Skip navigation
Dobitka

Privacy policy

Effective from June 1, 2026. Last updated: September 3, 2026. This English version is provided for convenience. The Polish version is the binding version of the document.

1. Data controller

The controller of personal data for Dobitka users is Mateusz Rutkowski Testy, Kraków, Poland, NIP: 7962790612, REGON: 381659867.

Privacy contact: rododobitka.pl.

2. Data we process

  • Account email, optional nickname and favourite club.
  • Adult confirmation timestamp and terms acceptance audit.
  • Match setups: lineup, formation, playing style and changes.
  • Simulation results, points, rankings and tournament picks.
  • Subscription and payment data (if we enable payments) handled through Stripe; card data is not stored by Dobitka. Voluntary support (“buy us a coffee”) runs through an external Stripe payment link.
  • Transactional email delivery data through Resend.
  • Technical data such as hashed IP, user agent, CSRF/session data and security logs.

3. Legal basis

  • GDPR art. 6(1)(b): account, simulation and digital service delivery.
  • GDPR art. 6(1)(a): optional consent and 18+ declaration.
  • GDPR art. 6(1)(c): accounting, tax and legal obligations.
  • GDPR art. 6(1)(f): security, abuse prevention, rate limiting and fraud prevention.

4. Retention

  • Account data: until account deletion.
  • Setups and simulation results: through the relevant football season, then aggregated where possible.
  • Payments and invoices: for the required accounting retention period.
  • Hashed IP and request metadata: up to 30 days.
  • Server logs: according to provider retention policies.

5. Processors

Dobitka uses Vercel, Supabase, Stripe (including the voluntary “buy us a coffee” payment link), Resend, Anthropic, a model service host, Upstash, Google Tag Manager (Google Ireland Limited), Meta Pixel and API-Sports/API-Football. Google Tag Manager loads only after consent on anonymous campaign landing pages. Its bootstrap receives standard HTTP request metadata for delivery and diagnostics; measurement tags require a separate review before publication. The remaining services process only the data needed for hosting, authentication, simulation, email, payments, security, campaign measurement or football data.

6. Your rights

Under GDPR you may request access, correction, deletion, restriction, portability, objection and withdrawal of consent where applicable. You may also lodge a complaint with the Polish data protection authority.

7. Minimum age

Dobitka is intended for adults, 18+. If we learn that an account belongs to a minor, the account and related personal data will be removed.

8. Cookies and similar technologies

We use strictly necessary cookies and local storage for login, CSRF protection, session state and interface preferences. The session cookie dobitka_marketing_auth_fence, per-attempt cookies with the dobitka_marketing_auth_fence_flow_prefix and their matching local/session storage state prevent Google Tag Manager from loading during sign-in transitions between browser tabs. They hold only random generations and a pending/clear status, not account data.

Analytics and marketing tools, including Vercel Analytics, Google Tag Manager and Meta Pixel, are loaded only after optional consent. Google Tag Manager is limited to anonymous campaign landing pages; it does not run on sign-in, account, payment, setup or admin pages. As remotely supplied first-party code, an active container can technically access the browser context of that public page. We do not start it while the tab stores an e-mail awaiting an OTP code, and container versions require access and data-scope review. These tools help us measure traffic, campaign performance and registration events. Refusing consent does not block access to Dobitka.

9. Changes

We may update this policy. Material changes are communicated by email to active users or by an in-product banner in advance.