Privacy Policy
Effective Date: 4/30/2026
Lucky Reg Pro (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our website and services.
1. Introduction and Scope
This Privacy Policy describes how Lucky Reg Pro, LLC, a Texas limited liability company (“Lucky Reg Pro,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information in connection with the Lucky Reg Pro software platform and associated services.
Lucky Reg Pro is a business-to-business (B2B) SaaS platform. Our direct customers are licensed sweepstakes and gaming Operators (“Clients” or “Operators”). The platform also processes certain data about individuals who register at Operator locations (“players” or “patrons”) as part of the services we provide to Clients.
Important — Role Clarification: Lucky Reg Pro acts as a data processor on behalf of Operators with respect to player data. Operators are the data controllers. Lucky Reg Pro is a controller of Operator business data. This distinction affects rights and obligations under applicable privacy laws and is described further in Section 9.
This policy does not cover the independent data practices of Operators, third-party gaming platforms integrated by Operators, Stripe, or our email service provider. Each of those parties maintains its own privacy policies.
2. Information We Collect
2a. Operator / Client Business Information
When an Operator signs up for Lucky Reg Pro, we collect:
- Business name, address, phone number, and email address
- Business type and EIN
- Primary contact name, phone number, and email address
- Sweepstakes or gaming license number(s) and state(s) of operation
- Tax ID information
- Billing information processed by Stripe (Lucky Reg Pro does not store payment card or bank account data)
- Platform usage data (feature usage, session data, error logs)
2b. Player Data — Collected at Point of Registration
When a player registers at an Operator location, the Lucky Reg Pro application reads the driver’s license barcode via a connected scanner, parses the data in-process, and stores a defined subset in a local SQLite database (“patrons” table) on hardware at the Operator’s premises:
Field | Source | Purpose |
First Name | DAC / DCT | Registration record |
Last Name | DAB / DCS | Registration record |
Date of Birth | DBB | Registration; age on file |
DL Issuing State | License header | Registration record |
DL Number | DAQ | Registration record |
Phone Number | Entered by patron | Required for account creation; stored in patrons table |
Email Address | Entered by patron | Optional; stored in patrons table if provided |
Fields parsed in memory only — not retained: Middle name, address, city, ZIP, country, height, eye color, sex/gender (from scan), license issue date, expiration date, and raw barcode string are parsed temporarily for display purposes and are discarded — not written to any database.
2c. Welcome Email
Upon successful registration, the platform sends a configurable welcome email to the patron on behalf of the Operator. The welcome email is sent only if the patron provided an email address at registration — no email is sent when the field is left blank.
3. How We Use Information
3a. Operator Business Data
- To provide, operate, and improve the Lucky Reg Pro platform
- To process payments and issue invoices via Stripe
- To communicate about accounts, updates, and this policy
- To comply with applicable legal and regulatory obligations
3b. Player Data
- To populate the Operator’s registration form at point of onboarding
- To create a local registration record on behalf of the Operator
- To transmit required fields to third-party gaming platforms configured by the Operator (see Section 4b)
- To generate a membership card for the player at the Operator’s location
Lucky Reg Pro does not use player data for its own marketing, analytics, profiling, or any purpose beyond service delivery on behalf of Operators.
4. How We Share Information
4a. Stripe
Operator billing data is processed by Stripe, Inc. Lucky Reg Pro does not store payment card or bank account data. See stripe.com/privacy.
4b. Third-Party Gaming Platform Integrations
Where an Operator has configured a third-party integration (such as Fortune2Go, RiverPay, River Sweeps, or similar), the platform transmits a subset of player registration data to that platform via API on behalf of the Operator. Data transmitted may include first/last name, date of birth, DL issuing state, DL number, and phone number, depending on the requirements of the configured platform.
This transmission occurs at the direction of and on behalf of the Operator. The receiving platform’s data practices are governed by its own privacy policy. Lucky Reg Pro is not responsible for data handling by third-party platforms once data is received. Operators are responsible for ensuring these integrations comply with applicable law.
4c. Email Service Provider
Welcome emails are transmitted via Microsoft Outlook using .NET’s built-in SMTP client. Player email addresses used for this purpose are subject to Microsoft’s data handling practices. See microsoft.com/privacy.
4d. No Sale of Data
Lucky Reg Pro does not sell, rent, or trade Operator or player data to any third party for commercial or marketing purposes.
4e. Legal Disclosure
Lucky Reg Pro may disclose information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of Lucky Reg Pro, Clients, or others.
4f. Business Transfers
Lucky Reg Pro does not hold patron data. All patron data collected through the platform is stored locally on hardware at the Operator’s premises and remains the property and responsibility of the Operator. In the event of a merger, acquisition, reorganization, or sale of all or a portion of Lucky Reg Pro’s assets or business, no patron data transfers to any successor entity, because Lucky Reg Pro does not retain or control that data. Operators retain full ownership and custody of patron data at all times, and any obligations with respect to that data in connection with a business transfer remain solely with the Operator. Lucky Reg Pro will provide reasonable advance notice to Operators of any such transaction to the extent it may affect platform availability or service terms.
5. Data Security
Lucky Reg Pro employs reasonable technical and organizational measures to protect Operator data. Player data retained in the local SQLite database is encrypted at rest using SQLCipher with AES-256 encryption. The database resides on hardware at the Operator’s physical location. Operators are responsible for physical and network security of that hardware.
Breach notification: In the event Lucky Reg Pro becomes aware of a security incident affecting the Lucky Reg Pro platform or software that could reasonably impact the confidentiality or integrity of data stored on Operator hardware, Lucky Reg Pro will notify affected Operators without unreasonable delay and no later than 72 hours after Lucky Reg Pro’s determination that such an incident occurred. Lucky Reg Pro’s notification obligation is limited to platform-level incidents within Lucky Reg Pro’s control. Because patron data is stored solely on Operator hardware and Lucky Reg Pro has no remote access to that data, Operators are solely responsible for detecting, investigating, and reporting any breach of locally stored patron data to applicable regulators and affected individuals, as required by applicable law.
6. Data Retention
6a. Operator Business Data
Lucky Reg Pro retains Operator billing and financial records (including invoices, payment history, and tax documentation) for seven (7) years from the date of the transaction, consistent with federal and state tax record retention requirements. Operator account and contact information is retained for the duration of the active subscription and for two (2) years following termination or expiration of the agreement, after which it is deleted or anonymized except where a longer retention period is required by applicable law.
6b. Player Data in Local Database
Player registration records are stored in the local SQLite database on Operator hardware. Lucky Reg Pro does not have remote access to patron data stored on Operator hardware. Retention of patron data is entirely within the Operator’s control. Following termination of platform access, the encrypted database file remains on the Operator’s hardware but becomes inaccessible without an active Lucky Reg Pro subscription, as the encryption keys and application required to read the data are not available. The database file is removed only if the Operator uninstalls the Lucky Reg Pro application. Operators are solely responsible for managing, retaining, and deleting patron data in compliance with all applicable laws, including applicable data privacy and gaming regulations in their jurisdiction.
6c. Third-Party Platform Data
Once player data is transmitted to a third-party gaming platform, that platform’s own retention policies apply. Lucky Reg Pro has no control over data after receipt by a third party.
7. Operator Responsibilities Regarding Player Privacy
Operators using Lucky Reg Pro are responsible for:
- Providing players with all required notices and disclosures about data collection at the point of registration
- Obtaining any required consents under applicable law before driver’s license scanning occurs
- Ensuring their use of Lucky Reg Pro and all third-party integrations complies with all applicable privacy, gaming, and ID data laws in their jurisdictions
- Maintaining appropriate physical and network security for hardware on which the local database is stored
- Defining and implementing data retention and deletion practices consistent with applicable law
- Notifying affected individuals and regulators of any data breach involving locally stored player data, as required by applicable law
8. Multi-State Privacy Law Compliance
Lucky Reg Pro and its Operator customers may be subject to comprehensive consumer privacy laws in multiple states. The table below summarizes the laws Lucky Reg Pro has identified as potentially applicable, along with key obligations. This table is provided for informational purposes and does not constitute legal advice.
[ATTORNEY REVIEW REQUIRED]: The analysis below is a starting framework. Counsel must assess Lucky Reg Pro’s specific obligations as a data processor/service provider under each applicable law, determine which obligations pass through to Operators, and confirm whether any law’s thresholds (revenue, volume, geography) are met by Lucky Reg Pro at current and projected scale.
State | Law | Effective | Applies to Lucky Reg Pro? | Consumer Rights | Key Notes for Lucky Reg Pro |
California | CCPA / CPRA | Jan 1, 2020 / Jan 1, 2023 | Yes — broad | Access, delete, correct, opt-out of sale/sharing, limit sensitive data use | DL number = sensitive PI; CPRA adds contractor obligations |
Virginia | VCDPA | Jan 1, 2023 | Yes | Access, delete, correct, portability, opt-out of profiling | No specific ID carve-out; DOB = sensitive data |
Colorado | CPA | Jul 1, 2023 | Yes | Access, delete, correct, portability, opt-out of profiling/targeted ads | DOB = sensitive; requires data protection assessment |
Connecticut | CTDPA | Jul 1, 2023 | Yes | Access, delete, correct, portability, opt-out | DOB = sensitive; processor agreement required |
Utah | UCPA | Dec 31, 2023 | Yes — lighter | Access, delete, portability, opt-out of sale | Lighter obligations; controller-focused |
Texas | TDPSA | Jul 1, 2024 | Yes | Access, delete, correct, portability, opt-out | DOB = sensitive data; applies to entities conducting business in TX |
Montana | MCDPA | Oct 1, 2024 | Yes | Access, delete, correct, portability, opt-out | DOB = sensitive data |
Oregon | OCPA | Jul 1, 2024 | Yes | Access, delete, correct, portability, opt-out | Broad sensitive data definition includes gov-issued ID numbers |
Florida | FDBR | Jul 1, 2024 | Controllers >$1B only | Access, delete, correct, portability, opt-out | Limited applicability for Lucky Reg Pro at current scale |
Delaware | DPDPA | Jan 1, 2025 | Yes | Access, delete, correct, portability, opt-out | DOB = sensitive; minor-protective provisions |
Iowa | ICDPA | Jan 1, 2025 | Yes | Access, delete, portability, opt-out of sale | Lighter framework; processor agreements encouraged |
Indiana | INCDPA | Jan 1, 2026 | Yes | Access, delete, correct, portability, opt-out | DOB = sensitive data |
Tennessee | TIPA | Jul 1, 2025 | Yes | Access, delete, correct, portability, opt-out | DOB = sensitive data |
New Hampshire | NHPDA | Jan 1, 2025 | Yes | Access, delete, correct, portability, opt-out | DOB = sensitive data |
New Jersey | NJDPA | Jan 15, 2025 | Yes | Access, delete, correct, portability, opt-out | DOB = sensitive; DL number likely sensitive |
Kentucky | KCDPA | Jan 1, 2026 | Yes | Access, delete, correct, portability, opt-out | DOB = sensitive data |
Nebraska | NDPA | Jan 1, 2025 | Yes | Access, delete, correct, portability, opt-out | DOB = sensitive; processor agreements required |
Maryland | MODPA | Oct 1, 2025 | Yes — strict | Access, delete, correct, portability, opt-out; data minimization mandate | One of strictest; sensitive data use minimization required |
Minnesota | MHMD / MNCDPA | Jul 31, 2025 | Yes | Access, delete, correct, portability, opt-out | Sensitive data includes gov-issued ID; strict processor rules |
Illinois | BIPA (740 ILCS 14/) | Oct 3, 2008 | Yes — biometric focus | Informed written consent before collection; no sale; retention schedule; destruction policy | DL scanning may trigger if biometric identifiers extracted; significant litigation risk; statutory damages $1,000–$5,000 per violation |
Texas | CUBI (Bus. & Comm. §503.001) | 2009 | Yes — biometric focus | Consent before capture; no sale; reasonable care; destruction within 1 yr of purpose | Overlaps with BIPA for TX operators; DL scan biometric question requires legal analysis |
8a. Special Categories: Illinois BIPA and Texas CUBI
Illinois BIPA (740 ILCS 14/): BIPA imposes strict requirements on collection of “biometric identifiers” and “biometric information,” including fingerprints, retina/iris scans, face geometry, voiceprints, and hand geometry. Whether driver’s license scanning constitutes biometric data collection under BIPA depends on the specific technical implementation and whether any biometric identifiers are extracted from the scan. Lucky Reg Pro’s current implementation parses text fields only (name, DOB, DL state/number) from the AAMVA barcode and does not extract biometric identifiers from the license photo or physical features. This must be confirmed by legal counsel.
If BIPA applies, obligations include: informed written consent before collection; a publicly available retention schedule; no sale or profit from biometric data; reasonable care standard; destruction within 3 years or when purpose is fulfilled. Statutory damages range from $1,000 (negligent violation) to $5,000 (intentional/reckless violation) per violation, plus attorney’s fees. BIPA litigation is active and aggressive.
Texas CUBI (Bus. & Comm. Code §503.001): Similar to BIPA but applies to “biometric identifiers” captured or used for commercial purposes. Requires informed consent before capture, prohibits sale, requires reasonable care, and mandates destruction within 1 year of purpose fulfillment or within 1 year of last interaction. Enforced by the Texas AG. Same technical analysis applies as with BIPA — whether DL scanning triggers CUBI depends on whether biometric identifiers are extracted.
8b. California — CCPA / CPRA
The California Consumer Privacy Act (as amended by the California Privacy Rights Act) is the most comprehensive state privacy law and sets the baseline for many others. Key provisions affecting Lucky Reg Pro:
- DL numbers are expressly defined as sensitive personal information under CCPA/CPRA.
- Consumers have rights to: know what data is collected, delete data, correct data, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination for exercising rights.
- Lucky Reg Pro’s role: as a service provider acting on behalf of Operators, Lucky Reg Pro must enter into a CPRA-compliant service provider agreement with each California Operator, limiting Lucky Reg Pro’s use of data to service-related purposes only.
- Annual privacy notice update required; must maintain records of data processing activities.
8c. Texas — TDPSA
The Texas Data Privacy and Security Act (effective July 1, 2024) applies to entities that conduct business in Texas or produce products or services consumed by Texas residents. Given Lucky Reg Pro’s current deployment in Texas, this law is immediately applicable. Key obligations:
- Date of birth is classified as sensitive data requiring opt-in consent before processing.
- Operators must provide a privacy notice at or before point of data collection.
- Data processing agreements between Lucky Reg Pro and Texas Operators are required.
- Enforced by the Texas AG with civil penalties. No private right of action (unlike BIPA).
9. Your Rights and How to Exercise Them
9a. Operator Rights
Operators may request access to, correction of, or deletion of their business data by contacting us using the information below. We will respond within 45 days consistent with applicable law.
9b. Player Rights
Because player data is processed by Lucky Reg Pro as a data processor on behalf of Operators, players seeking to exercise privacy rights should contact the Operator at whose location they registered. Lucky Reg Pro will cooperate with Operator requests to access or delete locally stored player data to the extent technically feasible. Note that Lucky Reg Pro does not have remote access to patron data and cannot directly fulfill consumer requests without Operator involvement.
10. Changes to This Policy
Lucky Reg Pro may update this Privacy Policy. Operators will be notified of material changes via email at least 30 days prior to the effective date. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
11. Contact Us
For questions about this Privacy Policy or to exercise your rights:
Lucky Reg Pro, LLC
Email: Legal@LuckyRegPro.com
Phone: (512) 576-4618