Scope of this privacy policy
This Privacy Policy explains how QPSCheck collects, uses, discloses, stores, and protects personal information when people visit our public website, request access, receive invitations, or use the QPSCheck platform on behalf of an organization.
This policy is intended to give a strong baseline disclosure for our current beta service. Customer contracts, data processing addenda, or employment policies may also apply to information processed through the platform.
Categories of information we collect
- Identifiers and account details, such as name, email address, profile image, organization membership, role, time zone, and authentication-related account metadata.
- Operational records, such as player profile data, aliases, descriptors, notes, flags, opportunities, session activity, financial entries, reports, notifications, and media uploaded into the platform.
- Device, usage, and network information, such as browser type, pages viewed, approximate location derived from IP, request metadata, referring pages, audit metadata, and security event data.
- Communications and support content, such as feedback submissions, invitation status, customer correspondence, and administrative notes tied to support or product operations.
Sources of information
- Directly from you when you sign in, complete forms, upload media, provide feedback, or communicate with us.
- From the organization or administrator that invites, sponsors, or manages your access.
- From customer-provided imports, seed data, or operational records that an authorized organization loads into the platform.
- Automatically from your browser, device, and interactions with our public website or platform, including analytics and security tooling when enabled.
Why we use personal information
- To authenticate users, maintain sessions, and enforce tenant, organization, casino, and role-based access rules.
- To operate player intelligence, reporting, workflow, media, notification, staffing, support, and administrative features requested by authorized customers.
- To protect the service, detect abuse, investigate incidents, troubleshoot errors, maintain audit history, and improve reliability, security, and usability.
- To communicate about invitations, product changes, service notices, support matters, or contractual and administrative issues.
- To comply with legal obligations, enforce agreements, and protect rights, safety, systems, and property.
Cookies and similar technologies
QPSCheck uses essential technologies needed to run the site and platform, such as session and security cookies used for authentication, CSRF protection, and state continuity.
When analytics is enabled, we may also use analytics technologies to understand how the public site and application are being used so we can improve product performance, navigation, and adoption. You can accept or decline non-essential analytics cookies through our consent banner.
- Essential cookies: required for sign-in, session integrity, security, and core site behavior.
- Analytics cookies: used to measure site usage, page engagement, and product performance trends.
- You can manage browser cookies through your browser settings, but disabling essential cookies may prevent parts of the service from working correctly.
How we disclose information
- To the organization, company administrators, casino administrators, and authorized staff members that are permitted to access the information inside the platform.
- To vendors and service providers that help us operate hosting, storage, security, authentication, analytics, communications, and support functions.
- To professional advisers, auditors, insurers, regulators, courts, or law enforcement where reasonably necessary to comply with law, protect rights, or respond to legal process.
- In connection with a corporate transaction, such as a financing, acquisition, reorganization, or sale, subject to appropriate confidentiality and transfer safeguards.
Data retention
We retain information for as long as reasonably necessary to provide the service, maintain security and audit records, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by record family, sensitivity, customer relationship, and legal obligations.
Our current beta baseline includes indefinite audit retention, short-lived export artifacts, archive-first treatment for tenant operational records, and bounded retention windows for selected support and security telemetry records. Some records are archived instead of immediately deleted when they are no longer actively used.
- Revoked access grants and invitation records are retained for security and audit history.
- Feedback and support records are retained only as long as needed for support, security, audit, and legal obligations.
- Security telemetry and sanitized exception ledgers are retained for bounded operational windows unless a legal hold, security investigation, or audit requirement requires longer retention.
Legal holds and customer offboarding
If a legal hold, investigation, dispute, or comparable obligation applies, we may preserve affected records beyond their ordinary lifecycle and pause purge, disposal, or offboarding-destruction steps until release is approved through our internal controls.
When an organization's use of QPSCheck ends, the default offboarding path is a customer export plus a bounded archive window for tenant-owned operational records before disposal review, while immutable audit/security records and any records under legal hold remain retained.
Security and storage practices
We use safeguards designed to protect personal information against unauthorized access, loss, misuse, and disclosure. Those controls may include access management, server-side authorization, scoped media workflows, audit logging, encryption and storage protections, environment isolation, and operational monitoring.
No method of transmission, storage, or security control is perfect. If you believe your account or information has been compromised, contact us promptly.
Your privacy rights and choices
Depending on where you live, you may have rights to request access to personal information, correction of inaccurate information, deletion of certain information, or information about our disclosure practices.
To make a privacy request, contact access@qpscheck.com and identify your organization, relationship to QPSCheck, and the request you want to make. We verify identity and authority before acting on a request, and requests involving customer-supplied player data may be routed through the responsible organization unless law requires us to handle them directly.
- We do not use this public policy page to represent that we sell personal information in exchange for money.
- Deletion requests do not override audit retention, legal holds, fraud or security exceptions, or other documented legal obligations.
- Corrections are handled in a way that preserves auditability and does not silently rewrite immutable audit history.
- If a specific law gives you additional rights, we will process verified requests as required by applicable law.
- We will not intentionally use dark patterns to obtain consent or to interfere with your privacy choices.
Service providers and data processing addenda
QPSCheck uses service providers to support hosting, authentication, storage, security, analytics, communications, and support operations. Current provider categories include Google / Firebase / Google Cloud services, Google Analytics when analytics cookies are accepted, and Google Workspace or Gmail-based invitation delivery.
For production customer use, QPSCheck supports a public subprocessor-list and a data processing addendum on request. Signed customer agreements or DPAs control over this public summary where they conflict.
California privacy disclosures
If the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to our processing, California residents may have rights to know, access, delete, correct, and limit certain uses of personal information, subject to exceptions.
Our current categories of collected information, sources, purposes, and disclosures are described in this policy. We post this Privacy Policy through a homepage link using the word privacy and will update it as our practices evolve.
Children's privacy
QPSCheck is intended for business use and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13 through the public site or service.
Changes and contact information
We may update this Privacy Policy from time to time to reflect changes in the product, law, vendors, or business operations. When we do, we will update the effective date on this page.
Questions, complaints, privacy requests, or DPA/subprocessor inquiries may be sent to access@qpscheck.com.