Privacy policy
What LuckLogic collects, why, where it is kept, for how long, and who else handles it. Written from how the service actually works, so it is specific rather than general.
1. Who we are and when this applies
LuckLogic (“we”, “us”) provides infrastructure for on-pack and instant-win promotions: an API, an agency and brand portal, a hosted entry page, an embeddable widget and a staff app for handing over prizes. LuckLogic is operated by Dacoda ehf., company registration number (kennitala) 540102-4060, Hafnargata 51–55, 230 Reykjanesbær, Iceland, until LuckLogic’s own company is registered. Dacoda is the controller and processor referred to in this policy. Contact us about anything in this policy at hello@lucklogic.dev.
We handle personal data in two different roles:
- As controller for visitors to lucklogic.dev and for the people who use our portal and API: agency and brand staff. Sections 2 and 3 cover this.
- As processor for the people who enter promotions run on LuckLogic. The agency or brand running the promotion (our customer) decides why and how that data is used, and their privacy notice is the one that governs it. Section 4 describes what we process for them.
2. Visitors to lucklogic.dev
- No cookies, no analytics. The website sets no cookies, uses no browser storage, runs no analytics or advertising scripts, and serves its own fonts.
- Hosting. The site is served by Vercel, which processes your IP address and request details to deliver pages and keeps short-lived technical logs.
- Contact form. When you use /contact we receive your name, email address, company (if given), the topic and your message. It is delivered to our inbox by Resend, and we use it only to answer you. The form is protected by Cloudflare Turnstile, which checks your browser and IP address to tell people from bots. We keep correspondence for as long as it is useful for the conversation and any business relationship that follows.
3. Portal and API users
If you have a LuckLogic account, or someone invites you to one, we process:
- Account details: your name and email address, and your password stored only as a scrypt hash. Accounts created with Google or GitHub have no password; we store the provider’s account identifier and the verified email address it reported.
- Membership: which workspaces and brands you belong to, and your role in each.
- Sessions: when you sign in we keep a hash of your session token, your browser’s user agent and when the session was last used. A session lasts up to 30 days.
- Invitations and password resets: the invited email address and role, valid for 7 days; reset links valid for 1 hour and usable once. We send these emails through Resend.
- What you do in the portal: changes to campaigns and prize claims are recorded with the account that made them, so customers have an audit trail.
- Bot protection: sign-up and password-reset forms use Cloudflare Turnstile.
- Customer contacts: agencies can record a contact person (name, email, phone) for each brand they work with.
We use this to provide the service, keep accounts secure, and contact you about your account. We do not send marketing email, and we do not sell personal data.
4. People who enter promotions
LuckLogic is built to decide whether a code wins without knowing who entered it. We never ask for a participant’s name, email address or phone number. On behalf of the agency or brand running the promotion we process:
- Codes, stored only as keyed hashes. The printable files of codes that customers download for packaging are kept in object storage in the EU.
-
A participant identifier chosen by the customer, used for entry limits and their own
reconciliation. On our hosted entry page and widget it is a random token kept in a cookie or in browser
storage (
ll_pt, one year), so repeat entries from the same browser can be limited. - IP addresses of people entering through the hosted page or widget, or supplied by the customer, used to limit abuse (per-address limits and, when a campaign asks for it, a Cloudflare Turnstile check). We keep them for at most 12 months.
- Entries and outcomes: each attempt, whether it won, and for winners the prize claim, its status, and any notes or references the customer records while handing the prize over.
Customers can send their own fields with an entry. We ask them not to send names, contact details or other identifying data, but if they do, we process it as their processor too.
To exercise your rights over promotion data, contact the promoter named in the promotion’s terms. They control the data; we help them answer you. If you contact us, we will pass your request to them.
5. Legal bases
- Contract: to provide your account and the service you signed up for.
- Legitimate interests: to answer enquiries, keep the service secure and prevent fraud and abuse, and keep audit records our customers rely on.
- Legal obligation: to keep records the law requires, such as invoices.
For promotion data, the legal basis is the promoter’s, as their processor.
6. Service providers
These companies process personal data for us, each only for the purpose listed:
| Provider | What for | Where |
|---|---|---|
| Railway | The API, its database, background jobs and the hosted entry page | EU (Amsterdam) |
| Cloudflare | DNS, storage of code files, Turnstile bot checks, forwarding of our email | EU storage; global network |
| Vercel | The website, the portal and the Verify app | EU (Frankfurt) for the portal and Verify; global network |
| Resend | Sending account emails and contact-form messages | United States |
| Sign in with Google, and our email inbox | Global | |
| GitHub | Sign in with GitHub | United States |
Where data leaves the European Economic Area, we rely on the provider’s certification under the EU–U.S. Data Privacy Framework or on the European Commission’s standard contractual clauses. We will update this list before adding a provider that handles promotion data.
7. How long we keep it
| Sessions | Up to 30 days of use; the record stays for security history |
| Password reset links | Valid 1 hour, once |
| Invitations | Valid 7 days |
| IP addresses of people entering promotions | 12 months, then deleted automatically, in the entry log and in entry records alike |
| Entry-limit counters | Deleted automatically once their limit window has ended (at most about a month) |
| Retry protection for API requests | 24 hours |
| Workspaces, campaigns, entries, claims and code files | Until the workspace is closed, so campaigns can be reconciled and audited |
Deleting your account. You can delete your own account at any time in the portal (Profile, then Delete account). Your name, email address, password and Google or GitHub links are erased and you are signed out; records of what you did in a workspace keep only an anonymous reference.
Closing a workspace. A workspace admin can close it in Settings. Thirty days later the workspace and everything in it (campaigns, codes and code files, entries, claims, keys, webhooks, clients and locations) is deleted automatically; until then it can be exported or reopened. We also delete a workspace on request, and keep only records the law requires.
8. Security
All traffic is encrypted in transit. Passwords, session tokens, invitation and reset tokens are stored only as hashes, and codes only as keyed hashes. API keys are scoped to sandbox or production, and access in the portal follows each person’s role. The security page has more detail.
9. Your rights
You can ask us for a copy of your personal data, to correct or delete it, to restrict or object to how we use it, and to receive it in a portable format. Write to hello@lucklogic.dev; we answer within one month. You can also complain to a data protection authority: in Iceland that is Persónuvernd (personuvernd.is), or the authority where you live or work.
10. Changes
We will post any change here with a new effective date, and tell account holders by email before a material change takes effect. When LuckLogic’s own company takes over from Dacoda, we will update this policy and tell account holders.