Privacy Policy
Last updated: June 30, 2026
Contents
1. The short version
- We collect your phone number, basic device and security information, and your transaction history — the minimum needed to run a safe, lawful noncash redemption service.
- We do not collect your Social Security number and we do not perform identity (KYC) checks. When you set up a prepaid card, you give your name and contact/mailing details to the issuing bank's page, not to us.
- We do not sell your information and we do not use it for advertising.
- We keep records for at least six years, because the law governing COAM redemption requires long retention.
2. Information we collect
You give us
- Mobile phone number (required); display name (optional).
- Your confirmations and choices in the app (loads, replays, card conversions).
Collected automatically for security and compliance (device information)
- Device identifier, model, operating system and version, app version, screen size, language, and time zone.
- IP address and, where available, mobile carrier.
- Push-notification token.
- Approximate location at the moment of sign-up or a load, only if you grant permission, used to confirm you are at a participating location. We do not track your location continuously or in the background.
Created by your activity
- Your gift-card balance and full transaction history — every load (with the related machine and voucher reference), replay redemption, card conversion, fee, and reversal — each tied to a receipt, the clerk, the device, the location, and the time.
- Consent records: which version of the Terms and Privacy Policy you accepted, and your text-message opt-in, each with date, IP, and device.
What we do NOT collect
Social Security numbers, government-ID numbers, bank-account or payment-card numbers (you have no payment method on file because you cannot add money), or biometric identifiers.
3. Information the issuing bank collects (not us)
When you convert balance to a prepaid card, the card issuer and its sponsor bank collect the information they need to issue and mail the card — typically your name, email, phone, and address — on their own page. That information is governed by their privacy policy and cardholder agreement. We pass them only what is needed to request your card; we never receive or store the identity details you enter on their page.
4. Why we use your information
- To run the Service: create your account, load winnings, process replays and card conversions, and issue receipts.
- To keep the Service safe and lawful: verify you are at a participating location, prevent duplicate or fraudulent loads, detect abuse, and meet the record-keeping obligations that apply to COAM noncash redemption.
- To support you: respond to help requests and re-send receipts.
- To send account messages by text (verification codes, receipts, service notices).
We rely on your consent (which you can manage) and on our legitimate interest in operating a secure, compliant service.
5. Who can see your information
- The participating location operator and its clerks can see your profile and activity for their own locations — your balance, history, signup details, and device/security information — to serve you and meet their own COAM compliance duties. An operator may limit what its clerks see. Operators cannot see your activity at other companies' locations.
- Our platform staff can see profiles across the service to provide support and oversight. Every time anyone opens your profile, that view is recorded in an audit log.
- The card issuer and its bank, to issue your prepaid card.
- Service providers that help us operate (for example, our text-message provider and cloud hosting), under contracts that limit them to our instructions.
- Regulators, including the Georgia Lottery Corporation and law enforcement, when required by law or to support a location's lawful reporting and audits.
- We never sell your information and never share it for advertising.
6. How long we keep it
We retain your account and transaction records for at least six years, consistent with the long retention required for COAM noncash redemption, and longer where a law, audit, or dispute requires it. Security and device information is kept for the same period because it is part of the compliance record.
7. How we protect it
We use access controls, encryption in transit, audited staff access, and an append-only record system designed so transaction history cannot be quietly altered. No system is perfectly secure, but we work to protect your information and to limit who can see it.
8. Your choices & rights
- Location permission is optional and controlled in your phone settings.
- Text messages: reply STOP to opt out of non-essential texts; essential security and transaction texts may still be sent.
- Access and correction: contact support to ask what we hold about you or to correct it, subject to the record-keeping the law requires (we generally cannot delete transaction records within the retention period).
- Depending on where you live, you may have additional rights under applicable state privacy law; contact us to exercise them and we will respond as the law requires.
9. Children
The Service is not for anyone under 18 or under the legal age to play COAM in Georgia, and we do not knowingly collect information from them.
10. Changes to this policy
If we change this policy we will post the new version, update the date, and bring material changes to your attention in the app. We record the version you accepted.
11. Contact
Reach us through support in the app, or at info@coamredemption.com.