Skip to content

Privacy Policy

Simply Raffle — simplyraffle.com

Operator: Simply Raffle  | Contact: [email protected]
Effective Date: February 28, 2026  | Last Updated: July 23, 2026


1. Who We Are

Simply Raffle is a web-based raffle administration platform developed and operated by Simply Raffle. We provide software to schools, parent-teacher groups (PTGs/PTAs), nonprofits, community organizations, and other groups for the purpose of managing fundraiser raffles.

Contact: [email protected]. We respond within 5 business days.

2. What Data We Collect

We collect only the minimum data necessary to administer a raffle on behalf of the Organization:

DataWhy We Collect It
Participant first and last nameTo identify raffle participants and record draw results
Grade level (school/educational orgs only)To organize participants within the raffle
Email address (participant or parent/guardian)To deliver magic-link portal access and draw result notifications
Phone number (only if the Organization turns this on)To let the Organization contact a participant about their entry or prize
Raffle ticket allocation countsTo calculate weighted draw probability and maintain participation records
Administrator login credentialsTo authenticate organization staff (stored as a one-way bcrypt hash — never readable)
Magic-link access tokensTo provide time-limited, password-free access to the participant portal

We do not collect: payment information, social security numbers, government ID numbers, dates of birth, home addresses, health information, or disciplinary records.

3. How We Use This Data

Participant data is used only for administering the Organization's fundraiser raffle — displaying ticket allocations, calculating draw results, sending magic-link access emails, and allowing Organization administrators to manage participant records. We do not use your data for any commercial purpose.

4. What We Do Not Do

  • ❌ We do not sell participant data — ever, to anyone, for any reason.
  • ❌ We do not rent or trade participant data.
  • ❌ We do not use participant data for advertising or marketing.
  • ❌ We do not build behavioral profiles of participants or their families.
  • ❌ We do not share data with third parties for any commercial purpose.
  • ❌ We do not retain data indefinitely — participant data is deleted on a defined schedule.

5. Who Can Access Your Data

WhoWhat they can see
Organization administratorsAll participant data for their raffle
Participants / parents / guardiansOnly their own family's ticket allocation and draw results
Developer (operator)Access for system maintenance and security purposes only
Railway, Inc. (infrastructure)Encrypted database storage only — see Section 8

6. Data Retention

  • Active raffle: Participant records are retained while the raffle they entered is active.
  • Non-winning participants: Contact information (name, email address, and phone number if collected) is removed within 45 days of the raffle a participant entered, or upon Organization request if sooner.
  • Winners: The winner's name and the prize they won are kept as part of the raffle's published result. Their contact information (email address and phone number) is removed on the same 45-day schedule as everyone else.
  • Recurring series: For Organizations that run repeat raffles, the 45-day clock applies per raffle — each raffle's non-winning participants are scrubbed 45 days after that raffle, independent of any later raffle in the series.
  • Standing membership rosters: Some Organizations (for example a club running a members' draw) keep the same roster across repeat raffles rather than clearing it. Those members remain on the Organization's active roster and are not on the 45-day schedule while the roster is in use — their records are retained until the Organization removes them or closes its account, at which point the schedules above apply. An account whose service has ended, or that shows no activity for an extended period (currently 12 months, matching the paid-plan service window in our Terms), is treated as closed: after advance notice to the Organization, its data enters the deletion schedule above, beginning with a full data export to the Organization.
  • Organization termination: All participant data is deleted after a data export is provided to the Organization.
  • Backups: Encrypted backups are kept on a rolling schedule for disaster recovery. Because a backup is a point-in-time copy, data that has been deleted or scrubbed can persist in backups until they age out — up to 59 days after the deletion. Backups are never used to restore data that was deleted on request, and any restore re-applies prior deletions.

To request earlier deletion, contact us at [email protected] or ask your Organization's administrator.

7. Security

  • Encryption in transit: All data is encrypted using HTTPS (TLS).
  • Encryption at rest: Database hosted on Railway (Google Cloud), which provides encryption at rest by default.
  • Password security: Administrator passwords stored using bcrypt hashing — never stored in readable form.
  • Magic-link tokens: Time-limited (expire within 14 days) and single-use.
  • Access controls: Role-based access enforced at the API level — participants see only their own records.

To report a security vulnerability, email [email protected].

8. Third-Party Subprocessors

We use the following third-party infrastructure providers. All are located in the United States.

Railway, Inc.

Role: Cloud hosting and PostgreSQL database hosting

Privacy Policy: railway.com/legal/privacy

Cloudflare, Inc.

Role: Content delivery, DNS, and encrypted object storage (uploaded images, database backups, and data exports)

Privacy Policy: cloudflare.com/privacypolicy

Resend (Plus Five Five, Inc.)

Role: Transactional email delivery (entry confirmations, winner notifications, and organizer notices)

Privacy Policy: resend.com/legal/privacy-policy

GitHub, Inc. (Microsoft)

Role: Automated encrypted database backups, retained up to 30 days

Privacy Policy: github.com privacy statement

We do not use advertising networks, analytics platforms, or social media trackers.

9. Children's Privacy (COPPA)

For Organizations that serve participants under the age of 13 (including schools and PTGs), we operate under the school consent pathway established by the FTC's COPPA Rule (16 C.F.R. Part 312). Where the Organization is a school, the school provides authorization on behalf of parents and guardians for the collection of participant information solely for the fundraising purpose described in this policy. Where the Organization is not a school, the Organization represents that it has obtained verifiable parental consent before submitting any participant under 13. We do not collect personal information from individuals under 13 for any commercial purpose.

10. Your Rights

Participants and their families may request access to, correction of, or deletion of their data at any time.

The Organization may request a full data export, deletion of all participant data, or an audit of our data handling practices at any time.

To exercise these rights, email [email protected]. We respond within 10 business days and fulfill verified requests within 30 days.

11. Data Breach Notification

In the event of a breach involving California residents' personal information, we will notify the Organization within 48 hours and notify affected individuals within 30 calendar days of discovery, consistent with California Civil Code § 1798.82 (as amended by SB 446, effective January 1, 2026).

12. Updates to This Policy

We will notify the Organization at least 30 days before making any material changes to this policy and obtain written consent before implementing such changes.

13. Contact

[email protected]
simplyraffle.com

Privacy Policy — Simply Raffle