Australian Consumer Law - Consumer data rights

15.2 Regulatory Authority

Office of the Australian Information Commissioner (OAIC)

Website: www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au

15.3 Industry Standards

We follow industry best practices including:

  • ISO/IEC 27001 (Information Security Management)
  • OWASP Top 10 (Web Application Security)
  • NIST Cybersecurity Framework

ACKNOWLEDGMENT

By creating an account or using the Punters Republic platform, you acknowledge that:

  1. You have read and understood this Privacy Policy in its entirety
  2. You consent to the collection, use, and disclosure of your personal information as described
  3. You understand your privacy rights and how to exercise them
  4. You agree to receive essential communications related to your account and the Competition
  5. You understand that certain information will be publicly visible on leaderboards
  6. You are at least 18 years of age

Last Updated: 22 October 2025

Version: 2.0

Effective Date: 1 July 2025

This Privacy Policy is effective as of the date indicated above. Please review this page periodically for updates. For questions, contact legal@puntersrepublic.com.

Exercise Your Rights

You can exercise your privacy rights directly from your account settings or by contacting us.