Privacy Policy
Last updated: 13 August 2026
1. Who We Are
Thedigitalab ltd ("we", "us", "our") operates Ressq accessible at getressq.com. Our registered address is 45 Fitzroy Street, London, W1T 6EB, London, UK. You can reach us at contact@getressq.com.
2. What This Policy Covers
This policy explains what personal data we collect, why we collect it, how we use it, and your rights. It applies to our website, apps and services (collectively, the "Service").
3. Data We Collect & Why
Account data
- Examples: name, email address, username and authentication identifier
- Source: you and Firebase Authentication. Your password is handled by Firebase and is not visible to Ressq.
- Why: create and manage your account
- Legal basis: contract necessity
Payment data
- Examples: transaction and subscription identifiers, product, status and renewal dates. Stripe, Apple or Google processes payment credentials; Ressq does not store full card numbers.
- Source: Stripe, Apple, Google Play and RevenueCat
- Why: process payments, prevent fraud, keep accounting records
- Legal basis: contract necessity / legitimate interests / legal obligation
Preferences & saved content
- Examples: followed teams and leagues, notification settings, product mode, saved betting history, community votes and ACCA research
- Source: you
- Why: provide the features you choose and sync them across signed-in devices
- Legal basis: contract necessity
AI conversations
- Examples: prompts you submit and the football context needed to answer them
- Source: you and Ressq match data
- Why: generate the explanation or analysis you request using our AI provider
- Legal basis: contract necessity / consent where required
Usage & analytics data
- Examples: pages viewed, clicks, events, session duration
- Source: PostHog, Vercel Analytics and app event measurement tools
- Why: understand how the product is used and improve it
- Legal basis: legitimate interests / consent (where required)
Device & cookie data
- Examples: IP address, user agent, app instance or device identifiers, push token, cookies/local storage IDs, crash and performance information
- Source: collected automatically
- Why: authentication, push notifications, security, debugging, fraud prevention and delivery of ads to free users
- Legal basis: legitimate interests / consent
Support communications
- Examples: emails, chat transcripts
- Source: you
- Why: respond to enquiries and provide support
- Legal basis: legitimate interests / contract
5. Ads & Analytics
- PostHog and Vercel Analytics: product interaction and performance measurement used to improve Ressq.
- Firebase Authentication: account authentication, identity verification and password-reset delivery.
- Google Mobile Ads: non-personalised advertising for free users, including delivery, measurement and fraud prevention.
- Expo and Apple/Google push services: device tokens and delivery information for notifications you enable.
- RevenueCat: native subscription status and purchase entitlement management.
- Google Gemini: processes prompts and supplied match context when you ask the AI assistant a question. Do not include unnecessary personal information in a prompt.
Each vendor acts as a processor or independent controller depending on context. Review their privacy policies and data processing terms. International data transfers are protected via SCCs/UK Addendum or equivalent safeguards.
6. Payments & Subscriptions
Stripe processes web payments. Apple and Google process native app purchases, and RevenueCat helps Ressq keep your entitlement in sync. We never store full card numbers. We retain limited transaction metadata for subscription support, accounting and fraud prevention.
7. How Long We Keep Data
We keep personal data only as long as necessary for the purposes above, then delete or anonymise it. Typical retention periods:
- Account and saved feature data: while your account is active
- Transaction records: 7 years (tax/legal)
- Analytics events: 18 months
- Push tokens: until you sign out, disable notifications or delete your account, subject to delivery-provider retention
9. International Transfers
If we transfer data outside the UK/EU, we rely on Standard Contractual Clauses (SCCs), the UK Addendum, or another valid mechanism. Details available on request.
10. Your Rights
Depending on your location, you may have the right to access, correct, delete, or port your data; object to or restrict processing; withdraw consent; or opt out of certain data sharing (“sale”/“sharing” under US state laws).
To exercise rights, email contact@getressq.com with the subject line “Data Request” and include: (1) which right you’re exercising, (2) what data it concerns, and (3) proof of identity. We’ll respond within applicable legal deadlines.
You can delete a Ressq account directly in the mobile app from Profile → Account → Delete Account. This removes the account and associated Ressq profile, saved history, favourites, notification data and entitlements. Deleting an account does not cancel an Apple or Google subscription, which must be managed through the relevant store. Limited transaction records may be retained where law requires.
11. Children
We do not knowingly collect data from individuals under 18. If you believe we have collected such data, contact us and we will delete it.
12. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you (e.g., by email or a banner). Check the “Last updated” date at the top.
13. Contact Us
THEDIGITALAB LIMITED is the data controller and operator of the Ressq platform available at https://getressq.com.
Questions or concerns? Email contact@getressq.com or write to us at 45 Fitzroy Street, London, W1T 6EB, London, UK.
