LolaJack privacy policy: follow personal data through the account

Privacy becomes practical when each piece of information can be connected to a purpose and a control. LolaJack’s notice covers data supplied at registration, records created through account use, due-diligence material and technical information. It also describes legal grounds, recipient categories, international transfers and individual rights.
Follow the data lifecycle: collection, purpose, recipients, retention and available action. Focused privacy requests use [email protected]; general account questions use [email protected] or 24/7 live chat.

Data collected at registration and during use

Registration data may include email, date of birth, country, telephone number, gender, full name, a social-security identifier where applicable, postcode, username, IP address and location data. Entering accurate information reduces conflicts between the profile, payment records and later identity checks.
Due-diligence data may include identity-document details, proof of address, source of funds or wealth, bank identifiers and financial information. The notice explains that KYC may support age, identity, anti-money-laundering, payment and legal checks. Only the material requested through the designated process should be submitted.

Data categoryTypical purpose described by the noticePractical control
Identity and contact detailsCreate and administer the accountKeep the profile accurate and current
Login and device dataSecurity, fraud prevention and service operationProtect credentials and review unusual activity
Transaction informationProcess and reconcile paymentsKeep references and query mismatches promptly
Gameplay and betting recordsOperate products and maintain account historyPreserve round or bet IDs for disputes
Due-diligence documentsIdentity, payment, AML and legal checksUpload only through the requested secure route
Marketing preferencesSend communications where permittedChange preferences or withdraw consent

Why LolaJack may process information

The notice identifies contract, legal obligation, legitimate interests and consent as grounds. These can support account services, required checks, security, fraud prevention and service improvement according to the activity involved.
Consent applies where a genuine choice is offered. Withdrawal affects processing based on that consent; it does not automatically erase records held under another valid ground. Identify the communication or activity concerned.

Who may receive account data

The stated recipient categories include payment providers, service providers, marketing partners, fraud-prevention agencies, game providers, analytics providers, law enforcement and regulators. A recipient category explains a function, not necessarily that every member receives every account record. The information shared should relate to the service, security or obligation involved.
When asking who received data, define the event and period. Include the account identifier and relevant transaction or case reference, but never send passwords or one-time codes.

Transfers beyond the EU or EEA

The notice says data may transfer outside the EU or EEA with recognised safeguards. A request can ask which recipient, purpose and safeguard applies to a particular record.
A transfer enquiry should name the data category and ask for the destination, recipient category and safeguard. Do not attach identity files until a secure verification step requests them.

Security, accuracy and retention

Accuracy is an ongoing control. A changed address, telephone number or email should be updated through the proper profile process. If an editable field is locked, ask support how to submit a correction and what evidence is needed. Creating a second profile is not a reliable way to correct the first record.
Retention should be assessed by data purpose and applicable obligations rather than by assuming one universal deletion date. A request can ask which retention criterion applies to a named category, such as transaction records or an uploaded proof of address. Erasure may apply in some circumstances, but it is not absolute where another lawful ground requires continued retention.

Rights described in the privacy notice

The notice covers access, correction, erasure where applicable, restriction, portability, objection, consent withdrawal and a regulator complaint. These rights answer different problems. Access concerns what is held and processed; correction addresses inaccurate information; restriction can limit processing in qualifying circumstances; portability concerns eligible data in a usable format.

GoalClear request wordingHelpful reference
Obtain a copyRequest access to named account data and processing informationRegistered email and date range
Correct a recordState the incorrect value and accurate replacementProfile field and supporting record
Stop optional messagesWithdraw consent for the named channelEmail, SMS or other preference
Question retentionAsk for the criterion applied to a data categoryDocument or transaction type
Challenge processingIdentify the activity and request restriction or objection reviewEvent, date and reason

Prepare a useful DPO request

Write from the registered email where possible and use a precise subject, such as “Access request — account transaction data”. State the account username or registered address, the right being exercised, the data category and a reasonable date range. Explain the desired result in one or two sentences.
Do not send a full identity file bundle without instructions. The recipient may need to verify the requester, but verification should follow a secure and proportionate process. Keep a copy of the message, attachments list and sent time. If a case reference is returned, use it in follow-up correspondence.
A correction request should distinguish a factual error from a preference. An incorrect postcode needs correction; stopping promotional email uses consent or preference controls. A disputed transaction is primarily an account-support issue.

Everyday privacy habits

Review the profile and preferences periodically. Keep case references, but avoid unprotected identity copies on shared devices. Before sharing a screenshot, check for unrelated balances, addresses or payment details.
The notice shows an effective date of October 2024. Policies can change, so a request or account decision should use the version presented at the relevant time. Save the date and section relied upon when the wording affects an active case.