Operator: Simply Raffle | Contact: [email protected]
Effective Date: February 28, 2026 | Last Updated: September 16, 2026
1. Who We Are
Simply Raffle is a web-based raffle administration platform developed and operated by Simply Raffle. We provide software to employers, schools, parent-teacher groups (PTGs/PTAs), nonprofits, community organizations, and other groups that run raffles and prize drawings, whether to raise funds or as a staff, member or customer event.
Contact: [email protected]. We respond within 5 business days.
2. What Data We Collect
We collect only the minimum data necessary to administer a raffle on behalf of the Organization:
| Data | Why We Collect It |
|---|---|
| Participant first and last name | To identify raffle participants and record draw results |
| Grade level (school/educational orgs only) | To organize participants within the raffle |
| Employee number (only where the Organization identifies entrants this way) | To let someone enter at a walk-up event without giving an email address, and to recognize them if they come back |
| Workplace details the Organization provides: department, job title, region, work location | To label and group entrants, and to run a draw limited to one part of an organization |
| Answers to any extra questions the Organization adds to its own entry form | The Organization chooses these questions and what they are for; answers are stored with the entry |
| Email address (participant or parent/guardian) | To deliver magic-link portal access and draw result notifications |
| Phone number (only if the Organization turns this on) | To let the Organization contact a participant about their entry or prize |
| Raffle ticket allocation counts | To calculate weighted draw probability and maintain participation records |
| Administrator login credentials | To authenticate organization staff (stored as a one-way bcrypt hash — never readable) |
| Magic-link access tokens | To provide time-limited, password-free access to the participant portal |
We never ask for: payment information, social security numbers, government ID numbers, dates of birth, home addresses, health information, or disciplinary records. None of these is a field in our software.
The last row of the table is the one thing we cannot see in advance. An Organization can add its own questions to its entry form, so it is the Organization's responsibility not to ask participants for information of the kind listed above. Whatever it does collect that way is stored with the participant's entry, is never shown on the public results page, and is deleted on the schedule in Section 6 along with everything else.
3. How We Use This Data
Participant data is used only for administering the Organization's raffle — displaying ticket allocations, calculating draw results, sending magic-link access emails, and allowing Organization administrators to manage participant records. We do not use your data for any commercial purpose.
4. What We Do Not Do
- ❌ We do not sell participant data — ever, to anyone, for any reason.
- ❌ We do not rent or trade participant data.
- ❌ We do not use participant data for advertising or marketing.
- ❌ We do not build behavioral profiles of participants or their families.
- ❌ We do not share data with third parties for any commercial purpose.
- ❌ We do not retain data indefinitely — participant data is deleted on a defined schedule.
Cookies. We use cookies for one thing: keeping you signed in. An Organization administrator gets an encrypted session cookie when they log in to the admin area. A participant gets one when they follow their access link or enter at an event, so the site still knows them on the next page and they do not have to type their details again. Both are necessary for the service to function. We set no advertising, analytics or social-media cookies, and no third party sets a cookie through our service.
5. Who Can Access Your Data
| Who | What they can see |
|---|---|
| Organization administrators | All participant data for their raffle |
| Participants / parents / guardians | Only their own family's ticket allocation and draw results |
| Developer (operator) | Access for system maintenance and security purposes only |
| Infrastructure providers | Encrypted database storage only — see Section 8 for the full list |
6. Data Retention
- Active raffle: Participant records are retained while the raffle they entered is active.
- Free-tier raffles: Some Organizations run their raffle on our free tier, which is a short trial rather than ongoing storage. Those raffles close on a fixed schedule, 7 days after signup if no draw is run or 7 days after the draw, and every participant record in them is deleted from production systems within 7 days of closing. That is much sooner than the 45 day schedule above, never later. Raffles created before 12 September 2026 finish on the previous, longer schedule.
- Non-winning participants: Contact information (name, email address, and phone number if collected) is removed within 45 days of the raffle a participant entered, or upon Organization request if sooner. Two things are not covered by that removal: the name of a winner and the prize they won, which is the published result of the event and is kept, as described below; and the operator activity log, in which a participant's name and email address may appear in the record of an action taken on their entry. Those entries are redacted rather than deleted, and the log itself cannot be deleted.
- Winners: The winner's name and the prize they won are kept as part of the raffle's published result. Their contact information (email address and phone number) is removed on the same 45-day schedule as everyone else.
- Recurring series: For Organizations that run repeat raffles, the 45-day clock applies per raffle — each raffle's non-winning participants are scrubbed 45 days after that raffle, independent of any later raffle in the series.
- Standing membership rosters: Some Organizations (for example a club running a members' draw) keep the same roster across repeat raffles rather than clearing it. Those members remain on the Organization's active roster and are not on the 45-day schedule while the roster is in use — their records are retained until the Organization removes them or closes its account, at which point the schedules above apply. An account whose service has ended, or that shows no activity for an extended period, is treated as closed: after advance notice to the Organization, its data enters the deletion schedule above, beginning with a full data export to the Organization. The inactivity sequence is a warning email after about 11 months of no activity, the exemption released about a month later (12 months of inactivity), then deletion 45 days after that — about 13.5 months from the last sign of activity to erasure. Signing in at any point before the release resets the clock.
- Organization termination: All participant data is deleted after a data export is provided to the Organization.
- What the schedules above do NOT cover: the Organization's own account and billing contact records, which are kept while the account exists and removed when it is torn down; and our retention audit log, which records that a deletion happened — one-way hashes and counts only, never names, email addresses or phone numbers — and is kept as our evidence that we did what this policy says. A winner's name and prize also survive as the published result of the raffle, as described above.
- Activity log: Every administrative action in your account is recorded with who did it, what changed, the time, and the IP address it came from, so there is a record. It is kept for the life of the account and survives a factory reset by design.
- Backups: We take full-database snapshots for disaster recovery and keep them on a rolling schedule, so a snapshot taken before a deletion still contains that data until it ages out of that schedule. Backups are only ever used to recover from a disaster. We do not use them to restore data that was deleted, and where we restore for a genuine disaster-recovery reason we re-apply any deletions already carried out. If you need the current backup retention window in writing for a compliance review, email us and we will give you the figure as configured on that date.
To request earlier deletion, contact us at [email protected] or ask your Organization's administrator.
7. Security
- Encryption in transit: All data is encrypted using HTTPS (TLS).
- Encryption at rest: Databases are encrypted at rest on both hosting options described in Section 8.
- Password security: Administrator passwords stored using bcrypt hashing — never stored in readable form.
- Magic-link tokens: Participant access links are time-limited and expire 90 days after they are issued. An organizer can invalidate all outstanding links at any time from the admin area.
- Access controls: Role-based access enforced at the API level — participants see only their own records.
To report a security vulnerability, email [email protected].
8. Third-Party Subprocessors
Your raffle runs on operator-managed infrastructure in the San Francisco Bay Area, California by default, on every plan. The providers below are the third parties involved beyond that. All are located in the United States. We use no advertising, analytics, or social-media processors.
Operator-managed infrastructure (San Francisco Bay Area, CA)
Role: Default application and PostgreSQL database hosting for all plans. Data is encrypted at rest and in transit and is not shared with any hosting vendor.
Railway, Inc. (exception, not the default)
Role: Cloud application and PostgreSQL hosting (US-East) for the small number of raffles not yet on the operator-managed infrastructure above. Your Organization administrator can ask us which applies to your raffle.
Privacy Policy: railway.com/legal/privacy
Cloudflare, Inc. (including Cloudflare R2)
Role: Content delivery and DNS; and, via Cloudflare R2 object storage, the encrypted storage of uploaded images, database backups, and the data exports we send an Organization before deletion
Privacy Policy: cloudflare.com/privacypolicy
Resend (Plus Five Five, Inc.)
Role: Transactional email delivery (entry confirmations, winner notifications, and organizer notices)
Privacy Policy: resend.com/legal/privacy-policy
GitHub, Inc. (Microsoft)
Role: Source code hosting and the private container registry that stores the application image. No participant data is stored at GitHub. A nightly backup copy was previously held there as GitHub Actions artifacts; that leg was removed and the stored artifacts deleted on 14 September 2026.
Privacy Policy: github.com privacy statement
Stripe, Inc.
Role: Subscription billing for the Organization's plan. Stripe processes the Organization's billing contact and payment details. No participant data is ever sent to Stripe — participants never pay us.
Privacy Policy: stripe.com/privacy
Google LLC (Gemini API)
Role: Optional AI assistance for Organization administrators: the setup assistant, and importing a prize list or roster. For an import the vendor receives the file you upload and, so that it can match new rows against people already entered, the names and email addresses already on your participant list. Content sent for these features is retained by Google for 55 days so it can detect misuse of its API, and is not used to train its models.
Privacy Policy: policies.google.com/privacy
Anthropic, PBC (Claude API)
Role: Optional AI assistance for Organization administrators, on the same terms as above. Content sent for these features is deleted by Anthropic within 30 days and is not used to train its models. Anthropic keeps it longer only where its systems flag a suspected policy violation.
Privacy Policy: anthropic.com/legal/privacy
We do not use advertising networks, analytics platforms, or social media trackers.
Do Not Track. We do not track visitors across other websites, so there is no cross-site tracking for a Do Not Track signal to turn off. We do not respond to Do Not Track signals and we do not allow any third party to collect personally identifiable information about your activity across other sites through our service.
9. Children's Privacy
SimplyRaffle is a tool for adult event organizers. Participants are entered by the Organization or enter themselves through a short entry form; Section 2 lists what that form can collect. We never ask for age or date of birth, and we do not knowingly collect personal information from a child under 13. Where an event involves participants under 13, such as a school or youth-group raffle, the Organization is responsible for having whatever authorization applies before it enters a child's information, including verifiable parental consent where COPPA requires it. If you believe we hold a child's information without that authorization, email [email protected] and we will delete it.
10. Your Rights
Participants and their families may request access to, correction of, or deletion of their data at any time.
The Organization may request a full data export or deletion of all participant data at any time.
To exercise these rights, email [email protected]. We respond within 10 business days and do our best to complete verified requests within 30 days.
11. Data Breach Notification
SimplyRaffle holds participant data on behalf of the Organization, which decides what is collected and why. If we discover a security breach affecting participant data, we will notify the Organization without unreasonable delay and no later than 48 hours after discovery, with what we know about what happened, which data was involved and what we are doing about it, and we will help the Organization with any notice it decides to give to participants. Notifying participants and any regulator is the Organization's decision and its responsibility, because the Organization is the party that holds the relationship with them. This reflects California Civil Code 1798.82(b), which places the notify-the-owner duty on a party in our position.
12. Updates to This Policy
The Last Updated date at the top of this page always reflects the current version. When we change how participant data is actually handled, and that change reduces the protection described here, we email the Organization's account contact before it takes effect. We do not ask the Organization to countersign a change. An Organization that does not accept one can end its service and ask us to export or delete its data under Section 10, and we will do that rather than hold it to a policy it did not agree to.
Corrections are different from changes, and this section used to conflate them. Where this policy described our practices inaccurately and we fix the wording so it matches what the software already does, that is a correction and we make it without advance notice. The September 2026 updates were of that kind: they listed data the software already collected, removed a retention figure that was wrong, and corrected a token-expiry period that had never been 14 days. Nothing about how the data is handled changed. Promising 30 days notice and written consent for every such fix was a promise this page broke each time it was corrected, which is why it is no longer made.