Privacy Policy

Effective Date: 4/30/2026

Lucky Reg Pro (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our website and services.

1. Introduction and Scope

This Privacy Policy describes how Lucky Reg Pro, LLC, a Texas limited liability company (“Lucky Reg Pro,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information in connection with the Lucky Reg Pro software platform and associated services.

Lucky Reg Pro is a business-to-business (B2B) SaaS platform. Our direct customers are licensed sweepstakes and gaming Operators (“Clients” or “Operators”). The platform also processes certain data about individuals who register at Operator locations (“players” or “patrons”) as part of the services we provide to Clients.

Important — Role Clarification: Lucky Reg Pro acts as a data processor on behalf of Operators with respect to player data. Operators are the data controllers. Lucky Reg Pro is a controller of Operator business data. This distinction affects rights and obligations under applicable privacy laws and is described further in Section 9.

This policy does not cover the independent data practices of Operators, third-party gaming platforms integrated by Operators, Stripe, or our email service provider. Each of those parties maintains its own privacy policies.

2. Information We Collect

2a. Operator / Client Business Information

When an Operator signs up for Lucky Reg Pro, we collect:

  • Business name, address, phone number, and email address
  • Business type and EIN
  • Primary contact name, phone number, and email address
  • Sweepstakes or gaming license number(s) and state(s) of operation
  • Tax ID information
  • Billing information processed by Stripe (Lucky Reg Pro does not store payment card or bank account data)
  • Platform usage data (feature usage, session data, error logs)

2b. Player Data — Collected at Point of Registration

When a player registers at an Operator location, the Lucky Reg Pro application reads the driver’s license barcode via a connected scanner, parses the data in-process, and stores a defined subset in a local SQLite database (“patrons” table) on hardware at the Operator’s premises:

Field

Source

Purpose

First Name

DAC / DCT

Registration record

Last Name

DAB / DCS

Registration record

Date of Birth

DBB

Registration; age on file

DL Issuing State

License header

Registration record

DL Number

DAQ

Registration record

Phone Number

Entered by patron

Required for account creation; stored in patrons table

Email Address

Entered by patron

Optional; stored in patrons table if provided

Fields parsed in memory only — not retained: Middle name, address, city, ZIP, country, height, eye color, sex/gender (from scan), license issue date, expiration date, and raw barcode string are parsed temporarily for display purposes and are discarded — not written to any database.

2c. Welcome Email

Upon successful registration, the platform sends a configurable welcome email to the patron on behalf of the Operator. The welcome email is sent only if the patron provided an email address at registration — no email is sent when the field is left blank.

3. How We Use Information

3a. Operator Business Data

  • To provide, operate, and improve the Lucky Reg Pro platform
  • To process payments and issue invoices via Stripe
  • To communicate about accounts, updates, and this policy
  • To comply with applicable legal and regulatory obligations

3b. Player Data

  • To populate the Operator’s registration form at point of onboarding
  • To create a local registration record on behalf of the Operator
  • To transmit required fields to third-party gaming platforms configured by the Operator (see Section 4b)
  • To generate a membership card for the player at the Operator’s location

Lucky Reg Pro does not use player data for its own marketing, analytics, profiling, or any purpose beyond service delivery on behalf of Operators.

4. How We Share Information

4a. Stripe

Operator billing data is processed by Stripe, Inc. Lucky Reg Pro does not store payment card or bank account data. See stripe.com/privacy.

4b. Third-Party Gaming Platform Integrations

Where an Operator has configured a third-party integration (such as Fortune2Go, RiverPay, River Sweeps, or similar), the platform transmits a subset of player registration data to that platform via API on behalf of the Operator. Data transmitted may include first/last name, date of birth, DL issuing state, DL number, and phone number, depending on the requirements of the configured platform.

This transmission occurs at the direction of and on behalf of the Operator. The receiving platform’s data practices are governed by its own privacy policy. Lucky Reg Pro is not responsible for data handling by third-party platforms once data is received. Operators are responsible for ensuring these integrations comply with applicable law.

4c. Email Service Provider

Welcome emails are transmitted via Microsoft Outlook using .NET’s built-in SMTP client. Player email addresses used for this purpose are subject to Microsoft’s data handling practices. See microsoft.com/privacy.

4d. No Sale of Data

Lucky Reg Pro does not sell, rent, or trade Operator or player data to any third party for commercial or marketing purposes.

4e. Legal Disclosure

Lucky Reg Pro may disclose information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of Lucky Reg Pro, Clients, or others.

4f. Business Transfers

Lucky Reg Pro does not hold patron data. All patron data collected through the platform is stored locally on hardware at the Operator’s premises and remains the property and responsibility of the Operator. In the event of a merger, acquisition, reorganization, or sale of all or a portion of Lucky Reg Pro’s assets or business, no patron data transfers to any successor entity, because Lucky Reg Pro does not retain or control that data. Operators retain full ownership and custody of patron data at all times, and any obligations with respect to that data in connection with a business transfer remain solely with the Operator. Lucky Reg Pro will provide reasonable advance notice to Operators of any such transaction to the extent it may affect platform availability or service terms.

5. Data Security

Lucky Reg Pro employs reasonable technical and organizational measures to protect Operator data. Player data retained in the local SQLite database is encrypted at rest using SQLCipher with AES-256 encryption. The database resides on hardware at the Operator’s physical location. Operators are responsible for physical and network security of that hardware.

Breach notification: In the event Lucky Reg Pro becomes aware of a security incident affecting the Lucky Reg Pro platform or software that could reasonably impact the confidentiality or integrity of data stored on Operator hardware, Lucky Reg Pro will notify affected Operators without unreasonable delay and no later than 72 hours after Lucky Reg Pro’s determination that such an incident occurred. Lucky Reg Pro’s notification obligation is limited to platform-level incidents within Lucky Reg Pro’s control. Because patron data is stored solely on Operator hardware and Lucky Reg Pro has no remote access to that data, Operators are solely responsible for detecting, investigating, and reporting any breach of locally stored patron data to applicable regulators and affected individuals, as required by applicable law.

6. Data Retention

6a. Operator Business Data

Lucky Reg Pro retains Operator billing and financial records (including invoices, payment history, and tax documentation) for seven (7) years from the date of the transaction, consistent with federal and state tax record retention requirements. Operator account and contact information is retained for the duration of the active subscription and for two (2) years following termination or expiration of the agreement, after which it is deleted or anonymized except where a longer retention period is required by applicable law.

6b. Player Data in Local Database

Player registration records are stored in the local SQLite database on Operator hardware. Lucky Reg Pro does not have remote access to patron data stored on Operator hardware. Retention of patron data is entirely within the Operator’s control. Following termination of platform access, the encrypted database file remains on the Operator’s hardware but becomes inaccessible without an active Lucky Reg Pro subscription, as the encryption keys and application required to read the data are not available. The database file is removed only if the Operator uninstalls the Lucky Reg Pro application. Operators are solely responsible for managing, retaining, and deleting patron data in compliance with all applicable laws, including applicable data privacy and gaming regulations in their jurisdiction.

6c. Third-Party Platform Data

Once player data is transmitted to a third-party gaming platform, that platform’s own retention policies apply. Lucky Reg Pro has no control over data after receipt by a third party.

7. Operator Responsibilities Regarding Player Privacy

Operators using Lucky Reg Pro are responsible for:

  • Providing players with all required notices and disclosures about data collection at the point of registration
  • Obtaining any required consents under applicable law before driver’s license scanning occurs
  • Ensuring their use of Lucky Reg Pro and all third-party integrations complies with all applicable privacy, gaming, and ID data laws in their jurisdictions
  • Maintaining appropriate physical and network security for hardware on which the local database is stored
  • Defining and implementing data retention and deletion practices consistent with applicable law
  • Notifying affected individuals and regulators of any data breach involving locally stored player data, as required by applicable law

8. Multi-State Privacy Law Compliance

Lucky Reg Pro and its Operator customers may be subject to comprehensive consumer privacy laws in multiple states. The table below summarizes the laws Lucky Reg Pro has identified as potentially applicable, along with key obligations. This table is provided for informational purposes and does not constitute legal advice.

[ATTORNEY REVIEW REQUIRED]: The analysis below is a starting framework. Counsel must assess Lucky Reg Pro’s specific obligations as a data processor/service provider under each applicable law, determine which obligations pass through to Operators, and confirm whether any law’s thresholds (revenue, volume, geography) are met by Lucky Reg Pro at current and projected scale.

State

Law

Effective

Applies to Lucky Reg Pro?

Consumer Rights

Key Notes for Lucky Reg Pro

California

CCPA / CPRA

Jan 1, 2020 / Jan 1, 2023

Yes — broad

Access, delete, correct, opt-out of sale/sharing, limit sensitive data use

DL number = sensitive PI; CPRA adds contractor obligations

Virginia

VCDPA

Jan 1, 2023

Yes

Access, delete, correct, portability, opt-out of profiling

No specific ID carve-out; DOB = sensitive data

Colorado

CPA

Jul 1, 2023

Yes

Access, delete, correct, portability, opt-out of profiling/targeted ads

DOB = sensitive; requires data protection assessment

Connecticut

CTDPA

Jul 1, 2023

Yes

Access, delete, correct, portability, opt-out

DOB = sensitive; processor agreement required

Utah

UCPA

Dec 31, 2023

Yes — lighter

Access, delete, portability, opt-out of sale

Lighter obligations; controller-focused

Texas

TDPSA

Jul 1, 2024

Yes

Access, delete, correct, portability, opt-out

DOB = sensitive data; applies to entities conducting business in TX

Montana

MCDPA

Oct 1, 2024

Yes

Access, delete, correct, portability, opt-out

DOB = sensitive data

Oregon

OCPA

Jul 1, 2024

Yes

Access, delete, correct, portability, opt-out

Broad sensitive data definition includes gov-issued ID numbers

Florida

FDBR

Jul 1, 2024

Controllers >$1B only

Access, delete, correct, portability, opt-out

Limited applicability for Lucky Reg Pro at current scale

Delaware

DPDPA

Jan 1, 2025

Yes

Access, delete, correct, portability, opt-out

DOB = sensitive; minor-protective provisions

Iowa

ICDPA

Jan 1, 2025

Yes

Access, delete, portability, opt-out of sale

Lighter framework; processor agreements encouraged

Indiana

INCDPA

Jan 1, 2026

Yes

Access, delete, correct, portability, opt-out

DOB = sensitive data

Tennessee

TIPA

Jul 1, 2025

Yes

Access, delete, correct, portability, opt-out

DOB = sensitive data

New Hampshire

NHPDA

Jan 1, 2025

Yes

Access, delete, correct, portability, opt-out

DOB = sensitive data

New Jersey

NJDPA

Jan 15, 2025

Yes

Access, delete, correct, portability, opt-out

DOB = sensitive; DL number likely sensitive

Kentucky

KCDPA

Jan 1, 2026

Yes

Access, delete, correct, portability, opt-out

DOB = sensitive data

Nebraska

NDPA

Jan 1, 2025

Yes

Access, delete, correct, portability, opt-out

DOB = sensitive; processor agreements required

Maryland

MODPA

Oct 1, 2025

Yes — strict

Access, delete, correct, portability, opt-out; data minimization mandate

One of strictest; sensitive data use minimization required

Minnesota

MHMD / MNCDPA

Jul 31, 2025

Yes

Access, delete, correct, portability, opt-out

Sensitive data includes gov-issued ID; strict processor rules

Illinois

BIPA (740 ILCS 14/)

Oct 3, 2008

Yes — biometric focus

Informed written consent before collection; no sale; retention schedule; destruction policy

DL scanning may trigger if biometric identifiers extracted; significant litigation risk; statutory damages $1,000–$5,000 per violation

Texas

CUBI (Bus. & Comm. §503.001)

2009

Yes — biometric focus

Consent before capture; no sale; reasonable care; destruction within 1 yr of purpose

Overlaps with BIPA for TX operators; DL scan biometric question requires legal analysis

8a. Special Categories: Illinois BIPA and Texas CUBI

Illinois BIPA (740 ILCS 14/): BIPA imposes strict requirements on collection of “biometric identifiers” and “biometric information,” including fingerprints, retina/iris scans, face geometry, voiceprints, and hand geometry. Whether driver’s license scanning constitutes biometric data collection under BIPA depends on the specific technical implementation and whether any biometric identifiers are extracted from the scan. Lucky Reg Pro’s current implementation parses text fields only (name, DOB, DL state/number) from the AAMVA barcode and does not extract biometric identifiers from the license photo or physical features. This must be confirmed by legal counsel.

If BIPA applies, obligations include: informed written consent before collection; a publicly available retention schedule; no sale or profit from biometric data; reasonable care standard; destruction within 3 years or when purpose is fulfilled. Statutory damages range from $1,000 (negligent violation) to $5,000 (intentional/reckless violation) per violation, plus attorney’s fees. BIPA litigation is active and aggressive.

Texas CUBI (Bus. & Comm. Code §503.001): Similar to BIPA but applies to “biometric identifiers” captured or used for commercial purposes. Requires informed consent before capture, prohibits sale, requires reasonable care, and mandates destruction within 1 year of purpose fulfillment or within 1 year of last interaction. Enforced by the Texas AG. Same technical analysis applies as with BIPA — whether DL scanning triggers CUBI depends on whether biometric identifiers are extracted.

8b. California — CCPA / CPRA

The California Consumer Privacy Act (as amended by the California Privacy Rights Act) is the most comprehensive state privacy law and sets the baseline for many others. Key provisions affecting Lucky Reg Pro:

  • DL numbers are expressly defined as sensitive personal information under CCPA/CPRA.
  • Consumers have rights to: know what data is collected, delete data, correct data, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination for exercising rights.
  • Lucky Reg Pro’s role: as a service provider acting on behalf of Operators, Lucky Reg Pro must enter into a CPRA-compliant service provider agreement with each California Operator, limiting Lucky Reg Pro’s use of data to service-related purposes only.
  • Annual privacy notice update required; must maintain records of data processing activities.

8c. Texas — TDPSA

The Texas Data Privacy and Security Act (effective July 1, 2024) applies to entities that conduct business in Texas or produce products or services consumed by Texas residents. Given Lucky Reg Pro’s current deployment in Texas, this law is immediately applicable. Key obligations:

  • Date of birth is classified as sensitive data requiring opt-in consent before processing.
  • Operators must provide a privacy notice at or before point of data collection.
  • Data processing agreements between Lucky Reg Pro and Texas Operators are required.
  • Enforced by the Texas AG with civil penalties. No private right of action (unlike BIPA).

9. Your Rights and How to Exercise Them

9a. Operator Rights

Operators may request access to, correction of, or deletion of their business data by contacting us using the information below. We will respond within 45 days consistent with applicable law.

9b. Player Rights

Because player data is processed by Lucky Reg Pro as a data processor on behalf of Operators, players seeking to exercise privacy rights should contact the Operator at whose location they registered. Lucky Reg Pro will cooperate with Operator requests to access or delete locally stored player data to the extent technically feasible. Note that Lucky Reg Pro does not have remote access to patron data and cannot directly fulfill consumer requests without Operator involvement.

10. Changes to This Policy

Lucky Reg Pro may update this Privacy Policy. Operators will be notified of material changes via email at least 30 days prior to the effective date. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

11. Contact Us

For questions about this Privacy Policy or to exercise your rights:

Lucky Reg Pro, LLC

Email: Legal@LuckyRegPro.com

Phone: (512) 576-4618

Scroll to Top