Legal
Privacy Policy
Version 2026-09-14.3 · Aligned with the Tanzania Personal Data Protection Act 2022 and EU GDPR principles.
The English version of this document is the legally binding text; translations are provided for convenience.
1.Data controller
50pick Ltd, Dar es Salaam, Tanzania. Contact: msaada@50pick.tz. Our data protection officer (DPO) is reachable at the same address.
2.What we collect
- Identity: full name and date of birth; the type and number of one of four documents — a National ID (NIDA), a passport, a driving licence or a voter's card — and its expiry date where the document has one; photographs of that document; and a selfie
- Contact: phone number (E.164), email address, region
- Financial: deposit and withdrawal records, mobile-money MSISDN, prediction activity; for a card deposit, the billing name and address you enter; and the name registered to a mobile-money number you withdraw to
- Technical: IP address and browser user-agent string, recorded on sign-in and security events; session issue and expiry times
- Behavioural: deposit and loss limit changes, self-exclusion and cooling-off periods
3.Lawful basis
- Performance of contract: account, wallet, bet placement, settlement
- Legal obligation: identity verification (KYC) and AML/CFT under the Anti-Money Laundering Act and POCA, tax under the Income Tax Act
- Legitimate interest: fraud prevention, market-integrity monitoring, security alerting
- Consent: marketing communications — you can withdraw it at any time under Profile → Notifications
4.Sharing
We share data with:
- Selcom, our payment gateway, which processes deposits and withdrawals: it receives the mobile-money number and the amount; for a card deposit, also your email address, your account name, your phone number and the billing name and address you enter; and before a withdrawal it tells us the name registered to the receiving number
- Gaming Board of Tanzania, Tanzania Revenue Authority, FIU when legally compelled
- Cloud hosting providers: Railway, in the United States (region us-west2), which runs the app, holds its databases and keeps backups of them; and Cloudflare R2, in Western Europe, which stores identity documents, selfies and encrypted database backups; and GitHub Actions, in the United States, which creates the nightly database backup and test-restores it before it is encrypted and stored
- Cloudflare's network, which carries every connection to www.50pick.tz: each request is decrypted at the Cloudflare data centre nearest to you and encrypted again on its way to our servers
- Postmark, in the United States, which sends our emails: it keeps a record of each email, and records when an email is opened and which link in it is clicked
- Anthropic, which writes the answers in the 50pick Help chat: it receives the messages of that conversation, not your account details; it stores data in the United States and may process a request in the United States, Europe, Asia or Australia
- Sentry, in the European Union, which receives error reports from our servers: Tanzanian phone numbers, email addresses and long numbers such as a NIDA number are removed from a report before it is sent
- If you turn on notifications, the push service of your browser, run by the company that makes it, delivers them; the content of each notification is encrypted
We never sell personal data.
5.Retention
- Account and identity (KYC) records: at least 7 years after the account is closed (AML statutory). If you ask us to erase a closed account, your contact details, password and the name and number on your identity record are removed at once; the images of your identity documents are kept until at least 7 years after closure
- Prediction and transaction history: at least 7 years
- Audit log entries: at least 7 years
- Marketing consent: until you withdraw it, close your account, or 2 years pass without you signing in
6.Your rights
- Access: request a copy of your data (delivered within 30 days)
- Rectification: correct inaccurate data
- Erasure: subject to AML retention requirements
- Portability: receive your data in a machine-readable format
- Objection: object to how we use your data by writing to us; we do not profile you for marketing
- Complaint: with the Personal Data Protection Commission of Tanzania
7.Cookies
We use a minimum-necessary set of cookies: your sign-in session (HMAC-signed HttpOnly cookies that end at most 7 days after you sign in), your language, a note kept for 30 seconds that explains why you were signed out, a record that you dismissed the identity notice on your wallet, and, on staff accounts only, the two-factor sign-in cookies. No third-party advertising or tracking cookies. Some display choices, such as hiding your balance or dismissing a prompt, are kept in your browser's own storage on your device.
8.Security
Sessions signed with HMAC-SHA-256. OTP codes hashed with scrypt + per-OTP salt + global pepper. Passwords: scrypt with a per-user salt. Connections to our website and app are encrypted in transit with TLS (HTTPS). Two-factor authentication keys are encrypted in the database with AES-256-GCM, and database backups are encrypted with AES-256-GCM before they are stored. Annual ISO 27001 audit cadence; pentest twice a year.
9.People who are not our customers (referees)
When someone applies to become a 50pick agent, they give us the names, contact details and national-ID scans of two referees, and attest that each referee agreed to this. If you are such a referee: we hold your details only to verify that application; the ID scan is destroyed 90 days after the decision, and immediately if the application is refused; we never contact you for marketing; and you may ask us to destroy your information sooner by writing to the data controller named in §1 — you do not need an account to do so.