Privacy Policy
Poker Grind Ledger (“PGL”) is a poker tracking, ledger and analytics product. This policy explains how DAVAND, Lda. processes personal data when you use the PGL Public Beta.
1. Controller and contact
DAVAND, Lda., a Portuguese limited liability company, NIPC/NIF 516751298, is the operator and data controller for PGL. Its registered office and full public identification are available on the Legal Information page. Contact us about privacy, data rights or support at support@pokergrindledger.com. PGL has not appointed a Data Protection Officer.
2. Data we process
- Account and authentication: email address, Supabase user identifier, authentication provider, account creation, confirmation and sign-in metadata, and authentication or recovery session information. Password credentials and OAuth tokens are handled through Supabase Auth and, when selected, Google OAuth; PGL application screens do not read your password.
- Profile, goals and preferences: name, nickname, country, poker focus, goals, language, timezone, visual theme, Reporting Currency and compatibility currency metadata needed to preserve existing records.
- Poker records: dates, times and hours, formats, official or Custom Rooms, tournament or cash-session details, entries and re-entries, buy-ins, cash-outs, stakes, results, currencies and historical FX/conversion information. PGL derives P&L, ROI, ABI, hourly results, volume, trends and similar reports from the information you enter.
- Browser and convenience state: account-scoped caches, drafts, preferences, Quick Buy-Ins, recent currencies, active-page state, and synchronization, migration, restore and recovery checkpoints.
- Support and account deletion: request type and description, expected result, limited page/language/browser-device context, request status and lifecycle dates. PGL instructs users not to submit passwords, access tokens, backup files or unnecessary poker history.
- Backup, restore and operational evidence: restore/delete operation identifiers, hashes, status and generation/revision information. A downloaded PGL Backup contains the account data described in the product before it is saved by you.
- Administration and security: minimized administrator identifiers, bounded actions/targets, outcomes, timestamps, revisions and device identifiers. Infrastructure providers may also process IP address, user-agent/device, request, authentication and error information in their logs.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Create and secure your account; provide login, recovery and account isolation | Account, authentication and technical data | Performance of our agreement; legitimate interests in service and account security |
| Store, synchronize, back up and report your ledger | Profile, goals, poker, room, FX and preference data | Performance of our agreement |
| Protect PGL, prevent misuse and maintain operational evidence | Technical, security and limited account data | Legitimate interests in protecting users and the service; legal obligations where applicable |
| Respond to support, rights and deletion requests | Request, contact and limited account context | Performance of the agreement, legitimate interests in support and improvement, and legal obligations concerning rights requests |
PGL does not sell personal data, process payments or bankrolls, use personal data for advertising, or perform automated decision-making that produces legal or similarly significant effects.
4. Service providers and international processing
PGL uses Supabase for authentication, database functions and the current Auth email arrangement; Vercel for hosting and server functions; Google OAuth if you choose Google sign-in; Google Fonts for externally hosted typefaces; jsDelivr to deliver the Supabase browser library; and the Frankfurter FX service for historical exchange-rate information. These providers receive the information needed for their functions, including ordinary request metadata. Provider regions, subprocessors, transfer arrangements and technical-log settings depend on the applicable service configuration and will be maintained and verified as part of Production operations. We do not claim a specific location or transfer mechanism where it has not been confirmed.
5. Browser storage, cookies and analytics
PGL uses functional browser storage for Auth persistence, account and session state, caches and drafts, preferences, recovery routing, and synchronization or migration checkpoints. Supabase Auth may maintain authentication material in browser storage. Browser storage mechanisms are not all cookies.
The audited PGL application sets no non-essential analytics or advertising cookies and contains no Google Analytics, Vercel Analytics, Meta Pixel, marketing pixel, behavioral analytics or session replay. PGL therefore does not display a consent banner for technology it does not use. Before any non-essential analytics, advertising or replay technology is activated, PGL will reassess the required disclosure and consent position.
6. Backups and retention
A PGL Backup is generated in your browser from current account/device state and downloaded directly by you. It may include sessions, room configuration, profile, goals, preferences, Quick Buy-Ins and recent currencies; drafts are excluded. A restore sends the selected backup to Supabase so that applicable server data can be replaced. PGL does not maintain your downloaded file as a separate server-side backup archive. After download, you control that copy.
- Active account and poker data: retained while the account is active and as needed to provide PGL.
- Support requests: operationally retained for up to two years after resolution or closure, unless a longer period is genuinely necessary for legal claims, security, dispute handling or another lawful requirement.
- Account-deletion evidence: only minimized evidence needed to process or demonstrate the operation may be retained, operationally for up to five years where justified for accountability or legal evidence. Deleted poker payloads are not retained merely as deletion evidence.
- Administrator and security audit evidence: operationally retained for up to two years unless a specific incident, legal claim or lawful security need justifies longer retention.
- Provider logs and infrastructure copies: retained according to applicable provider configuration and proportionate operational, security and legal necessity. Exact provider periods are not stated where they have not been verified.
These are PGL operational periods and criteria, not immutable statutory periods. Applicable legal duties or a legitimate dispute/security need may require a shorter or longer period.
7. Your rights
Depending on applicable law and circumstances, you may request access, rectification, erasure, restriction, objection, or portability, and may withdraw consent where processing actually relies on consent. You can view and correct profile/session information and download a PGL Backup in the product. Send other requests to support@pokergrindledger.com. We may make proportionate checks to verify your identity.
8. Delete Poker Data and Account Deletion
Delete Poker Data is not Account Deletion. Delete Poker Data removes the poker dataset covered by that product workflow while retaining the PGL login account and basic profile/preferences.
Account Deletion requests closure of the account and deletion of associated ordinary PGL account data under the account-deletion process. Submit an authenticated request in PGL or email support@pokergrindledger.com, preferably from the registered email. Do not send a password, access token or unnecessary identity document.
PGL aims to complete a valid Account Deletion request within 30 days. This is not a promise of immediate removal from every infrastructure copy: limited information may be retained where lawfully required, and provider backups or logs may expire according to their applicable schedules. Browser-local data and backups downloaded by you cannot be erased remotely.
9. Security and required information
PGL uses account isolation, row-level access controls, revision checks and restricted administrator access. No online service can guarantee absolute security. Email and authentication data are required for a hosted PGL account; other profile and poker fields are provided when you use the corresponding features.
10. Age and service scope
The Public Beta is intended for people aged 18 or older who can lawfully use the service. PGL is a tracking and analytics ledger—not a poker room, casino, wagering service, gambling operator, bankroll custodian or solver. Availability does not mean that PGL guarantees poker activity is lawful in every jurisdiction.
11. Complaints and changes
You may complain to the competent data-protection authority, including the authority where you live or work or where an alleged infringement occurred. The Portuguese supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD). The CNPD has not reviewed or approved PGL.
We will date updates to this policy and communicate material changes appropriately.
POKER GRIND LEDGER