What personal information PuntersEdge collects, why, who sees it, how long we keep it, and what you can ask us to do with it. The short version is first; the detail follows.
PuntersEdge is the trading name of Hamish William Carter, a sole trader registered in Australia under ABN 32 571 495 604 ("we", "us", "our"). We operate puntersedge.online and its subdomains, the PuntersEdge API at api.puntersedge.online, the account console, the embeddable widgets, our developer tooling and our newsletters.
This policy covers the personal information we handle in running those services, whoever you are: an API customer, a visitor to the website, a reader of one of our emails, a visitor to a third-party site that embeds our widget, or someone we have contacted about PuntersEdge. It should be read with our Terms & Conditions.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and we apply the same standards to everyone regardless of where they are. If you are in the United Kingdom or the European Economic Area, section 9.6 describes the additional rights that apply to you.
Every API request is metered: we record the key, the endpoint, the time, the response status and the credits charged. These metering records contain no IP address. Separately, our servers write request logs that include the IP address, the client software, the request identifier and a masked form of the account address; those logs are kept for 14 days for security, support and abuse investigation and then rotate away. We also keep the delivery record of each webhook we send you: the event, the time, the status your endpoint returned, the attempt count and, for failed deliveries, the error.
If you subscribe to the developer newsletter we hold your email address, where you subscribed and whether you have unsubscribed, plus a record of which issues were sent to you. Feature requests and showcase submissions are stored with the text you entered, any email address you chose to give, a hashed form of your IP address and your browser identifier, used to limit abuse. Enterprise enquiries hold the name, company, email, expected volume and use case you entered.
When a third-party site embeds a PuntersEdge widget, your browser requests the widget frame from our servers, which record your IP address, your browser and the address of the page the widget is embedded on in the web-server logs described in 2.3. The widget frame sets no cookies and loads no analytics or tracking script. The embedding site's own privacy policy governs that site.
We sometimes write to businesses and developers who publish racing or sports products, to introduce the API. If you hear from us without an existing relationship, we obtained your business contact details, typically a name, a role, a company and a work email address, from a public source such as your website, a public repository or a public profile. Reply or email us to say stop and we add your address to our suppression list so that it does not happen again.
PuntersEdge Members, our former tipping membership, is no longer offered. We still hold the records of former members: the website login (email and hashed password), the Telegram identifier and username used to deliver content, subscription status and history, and records of which tips were delivered. We no longer use this data and will delete your part of it at any time on request (section 9.3).
We never see or store card numbers; payment details are entered directly with Stripe. We do not collect government identifiers, precise location, or information about your betting accounts or bets. We do not receive the personal information of your own users when you build a product on the API, except as described in 2.5 for visitors to embedded widgets.
Decisions made without a person involved are limited to the signup checks and rate limits above, the usage-triggered service messages, and the automatic expiry of trials. None of them is a decision about you with legal or similarly significant effect; if one of them blocks you and you think it is wrong, email us and a person will look.
We do not sell, rent or trade personal information, and we do not share it with anyone for their own marketing. It goes to the service providers we rely on to run PuntersEdge, each of which handles it under its own privacy policy and only for the purpose described.
| Provider | What they do for us | What they receive | Where |
|---|---|---|---|
| Stripe | Payments, invoices, the customer portal | Your email, card details (entered with Stripe directly), billing name and address if Stripe asks for them, plan and metadata such as attribution tags and a partner referral identifier | Australia, United States |
| Resend | Sends our email: verification, keys, service notices, the newsletter | Your email address, the message, and delivery and bounce status | United States |
| Analytics (anonymised), fonts on the website, our business email, and measurement of our advertising | Analytics events without your IP address; your IP address when your browser fetches fonts; correspondence you send to our Google Workspace address; the click identifier of a Google ad you arrived from, which may be reported back to Google Ads when it leads to a signup or purchase | United States | |
| PromoteKit | Attributes signups to the partners who refer them | A referral cookie set when you arrive through a partner's link, and, from Stripe, the details of a sale attributed to that partner | Outside Australia |
| DigitalOcean | Hosts our servers and database | Everything in this policy, on infrastructure in Sydney, Australia | Australia |
| Cloudflare | Stores copies of our database backups | Backup copies of the database, encrypted at rest by the provider | May be outside Australia |
| Telegram | Delivers operational alerts to us | A new-signup alert to our own account that includes the email address and plan of the new signup; service-health alerts contain no personal information | Hosted globally |
| Have I Been Pwned | Compromised-password check | The first five characters of a SHA-1 hash of a password you are setting; never the password or your identity | Hosted globally |
| Anthropic | AI tooling we use to help draft support replies and operate the service | The content of a support request we are answering and the account records relevant to it, processed under our instructions | United States |
Some of these providers are outside Australia, chiefly in the United States. Before disclosing personal information to an overseas provider we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, including by sending the minimum needed and relying on the provider's published commitments and contractual terms.
We may also disclose personal information where the law requires it, for example to a court, regulator or law-enforcement body with proper authority; to our professional advisers under confidentiality; and to a buyer or successor if the PuntersEdge business is sold or transferred, in which case we will tell you.
| Name | Set by | Purpose | Lasts |
|---|---|---|---|
pe_utm | Us | Remembers how you arrived (referrer, landing page, campaign tags, click identifiers) so that a later signup can be attributed. Not readable by scripts. | 30 days |
pe_session | Us | Keeps you signed in to the legacy website login used for administration and former Members accounts. | 30 days |
pe_console_key | Us (browser storage) | Your console sign-in token, stored in your browser's local storage after you log in to the API console. The matching server session expires after 30 days and can be ended from the console at any time. | Until you log out or 30 days |
pe_age_ack_v1 | Us (browser storage) | Records that you confirmed you are 18 or over, so the notice is not repeated. | Until cleared |
_ga, _ga_* | Google Analytics | Distinguishes visitors for aggregate analytics. IP addresses are anonymised. | Up to 2 years |
promotekit_referral | PromoteKit script | Set when you arrive through a partner's referral link, and read at checkout so the partner is credited. | Set by PromoteKit |
Stripe sets its own cookies on its checkout and portal pages. You can block or delete cookies in your browser; the attribution and analytics cookies are not needed for the site to work, but the sign-in cookies and storage are needed to stay signed in. The embedded widget frames set no cookies.
All traffic to the website and the API is encrypted in transit. Passwords are stored as bcrypt hashes and API keys as cryptographic hashes; neither can be read back. Sensitive actions in the console, such as revealing a key or opening billing, ask you to confirm your password or to use a fresh sign-in. You can end every session on your account from the console, and we email you whenever your password is set or changed. Paid plans can restrict a key to listed IP addresses. Access to production systems is limited to the operator, and the database is backed up nightly with copies kept offsite. Payment data is handled entirely by Stripe.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires. If you believe you have found a security problem, email hamish@punters-edge.com.
| Information | Kept for |
|---|---|
| Account records (email, hashes, plan, settings, consent records) | While your account exists, then deleted on request. Records we must keep for tax and accounting purposes, such as invoices and payment history, are kept for at least five years after the transaction. |
| Request metering records | While your account exists. Once the account is deleted they no longer identify you. |
| API server logs (with IP addresses) | 14 days |
| Web-server access logs | About a week |
| Console sessions, sign-in links, password-reset links | 30 days, 15 minutes, 30 minutes |
| Signup rate-limit counters (by IP address) | 29 days |
| Attribution cookie | 30 days |
| Email delivery records (address, subject, time, status) | Kept to handle delivery problems and complaints; redacted when your account is deleted. |
| Suppression list (addresses that asked not to be contacted) | Indefinitely, because it is what keeps the promise. |
| Newsletter subscriptions | Until you unsubscribe, after which the address is kept flagged so that it is not emailed again, or deleted on request. |
| Feedback, testimonials and showcase listings | While published or while your account exists; removed on request. |
| Business contacts we approached | Until you ask us to stop, when the address moves to the suppression list. |
| Backups | Nightly backups are kept for 7 days, weekly backups for 8 weeks and monthly archives for 24 months. Information deleted from the live database remains in those backups until they expire and is not restored except to recover from a failure. |
You can see and change most of your account details in the console. For anything else, email us from your account address and we will send you a copy of the personal information we hold about you, or correct it, usually within 30 days. We may ask you to confirm your identity first.
On request we will give you your account data, including your usage records and attribution, in a machine-readable form.
Email us from your account address and we will deactivate your keys and delete the personal information we hold about you, including former Members records. We keep what the law requires us to keep, principally tax and billing records, and the minimum needed to honour a request not to be contacted again. Deleted information also persists in backups until they expire (section 8).
Promotional email is sent only if you opted in, at signup or in the console. Opt out at any time from the console, from the unsubscribe link in any such email, or by emailing us. The developer newsletter is a separate list with its own subscribe and unsubscribe. Service messages about your keys, billing and changes to the service continue while you hold an account, because they are part of providing it.
If you think we have mishandled your personal information, email us first and we will investigate and reply within 30 days. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
We process your personal information to perform our contract with you (providing and billing the service), for our legitimate interests in securing the service, preventing abuse and understanding how it is used, with your consent where we send marketing, and to comply with law. You have the rights of access, rectification, erasure, restriction, portability and objection described above, and the right to withdraw consent at any time, which does not affect processing already carried out. You may also complain to your local supervisory authority. Transfers to Australia and to the providers in section 5 are made on the basis of the providers' contractual commitments and the measures described in this policy.
PuntersEdge is for adults aged 18 and over and we do not knowingly collect personal information from anyone younger. If we learn that an account belongs to a minor we close it and delete the information.
When we change how we handle personal information we update this page and the date at the top. For a change that materially affects you we also email the address on your account before it takes effect. Earlier versions are available on request.
PuntersEdge, the trading name of Hamish William Carter
ABN 32 571 495 604 · Queensland, Australia
Privacy enquiries: hamish@punters-edge.com · Contact page