Legal

Privacy Policy

Last updated: 7 May 2026. This policy explains what we collect, why and how to exercise your rights.

1. Data we collect

We collect the email address and password used to create an account, the display name and country you optionally provide in your profile, and the entry orders, ticket IDs and payment references generated when you take part in a draw. Card data is handled directly by our payment provider; we never store full card numbers on our servers.

2. How we use your data

Your data is used to operate your account, process entries, contact you about draws and winners, prevent fraud, comply with our legal obligations and improve the platform. We do not sell your personal data to third parties.

3. Cookies and analytics

We use strictly necessary cookies to keep you signed in and to remember your preferences. We may also use privacy-respecting analytics to measure aggregate traffic patterns. You can clear cookies at any time from your browser settings.

4. Data sharing

We share data with our payment processor to handle transactions, with our hosting and database provider to operate the service, and with identity verification providers when a winner is being confirmed. Each provider is bound by data processing agreements that match the protections described in this policy.

5. Data retention

Account and order data is kept for as long as your account is active and for the period required to comply with tax, accounting and anti-fraud obligations. You can ask us to delete your account at any time; some records may be retained in anonymised form for legal reasons.

6. Your rights

You can request access to your personal data, correction of inaccurate information, deletion, restriction of processing or portability of your data. To exercise these rights, contact us using the email address on the Contact page. We will reply within 30 days.

7. Security

Data is encrypted in transit and at rest. Access to production systems is limited to a small number of authorised staff and protected by multi-factor authentication. We monitor for suspicious activity and notify affected users in the event of a confirmed data breach in line with applicable law.

8. International transfers

Some of our service providers operate outside your country of residence. When personal data is transferred internationally we rely on Standard Contractual Clauses or equivalent safeguards to make sure your data stays protected.

9. Updates to this policy

We may update this policy when our practices change. Material changes will be highlighted on the platform and, where appropriate, communicated by email. Continued use of wincars.ae after an update means you accept the updated policy.