SharpRelayLegal & trust
Version technical-pilot-v1Effective 2026-08-21Manifest SHA-256 f09a494b248afeba5fa12ab4bd1d43a4a333fe7b6614ed16a6e6ba2ee765122a

Invitation-only technical pilot

Pilot Privacy Notice

This notice explains the limited account, security, consent, and usage data processed to operate the free SharpRelay technical pilot.

1. Contact

Privacy and account questions can be sent to [email protected]. Security incidents should be sent to [email protected]. SharpRelay technical pilot is an unincorporated, invitation-only evaluation service and does not present itself as a registered company.

2. Data processed

The service processes the invited business name, business-registration evidence reference, authorised contact email, invitation and acceptance records, plan and key status, API usage and credit ledger, request identifiers, endpoint and response-status metadata, security events, recovery state, and support correspondence. API keys and recovery capabilities are stored as protected values or one-way hashes as appropriate.

Failed-request diagnostics are designed to avoid storing response bodies, query-string values, API keys, or private source details. Participants must not place personal data, credentials, or other sensitive material in API query parameters or free-text identifiers.

3. Purposes and sharing

Data is used to verify admission, provide and secure access, meter quotas, diagnose errors, prevent abuse, recover accounts, communicate operational notices, and maintain audit evidence. Necessary data may be processed by infrastructure, edge-security, transactional-email, monitoring, and encrypted-backup providers used to operate the service.

No payment data is collected for the pilot. Participant account data is not sold. Public source data returned by the API is separate from participant account and usage metadata.

4. Retention and security

The raw visitor IP address is used in Redis fixed-window rate-limit keys that expire within at most two minutes. Cloudflare Turnstile performs bot and abuse verification for private-beta invitation activation and account recovery. Short-lived verification, delivery, and recovery capabilities expire automatically. Failed-request detail is retained for a bounded diagnostic period. Core account, consent, security, metering, private-beta invitations, and admission events are retained for the pilot and a reasonable period afterward for security, dispute, and operational audit, then deleted or anonymised when no longer needed. Encrypted backups expire under the backup-retention schedule.

The service uses access controls, encrypted secret storage, hashed credentials, isolated datastores, rate limits, audit records, protected backups, and restricted administrative access. No system can promise absolute security.

6. Data source

SharpRelay provides Pinnacle-sourced sports odds and market data. SharpRelay is not affiliated with, endorsed by, or sponsored by Pinnacle. Pinnacle is a trademark of its respective owner.

5. Requests

The invited contact may request access, correction, export, or deletion of account information by writing to [email protected]. Identity and authority will be verified before disclosure or deletion. Some records may be retained where reasonably necessary for security, legal claims, or mandatory obligations.