Pitch

OnPitch — Privacy Policy

Effective date: 11 September 2026 Version: 1.0 Contact: support@onpitch.gg

This Privacy Policy explains how we collect, use, share, and protect personal data when you use https://onpitch.gg, its subdomains, and any related application or API (the "Service"). It also explains your rights under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and how to exercise them.

Please read this alongside our Terms of Service.

In short: we ask for your email, we see your wallet address, we look up your country from your IP to apply access restrictions, and we count page views without cookies. We do not sell your data, we do not run advertising, we do not profile you, and we hold none of your money.


1. Who we are

Data controller:

UAB "Vertex" Liepų g. 83, LT-92195 Klaipėda, Republic of Lithuania Company code: 120320756 · VAT: LT203207515 Email: support@onpitch.gg

We are the controller for the personal data described in this Policy.

Data protection officer. We have not appointed a data protection officer. Our processing does not meet the criteria in Article 37(1) GDPR: our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, and we do not process special category data on a large scale. All privacy questions, requests, and complaints go to support@onpitch.gg and are handled by our management.

EU representative. Not applicable — we are established in the European Union.


2. Scope, and what this Policy does not cover

2.1. This Policy covers processing carried out by us, as controller, in operating the Service.

2.2. It does not cover:

(a) Polymarket. When you place an order, you transact directly with the Polymarket protocol and its operators. They are independent controllers of any data they process about you, under their own privacy policy. We do not control what they collect or how they use it. (b) Privy. Our wallet infrastructure provider, Privy (Horkos, Inc. d/b/a Privy), processes data about you under its own privacy policy and security model. See https://www.privy.io. (c) Card funding providers. If you fund your wallet by card, the purchase is handled inside the wallet widget by third-party payment and on-ramp providers: Meld routes the transaction, and depending on your currency it is completed by Stripe (EUR) or MoonPay (USD and GBP). Each is an independent controller and processes your data under its own terms and privacy policy. MoonPay in particular performs its own identity verification and may ask you for identity documents. Card details, identity documents, and verification data go to those providers, not to us. Their policies are at stripe.com/privacy, meld.io/policy/privacy-policy, and moonpay.com/legal/privacy_policy. (d) Public blockchains. Data written to a public blockchain is public, permanent, and controlled by no one. See section 6. (e) Third-party sites and platforms. News outlets, X, Reddit, and other sites we link to or embed from have their own policies. Following a link takes you outside this Policy.

We encourage you to read those policies before using the Service.


3. What personal data we collect

3.1. Data you give us

Data Detail When
Email address Your registration email Account creation
Account settings Display name, notification and alert preferences, watchlists, saved filters, theme While using the Service
Support correspondence Content of emails to support@onpitch.gg, including anything you volunteer in them When you contact us
Marketing preferences Whether you have consented to, or opted out of, marketing email On signup or in settings
Feedback Survey answers, bug reports, feature requests Voluntarily
Age confirmation Your confirmation that you are 18 or over Account creation

We do not ourselves collect identity documents, government identifiers, payment card details, or bank account details, and we do not perform identity verification (KYC). If you fund your wallet by card, that purchase and any identity check it involves are carried out by the third-party providers described in section 2.2(c), under their own terms; the data goes to them, not to us. If we ourselves begin to collect any of this data, we will update this Policy and notify you before it applies to you.

3.2. Data generated when you use the Service

Data Detail
Wallet address The public address of the wallet you connect or provision, and its association with your account
Order and routing metadata Orders you compose and submit through our interface: market, side, size, price, timestamps, our builder code attribution, submission and error status
Position and portfolio views Positions we read from public on-chain state and display to you
Usage data Aggregate page and news-item views, referrers, and feature usage, measured without cookies (section 5)
Device and technical data IP address, browser type and version, operating system, language, and a server-side session identifier
Derived country The country resolved from your IP address (section 3.3)
Diagnostic data Application error logs, stack traces, and performance timings, stored on our own servers
Communications metadata Delivery and bounce events for transactional and marketing email

3.3. Data we derive

Data Detail
Country determination Your country, derived from your IP address, used to apply the access restrictions in Annex A of the Terms. See section 8 — this is an automated decision. Country-level only: we do not derive your region, province, city, or precise location.
Restriction status Whether your session is Full-access, Close-Only, or Blocked, and the reason
Abuse signals Indicators of multi-accounting, circumvention attempts, bot traffic, scraping, or market-abuse patterns
Aggregated statistics Non-identifying totals and trends about usage of the Service

3.4. Data from third parties

3.5. What we do not collect

We do not collect or process:

Please do not send us special category data. If you volunteer it in a support message, we will process it only as necessary to answer you and will delete it when no longer needed.

3.6. We do not screen wallets

We do not currently perform wallet-address screening, blockchain analytics, or transaction-risk scoring, and we do not send your wallet address to any screening vendor. If we introduce screening, we will update this Policy first.


4. Why we process your data, and our legal basis

# Purpose Data used Legal basis (GDPR Art. 6)
1 Create and operate your account; authenticate you Email, account settings, session data Contract (Art. 6(1)(b))
2 Provide the news service, alerts, and personalised views Account settings, usage data Contract (Art. 6(1)(b))
3 Let you compose and submit orders, and display your positions Wallet address, order metadata, on-chain data Contract (Art. 6(1)(b))
4 Attribute orders routed through the Service using our builder code Order metadata, wallet address Legitimate interests (Art. 6(1)(f)) — accounting for activity our Interface originates
5 Send transactional email (verification, security, service and legal notices) Email, communications metadata Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for legally required notices
6 Enforce jurisdictional restrictions (Blocked / Close-Only) IP address, derived country, restriction status Legal obligation (Art. 6(1)(c)) for sanctions-driven blocks; legitimate interests (Art. 6(1)(f)) for the remainder — complying with regulatory expectations and with our counterparty's requirements, and protecting the lawfulness of our operations
7 Enforce the age requirement (18+) Age confirmation, session data Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) — protecting minors
8 Detect and prevent fraud, abuse, circumvention, market abuse, bots, and scraping Usage, technical, abuse signals, order metadata Legitimate interests (Art. 6(1)(f)) — protecting the Service, other users, and market integrity
9 Secure the Service; investigate incidents; keep audit logs Technical, diagnostic, access logs Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) where applicable
10 Provide support Support correspondence, account data Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
11 Measure and improve the Service using cookieless, non-identifying analytics Aggregate usage data Legitimate interests (Art. 6(1)(f)) — understanding which features are used, with minimal privacy impact and no tracking
12 Debug faults Diagnostic and error data Legitimate interests (Art. 6(1)(f))
13 Send marketing email and product updates Email, marketing preferences, communications metadata Consent (Art. 6(1)(a)), withdrawable at any time
14 Handle notices about content, and comply with the Digital Services Act where applicable Notice content, contact details Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))
15 Establish, exercise, or defend legal claims; respond to lawful requests; comply with court orders As relevant Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))
16 Corporate transactions (merger, acquisition, financing, sale of assets) As relevant Legitimate interests (Art. 6(1)(f))

Legitimate interests balancing. Where we rely on legitimate interests, we have assessed our interest against your rights and freedoms and concluded that our processing is necessary, proportionate, and within your reasonable expectations. You may object at any time (section 10.6), and you may ask us for a summary of the relevant assessment.


5. Cookies, analytics, and why there is no cookie banner

5.1. We set no tracking cookies at all. We do not use advertising cookies, profiling cookies, cross-site trackers, pixels, fingerprinting, or any non-essential storage. We do not use Google Analytics or any comparable product.

5.2. Analytics are cookieless. We use Plausible Analytics, provided by Plausible Insights OÜ (Estonia, European Union), hosted in the EU. Plausible sets no cookies, stores nothing on your device, does not track you across sites or sessions, and does not collect or retain personal data or your IP address. It produces aggregate counts only. We therefore rely on legitimate interests, not consent.

5.3. Strictly necessary cookies only. The only cookies and local storage we use are strictly necessary to deliver a service you have requested, and are exempt from the consent requirement under Article 5(3) of the ePrivacy Directive as implemented in Lithuanian law:

Name Set by Purpose Type Lifetime
onpitch_session onpitch.gg (first party) Maintains your signed-in session Strictly necessary Session, expiring on logout or after inactivity
XSRF-TOKEN onpitch.gg (first party) Protects against cross-site request forgery Strictly necessary Session
privy-token Privy Short-lived authentication token for your wallet session Strictly necessary Approximately 1 hour
privy-refresh-token Privy Renews your wallet session so you are not signed out constantly Strictly necessary Up to 30 days
Local storage: interface preferences onpitch.gg (first party) Remembers your theme, watchlists, and display settings Strictly necessary / functional Until you clear it

5.4. Why you will not see a cookie banner. Because we use no consent-requiring technologies, there is nothing for you to consent to. A banner would be a meaningless click. If we ever introduce analytics, advertising, or any other non-essential technology, we will implement a proper consent mechanism and update this Policy before doing so.

5.5. Blocking cookies. Most browsers let you block or delete cookies. Blocking the strictly necessary cookies above will prevent you from signing in and using the Service.


6. Blockchain data — read this carefully

6.1. When you transact, data is written to a public blockchain. This includes your wallet address, the market, the size, the price, the timestamp, and the builder-code attribution associated with the order.

6.2. This data is:

6.3. Consequences for your rights. Because on-chain data is immutable and outside our control, we cannot erase, rectify, or restrict it, and your rights of erasure, rectification, and restriction (section 10) cannot be exercised against the blockchain. Those rights apply to the data we hold in our own systems — your account record, our off-chain logs, our analytics — and we will honour them there in full.

6.4. Please treat any decision to transact on-chain as a decision to publish that transaction permanently. If pseudonymity matters to you, consider carefully which wallet address you connect.


7. Who we share your data with

We do not sell your personal data, we do not share it for advertising, and we do not disclose it to data brokers.

7.1. Recipients

Recipient Role Location Why Data
OVHcloud (OVH SAS) Processor European Union Hosting, servers, databases, storage, application and error logs, and email infrastructure for our domain All data we hold, in transit and at rest
Privy (Horkos, Inc. d/b/a Privy) Processes your data under its own terms and privacy policy (section 2.2(b)); independent controller for its own operations United States Wallet provisioning, authentication, and signing Email, authentication events, wallet address
Google Ireland Limited / Google LLC (Google Workspace) Processor EU / United States Our support mailbox — receiving and sending email to support@onpitch.gg Your email address and the content of your correspondence
Plausible Insights OÜ Processor Estonia, EU Cookieless, aggregate analytics Aggregate page-view counts. No cookies, no IP retention, no personal data
Polymarket Independent controller Outside our control Receiving your signed order and our builder code, and reading your positions Wallet address, order data, builder code
Public blockchain networks No controller Global Settlement and record of your transactions On-chain transaction data (section 6)
Professional advisers (lawyers, accountants, auditors) Processor or independent controller EU Advice, compliance, defence of claims As relevant
Authorities (courts, regulators, law enforcement, financial-intelligence units) Independent controllers As applicable Where legally required, or necessary to establish or defend legal claims As relevant
An acquirer or investor Independent controller As applicable In a merger, acquisition, financing, insolvency, or sale of assets As relevant, under confidentiality

7.2. No geolocation vendor

Our IP geolocation uses a local database file installed on our own servers (section 8.3). No third party receives your IP address for this purpose — there is no geolocation API call, no lookup service, and no vendor involved at request time.

7.3. Processors

OVHcloud, Google, and Plausible act on our instructions as processors under written terms meeting Article 28 GDPR, are bound by confidentiality, and may not use your data for their own purposes. Privy processes your data under its own terms of service and privacy policy (section 2.2(b)).

7.4. Independent controllers

Polymarket and public blockchain participants act as independent controllers or as no controller at all. Once data reaches them, this Policy no longer governs it.

7.5. Lawful requests

We will disclose data where compelled by valid legal process, or where we reasonably believe disclosure is necessary to comply with law or sanctions, to protect our rights or property, to protect the safety of any person, or to investigate fraud or market abuse. Where lawful and practicable, we will notify you first. In some cases we are legally prohibited from doing so.


8. Automated decision-making: how geo-restriction works

8.1. We use automated processing to determine which access category applies to you: Full access, Close-Only (you may only reduce or close existing positions), or Blocked (no access). This is applied automatically, without human involvement, each time you access the Service.

8.2. The logic. Your IP address is read from the request. It is looked up against a country-level IP geolocation database to produce a two-letter country code. That country code is matched against the lists in Annex A of the Terms of Service. The resulting category is applied to your session. Signals suggesting deliberate circumvention may also result in restriction.

8.3. Where the lookup happens — and what does not leave our servers. The geolocation database is the DB-IP "IP to Country Lite" database, distributed by DB-IP (https://db-ip.com) as a single file of approximately 8 MB. That file is bundled inside our application and installed on our own servers. The lookup is a local, in-process file read. Consequently:

8.4. Country-level only. The database resolves to a country and nothing more. We do not determine, and cannot determine, your region, state, province, city, postcode, or coordinates from it. Where a legal restriction applies only to part of a country, we apply it to the whole country rather than attempt finer resolution — which is why the whole of Ukraine and the whole of Canada are restricted. See clause 4.5 of the Terms.

8.5. Client IP determination. Our application runs behind our own ingress infrastructure, and we read your originating IP address from the forwarded request headers so that the restriction is applied to you rather than to our own load balancer.

8.6. Significance and consequences. A Blocked determination prevents you from using the Service. A Close-Only determination prevents you from opening or increasing a position. Neither affects positions you already hold on-chain, which remain yours and remain accessible directly through Polymarket or your wallet.

8.7. Legal basis and safeguards. We consider this processing necessary for entering into and performing our contract with you, and necessary for compliance with legal obligations to which we are subject, within Articles 22(2)(a) and 22(2)(b) GDPR. In any event, and regardless of whether Article 22 applies, we give you these safeguards:

8.8. No profiling for advertising. We do not profile you for advertising, pricing, or content-personalisation purposes.

8.9. Attribution. IP Geolocation by DB-IP, used under the Creative Commons Attribution 4.0 International licence.


9. International transfers

9.1. We are established in Lithuania. Our hosting, databases, logs, and analytics are located in the European Union (OVHcloud and Plausible), so the majority of our processing involves no transfer outside the EEA.

9.2. Two providers involve a transfer to the United States:

Provider Purpose Safeguard
Privy (Horkos, Inc. d/b/a Privy) Wallet infrastructure and authentication No adequacy decision covers this recipient. Where you choose an embedded wallet, we rely on the derogation in Article 49(1)(b) GDPR: the transfer is necessary to perform our contract with you, because an embedded wallet cannot be provisioned or used without it. If you connect your own external wallet instead, we transfer no data to Privy. Privy applies its own technical and organisational measures, described in its privacy policy
Google LLC (via Google Ireland Limited) Support mailbox The EU–US Data Privacy Framework adequacy decision of 10 July 2023, under which Google LLC is certified, and, additionally, Standard Contractual Clauses

9.3. Blockchain networks are global by design. On-chain data is replicated worldwide across nodes we neither operate nor select. This is inherent to the technology and cannot be constrained by contract. By transacting, you accept that on-chain data will be published globally.

9.4. You may request a copy of the Standard Contractual Clauses we rely on for the Google transfer by emailing support@onpitch.gg.


10. Your rights

Subject to the conditions and exemptions in the GDPR, you have the following rights.

10.1. Access — obtain confirmation of whether we process your data, a copy of it, and information about the processing.

10.2. Rectification — have inaccurate data corrected and incomplete data completed.

10.3. Erasure ("right to be forgotten") — have your data deleted where it is no longer needed, where you withdraw consent and there is no other basis, where you successfully object, or where processing is unlawful. This does not extend to blockchain data (section 6.3), or to data we must retain to comply with a legal obligation or to establish or defend legal claims.

10.4. Restriction — have processing limited, for example while you contest accuracy or an objection is being considered.

10.5. Portability — receive the data you provided to us, and data generated by your use, in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible. This applies to processing based on consent or contract and carried out by automated means.

10.6. Objection — object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 6(1)(f)). We will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is for legal claims. You may object to direct marketing at any time, for any reason, and we will stop unconditionally.

10.7. Withdraw consent — withdraw consent at any time where processing is based on it. In practice this means marketing email, which is the only processing we base on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.

10.8. Human review of an automated decision — see section 8.7.

10.9. How to exercise your rights. Email support@onpitch.gg from your registered email address, or from another address together with enough information for us to identify you. We will:

10.10. Complaints. If you are unhappy with how we handle your data, please tell us first at support@onpitch.gg so we can put it right. You also have the right to lodge a complaint with a supervisory authority — in Lithuania:

Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate) L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania Telephone: +370 5 271 2804 Email: ada@ada.lt · Web: https://vdai.lrv.lt

You may also complain to the supervisory authority in your EU country of residence or place of the alleged infringement.


11. How long we keep your data

We keep personal data only as long as necessary for the purpose it was collected for, and then delete or anonymise it.

Data Retention Rationale
Account record (email, settings) For the life of the account, then 90 days after closure Reversal of accidental closure, then deletion
Wallet address ↔ account association For the life of the account, then 5 years Defence of claims; responding to lawful requests
Order and routing metadata (off-chain records) 5 years from the order Attribution, dispute handling, record-keeping
IP address in application logs 12 months, then deleted Demonstrating that access restrictions were correctly applied; incident investigation
Country code derived from IP Retained with the session and restriction record for 5 years Evidence of compliance with sanctions and access rules. The country code alone is far less identifying than the IP address it came from
Security and access logs 12 months Incident investigation
Diagnostic and error data 90 days Debugging
Analytics Aggregate, non-identifying counts only — no personal data is retained Plausible stores no personal data or IP addresses
Support correspondence 3 years from resolution Service quality; defence of claims
Marketing consent and opt-out records Until withdrawn, then 5 years as a suppression record Proving we honoured your opt-out
Content notices and our decisions 5 years Digital Services Act record-keeping, where applicable
Accounting records 10 years, as required by Lithuanian law Statutory retention under the Law on Accounting of the Republic of Lithuania
Records subject to a legal claim, investigation, or legal hold Until the matter is finally resolved plus the applicable limitation period Establishing or defending legal claims
On-chain data Permanent — outside our control See section 6

Where a retention period expires but the data is still needed for a specific, documented legal claim, we retain only what is necessary for that claim and delete the rest.


12. Security

12.1. We implement technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest at our hosting provider, access controls on a need-to-know basis, environment separation, secrets management, logging and monitoring, dependency management, and supplier due diligence.

12.2. We do not hold your private keys or your funds. Key material is handled by Privy or by you. This meaningfully limits what an attacker could obtain from us — but it also means we cannot restore access to a wallet, reverse a transaction, or recover lost assets.

12.3. We hold no payment card or bank data, because we do not process payments ourselves. Card funding is processed by the providers in section 2.2(c).

12.4. No system is perfectly secure. We cannot guarantee absolute security, and transmission over the internet is at your own risk.

12.5. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the State Data Protection Inspectorate within 72 hours of becoming aware of it, and will notify you without undue delay where the risk is high.


13. Children

The Service is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18. If we learn that we have, we will close the account and delete the data promptly. If you believe a minor is using the Service, contact support@onpitch.gg.


14. Marketing

14.1. We send marketing email only with your consent, or where permitted by law to an existing customer about similar services, with a clear opt-out in every message.

14.2. Every marketing email contains a one-click unsubscribe. You can also change your preferences in your account or email support@onpitch.gg.

14.3. Opting out of marketing does not stop transactional and service messages (security alerts, account notices, changes to these documents), which are part of providing the Service.

14.4. We do not share your email address with any third party for that party's own marketing.


15. Changes to this Policy

15.1. We may update this Policy. The current version is always at https://onpitch.gg with a version number and effective date.

15.2. Where a change is material, we will notify you by email or prominent in-Service notice at least 15 days before it takes effect, unless a shorter period is required by law.

15.3. Where a change requires your consent — for example, introducing analytics or advertising technologies that set non-essential cookies — we will ask for it before the change applies to you.


16. Contact

Questions, requests, or complaints about privacy:

UAB "Vertex" Liepų g. 83, LT-92195 Klaipėda, Republic of Lithuania Company code: 120320756 · VAT: LT203207515 Email: support@onpitch.gg


OnPitch is operated by UAB "Vertex", Klaipėda, Republic of Lithuania. OnPitch aggregates news published by third parties and provides a non-custodial interface to Polymarket: you submit your own signed orders, we hold no funds, take no other side, and exercise no discretion over your trades. IP Geolocation by DB-IP.