Privacy policy
This policy explains how Kamys, LLC, through its BoundsCheck division ("BoundsCheck", "we", "us"), handles personal information. It covers two different situations, because our role is different in each:
- Our website and business contacts. When you visit boundscheck.com or email us, we decide what information to collect and why. Sections 1 to 3 apply.
- The BoundsCheck service. When a gaming operator uses BoundsCheck to check where its players are, we process player information on the operator's behalf and under its instructions. The operator is responsible for its players' information and its own privacy notice governs it. Sections 4 to 8 apply.
There is one exception to the second situation. To detect players who hold several accounts or abuse promotions, we pool a small set of fraud signals across all the operators we serve (the "fraud network", described in section 5). For the fraud network we decide how those signals are used, and section 8 explains how to contact us about it directly.
1. Information we collect through our website
Information you send us. If you email us or use the contact form, we receive what you choose to include, such as your name, work email, company, product type and message. The contact form delivers your message to us by email; we do not keep a separate copy of submissions on the website. To limit abuse, the website briefly keeps a one-way hashed form of your IP address and a count of recent submissions, which is deleted within an hour.
Technical information. Our web server records standard request logs, including IP address, browser type, the page requested and the time. We use these logs to operate and secure the site. Our web host processes them into traffic statistics and then discards the raw logs, usually within a day. Those statistics summarize visits and can include visitor IP addresses.
No tracking. The website does not use analytics, advertising pixels or tracking cookies. Pages load fonts from Google Fonts, which means your browser sends a request, including your IP address, to Google when a page loads. Google's handling of that request is described in Google's own privacy policy.
Chat. Every page loads a small chat button from our chat provider, Chatter (chatter.inherent.com). The chat window itself only loads if you open it. If you do, what you type, and any name or email you give, is sent to Chatter so we can answer you. Chatter's AI assistant may reply first using an AI model provider, and a person on our team can take over. The chat window stores an anonymous identifier in your browser so your conversation continues across pages; it does not use cookies. Chat conversations are kept as part of our business communications and are covered by sections 2, 3 and 9.
2. How we use website and contact information
We use it to reply to you, to discuss and provide our service, to keep records of our business communications, to operate and secure the website, and to meet legal obligations. We do not sell this information and we do not use it for targeted advertising.
3. Sharing of website and contact information
We share it only with service providers that host our website and email on our behalf, with professional advisers where needed, where required by law, or as part of a merger or sale of our business.
4. Information we process when providing the service
Operators integrate BoundsCheck into their apps and websites to check whether a player is in a location where a given activity, such as a paid contest entry, purchase or withdrawal, is allowed. For each check, the operator sends us some or all of the following:
- Device location: latitude and longitude, accuracy, the time the location was captured, the device's timezone and platform, and whether the device reports that the location may be simulated.
- Network information: the player's IP address, and location and network details derived from it by the operator's content delivery network, such as approximate region and network operator.
- Identifiers: the operator's own player identifier and session identifier. We do not need, and ask operators not to send, names or other directly identifying details, and we never accept an email address or phone number in readable form.
- Hashed contact details: a one-way hash of the player's email address and phone number. The operator converts each into a hash before sending it, so we never receive the address or number itself. Hashed contact details are still personal information, and we protect them as such.
- Device identifiers and integrity: an identifier the operator's app creates for the device, and the results of integrity checks run by Apple or Google on the device, which say whether the app is genuine and whether the device appears to be an emulator or has been modified.
- Context: the activity being checked, the contest format, and in some cases the entry amount.
From this we produce a decision (for example allow or block), the reasons for it, the jurisdiction we resolved, and a check identifier. We also tell the operator how many of its own accounts have used the same device, email address or phone number, and what the fraud network knows about them and about the network address (see section 5). We also keep records of changes operators' administrators make to their policy settings, including which administrator made each change, and of any account an operator reports to us as confirmed promotion abuse.
Precise location is sensitive. Several U.S. state privacy laws treat precise geolocation as sensitive information. Operators are responsible for giving players notice and obtaining any consent their laws require before sending us a player's location.
Operators must tell players about the fraud network. Operators are responsible for telling their players, in their own privacy notices, that device, network and hashed contact signals are shared with other operators through BoundsCheck to prevent fraud and multiple accounts.
5. How we use service information
We use service information to provide the service to the operator that sent it: to make location decisions, to keep the audit record the operator relies on to demonstrate its compliance, to detect location spoofing, multiple accounts and abuse of the service, to secure and maintain the service, and to support the operator. We may also use aggregated or de-identified data that cannot reasonably identify a player to measure and improve the service.
The fraud network. Beyond that, we use a limited set of signals across all the operators we serve, for one purpose only: detecting players who hold several accounts or abuse sign-up and deposit promotions.
- What goes into it: device identifiers, IP addresses and hashed email addresses and phone numbers, each stored only as a one-way hash with a secret key that we hold and operators do not. Alongside each, how many accounts have been seen with it, whether the device passed its integrity checks, and whether an operator has reported a linked account as confirmed promotion abuse.
- What never goes into it: precise location, the operator's player or session identifiers, entry or deposit amounts, location decisions, or anything else in section 4.
- What another operator receives: whether a device, network address, email address or phone number the player uses is linked to an account another operator has confirmed as promotion abuse. For devices and network addresses, it also receives how many accounts across the network have used them. For email addresses and phone numbers it receives only confirmed abuse, because having accounts with several operators is normal. Operators never learn which other operators a player uses or which operator a signal came from, and never receive another operator's player identifiers or data.
- How operators may use it: to decide eligibility for promotions or to send an account for review. We ask operators not to close an account or withhold a player's winnings on a fraud network signal alone, without their own review.
We do not sell service information and we do not share it for cross-context behavioral advertising.
6. Retention
We keep the most sensitive information for the shortest time. The record operators need to show their compliance is kept longer, but without the player's precise location.
- Precise device location and IP address: 90 days. This gives operators time to investigate disputes and suspected location spoofing. After 90 days we delete the IP address and reduce the device location to roughly 1 kilometer.
- Decision records: 3 years. A decision record holds the decision, its reasons, the state and county we resolved, the location accuracy, the policy version applied, the check identifier and the time. It lets operators answer payment processors and regulators about past transactions. An operator can choose a shorter period, or a longer one of up to 7 years where its licenses or regulators require it.
- Policy change records: 3 years, on the same terms as decision records.
- Device identifiers, hashed contact details and the links between an operator's own accounts: 3 years after they were last seen, on the same terms as decision records.
- Fraud network signals: hashed IP addresses for 90 days, the same as the addresses themselves. Hashed device identifiers, email addresses and phone numbers for 3 years after they were last seen. A confirmed abuse report for 3 years after it was made, or until the operator withdraws it or we remove it on review (section 8).
- When a contract ends: we offer the operator an export of its records, then delete its service information within 30 days, unless the law requires us to keep it longer. In the same 30 days we remove everything that operator contributed to the fraud network, including its abuse reports.
7. Where data is stored and how it is protected
Service data is stored in the United States, on Amazon Web Services in the US West (Oregon) region. We protect it with encryption of stored data and of our backups, encryption of connections that cross the public internet, access controls on our systems, authenticated access for operators, and logging of administrative changes. Connections between an operator and our servers inside a private cloud network may not be separately encrypted. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We use these service providers for the service. Each receives only what it needs for its task:
- Amazon Web Services hosts our infrastructure and stores service data, in the United States.
- proxycheck.io tells us whether an IP address belongs to a VPN, proxy or hosting provider. For some checks it receives the player's IP address and nothing else. It answers our requests from its servers in Canada, keeps addresses it identifies as a VPN, proxy or hosting provider for up to 180 days, and keeps other addresses for a few minutes.
- ipapi.co (Kloudend, Inc.) is a backup IP location lookup, used only when our own database cannot place an IP address. It receives the IP address and nothing else, in the United States.
- Apple (DeviceCheck), for players using an operator's iOS app, receives a token from the app so we can read and set two flags Apple keeps for that device: whether it has been used for an account before, and whether it has been linked to confirmed abuse. Apple does not receive the player's identity, location or contact details.
We also use IP location databases from MaxMind, which run on our own servers; no data is sent to MaxMind.
8. Players' choices and rights
If you are a player and want to access, correct or delete information about you, or exercise another privacy right, please contact the operator whose app or website you use. Operators control their players' information, and we help them respond to requests under our agreement with them. If you contact us directly, we will refer your request to the relevant operator where we can identify it.
The fraud network. Because we decide how fraud network signals are used, you can also contact us directly about them at privacy@boundscheck.com. You can ask whether the network holds signals about your device, email address or phone number, or ask us to review a signal you believe is wrong, for example because your household shares a device. We will verify your request before acting on it. If we find a signal is wrong, we remove it, and it is no longer reported to any operator.
9. Your rights as a website visitor or business contact
Depending on where you live, you may have the right to know what personal information we hold about you, to receive a copy, to correct it, to delete it, and to opt out of certain uses. To make a request, email privacy@boundscheck.com. We will verify your request before acting on it and will not discriminate against you for making it. An authorized agent may make a request on your behalf with proof of authorization.
10. Children
Our website and service are intended for businesses. We do not knowingly collect personal information from children under 13 through our website. Operators are responsible for the age requirements of their own products.
11. Changes to this policy
We may update this policy from time to time. When we do, we will change the "last updated" date above, and if the changes are significant we will tell operators directly.
12. Contact
Questions about this policy or our privacy practices: privacy@boundscheck.com.
Postal address: Kamys, LLC (BoundsCheck), 1 Embarcadero Center, Suite 1200, San Francisco, CA 94111