Collect less. Explain the rest.
Effective August 24, 2026. ScratchSignal is independently operated and is responsible for the information described here. A monitored privacy contact will be published before paid checkout opens.
Account and billing data
Account authentication is processed by Supabase Auth. ScratchSignal stores the Supabase user identifier, verified email address, and optional display name needed to recognize an account and connect it to service access. ScratchSignal never stores a plaintext or reversible password; password verification and salted password hashes are handled by Supabase. If you use Google sign-in, Google and Supabase handle those credentials.
Stripe—not ScratchSignal—collects and stores payment-card details. ScratchSignal stores Stripe customer and subscription identifiers, billing status, and paid-through dates needed to provide and manage Signal Pro access.
Alerts and community reports
When you request an alert, ScratchSignal stores the email address, selected state and game, consent record, and delivery status needed to send or stop that alert. Stock reports store the selected retailer, game, observation type, time, and an abuse-prevention account identifier. Precise device location and travel history are not required; users select a retailer manually.
Community reports are excluded from signals after 72 hours and deleted during routine cleanup once older than 30 days. Operational logs may contain request and payment event identifiers, but not card details, passwords, or secret keys.
Private ticket ledger
Signed-in users may save structured ticket records including the monitored game, purchase date, quantity, price recorded from the official game feed, and optional retailer, note, result, and winnings amount. Entries are not publicly displayed and access is restricted to the signed-in account, subject to limited authorized operational access and infrastructure processing needed to run, secure, and support the service. Users can delete individual entries from the account page.
The ledger does not accept or store ticket photos, barcodes, or dedicated serial- or claim-number fields. Do not put sensitive ticket identifiers in the optional note. ScratchSignal is a supplemental recordkeeping aid; retain original tickets, receipts, tax forms, and other supporting records.
Aggregate analytics
ScratchSignal uses privacy-preserving daily traffic and conversion counters and does not set an analytics cookie. The service stores only a calendar day, an allowlisted page or funnel event, a coarse referrer category such as search, AI, or direct, and an aggregate count. It does not store an analytics event row, email address, account identifier, analytics cookie, browser identifier, full IP address, user agent, precise location, query string, or full referrer URL. A daily HMAC pseudonym is used only in the rate-limit table, expires about one minute after the latest counted request, and may remain until a later cleanup pass; the source address is never stored and the pseudonym is never written to the analytics table. Cloudflare may set essential security or abuse-prevention cookies at the infrastructure layer.
Request access, correction, alert removal, or account deletion through the support page.