Operator: Simply Raffle | Contact: [email protected]
Effective Date: February 28, 2026 | Last Updated: July 23, 2026
1. Who We Are
Simply Raffle is a web-based raffle administration platform developed and operated by Simply Raffle. We provide software to schools, parent-teacher groups (PTGs/PTAs), nonprofits, community organizations, and other groups for the purpose of managing fundraiser raffles.
Contact: [email protected]. We respond within 5 business days.
2. What Data We Collect
We collect only the minimum data necessary to administer a raffle on behalf of the Organization:
| Data | Why We Collect It |
|---|---|
| Participant first and last name | To identify raffle participants and record draw results |
| Grade level (school/educational orgs only) | To organize participants within the raffle |
| Email address (participant or parent/guardian) | To deliver magic-link portal access and draw result notifications |
| Phone number (only if the Organization turns this on) | To let the Organization contact a participant about their entry or prize |
| Raffle ticket allocation counts | To calculate weighted draw probability and maintain participation records |
| Administrator login credentials | To authenticate organization staff (stored as a one-way bcrypt hash — never readable) |
| Magic-link access tokens | To provide time-limited, password-free access to the participant portal |
We do not collect: payment information, social security numbers, government ID numbers, dates of birth, home addresses, health information, or disciplinary records.
3. How We Use This Data
Participant data is used only for administering the Organization's fundraiser raffle — displaying ticket allocations, calculating draw results, sending magic-link access emails, and allowing Organization administrators to manage participant records. We do not use your data for any commercial purpose.
4. What We Do Not Do
- ❌ We do not sell participant data — ever, to anyone, for any reason.
- ❌ We do not rent or trade participant data.
- ❌ We do not use participant data for advertising or marketing.
- ❌ We do not build behavioral profiles of participants or their families.
- ❌ We do not share data with third parties for any commercial purpose.
- ❌ We do not retain data indefinitely — participant data is deleted on a defined schedule.
5. Who Can Access Your Data
| Who | What they can see |
|---|---|
| Organization administrators | All participant data for their raffle |
| Participants / parents / guardians | Only their own family's ticket allocation and draw results |
| Developer (operator) | Access for system maintenance and security purposes only |
| Railway, Inc. (infrastructure) | Encrypted database storage only — see Section 8 |
6. Data Retention
- Active raffle: Participant records are retained while the raffle they entered is active.
- Non-winning participants: Contact information (name, email address, and phone number if collected) is removed within 45 days of the raffle a participant entered, or upon Organization request if sooner.
- Winners: The winner's name and the prize they won are kept as part of the raffle's published result. Their contact information (email address and phone number) is removed on the same 45-day schedule as everyone else.
- Recurring series: For Organizations that run repeat raffles, the 45-day clock applies per raffle — each raffle's non-winning participants are scrubbed 45 days after that raffle, independent of any later raffle in the series.
- Standing membership rosters: Some Organizations (for example a club running a members' draw) keep the same roster across repeat raffles rather than clearing it. Those members remain on the Organization's active roster and are not on the 45-day schedule while the roster is in use — their records are retained until the Organization removes them or closes its account, at which point the schedules above apply. An account whose service has ended, or that shows no activity for an extended period (currently 12 months, matching the paid-plan service window in our Terms), is treated as closed: after advance notice to the Organization, its data enters the deletion schedule above, beginning with a full data export to the Organization.
- Organization termination: All participant data is deleted after a data export is provided to the Organization.
- Backups: Encrypted backups are kept on a rolling schedule for disaster recovery. Because a backup is a point-in-time copy, data that has been deleted or scrubbed can persist in backups until they age out — up to 59 days after the deletion. Backups are never used to restore data that was deleted on request, and any restore re-applies prior deletions.
To request earlier deletion, contact us at [email protected] or ask your Organization's administrator.
7. Security
- Encryption in transit: All data is encrypted using HTTPS (TLS).
- Encryption at rest: Database hosted on Railway (Google Cloud), which provides encryption at rest by default.
- Password security: Administrator passwords stored using bcrypt hashing — never stored in readable form.
- Magic-link tokens: Time-limited (expire within 14 days) and single-use.
- Access controls: Role-based access enforced at the API level — participants see only their own records.
To report a security vulnerability, email [email protected].
8. Third-Party Subprocessors
We use the following third-party infrastructure providers. All are located in the United States.
Railway, Inc.
Role: Cloud hosting and PostgreSQL database hosting
Privacy Policy: railway.com/legal/privacy
Cloudflare, Inc.
Role: Content delivery, DNS, and encrypted object storage (uploaded images, database backups, and data exports)
Privacy Policy: cloudflare.com/privacypolicy
Resend (Plus Five Five, Inc.)
Role: Transactional email delivery (entry confirmations, winner notifications, and organizer notices)
Privacy Policy: resend.com/legal/privacy-policy
GitHub, Inc. (Microsoft)
Role: Automated encrypted database backups, retained up to 30 days
Privacy Policy: github.com privacy statement
We do not use advertising networks, analytics platforms, or social media trackers.
9. Children's Privacy (COPPA)
For Organizations that serve participants under the age of 13 (including schools and PTGs), we operate under the school consent pathway established by the FTC's COPPA Rule (16 C.F.R. Part 312). Where the Organization is a school, the school provides authorization on behalf of parents and guardians for the collection of participant information solely for the fundraising purpose described in this policy. Where the Organization is not a school, the Organization represents that it has obtained verifiable parental consent before submitting any participant under 13. We do not collect personal information from individuals under 13 for any commercial purpose.
10. Your Rights
Participants and their families may request access to, correction of, or deletion of their data at any time.
The Organization may request a full data export, deletion of all participant data, or an audit of our data handling practices at any time.
To exercise these rights, email [email protected]. We respond within 10 business days and fulfill verified requests within 30 days.
11. Data Breach Notification
In the event of a breach involving California residents' personal information, we will notify the Organization within 48 hours and notify affected individuals within 30 calendar days of discovery, consistent with California Civil Code § 1798.82 (as amended by SB 446, effective January 1, 2026).
12. Updates to This Policy
We will notify the Organization at least 30 days before making any material changes to this policy and obtain written consent before implementing such changes.