Privacy Policy
Last Updated: January 27, 2026
At Ridha Tech ("we," "us," or "our"), we are committed to protecting your privacy and ensuring transparency in how we collect, use, and protect your personal information. This Privacy Policy explains how we handle data when you use our website (ridhatech.com) and our Sports Intelligence Platform and Outcome Probability Assessment Platform ("SIPAP").
By using our services, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Information You Provide
- Contact Information: Name, email address, company name, phone number when you contact us or sign up for our services
- Account Information: Username, password, and profile information when you create an account
- Communication Data: Messages sent via WhatsApp or our contact forms, including queries about sports events and betting opportunities
- Payment Information: Billing details and transaction information (processed securely through third-party payment processors)
1.2 Information Automatically Collected
- Usage Data: Pages visited, time spent on pages, links clicked, and other interaction data
- Device Information: IP address, browser type, device type, operating system, and unique device identifiers
- Location Data: General geographic location based on IP address
- Cookies and Tracking: See our Cookie Policy below for details on cookies and similar technologies
1.3 Information from Third Parties
- Sports Data Providers: We receive sports statistics, odds, and event data from third-party APIs (Football-Data.org, The Odds API, TheSportsDB)
- WhatsApp Business API: Message metadata and delivery status via Twilio WhatsApp integration
- Analytics Services: Aggregated analytics data from Google Analytics and similar services
2. How We Use Your Information
We use the information we collect for the following purposes:
- Provide Services: Deliver SIPAP sports intelligence, process your queries, and send WhatsApp notifications
- Improve Services: Analyze usage patterns, conduct A/B testing, and enhance platform features
- Personalization: Customize content and recommendations based on your preferences and behavior
- Communication: Send service updates, newsletters (with consent), and respond to inquiries
- Security: Detect fraud, prevent abuse, and ensure platform security
- Legal Compliance: Comply with applicable laws, regulations, and legal processes
- Analytics: Understand user behavior, measure marketing effectiveness, and generate insights
3. How We Share Your Information
We do not sell your personal information. We may share your information with:
- Service Providers: Third-party vendors who help us operate our platform (AWS, Twilio, analytics providers, payment processors)
- AI Service Providers: Anthropic (Claude AI via AWS Bedrock) for natural language processing
- Legal Requirements: Government authorities when required by law or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize us to share specific information
All third-party service providers are contractually obligated to protect your data and use it only for the purposes we specify.
4. Data Retention
We retain your personal information for as long as necessary to:
- Provide our services to you
- Comply with legal obligations (typically 7 years for financial records)
- Resolve disputes and enforce agreements
- Improve our services through analytics
Typical Retention Periods:
- Account Data: Until account deletion + 30 days (backup retention)
- WhatsApp Messages: 90 days (unless required for support or legal purposes)
- Analytics Data: 26 months (Google Analytics standard)
- Transaction Records: 7 years (tax and legal compliance)
5. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal information we hold about you
- Correction: Update or correct inaccurate or incomplete information
- Deletion: Request deletion of your personal information (subject to legal obligations)
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Restriction: Request restriction of processing in certain circumstances
- Withdraw Consent: Withdraw consent for marketing communications at any time
To exercise these rights, contact us at privacy@ridhatech.com. We will respond within 30 days.
6. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Essential Cookies: Required for site functionality (session management, authentication)
- Analytics Cookies: Google Analytics to understand usage patterns
- Preference Cookies: Remember your settings and preferences
You can control cookies through your browser settings. Note that disabling cookies may affect site functionality.
7. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: All data transmitted via HTTPS/TLS. Data at rest encrypted in AWS.
- Access Controls: Role-based access with multi-factor authentication for team members
- Infrastructure: AWS cloud infrastructure with SOC 2 Type II compliance
- Monitoring: Continuous monitoring for security threats and anomalies
- Audits: Regular security audits and penetration testing
While we take security seriously, no system is 100% secure. If you discover a security vulnerability, please report it to security@ridhatech.com.
8. International Data Transfers
Ridha Tech operates globally and serves users worldwide. Your information may be transferred to and processed in multiple regions to provide optimal service, including:
- United States: Primary AWS infrastructure (us-east-1 region)
- European Union: EU AWS regions for European users
- Asia-Pacific: Regional AWS infrastructure for optimal performance
- Global CDN: Content delivery via CloudFront edge locations worldwide
We ensure appropriate safeguards are in place through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all third-party processors
- Compliance with GDPR, CCPA, and other applicable privacy laws
9. Children's Privacy
SIPAP is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@ridhatech.com and we will delete the information.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify you via email (if you have an account) or prominent notice on our website
- Provide 30 days' notice before material changes take effect
Continued use of our services after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Regulatory Compliance
GDPR (European Users): We are committed to complying with the General Data Protection Regulation. You have the right to lodge a complaint with a supervisory authority in your jurisdiction.
CCPA (California Users): California residents have additional rights under the California Consumer Privacy Act. See Section 5 for details on your rights, including the right to opt-out of the sale of personal information (note: we do not sell personal information).