Privacy Policy
Effective Date: March 14, 2026 · Last Updated: March 14, 2026
1. Introduction
Wavestar Holdings LLC ("ReDuel," "Company," "we," "us," "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, store, and protect your personal information when you use the ReDuel platform, website, mobile applications, and related services (collectively, the "Platform").
This policy applies to all Users, including Fans, Creators, and visitors. By using the Platform, you consent to the practices described herein.
2. Information We Collect
2.1 Information You Provide
- • Account Registration: Phone number, email address (optional), username, and display name
- • Identity Verification (KYC): Full legal name, date of birth, physical mailing address, Social Security Number (U.S. users), government-issued photo identification (driver's license, passport, or state ID), and proof of residence (utility bill, bank statement)
- • Creator Verification: Streaming platform usernames, OAuth access tokens (temporary), follower counts, and platform-specific user IDs from Twitch, YouTube, TikTok, Instagram, and Kick
- • Financial Information: Payment method details processed through Stripe, deposit and withdrawal history, and tax identification information
- • Communications: Messages sent through the Platform, support inquiries, and feedback
2.2 Information Collected Automatically
- • Device Information: IP address, browser type and version, operating system, device identifiers, screen resolution, and language preferences
- • Usage Data: Pages visited, features used, click patterns, session duration, referral sources, and search queries
- • Geolocation: Approximate location derived from IP address; precise location when required for regulatory compliance (with your consent)
- • Transaction Data: Prediction history, credit transactions, referral activity, wager amounts, and settlement records
- • Cookies and Tracking: Essential cookies for authentication and session management, analytics cookies (with consent), and similar technologies. See Section 8 for details.
2.3 Information from Third Parties
- • Streaming Platforms: Follower counts, subscriber counts, and public profile data from platform APIs (Twitch, YouTube, TikTok, Instagram)
- • Identity Verification Providers: Results of identity checks and fraud screening
- • Payment Processors: Transaction confirmations and dispute information from Stripe
3. How We Use Your Information
- • Service Delivery: Operating the Platform, processing transactions, managing accounts, facilitating predictions and challenges
- • Identity Verification: Verifying age, identity, and eligibility for prediction markets and payouts (KYC/AML compliance)
- • Security & Fraud Prevention: Detecting and preventing fraud, unauthorized access, market manipulation, and other prohibited activities
- • Regulatory Compliance: Filing required reports (SARs, CTRs, tax forms) with regulatory authorities including FinCEN and the IRS
- • Communications: Sending account notifications, OTP codes, match updates, prediction results, and promotional messages (with consent)
- • Improvement: Analyzing usage patterns to improve features, fix bugs, and develop new products
- • Legal Obligations: Complying with applicable laws, court orders, and regulatory requests
4. How We Share Your Information
We do not sell your personal information.
We may share information with the following categories of recipients:
- • Service Providers: Twilio (SMS/OTP), Stripe (payments), Resend (email), and infrastructure providers who process data on our behalf under contractual obligations
- • Streaming Platforms: Only the minimum data required for OAuth authentication and creator verification (Twitch, YouTube, TikTok, Instagram APIs)
- • Regulators & Law Enforcement: When required by law, subpoena, court order, or as necessary to comply with anti-money laundering regulations, tax reporting, or fraud investigations
- • Public Leaderboards: Anonymized or display-name-only data for leaderboard rankings. Phone numbers, emails, and personally identifiable information are never exposed on public leaderboards
- • Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, subject to standard confidentiality requirements
5. Data Security
We implement industry-standard security measures including:
- • TLS/SSL encryption for all data in transit
- • AES-256 encryption for sensitive data at rest
- • Bcrypt password hashing with cost factor 12
- • Cryptographically secure random generation for referral codes and tokens
- • Rate limiting on all API endpoints to prevent brute-force attacks
- • PII stripped from application logs and error reports
- • JWT access tokens with 15-minute expiry and secure rotation
- • Regular security audits and vulnerability assessments
While we implement commercially reasonable security measures, no electronic system is 100% secure. We cannot guarantee absolute security of your data.
6. Data Retention
- • Active Accounts: Data retained for the duration of account activity plus applicable retention periods
- • Financial Records: Transaction data retained for a minimum of seven (7) years as required by tax and financial regulations
- • KYC Records: Identity verification records retained for a minimum of five (5) years after account closure per AML regulations
- • Deleted Accounts: Personal data is deleted or anonymized within ninety (90) days of account deletion, except where retention is legally required
- • Security Logs: Access logs and security-related data retained for twelve (12) months
7. SMS & Communications
By providing your phone number, you consent to receiving SMS messages for:
- • Account verification (OTP codes)
- • Security alerts and fraud prevention
- • Match and prediction notifications (optional)
- • Streak reminders and tier upgrades (optional)
Message and data rates may apply. We limit non-essential SMS to three (3) per day. You can opt out of non-essential messages at any time by replying STOP. All SMS include STOP instructions per TCPA requirements. Essential security messages (OTP, fraud alerts) cannot be opted out of while your account is active.
8. Cookies & Tracking Technologies
8.1 Essential Cookies
Required for authentication, session management, and security. These cannot be disabled.
8.2 Analytics Cookies
Used to understand Platform usage and improve features. Collected with your consent where required by law.
8.3 Your Controls
You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using certain Platform features.
9. Your Privacy Rights
9.1 California Residents (CCPA/CPRA)
If you are a California resident, you have the right to:
- • Know: Request disclosure of the categories and specific pieces of personal information collected about you
- • Delete: Request deletion of your personal information, subject to legal exceptions
- • Opt-Out: Opt out of the sale or sharing of personal information (we do not sell personal information)
- • Correct: Request correction of inaccurate personal information
- • Non-Discrimination: Not receive discriminatory treatment for exercising your privacy rights
- • Limit Use of Sensitive Information: Limit the use and disclosure of sensitive personal information to only what is necessary
To exercise these rights, contact privacy@reduel.xyz. We will verify your identity before processing requests and respond within forty-five (45) days.
9.2 EU/EEA Residents (GDPR)
If you are located in the European Union or European Economic Area, you have the right to:
- • Access: Obtain a copy of your personal data
- • Rectification: Correct inaccurate or incomplete data
- • Erasure: Request deletion of your data ("right to be forgotten")
- • Restriction: Request restriction of processing in certain circumstances
- • Portability: Receive your data in a structured, machine-readable format
- • Object: Object to processing based on legitimate interests or for direct marketing
- • Withdraw Consent: Withdraw consent at any time where processing is based on consent
- • Lodge Complaint: File a complaint with your local Data Protection Authority
Our legal bases for processing include: contract performance, legitimate interests, legal compliance, and consent.
9.3 All Users
Regardless of your location, you may at any time:
- • Access and update your account information
- • Opt out of marketing communications
- • Request a copy of your data
- • Request account deletion
10. Children's Privacy
The Platform is not intended for individuals under eighteen (18) years of age. We do not knowingly collect personal information from minors. If we discover that a minor has provided personal information, we will delete the account and all associated data promptly. If you believe a minor is using the Platform, contact us at privacy@reduel.xyz.
11. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence, including the United States. We implement appropriate safeguards for international transfers, including Standard Contractual Clauses (SCCs) where required by GDPR. By using the Platform, you consent to the transfer of your data to the United States.
12. Data Breach Notification
In the event of a data breach involving your personal information, we will notify affected users within seventy-two (72) hours of becoming aware of the breach, in accordance with applicable laws including GDPR and state breach notification statutes. Notification will include the nature of the breach, the data affected, steps taken, and recommended protective measures.
13. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via the Platform, email, or SMS at least thirty (30) days before taking effect. Your continued use after the effective date constitutes acceptance. The "Last Updated" date at the top of this page indicates the most recent revision.
14. Contact Us
Data Protection Contact:
Wavestar Holdings LLC
Email: privacy@reduel.xyz
Data Subject Requests: privacy@reduel.xyz
General Inquiries: hello@reduel.xyz