Last updated June 2026

Privacy Policy.

Who we are

World Cup Draw (worldcupdraw.world) is a sweepstake tool for the FIFA World Cup 2026. It is an independent project - not affiliated with FIFA or any official tournament body.

The site has three features. The free draw runs largely in your browser with no account required, though some draw data is logged server-side (see below). The paid Pro tier lets a group organiser set up a sweepstake, collect participant emails, and give everyone a personal tracking link. The prediction leagues feature lets authenticated users submit match and tournament predictions against their group.

Questions about this policy? Contact us at hello@worldcupdraw.world.

For information about the cookies we use, see our Cookie Policy.

What data we collect

Free draw tier

The free draw does not require an account or login, but an email address is required before running a draw. This email is used to enforce a 45-minute cooldown between redraws and to prevent abuse. Draw data (participant names and team allocations) is stored locally in your browser. When a draw is completed, a background request is sent to our server logging the following data:

  • Draw logYour email address, the participant count, optional group name, participant first names(as entered into the draw tool), and a timestamp are stored in our database (draw_events). Your email is used solely to enforce the draw cooldown and to detect whether you already have a Pro account. This data is not shared with any third party and your email is not used to contact you or for marketing.
  • AnalyticsUsage events including participant names and group name are also sent to Google Analytics 4 and PostHog when a draw is completed, if you have accepted cookies. See our Cookie Policy.
  • FixturesTo show the fixtures page, our server fetches publicly available match data from openfootball. No user data is involved.

Pro tier

When you purchase a Pro sweepstake, we collect and store the following personal data:

  • ChairThe email address you provide at setup and use to sign in. We store this in our database (Supabase) to link you to your sweepstake.
  • ParticipantsThe name and email address of each person in your group, as entered by you. These are stored in our database and used to send draw result emails and personal tracking links. Participant email addresses are not used for any marketing.
  • PaymentPayment is processed by Stripe. We never see or store your card number. Your email address is passed to Stripe at checkout so they can send you a payment receipt. We receive only a payment confirmation (session ID and status) from Stripe to unlock your draw.
  • AccountYour password is stored securely by Supabase Auth (hashed and salted - we cannot read it). Auth sessions are maintained via secure, HTTP-only cookies set by Supabase.

The lawful basis for processing free draw email addresses is legitimate interests - the email is necessary to enforce fair-use limits and prevent abuse of the free tier.

The lawful basis for processing Pro tier personal data is performance of a contract - the data is necessary to deliver the service you have paid for.

Your draw data (free tier)

The draw result (participant names, assigned teams, group name) is saved locally on your device in two ways and can be cleared at any time using the Reset or Clear all buttons in the draw tool, or by clearing your browser storage.

  • localStorageThe draw result, group name, and your email address are saved in your browser's localStorage so they survive a page refresh. You can clear them at any time by clicking Reset or Clear all in the draw tool, or by clearing your browser storage.
  • URL parameterAfter a draw, the result is also encoded into the ?draw= URL parameter. Sharing that URL lets others view the results. The data is decoded entirely in the browser - it is not read or logged by our server.
  • Server-sideYour email address, participant names, group name, and timestamp are stored server-side in our database when a draw completes (see Draw log above). This record persists after you clear your browser storage. To request deletion, email hello@worldcupdraw.world.

When a draw is completed, participant names are included in analytics events sent to Google Analytics 4 and PostHog (if you have accepted cookies).

Pro tier data and retention

All Pro sweepstake data (chair email, participant names and emails, team allocations) is stored in a Supabase database hosted in the EU (West Europe).

We retain Pro sweepstake data for as long as your account exists. You can delete your account at any time from the account menu — this will immediately and permanently remove your account, sweepstake, participants, leagues, and all associated data. Alternatively, email hello@worldcupdraw.world and we will remove it within 30 days.

Participant tracking links use a unique token (a random ID, not tied to any personal identifier). Anyone with the link can view the participant's team allocation and live match results. These links do not require a login.

Resend processes outbound emails on our behalf (draw results, tracking links, match updates). Resend does not use participant email addresses for any purpose other than delivery.

Prediction leagues

The site includes an optional prediction leagues feature where authenticated users can create or join a league, submit match score predictions, bracket predictions, and award predictions. This feature requires an account.

  • ProfileWhen you sign up, a profile is created with your email address (stored by Supabase Auth) and a username you choose. Your username is visible to other members of leagues you join.
  • PredictionsMatch score predictions, bracket picks, and award predictions are stored in our database linked to your user ID and the league you are in. These are visible to other members of the same league for leaderboard purposes.
  • ActivityYour last active timestamp is recorded each time you visit an authenticated page. This is used for internal analytics only and is not shared.

The lawful basis for processing this data is performance of a contract - the data is necessary to run the prediction league service. You can delete your account and all associated predictions at any time via the account menu, or by emailing hello@worldcupdraw.world.

Analytics

We use analytics services to understand how the site is used and to monitor performance. Analytics are only active after you acknowledge our cookie notice. For full details of the cookies these services set, see our Cookie Policy.

  • Google Analytics 4Records pageviews and custom events. When a free draw is completed, the group name and participant names are included in the event payload. Google Privacy Policy →
  • PostHogRecords the same set of events as GA4 and is used for product analytics. Privacy policy →
  • Vercel AnalyticsCookieless, aggregate-only usage analytics. Does not track individuals or use cookies. Privacy policy →
  • Vercel Speed InsightsCollects anonymised Core Web Vitals metrics. No personal data is retained.

Third-party services

  • VercelHosts the site and provides analytics and speed insights. Privacy policy →
  • SupabaseProvides the database and authentication service. Used by both the free draw (to store draw event records) and the Pro tier. Data is hosted in the EU (West Europe). Privacy policy →
  • StripePro tier only. Processes one-off payments. We never receive or store card details. Privacy policy →
  • ResendDelivers transactional emails. For the free draw: a notification to the site owner only. For Pro: draw results and elimination notifications to participants. Privacy policy →
  • Google Tag ManagerManages and loads third-party scripts including Google Analytics. Privacy policy →
  • flagcdn.comFlag images are loaded from flagcdn.com. Your browser makes a direct request to their servers for each flag image.
  • openfootballFixture data is fetched server-side from a public GitHub repository. No user data is involved.

Your rights

Free draw users

When you run a free draw, your email address is stored server-side in our database (see Draw log above). You have the right to request access to or deletion of this data. To do so, email hello@worldcupdraw.world and we will remove your record within 30 days. All other draw data (participant names, team allocations, group name) lives in your browser and can be removed at any time by clearing your browser's local storage or using the Reset / Clear all buttons.

Pro tier users

If you have a Pro account, you have the following rights under UK GDPR:

  • Access - you can request a copy of the personal data we hold about you.
  • Correction - you can ask us to correct inaccurate data.
  • Erasure - you can delete your account instantly via the account menu, or ask us to do it by email. All associated data is removed immediately.
  • Portability - you can ask us to provide your data in a machine-readable format.
  • Objection - you can object to processing in certain circumstances.

To exercise any of these rights, email hello@worldcupdraw.world. We will respond within 30 days. If you are unhappy with our response, you have the right to lodge a complaint with the ICO.

Participant data

If your name and email were added to a Pro sweepstake by a group organiser and you would like them removed, please contact us at hello@worldcupdraw.world and we will remove your record.

Changes to this policy

We may update this policy from time to time. When we do, we will update the date at the top of the page. Continued use of the site after changes constitutes acceptance of the revised policy.