Privacy Policy
Last updated: February 16, 2026
1. Introduction
Drawfetti is operated by AdRific Oy (Business ID: 2811204-7, VAT ID: FI28112047), a company registered in Finland ("we", "our", or "us"). We operate the website drawfetti.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this privacy policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information from Facebook
When you connect your Facebook account, we access the following data through the Meta (Facebook) Graph API, with your explicit permission:
- Your Facebook profile information (name, email, profile picture)
- List of Facebook Pages you manage
- Posts and comments on your managed Facebook Pages
2.2 Account Information
When you create an account, we store your name, email address, and profile picture as provided by Facebook.
2.3 Draw & Participant Data
When you create a giveaway draw, we temporarily store comment data (commenter names, comment text, timestamps) from the selected post to facilitate the draw. This data is used solely for running the draw and displaying results.
2.4 Payment Information
Payment processing is handled by Paddle.com ("Paddle"), who acts as our Merchant of Record. We do not collect, store, or have access to your credit card numbers, banking details, or full payment information. All payment data is collected and processed directly by Paddle in accordance with their Privacy Policy.
From Paddle, we receive and store only:
- Your Paddle customer ID and subscription ID
- Subscription status (active, cancelled, past due, etc.)
- Plan type and billing interval (monthly or annual)
- Transaction history (amounts, dates, currency)
Paddle may collect additional information from you at checkout, including your name, email, billing address, and payment method details. This data is governed by Paddle's Privacy Policy. Paddle also handles all sales tax, VAT, and GST collection and compliance as the Merchant of Record.
3. How We Use Your Information
We use the collected information to:
- Authenticate you and provide access to the Service
- Display your managed Facebook Pages
- Fetch post comments to run giveaway draws
- Generate and display draw results
- Process payments and manage subscriptions (via Paddle)
- Communicate with you about your account or the Service
- Improve and maintain the Service
4. Data Retention
We retain your account data for as long as your account is active. Draw participant data (comments fetched from posts) is retained according to your subscription:
- Free plan: Draw data is retained for 30 days after the draw
- Pro plan: Draw data is retained indefinitely while your subscription is active
You may request deletion of your data at any time (see Section 7).
5. Data Sharing & Disclosure
We do not sell, rent, or share your personal data with third parties for marketing purposes. We may share data only in the following circumstances:
- Public draw results: If you create a shareable results page, the draw winner names and statistics are visible via the shared link
- Payment processor (Paddle): When you subscribe to a paid plan, your account email and subscription details are shared with Paddle to process payments. Paddle acts as the Merchant of Record and independently processes your payment data under their own privacy policy
- Service providers: We use third-party services (Cloudflare for hosting, database providers for data storage) that process data on our behalf under data processing agreements
- Legal requirements: We may disclose data if required by law or to protect our rights
6. Data Security
We take reasonable measures to protect your data, including:
- All data transmitted over HTTPS/TLS encryption
- Facebook access tokens are stored securely and never exposed to the client
- Database access is restricted and password-protected
- Session management via secure, HTTP-only cookies
- Payment data is handled exclusively by Paddle's PCI-DSS compliant infrastructure — we never see or store your card details
7. Your Rights (GDPR)
If you are located in the European Economic Area (EEA), you have the following rights:
- Access: Request a copy of the data we hold about you
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Request your data in a portable format
- Objection: Object to data processing
- Withdraw consent: Revoke Facebook permissions at any time via your Facebook Settings → Apps and Websites
To exercise any of these rights, contact us at privacy@drawfetti.com.
For payment-related data held by Paddle, you may also contact Paddle directly through their Privacy Policy page to exercise your data rights.
8. Facebook Data
Our use of data received from Facebook APIs complies with the Meta Platform Terms and Developer Policies. We only use Facebook data for the stated purpose of running giveaway draws. You can revoke our access at any time through your Facebook Settings.
9. Cookies
We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies. Paddle may set cookies during the checkout process — please refer to Paddle's Privacy Policy for details.
10. Children's Privacy
Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
11. International Data Transfers
Your data may be processed outside your country of residence. AdRific Oy is based in Finland (EU). Paddle, as our payment processor and Merchant of Record, may process payment data in the UK and other jurisdictions. Paddle maintains appropriate safeguards for international data transfers in compliance with applicable data protection laws.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
13. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Privacy: privacy@drawfetti.com
- General: support@drawfetti.com
- Data Controller: AdRific Oy (VAT ID: FI28112047), Finland
- Payment data processor: Paddle.com (Merchant of Record)
