LuckLogic .dev
Product
How it worksFrom campaign setup to reconciliation Winning MomentsPrize rules, windows and release Brand PortalClient visibility without client control VerifyPrize handover at pickup ReportingAudit and end-of-campaign reconciliation
For Agencies Pricing
Developers
DocsQuickstart and API guide API ReferenceEvery endpoint, from the OpenAPI spec Code examplesNext.js, curl and webhooks SecurityHow entries and prizes are protected
Guides
Talk to us Open Sandbox
Legal

Privacy policy

Effective 6 October 2026

What LuckLogic collects, why, where it is kept, for how long, and who else handles it. Written from how the service actually works, so it is specific rather than general.

1. Who we are and when this applies

LuckLogic (“we”, “us”) provides infrastructure for on-pack and instant-win promotions: an API, an agency and brand portal, a hosted entry page, an embeddable widget and a staff app for handing over prizes. LuckLogic is operated by Dacoda ehf., company registration number (kennitala) 540102-4060, Hafnargata 51–55, 230 Reykjanesbær, Iceland, until LuckLogic’s own company is registered. Dacoda is the controller and processor referred to in this policy. Contact us about anything in this policy at hello@lucklogic.dev.

We handle personal data in two different roles:

  • As controller for visitors to lucklogic.dev and for the people who use our portal and API: agency and brand staff. Sections 2 and 3 cover this.
  • As processor for the people who enter promotions run on LuckLogic. The agency or brand running the promotion (our customer) decides why and how that data is used, and their privacy notice is the one that governs it. Section 4 describes what we process for them.

2. Visitors to lucklogic.dev

  • No cookies, no analytics. The website sets no cookies, uses no browser storage, runs no analytics or advertising scripts, and serves its own fonts.
  • Hosting. The site is served by Vercel, which processes your IP address and request details to deliver pages and keeps short-lived technical logs.
  • Contact form. When you use /contact we receive your name, email address, company (if given), the topic and your message. It is delivered to our inbox by Resend, and we use it only to answer you. The form is protected by Cloudflare Turnstile, which checks your browser and IP address to tell people from bots. We keep correspondence for as long as it is useful for the conversation and any business relationship that follows.

3. Portal and API users

If you have a LuckLogic account, or someone invites you to one, we process:

  • Account details: your name and email address, and your password stored only as a scrypt hash. Accounts created with Google or GitHub have no password; we store the provider’s account identifier and the verified email address it reported.
  • Membership: which workspaces and brands you belong to, and your role in each.
  • Sessions: when you sign in we keep a hash of your session token, your browser’s user agent and when the session was last used. A session lasts up to 30 days.
  • Invitations and password resets: the invited email address and role, valid for 7 days; reset links valid for 1 hour and usable once. We send these emails through Resend.
  • What you do in the portal: changes to campaigns and prize claims are recorded with the account that made them, so customers have an audit trail.
  • Bot protection: sign-up and password-reset forms use Cloudflare Turnstile.
  • Customer contacts: agencies can record a contact person (name, email, phone) for each brand they work with.

We use this to provide the service, keep accounts secure, and contact you about your account. We do not send marketing email, and we do not sell personal data.

4. People who enter promotions

LuckLogic is built to decide whether a code wins without knowing who entered it. We never ask for a participant’s name, email address or phone number. On behalf of the agency or brand running the promotion we process:

  • Codes, stored only as keyed hashes. The printable files of codes that customers download for packaging are kept in object storage in the EU.
  • A participant identifier chosen by the customer, used for entry limits and their own reconciliation. On our hosted entry page and widget it is a random token kept in a cookie or in browser storage (ll_pt, one year), so repeat entries from the same browser can be limited.
  • IP addresses of people entering through the hosted page or widget, or supplied by the customer, used to limit abuse (per-address limits and, when a campaign asks for it, a Cloudflare Turnstile check). We keep them for at most 12 months.
  • Entries and outcomes: each attempt, whether it won, and for winners the prize claim, its status, and any notes or references the customer records while handing the prize over.

Customers can send their own fields with an entry. We ask them not to send names, contact details or other identifying data, but if they do, we process it as their processor too.

To exercise your rights over promotion data, contact the promoter named in the promotion’s terms. They control the data; we help them answer you. If you contact us, we will pass your request to them.

5. Legal bases

  • Contract: to provide your account and the service you signed up for.
  • Legitimate interests: to answer enquiries, keep the service secure and prevent fraud and abuse, and keep audit records our customers rely on.
  • Legal obligation: to keep records the law requires, such as invoices.

For promotion data, the legal basis is the promoter’s, as their processor.

6. Service providers

These companies process personal data for us, each only for the purpose listed:

Provider What for Where
Railway The API, its database, background jobs and the hosted entry page EU (Amsterdam)
Cloudflare DNS, storage of code files, Turnstile bot checks, forwarding of our email EU storage; global network
Vercel The website, the portal and the Verify app EU (Frankfurt) for the portal and Verify; global network
Resend Sending account emails and contact-form messages United States
Google Sign in with Google, and our email inbox Global
GitHub Sign in with GitHub United States

Where data leaves the European Economic Area, we rely on the provider’s certification under the EU–U.S. Data Privacy Framework or on the European Commission’s standard contractual clauses. We will update this list before adding a provider that handles promotion data.

7. How long we keep it

Sessions Up to 30 days of use; the record stays for security history
Password reset links Valid 1 hour, once
Invitations Valid 7 days
IP addresses of people entering promotions 12 months, then deleted automatically, in the entry log and in entry records alike
Entry-limit counters Deleted automatically once their limit window has ended (at most about a month)
Retry protection for API requests 24 hours
Workspaces, campaigns, entries, claims and code files Until the workspace is closed, so campaigns can be reconciled and audited

Deleting your account. You can delete your own account at any time in the portal (Profile, then Delete account). Your name, email address, password and Google or GitHub links are erased and you are signed out; records of what you did in a workspace keep only an anonymous reference.

Closing a workspace. A workspace admin can close it in Settings. Thirty days later the workspace and everything in it (campaigns, codes and code files, entries, claims, keys, webhooks, clients and locations) is deleted automatically; until then it can be exported or reopened. We also delete a workspace on request, and keep only records the law requires.

8. Security

All traffic is encrypted in transit. Passwords, session tokens, invitation and reset tokens are stored only as hashes, and codes only as keyed hashes. API keys are scoped to sandbox or production, and access in the portal follows each person’s role. The security page has more detail.

9. Your rights

You can ask us for a copy of your personal data, to correct or delete it, to restrict or object to how we use it, and to receive it in a portable format. Write to hello@lucklogic.dev; we answer within one month. You can also complain to a data protection authority: in Iceland that is Persónuvernd (personuvernd.is), or the authority where you live or work.

10. Changes

We will post any change here with a new effective date, and tell account holders by email before a material change takes effect. When LuckLogic’s own company takes over from Dacoda, we will update this policy and tell account holders.

LuckLogic The infrastructure behind prize promotions. Built in Iceland.
Product How it works Winning Moments Brand Portal Verify Reporting For Agencies Pricing
Developers Docs Guides API Reference Code examples OpenAPI specification Security
Company Contact Privacy Terms Data Processing Agreement
© 2026 LuckLogic lucklogic.dev