← Home

Privacy Policy

Last updated: June 2026

1. Who We Are

This app ("Roma Pizza World Cup Prediction") is operated by Roma Pizza Romsey, located in Romsey, Hampshire, United Kingdom. We are committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. What Data We Collect

When you use our app, we collect:

  • Full name — to identify you on the leaderboard
  • Mobile phone number — for account verification via WhatsApp and to contact winners
  • Email address (optional) — for account recovery if provided
  • Prediction data — your match score predictions and points earned
  • Push notification subscription — to send you match alerts (if you opt in)

3. How We Use Your Data

We use your personal data to:

  • Verify your identity via WhatsApp OTP
  • Display your name on the public leaderboard
  • Calculate and award competition prizes
  • Send push notifications about match results and rank changes (if opted in)
  • Contact prize winners to arrange collection

4. Legal Basis

We process your data based on legitimate interest (running the prediction competition) and consent (you voluntarily sign up and provide your information). For push notifications, we rely on your explicit opt-in consent.

5. Data Sharing

We do not sell your data. We share limited data with:

  • WhatsApp (Meta) — your phone number, solely for sending verification codes
  • Amazon Web Services (AWS) — our hosting provider, data stored in EU (London region)

Your name appears on the public leaderboard within the app. No other personal data is publicly visible.

6. Data Retention

We keep your data for the duration of the FIFA World Cup 2026 competition and up to 30 days after the competition ends for prize distribution. After that, accounts and personal data are deleted unless you request earlier deletion.

7. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your account and data
  • Withdraw consent for push notifications at any time
  • Lodge a complaint with the ICO (Information Commissioner's Office)

8. Security

All data is encrypted in transit (HTTPS) and at rest. Passwords are hashed with bcrypt. OTP codes are stored as SHA-256 hashes and expire after 10 minutes. We use AWS infrastructure with industry-standard security controls.

9. Cookies

This app does not use cookies. We use browser localStorage to store your authentication session token. No third-party tracking or analytics cookies are used.

10. Contact

For any privacy questions or data requests, contact us at:
Roma Pizza Romsey
Email: romapizza.romsey@gmail.com
WhatsApp: +44 1794 830844