Privacy Policy#
Version 1.0. Effective 1 October 2026.
This explains what personal data Bzzoiro LLC ("Bzzoiro", "we", "us") collects when you use sports.bzzoiro.com, the BSD API, the WebSocket feeds and the MCP servers, and what we do with it. Bzzoiro LLC is the controller of that data.
The short version: you can browse the whole site without an account and without us setting a single cookie. If you create one, we hold your email, your username and what your API token did. We do not sell any of it.
1. What we collect#
If you only browse. Nothing that identifies you. No cookies are set on a visit without an account. Our analytics are self-hosted at analytics.bzzoiro.com and are cookieless: they record a page view, a referrer and a coarse device and country, with no identifier that follows you between visits or sites.
If you create an account. Your username, your email address, a one-way hash of your password (never the password itself), and the dates you joined and last signed in.
If you use the API. Per day and per account: how many requests you made, which endpoints, which search terms you passed, and the IP addresses the requests came from, with a count per address. This is what makes rate limits, quotas and abuse handling possible, and what lets us answer you when you ask why a call behaved as it did.
If you pay. Your name and email as you gave them to the payment provider, and the identifier that provider assigned to the transaction. We never receive or store your card number, and we never see your full payment details — those stay with the payment provider.
If you write to us. Feedback tickets, comments and their attachments, plus whatever you put in an email to us.
Server logs. Our web servers keep short-lived request logs including IP address and user agent, used for diagnosing faults and abuse.
2. Why, and on what legal basis#
| What | Why | Basis under the GDPR |
|---|---|---|
| Account, email, password hash | To give you an account and let you sign in | Performance of a contract |
| API usage counts, endpoints, IPs | To apply rate limits and quotas, to support you, to detect abuse | Performance of a contract; legitimate interests |
| Payment identifiers | To grant and renew what you paid for, and to keep records | Performance of a contract; legal obligation |
| Service emails (verification, renewals, ticket replies) | To operate your account | Performance of a contract |
| Marketing emails | To tell you about the product | Consent, which you can withdraw at any time |
| Analytics | To understand what the site is used for | Legitimate interests, with no cookies and no cross-site tracking |
| Server logs | Security and fault diagnosis | Legitimate interests |
3. Who we share it with#
We do not sell personal data and we do not share it for anyone else's advertising. We use these processors, each for one job:
| Processor | What it gets | Why |
|---|---|---|
| Dodo Payments | Name, email, transaction | Payments; merchant of record for the purchase |
| PayPal | Name, email, payer id | Payments |
| NOWPayments | Transaction identifiers | Cryptocurrency payments |
| Brevo | Name, email | Transactional and marketing email, contact list |
| SMTP2GO | Email address and message | Email delivery |
| Cloudflare | IP address, request metadata | CDN, TLS and protection against attacks |
| Hetzner | All data at rest and in transit | Hosting, in Germany and Finland |
Analytics are self-hosted, so no third party receives your browsing data.
We will also disclose data where the law requires it, and we will tell you unless we are legally prevented from doing so.
Payment providers and email providers are outside the EEA. Transfers to them rely on the European Commission's Standard Contractual Clauses or an adequacy decision, depending on the provider.
4. How long we keep it#
| What | Kept for |
|---|---|
| Account and profile | Until you delete the account |
| API usage history, including IP counts | Until you delete the account |
| Payment records | As long as tax and accounting law requires, typically seven years |
| Feedback tickets and comments | Indefinitely, because they are a public record of what was reported and fixed |
| Server logs | Days, not months |
Deleting your account from your dashboard removes the account record, the API token and the usage history, including the IP counts, immediately and by cascade. Payment records are kept for the period above because we are required to keep them.
5. Your rights#
Wherever you live, you can ask us to show you what we hold, correct it, delete it, give it to you in a portable form, or stop a particular use. If you are in the EEA or the UK you have those rights under the GDPR, including the right to object to processing based on legitimate interests and the right to complain to your supervisory authority. If you are in California you have the rights given by the CCPA/CPRA, including the right to know and to delete; we do not sell or share personal information as those terms are defined there.
Write to [email protected] and we will answer within 30 days. Deleting your account does most of this immediately and without asking anyone.
Marketing emails carry an unsubscribe link in every message. Unsubscribing does not stop service emails such as a renewal notice or a reply to your ticket, which are part of operating your account.
6. Security#
Traffic is encrypted in transit. Passwords are stored only as a salted one-way hash. API tokens are the credential for the API, which is why reissuing one is instant and free: tell us and we will replace it. Access to production data is limited to the people who operate the Service.
If a breach affects your personal data and presents a risk to you, we will tell you and the relevant supervisory authority within the time the law requires.
7. Children#
The Service is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, write to us and it will be deleted.
8. Changes#
This policy carries a version number and effective date. Material changes will be announced with reasonable notice and previous versions remain listed below.
Version history#
| Version | Effective | Notes |
|---|---|---|
| 1.0 | 1 October 2026 | First published version. |
Contact#
Bzzoiro LLC, New Mexico, United States — [email protected]
See also the Cookie Notice.