OnPitch — Privacy Policy
Effective date: 11 September 2026 Version: 1.0 Contact: support@onpitch.gg
This Privacy Policy explains how we collect, use, share, and protect personal data when you use https://onpitch.gg, its subdomains, and any related application or API (the "Service"). It also explains your rights under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and how to exercise them.
Please read this alongside our Terms of Service.
In short: we ask for your email, we see your wallet address, we look up your country from your IP to apply access restrictions, and we count page views without cookies. We do not sell your data, we do not run advertising, we do not profile you, and we hold none of your money.
1. Who we are
Data controller:
UAB "Vertex" Liepų g. 83, LT-92195 Klaipėda, Republic of Lithuania Company code: 120320756 · VAT: LT203207515 Email: support@onpitch.gg
We are the controller for the personal data described in this Policy.
Data protection officer. We have not appointed a data protection officer. Our processing does not meet the criteria in Article 37(1) GDPR: our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, and we do not process special category data on a large scale. All privacy questions, requests, and complaints go to support@onpitch.gg and are handled by our management.
EU representative. Not applicable — we are established in the European Union.
2. Scope, and what this Policy does not cover
2.1. This Policy covers processing carried out by us, as controller, in operating the Service.
2.2. It does not cover:
(a) Polymarket. When you place an order, you transact directly with the Polymarket protocol and its operators. They are independent controllers of any data they process about you, under their own privacy policy. We do not control what they collect or how they use it. (b) Privy. Our wallet infrastructure provider, Privy (Horkos, Inc. d/b/a Privy), processes data about you under its own privacy policy and security model. See https://www.privy.io. (c) Card funding providers. If you fund your wallet by card, the purchase is handled inside the wallet widget by third-party payment and on-ramp providers: Meld routes the transaction, and depending on your currency it is completed by Stripe (EUR) or MoonPay (USD and GBP). Each is an independent controller and processes your data under its own terms and privacy policy. MoonPay in particular performs its own identity verification and may ask you for identity documents. Card details, identity documents, and verification data go to those providers, not to us. Their policies are at stripe.com/privacy, meld.io/policy/privacy-policy, and moonpay.com/legal/privacy_policy. (d) Public blockchains. Data written to a public blockchain is public, permanent, and controlled by no one. See section 6. (e) Third-party sites and platforms. News outlets, X, Reddit, and other sites we link to or embed from have their own policies. Following a link takes you outside this Policy.
We encourage you to read those policies before using the Service.
3. What personal data we collect
3.1. Data you give us
| Data | Detail | When |
|---|---|---|
| Email address | Your registration email | Account creation |
| Account settings | Display name, notification and alert preferences, watchlists, saved filters, theme | While using the Service |
| Support correspondence | Content of emails to support@onpitch.gg, including anything you volunteer in them | When you contact us |
| Marketing preferences | Whether you have consented to, or opted out of, marketing email | On signup or in settings |
| Feedback | Survey answers, bug reports, feature requests | Voluntarily |
| Age confirmation | Your confirmation that you are 18 or over | Account creation |
We do not ourselves collect identity documents, government identifiers, payment card details, or bank account details, and we do not perform identity verification (KYC). If you fund your wallet by card, that purchase and any identity check it involves are carried out by the third-party providers described in section 2.2(c), under their own terms; the data goes to them, not to us. If we ourselves begin to collect any of this data, we will update this Policy and notify you before it applies to you.
3.2. Data generated when you use the Service
| Data | Detail |
|---|---|
| Wallet address | The public address of the wallet you connect or provision, and its association with your account |
| Order and routing metadata | Orders you compose and submit through our interface: market, side, size, price, timestamps, our builder code attribution, submission and error status |
| Position and portfolio views | Positions we read from public on-chain state and display to you |
| Usage data | Aggregate page and news-item views, referrers, and feature usage, measured without cookies (section 5) |
| Device and technical data | IP address, browser type and version, operating system, language, and a server-side session identifier |
| Derived country | The country resolved from your IP address (section 3.3) |
| Diagnostic data | Application error logs, stack traces, and performance timings, stored on our own servers |
| Communications metadata | Delivery and bounce events for transactional and marketing email |
3.3. Data we derive
| Data | Detail |
|---|---|
| Country determination | Your country, derived from your IP address, used to apply the access restrictions in Annex A of the Terms. See section 8 — this is an automated decision. Country-level only: we do not derive your region, province, city, or precise location. |
| Restriction status | Whether your session is Full-access, Close-Only, or Blocked, and the reason |
| Abuse signals | Indicators of multi-accounting, circumvention attempts, bot traffic, scraping, or market-abuse patterns |
| Aggregated statistics | Non-identifying totals and trends about usage of the Service |
3.4. Data from third parties
- Privy: authentication events, wallet provisioning status, and the public wallet address.
- Public blockchains: on-chain activity associated with your wallet address.
- DB-IP database: a country code, returned by a local database file (no data about you is sent anywhere — see section 8.3).
3.5. What we do not collect
We do not collect or process:
- identity documents, national identifiers, or biometric data;
- payment card, bank account, or IBAN details (card funding is handled by the providers in section 2.2(c), who receive that data directly);
- precise location data, GPS data, or region/city-level geolocation;
- advertising identifiers, cross-site tracking data, or third-party marketing profiles;
- special category data under Article 9 GDPR (health, ethnicity, political opinions, religion, trade union membership, genetic or biometric data, sex life or sexual orientation) or criminal offence data under Article 10.
Please do not send us special category data. If you volunteer it in a support message, we will process it only as necessary to answer you and will delete it when no longer needed.
3.6. We do not screen wallets
We do not currently perform wallet-address screening, blockchain analytics, or transaction-risk scoring, and we do not send your wallet address to any screening vendor. If we introduce screening, we will update this Policy first.
4. Why we process your data, and our legal basis
| # | Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| 1 | Create and operate your account; authenticate you | Email, account settings, session data | Contract (Art. 6(1)(b)) |
| 2 | Provide the news service, alerts, and personalised views | Account settings, usage data | Contract (Art. 6(1)(b)) |
| 3 | Let you compose and submit orders, and display your positions | Wallet address, order metadata, on-chain data | Contract (Art. 6(1)(b)) |
| 4 | Attribute orders routed through the Service using our builder code | Order metadata, wallet address | Legitimate interests (Art. 6(1)(f)) — accounting for activity our Interface originates |
| 5 | Send transactional email (verification, security, service and legal notices) | Email, communications metadata | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for legally required notices |
| 6 | Enforce jurisdictional restrictions (Blocked / Close-Only) | IP address, derived country, restriction status | Legal obligation (Art. 6(1)(c)) for sanctions-driven blocks; legitimate interests (Art. 6(1)(f)) for the remainder — complying with regulatory expectations and with our counterparty's requirements, and protecting the lawfulness of our operations |
| 7 | Enforce the age requirement (18+) | Age confirmation, session data | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) — protecting minors |
| 8 | Detect and prevent fraud, abuse, circumvention, market abuse, bots, and scraping | Usage, technical, abuse signals, order metadata | Legitimate interests (Art. 6(1)(f)) — protecting the Service, other users, and market integrity |
| 9 | Secure the Service; investigate incidents; keep audit logs | Technical, diagnostic, access logs | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) where applicable |
| 10 | Provide support | Support correspondence, account data | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| 11 | Measure and improve the Service using cookieless, non-identifying analytics | Aggregate usage data | Legitimate interests (Art. 6(1)(f)) — understanding which features are used, with minimal privacy impact and no tracking |
| 12 | Debug faults | Diagnostic and error data | Legitimate interests (Art. 6(1)(f)) |
| 13 | Send marketing email and product updates | Email, marketing preferences, communications metadata | Consent (Art. 6(1)(a)), withdrawable at any time |
| 14 | Handle notices about content, and comply with the Digital Services Act where applicable | Notice content, contact details | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
| 15 | Establish, exercise, or defend legal claims; respond to lawful requests; comply with court orders | As relevant | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
| 16 | Corporate transactions (merger, acquisition, financing, sale of assets) | As relevant | Legitimate interests (Art. 6(1)(f)) |
Legitimate interests balancing. Where we rely on legitimate interests, we have assessed our interest against your rights and freedoms and concluded that our processing is necessary, proportionate, and within your reasonable expectations. You may object at any time (section 10.6), and you may ask us for a summary of the relevant assessment.
5. Cookies, analytics, and why there is no cookie banner
5.1. We set no tracking cookies at all. We do not use advertising cookies, profiling cookies, cross-site trackers, pixels, fingerprinting, or any non-essential storage. We do not use Google Analytics or any comparable product.
5.2. Analytics are cookieless. We use Plausible Analytics, provided by Plausible Insights OÜ (Estonia, European Union), hosted in the EU. Plausible sets no cookies, stores nothing on your device, does not track you across sites or sessions, and does not collect or retain personal data or your IP address. It produces aggregate counts only. We therefore rely on legitimate interests, not consent.
5.3. Strictly necessary cookies only. The only cookies and local storage we use are strictly necessary to deliver a service you have requested, and are exempt from the consent requirement under Article 5(3) of the ePrivacy Directive as implemented in Lithuanian law:
| Name | Set by | Purpose | Type | Lifetime |
|---|---|---|---|---|
onpitch_session |
onpitch.gg (first party) | Maintains your signed-in session | Strictly necessary | Session, expiring on logout or after inactivity |
XSRF-TOKEN |
onpitch.gg (first party) | Protects against cross-site request forgery | Strictly necessary | Session |
privy-token |
Privy | Short-lived authentication token for your wallet session | Strictly necessary | Approximately 1 hour |
privy-refresh-token |
Privy | Renews your wallet session so you are not signed out constantly | Strictly necessary | Up to 30 days |
| Local storage: interface preferences | onpitch.gg (first party) | Remembers your theme, watchlists, and display settings | Strictly necessary / functional | Until you clear it |
5.4. Why you will not see a cookie banner. Because we use no consent-requiring technologies, there is nothing for you to consent to. A banner would be a meaningless click. If we ever introduce analytics, advertising, or any other non-essential technology, we will implement a proper consent mechanism and update this Policy before doing so.
5.5. Blocking cookies. Most browsers let you block or delete cookies. Blocking the strictly necessary cookies above will prevent you from signing in and using the Service.
6. Blockchain data — read this carefully
6.1. When you transact, data is written to a public blockchain. This includes your wallet address, the market, the size, the price, the timestamp, and the builder-code attribution associated with the order.
6.2. This data is:
- public — visible to anyone in the world, permanently, without needing your permission or ours;
- immutable — it cannot be altered, corrected, or deleted, by us or by anyone;
- outside our control — it is replicated across independent nodes we do not operate; and
- potentially linkable to you — chain-analysis techniques may associate a wallet address with a real-world identity, particularly if you have used that address on a verified exchange or disclosed it publicly.
6.3. Consequences for your rights. Because on-chain data is immutable and outside our control, we cannot erase, rectify, or restrict it, and your rights of erasure, rectification, and restriction (section 10) cannot be exercised against the blockchain. Those rights apply to the data we hold in our own systems — your account record, our off-chain logs, our analytics — and we will honour them there in full.
6.4. Please treat any decision to transact on-chain as a decision to publish that transaction permanently. If pseudonymity matters to you, consider carefully which wallet address you connect.
7. Who we share your data with
We do not sell your personal data, we do not share it for advertising, and we do not disclose it to data brokers.
7.1. Recipients
| Recipient | Role | Location | Why | Data |
|---|---|---|---|---|
| OVHcloud (OVH SAS) | Processor | European Union | Hosting, servers, databases, storage, application and error logs, and email infrastructure for our domain | All data we hold, in transit and at rest |
| Privy (Horkos, Inc. d/b/a Privy) | Processes your data under its own terms and privacy policy (section 2.2(b)); independent controller for its own operations | United States | Wallet provisioning, authentication, and signing | Email, authentication events, wallet address |
| Google Ireland Limited / Google LLC (Google Workspace) | Processor | EU / United States | Our support mailbox — receiving and sending email to support@onpitch.gg | Your email address and the content of your correspondence |
| Plausible Insights OÜ | Processor | Estonia, EU | Cookieless, aggregate analytics | Aggregate page-view counts. No cookies, no IP retention, no personal data |
| Polymarket | Independent controller | Outside our control | Receiving your signed order and our builder code, and reading your positions | Wallet address, order data, builder code |
| Public blockchain networks | No controller | Global | Settlement and record of your transactions | On-chain transaction data (section 6) |
| Professional advisers (lawyers, accountants, auditors) | Processor or independent controller | EU | Advice, compliance, defence of claims | As relevant |
| Authorities (courts, regulators, law enforcement, financial-intelligence units) | Independent controllers | As applicable | Where legally required, or necessary to establish or defend legal claims | As relevant |
| An acquirer or investor | Independent controller | As applicable | In a merger, acquisition, financing, insolvency, or sale of assets | As relevant, under confidentiality |
7.2. No geolocation vendor
Our IP geolocation uses a local database file installed on our own servers (section 8.3). No third party receives your IP address for this purpose — there is no geolocation API call, no lookup service, and no vendor involved at request time.
7.3. Processors
OVHcloud, Google, and Plausible act on our instructions as processors under written terms meeting Article 28 GDPR, are bound by confidentiality, and may not use your data for their own purposes. Privy processes your data under its own terms of service and privacy policy (section 2.2(b)).
7.4. Independent controllers
Polymarket and public blockchain participants act as independent controllers or as no controller at all. Once data reaches them, this Policy no longer governs it.
7.5. Lawful requests
We will disclose data where compelled by valid legal process, or where we reasonably believe disclosure is necessary to comply with law or sanctions, to protect our rights or property, to protect the safety of any person, or to investigate fraud or market abuse. Where lawful and practicable, we will notify you first. In some cases we are legally prohibited from doing so.
8. Automated decision-making: how geo-restriction works
8.1. We use automated processing to determine which access category applies to you: Full access, Close-Only (you may only reduce or close existing positions), or Blocked (no access). This is applied automatically, without human involvement, each time you access the Service.
8.2. The logic. Your IP address is read from the request. It is looked up against a country-level IP geolocation database to produce a two-letter country code. That country code is matched against the lists in Annex A of the Terms of Service. The resulting category is applied to your session. Signals suggesting deliberate circumvention may also result in restriction.
8.3. Where the lookup happens — and what does not leave our servers. The geolocation database is the DB-IP "IP to Country Lite" database, distributed by DB-IP (https://db-ip.com) as a single file of approximately 8 MB. That file is bundled inside our application and installed on our own servers. The lookup is a local, in-process file read. Consequently:
- your IP address is never transmitted to any third party for geolocation;
- there is no external API call, no lookup service, and no vendor that receives or logs your request;
- the database contains no data about you — it is a static mapping of IP ranges to countries; and
- it is refreshed only when we deploy a new version of our application. It does not connect to the internet or update itself.
8.4. Country-level only. The database resolves to a country and nothing more. We do not determine, and cannot determine, your region, state, province, city, postcode, or coordinates from it. Where a legal restriction applies only to part of a country, we apply it to the whole country rather than attempt finer resolution — which is why the whole of Ukraine and the whole of Canada are restricted. See clause 4.5 of the Terms.
8.5. Client IP determination. Our application runs behind our own ingress infrastructure, and we read your originating IP address from the forwarded request headers so that the restriction is applied to you rather than to our own load balancer.
8.6. Significance and consequences. A Blocked determination prevents you from using the Service. A Close-Only determination prevents you from opening or increasing a position. Neither affects positions you already hold on-chain, which remain yours and remain accessible directly through Polymarket or your wallet.
8.7. Legal basis and safeguards. We consider this processing necessary for entering into and performing our contract with you, and necessary for compliance with legal obligations to which we are subject, within Articles 22(2)(a) and 22(2)(b) GDPR. In any event, and regardless of whether Article 22 applies, we give you these safeguards:
- You may contest the determination and request human review by emailing support@onpitch.gg with your account email and the country you are actually in.
- A person will review the determination and correct it where it is wrong. IP geolocation is imperfect and mistakes happen, particularly with mobile networks, corporate VPNs, and satellite connections.
- Correcting a geolocation error does not grant access where the restriction genuinely applies to you.
8.8. No profiling for advertising. We do not profile you for advertising, pricing, or content-personalisation purposes.
8.9. Attribution. IP Geolocation by DB-IP, used under the Creative Commons Attribution 4.0 International licence.
9. International transfers
9.1. We are established in Lithuania. Our hosting, databases, logs, and analytics are located in the European Union (OVHcloud and Plausible), so the majority of our processing involves no transfer outside the EEA.
9.2. Two providers involve a transfer to the United States:
| Provider | Purpose | Safeguard |
|---|---|---|
| Privy (Horkos, Inc. d/b/a Privy) | Wallet infrastructure and authentication | No adequacy decision covers this recipient. Where you choose an embedded wallet, we rely on the derogation in Article 49(1)(b) GDPR: the transfer is necessary to perform our contract with you, because an embedded wallet cannot be provisioned or used without it. If you connect your own external wallet instead, we transfer no data to Privy. Privy applies its own technical and organisational measures, described in its privacy policy |
| Google LLC (via Google Ireland Limited) | Support mailbox | The EU–US Data Privacy Framework adequacy decision of 10 July 2023, under which Google LLC is certified, and, additionally, Standard Contractual Clauses |
9.3. Blockchain networks are global by design. On-chain data is replicated worldwide across nodes we neither operate nor select. This is inherent to the technology and cannot be constrained by contract. By transacting, you accept that on-chain data will be published globally.
9.4. You may request a copy of the Standard Contractual Clauses we rely on for the Google transfer by emailing support@onpitch.gg.
10. Your rights
Subject to the conditions and exemptions in the GDPR, you have the following rights.
10.1. Access — obtain confirmation of whether we process your data, a copy of it, and information about the processing.
10.2. Rectification — have inaccurate data corrected and incomplete data completed.
10.3. Erasure ("right to be forgotten") — have your data deleted where it is no longer needed, where you withdraw consent and there is no other basis, where you successfully object, or where processing is unlawful. This does not extend to blockchain data (section 6.3), or to data we must retain to comply with a legal obligation or to establish or defend legal claims.
10.4. Restriction — have processing limited, for example while you contest accuracy or an objection is being considered.
10.5. Portability — receive the data you provided to us, and data generated by your use, in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible. This applies to processing based on consent or contract and carried out by automated means.
10.6. Objection — object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 6(1)(f)). We will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is for legal claims. You may object to direct marketing at any time, for any reason, and we will stop unconditionally.
10.7. Withdraw consent — withdraw consent at any time where processing is based on it. In practice this means marketing email, which is the only processing we base on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
10.8. Human review of an automated decision — see section 8.7.
10.9. How to exercise your rights. Email support@onpitch.gg from your registered email address, or from another address together with enough information for us to identify you. We will:
- respond within one month, extendable by two further months for complex or numerous requests, in which case we will tell you within the first month;
- act free of charge, except where a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse and tell you why; and
- ask for additional information only where we genuinely cannot identify you, and only to the extent necessary.
10.10. Complaints. If you are unhappy with how we handle your data, please tell us first at support@onpitch.gg so we can put it right. You also have the right to lodge a complaint with a supervisory authority — in Lithuania:
Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate) L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania Telephone: +370 5 271 2804 Email: ada@ada.lt · Web: https://vdai.lrv.lt
You may also complain to the supervisory authority in your EU country of residence or place of the alleged infringement.
11. How long we keep your data
We keep personal data only as long as necessary for the purpose it was collected for, and then delete or anonymise it.
| Data | Retention | Rationale |
|---|---|---|
| Account record (email, settings) | For the life of the account, then 90 days after closure | Reversal of accidental closure, then deletion |
| Wallet address ↔ account association | For the life of the account, then 5 years | Defence of claims; responding to lawful requests |
| Order and routing metadata (off-chain records) | 5 years from the order | Attribution, dispute handling, record-keeping |
| IP address in application logs | 12 months, then deleted | Demonstrating that access restrictions were correctly applied; incident investigation |
| Country code derived from IP | Retained with the session and restriction record for 5 years | Evidence of compliance with sanctions and access rules. The country code alone is far less identifying than the IP address it came from |
| Security and access logs | 12 months | Incident investigation |
| Diagnostic and error data | 90 days | Debugging |
| Analytics | Aggregate, non-identifying counts only — no personal data is retained | Plausible stores no personal data or IP addresses |
| Support correspondence | 3 years from resolution | Service quality; defence of claims |
| Marketing consent and opt-out records | Until withdrawn, then 5 years as a suppression record | Proving we honoured your opt-out |
| Content notices and our decisions | 5 years | Digital Services Act record-keeping, where applicable |
| Accounting records | 10 years, as required by Lithuanian law | Statutory retention under the Law on Accounting of the Republic of Lithuania |
| Records subject to a legal claim, investigation, or legal hold | Until the matter is finally resolved plus the applicable limitation period | Establishing or defending legal claims |
| On-chain data | Permanent — outside our control | See section 6 |
Where a retention period expires but the data is still needed for a specific, documented legal claim, we retain only what is necessary for that claim and delete the rest.
12. Security
12.1. We implement technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest at our hosting provider, access controls on a need-to-know basis, environment separation, secrets management, logging and monitoring, dependency management, and supplier due diligence.
12.2. We do not hold your private keys or your funds. Key material is handled by Privy or by you. This meaningfully limits what an attacker could obtain from us — but it also means we cannot restore access to a wallet, reverse a transaction, or recover lost assets.
12.3. We hold no payment card or bank data, because we do not process payments ourselves. Card funding is processed by the providers in section 2.2(c).
12.4. No system is perfectly secure. We cannot guarantee absolute security, and transmission over the internet is at your own risk.
12.5. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the State Data Protection Inspectorate within 72 hours of becoming aware of it, and will notify you without undue delay where the risk is high.
13. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18. If we learn that we have, we will close the account and delete the data promptly. If you believe a minor is using the Service, contact support@onpitch.gg.
14. Marketing
14.1. We send marketing email only with your consent, or where permitted by law to an existing customer about similar services, with a clear opt-out in every message.
14.2. Every marketing email contains a one-click unsubscribe. You can also change your preferences in your account or email support@onpitch.gg.
14.3. Opting out of marketing does not stop transactional and service messages (security alerts, account notices, changes to these documents), which are part of providing the Service.
14.4. We do not share your email address with any third party for that party's own marketing.
15. Changes to this Policy
15.1. We may update this Policy. The current version is always at https://onpitch.gg with a version number and effective date.
15.2. Where a change is material, we will notify you by email or prominent in-Service notice at least 15 days before it takes effect, unless a shorter period is required by law.
15.3. Where a change requires your consent — for example, introducing analytics or advertising technologies that set non-essential cookies — we will ask for it before the change applies to you.
16. Contact
Questions, requests, or complaints about privacy:
UAB "Vertex" Liepų g. 83, LT-92195 Klaipėda, Republic of Lithuania Company code: 120320756 · VAT: LT203207515 Email: support@onpitch.gg
OnPitch is operated by UAB "Vertex", Klaipėda, Republic of Lithuania. OnPitch aggregates news published by third parties and provides a non-custodial interface to Polymarket: you submit your own signed orders, we hold no funds, take no other side, and exercise no discretion over your trades. IP Geolocation by DB-IP.