Privacy
This page describes what Quick Lotto actually stores, why, and what you can ask us to do about it. It is written from the system itself rather than from a template, so where something is unusual — the bet slip that never leaves your browser, the results feeds that never learn who you are — it says so.
Who we are
Quick Lotto (quicklotto.io) is a lottery betting site operated by QuickLotto. For anything on this page — a copy of your data, a correction, a deletion, or a question — write to support@quicklotto.io from your registered address.
What we collect, and why
Your account. Email address, phone number, username, first and last name, date of birth, country, and your chosen currency and language. Date of birth and country are not optional extras: this is an 18+ service and we have to be able to show that we checked.
How you signed in. We store a one-way hash of your password, never the password itself, and a hash of each session token rather than the token. A copy of our database taken by someone who should not have it does not let them sign in as you.
Your devices. For each sign-in we keep the IP address, the browser’s user-agent string, the country the sign-in came from and the time it was last used, plus the IP you registered from. The country is the one our network provider resolved at the moment you signed in — we do not send your address to any location-lookup service, then or later. This is what lets support answer “was that me?” and lets you see the list of sessions on your account.
Checks against duplicate accounts. Our terms allow one account per person, so we record signals that help us notice when several accounts are used from the same phone or browser:
- In our Android app, the phone’s Android device ID — a number Android gives our app on that phone, which other apps cannot read. The app sends it to us directly; it is never handed to the web page.
- On the website, once you are signed in, a browser fingerprint: a number calculated in your browser from characteristics such as the screen, the fonts and how the browser draws graphics. It is worked out by the open-source FingerprintJS library running on our own site and sent only to us — not to Fingerprint or any other company. We are trying it for a trial period and will stop if it proves unreliable, because many phones of the same model give the same number.
- The random device number described below, which your browser keeps in its local storage.
We do not store the Android device ID or the browser characteristics themselves. We store a one-way, keyed hash of each value, which cannot practically be turned back into it and cannot be matched against the same phone on another site. When two accounts share an Android device ID or the random device number — or an email address, a phone number or a payout destination — offer limits apply to them together and their withdrawals are checked by a person before they are paid. A shared browser fingerprint is never used for either, because many unrelated people share one — it is only shown to our staff alongside everything else. Closing an account is always a person’s decision. We keep each signal for 180 days after it was last reported.
Identity documents, if you send them. Images you upload for verification are stored in the same database as the rest of your account, with their review status and any note the reviewer wrote. They are not copied to a separate file store — a second place to keep documents is a second place to lose them.
What you agreed to. Your consents — that you are of age, the terms, and whether you want marketing email — are kept as an append-only history rather than a single current value, so the question “what had you agreed to when you placed that bet?” has an answer. Withdrawing a consent adds a record; it does not erase the earlier one.
Money and play. Deposits, withdrawals, every ledger entry, and every bet with its lines and outcome. These are the record of what we owe you and what you played, and they are the part of your data we are least able to delete on request — see retention below.
Usage. A small beacon records page paths and named events against your account, or against the ql_vid browser number described below when you are signed out. Those events go to our own database and nowhere else. There is no Google Analytics and no advertising pixel.
Microsoft Clarity. To see where people get stuck, we use Microsoft Clarity, which records where you tap and scroll and can replay a visit. Anything you type into a form is masked in your browser before it is sent. When you are signed in, the recording is labelled with a short eight-character account reference — never your name, email or phone number.
Email delivery. Our mail provider reports back when a message is delivered, opened, clicked, bounces or is marked as spam, and we keep those events against your address. Opens are measured with a tracking pixel, which is standard for email and which your mail client may already block.
Messages you send us. Support email is stored against your account so whoever answers can see the conversation.
What stays on your device
We set no advertising cookies, and nothing on this site is shared with an ad network. Microsoft Clarity, described above, is the one outside service that runs on our pages. What we do set is first-party and small: ql_locale remembers your language and display_country your display currency — both simply your own choices written down. Your theme preference and whether you have seen the lottery tour are kept in your browser’s local storage and never sent to us.
One more, and we would rather describe it plainly than bury it: ql_vid is a random number this browser is given, kept for a year, so that our own visitor counts are counts of browsers rather than of clicks. It lets us tell that one person read four pages, which is the difference between knowing whether the site works and guessing. It is not a fingerprint — it is not calculated from your device, your IP address or anything else about you, so clearing your cookies really does end it and nothing can reconstruct the old one. It is sent only to us, never to another site, and it is not joined to anything you did before it was created.
Three more are about duplicate accounts, described above. ql_did is a random device number kept in your browser’s local storage and sent when you register or sign in; like ql_vid, it is not calculated from anything about you. ql_bsig only remembers the day the browser fingerprint was last sent, so it is sent at most once a day. The browser fingerprint itself is not stored in your browser — it is calculated when it is sent. ql_acct remembers only that an account has been signed in on this browser, so the Create account page can remind you of our one-account rule; it is never sent to us. In our app, that page asks us whether the phone’s device ID already belongs to an account and receives a yes or no — never which account.
A bet slip you are part-way through building is held in your browser’s session storage until you buy the ticket. If you close the tab, it is gone — we never saw it.
Your session itself is held as a bearer token rather than a cookie. None of the cookies above are used to advertise to you or shared with anyone, and the analytics they feed are read only by us, from our own database.
Who else sees it
Payment providers, when you deposit or withdraw. They receive what a payment needs — amount, currency, a reference — and they hold their own record of the transaction under their own privacy terms.
Our email providers, who receive your address and the message in order to deliver it. We use separate senders for account email and marketing so that one has nothing to do with the other.
Microsoft, through Clarity, described above: where you tap and scroll on our pages, with typed input masked, and a short account reference when you are signed in.
Nobody, in the case of the lottery results feeds. Worth stating plainly because it is the opposite of what people assume: we ask those services what numbers were drawn. They are never told that you exist, what you played, or that anyone bet on anything.
Our own team, through an internal alerting channel that reports registrations and payments so the site can be watched in real time. Email addresses in those alerts are masked (ab***@example.com) and the account is identified by an internal id, precisely because a chat channel is a weaker container than the back office.
We do not sell your data, and we do not share it for anyone else’s marketing.
Marketing
We only send marketing to people who have opted in, and every marketing email has an unsubscribe link that works without signing in. Account email — verification, receipts, a win notice, a change to your account — is not marketing and cannot be unsubscribed from while your account is open.
If you unsubscribe, your address goes on a permanent suppression list. That list exists specifically so a later import of a mailing list cannot resurrect you: an opt-out that a spreadsheet can undo is not an opt-out. Keeping your address for that purpose is the only way to reliably stop mailing it.
How long we keep it
Duplicate-account signals — the hashed Android device ID and the hashed browser fingerprint — are deleted automatically 180 days after they were last reported.
Your account and its history are kept while the account is open, and after closure for as long as we are required to keep them. Financial records — deposits, withdrawals, ledger entries, settled bets — are the exception to almost everything else on this page: they are the accounting record, and deleting them on request is not something we can offer.
Gambling and anti-money-laundering rules usually impose a minimum retention period on exactly those records. We will tell you the applicable period when you ask about deletion rather than quoting a number here that may not be the one that governs your account.
What you can ask for
Write to support@quicklotto.io from your registered address and you can ask us to:
- send you a copy of the data we hold about you;
- correct anything that is wrong;
- delete your account and the data we are not required to keep — we will tell you specifically what has to stay and why;
- stop sending you marketing, which you can also do from any email;
- close or self-exclude your account, which we treat as urgent rather than as a request to be processed in turn.
You can see and end your own sessions, update your details and manage your marketing preference from your profile without asking anyone.
Security
Passwords are hashed, session tokens are stored only as hashes, the site is served over HTTPS, and identity documents live inside the same protected database as the rest of your account rather than in a public bucket. No system is perfect and we would rather say that than claim otherwise; if we ever have a breach that affects you, we will tell you.
Children
This service is for adults aged 18 and over. We do not knowingly hold data about anyone younger, and if we find that we have, we delete the account and refund the balance. See responsible gambling.
Changes
When this page changes materially we will say so on the site rather than editing quietly and relying on a date stamp nobody checks.