
Privacy Policy - T20Sports Fantasy
T20Sports Fantasy privacy policy: what data we collect, how we use it, your rights under DPDP Act 2023, retention periods.
Data handling in plain language
We collect the minimum data needed to operate a fantasy sports platform: name, mobile number, email, PAN for KYC, bank or UPI for withdrawals, and a password hash. We do not collect biometric data except the optional fingerprint or face template for device-level biometric login - and that template never leaves your device. We do not collect browsing history outside our platform, and we do not run third-party tracking pixels that follow you around the web.
KYC (Know Your Customer) data is collected for regulatory compliance under the Prevention of Money Laundering Act (PMLA) and FIFS code of conduct. We collect PAN card number, Aadhaar (optional, only for address verification), bank account or UPI ID for withdrawals, and a selfie for biometric match. All KYC documents are stored in encrypted storage at rest and decrypted only for verification review by authorized compliance staff. Third-party KYC processors we use (account aggregators, document verification APIs) are bound by data processing agreements.
We use your fantasy data - team selections, contest entries, captain picks - to compute league standings and to suggest improvements via the captain analytics engine. We do not share your individual team data with other players, advertisers, or partners. Aggregated, anonymized data (like "38% of players picked player X as captain") may be used in our transparency reports or partner dashboards, but you are never identifiable in those reports.
You can request a copy of all personal data we hold on you via Settings > Privacy > Download My Data. The export is delivered within 30 days as a JSON file. You can request deletion via the account deletion flow (see Delete Account page). After deletion, all personal data is purged within 30 days, with the exception of records we are legally required to retain for tax or anti-money-laundering compliance (typically 5 years for financial transactions). For any privacy question or complaint, email [email protected] and our Data Protection Officer will respond within 7 business days.
Privacy Policy
Summary
- We collect data needed to operate T20 fantasy services (account, KYC, gameplay)
- We do not sell your personal data to advertisers or third parties
- We retain data only as long as legally required (typically 5-7 years)
- You can request data export and deletion under DPDP Act 2023
- KYC documents are encrypted at rest and in transit
- Payment data is tokenized - we never store full card numbers
Data We Collect
| Category | Examples | Purpose | Retention |
|---|---|---|---|
| Identity | PAN, Aadhaar (masked), name | KYC verification | 7 years post-deletion |
| Contact | Mobile, email, address | Account access, notifications | Account lifetime |
| Financial | Bank/UPI, deposit history, withdrawals | Payments, TDS, anti-money laundering | 7 years per RBI |
| Gameplay | Teams, contests, leaderboard | Fantasy play, leaderboards | Account lifetime |
| Device | IP, browser, OS, app version | Security, fraud detection | 2 years |
Your Rights
Right to access
Request a copy of all personal data we hold about you. Delivered within 30 days via encrypted download.
Right to correct
Update incorrect data via Settings > Profile. Identity reverification may apply for sensitive fields like PAN.
Right to delete
Request deletion via account deletion flow. 7-day cooling-off, then permanent removal within 30 days.
Right to portability
Export your data in JSON format. Includes fantasy history, transactions, KYC metadata.
T20Sports Authority is the data fiduciary under the Digital Personal Data Protection Act 2023 (DPDP). Our privacy officer is available at [email protected] for data-related requests. For grievances not resolved within 30 days, you may escalate to the Data Protection Board of India.
We collect only the data needed to operate T20 fantasy services and meet regulatory obligations. We do not sell, rent, or share personal data with advertisers or third-party marketers. Payment card data is tokenized at the gateway - T20Sports Authority never stores full card numbers or CVV. KYC documents are encrypted with 256-bit AES at rest and TLS 1.3 in transit. Access to production systems requires multi-factor authentication and is logged for audit.
Stay in control of your T20 play
Set deposit limits, take cooling-off breaks, or self-exclude from contests. Fantasy contests should be entertainment, not financial pressure.
- ๐ iCall Helpline: 9152987821
- ๐ Gamblers Anonymous India: +91 22 2808 0412
- โฑ๏ธ Deposit limit: Settings > Limits
- ๐ซ Self-exclusion: 7d / 30d / 6mo / permanent
Ready to play T20 fantasy?
Join 2.4M+ T20 sports authority players. Sign up in 2 minutes, claim your โน100 bonus, build your first dream XI.
Browse by topic
Privacy & Data
How we collect, store, and use your personal data
t20sportsfantasy.com collects only the data necessary to operate a paid fantasy sports platform: identity verification data (PAN, Aadhaar-masked, DOB), contact data (phone, email), bank/payment data (UPI ID, last 4 digits of bank account), and platform usage data (IP, device, app behaviour). We do not sell user data. We do not share user data with advertising networks. Data is stored encrypted-at-rest using AES-256, encrypted-in-transit using TLS 1.3, and access-controlled via role-based ACL. Third-party processors we use are listed in full below with their data-handling contracts.
Data we collect and why
Identity (PAN, DOB, Aadhaar last 4) โ to verify 18+ age and comply with KYC rules. Phone (with OTP) โ to secure account access and prevent fraud. Email โ for contest confirmations, payout receipts, editorial newsletters. Bank (UPI, IFSC, account last 4) โ to process payouts and refunds. Device, IP, browser fingerprint โ to detect multi-accounts and prevent platform abuse. We do not collect biometric data. We do not collect Aadhaar image unless you opt into eKYC.
How long we retain your data
Account data: retained for the lifetime of the account, plus 5 years after closure for anti-money-laundering compliance per PMLA 2002. KYC documents: retained for 5 years post-closure. Transaction history: 7 years per Income Tax Act requirements. Marketing preferences: deleted within 30 days of opt-out. Anonymized usage analytics may be retained indefinitely but cannot be linked back to you.
Your rights under DPDP Act 2023
Under the Digital Personal Data Protection Act (DPDP), you have the right to: (a) access a copy of all personal data we hold, (b) correct inaccurate data, (c) request deletion (subject to the retention periods above), (d) nominate another person to exercise your rights in case of death or incapacity, (e) withdraw consent for optional processing (newsletter, marketing). To exercise these rights, write to [email protected] or use the Data Request link in your account settings.
Third-party processors and their roles
Payment processing: Razorpay (UPI, cards, netbanking). KYC: Signzy (PAN-Aadhaar verification, Aadhaar OTP eKYC). SMS and OTP: MSG91, Karix. Email: SendGrid. Push notifications: FCM (Firebase Cloud Messaging), APNs. Cloud hosting: AWS Mumbai region. Analytics: in-house only โ no Google Analytics or third-party trackers. Each processor signs a data-processing agreement restricting use to the documented purpose.
Pre-Toss Prep
Pull the latest squad update 60 minutes before the toss. Confirm playing XI, watch impact-player designation, lock your selections before the deadline.
In-Match Adjust
Substitutions are locked at toss. After that, only your captain multiplier moves โ every run, wicket, and catch updates instantly on the live feed.
Post-Match Review
Check the points statement within 9 minutes of the final ball. Disputes must be raised within 24 hours through customer care with the match-ID reference.
Data Breach Response and Disclosure
How we respond to a breach and what we tell you
In the event of a personal-data breach affecting you, we follow the DPDP Act 2023 framework: contain the breach within 24 hours, assess scope within 72 hours, and notify affected users within 7 days. Notification includes: what data was exposed, what we're doing, what you should do (change password, monitor accounts), and a free credit-monitoring offer via a partner if financial data is involved. We are also required to notify the Data Protection Board of India for breaches above the severity threshold.
Security measures and encryption
Data at rest: AES-256 encryption on all databases and backups. Data in transit: TLS 1.3 enforced on all HTTP traffic, mTLS on internal service-to-service. Access: role-based ACL with least-privilege principle, every admin action logged immutably to a separate audit trail. Quarterly penetration tests by a CREST-accredited firm. Annual SOC 2 audit by an independent auditor. We publish a yearly security report on this site.