Privacy Policy

Your privacy matters. This page explains exactly what data we collect, why, and how we protect it.

Last updated: 7 April 2026

1. Introduction and Operator Identification

This Privacy Policy applies to the website domain.com ("Site"), operated by CricketMatchDay ("we", "us", "our"). CricketMatchDay is an independent sports content website that publishes cricket match previews, statistical analysis, squad assessments and editorial predictions for the Indian Premier League (IPL) and other cricket tournaments. We are NOT a bookmaker, sportsbook, betting exchange or payment processor — our Site contains affiliate links to third-party betting operators, and we earn commission when users click through and register. This policy took effect on 1 January 2024 and was last updated on the date shown above. For all data protection queries, contact us at privacy@domain.com. We are committed to complying with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the Indian Information Technology Act 2000, and the Digital Personal Data Protection Act 2023 (DPDPA).

2. What Personal Data We Collect

A) Data You Provide Directly

When you use our contact form, you provide your name, email address, subject selection and message text. We use this data solely to respond to your enquiry. We do NOT collect payment data, betting account credentials, passwords, identity documents or any financial information. We do NOT have access to your accounts with any third-party betting operator — any data you share with a bookmaker after clicking an affiliate link is governed by that operator's own privacy policy.

B) Data Collected Automatically

IP address: collected by our hosting provider for geo-location (to serve relevant cricket content for your region), DDoS protection and security monitoring. Your IP address is anonymised in analytics within 24 hours.

Browser type and version (User-Agent): collected to optimise how the Site displays on your device. We use this to identify rendering issues and improve layout across Chrome, Safari, Firefox and Edge.

Operating system and device type: collected for responsive design — ensuring match previews render correctly on mobile phones, tablets and desktops.

Pages visited and time spent: collected via analytics to understand which match previews are most read, which teams generate the most interest, and where readers spend the most time. This helps us prioritise coverage of future fixtures.

Referrer URL: tells us where you came from (Google search, social media, direct visit). We use this to understand our traffic sources and improve our search visibility.

Browser language and screen resolution: used for content display and responsive layout optimisation.

C) Cookie Data

We use cookies for essential site functionality, analytics and affiliate tracking. Cookies are small text files stored on your device. For a complete list of every cookie we use, its purpose and duration, see our Cookie Policy.

3. Purposes of Data Processing

Providing and improving the service: we analyse which match previews are read most to improve coverage of future fixtures. If CSK vs MI previews consistently draw 3x more traffic than GT vs PBKS, we allocate more editorial depth to high-demand fixtures.

Analytics and statistics: aggregated visitor data helps us understand audience needs. We use Google Analytics 4 for this purpose. Data is anonymised and cannot identify individual users. We track page views, session duration and bounce rates — never personal identifiers.

Affiliate links: when you click a betting link on our Site, the partner betting operator may set a cookie to track the referral. This is necessary for the affiliate programme to function correctly. The cookie contains only a technical click identifier — not your name, email or personal data. See our Affiliate Disclosure for full details.

Security: we process server logs to protect the Site from malicious attacks, spam, bots and DDoS attempts. Cloudflare processes this data on our behalf.

Communication: if you contact us via the contact form, we use your email to respond to your enquiry and then retain the correspondence for 12 months.

Legal obligations: we may retain certain data as required by applicable law, including tax and accounting regulations.

4. Legal Basis for Processing (GDPR Art. 6)

Consent (Art. 6(1)(a)): for non-essential cookies including analytics and affiliate tracking cookies. You give consent via the cookie banner displayed on your first visit. You can withdraw consent at any time by clearing cookies or adjusting browser settings.

Legitimate interest (Art. 6(1)(f)): for server log analysis, site security, fraud prevention and understanding our audience. Our legitimate interest lies in maintaining a secure, functional website and improving content quality based on usage patterns.

Performance of contract (Art. 6(1)(b)): for processing enquiries submitted through our contact form — responding to your message is the service you requested.

Legal obligation (Art. 6(1)(c)): for data storage required by applicable taxation, accounting or regulatory law.

You may withdraw consent for cookie-based processing at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.

5. Data Sharing with Third Parties

Google Analytics 4 (Google LLC, USA): visitor analytics. Data transfer to the USA is secured by Standard Contractual Clauses (SCC) and the EU-US Data Privacy Framework. Data shared: anonymised IP address, site behaviour, device type, geographic region (country level).

Google Search Console (Google LLC, USA): search visibility analysis. Data shared: search queries that led users to our Site, click-through rates, search positions. This data does not identify individual users.

Betting affiliate networks: referral tracking via affiliate links. When you click through to a betting operator, the affiliate network (or operator's own programme) receives: click event, timestamp, geolocation (country level). The network does NOT receive your name, email or any personal data from us.

Cloudflare (Cloudflare Inc., USA): our hosting and CDN provider. Cloudflare processes server logs including IP addresses and request data for DDoS protection and page delivery. Cloudflare privacy policy: cloudflare.com/privacypolicy.

We do NOT sell personal data to third parties. We do NOT pass data to advertising networks for targeted advertising. We do NOT pass personal data directly to betting operators — operators receive data only if you click through and register on their site independently.

6. International Data Transfers

Some of our processors are located outside the European Economic Area. Google LLC is based in the USA. We protect data in international transfers through Standard Contractual Clauses (SCC) approved by the European Commission and, where applicable, the EU-US Data Privacy Framework. Cloudflare is also US-based and adheres to the same safeguards. You may request a copy of the data protection safeguards we rely on by writing to privacy@domain.com.

7. Data Retention Periods

Contact form data: 12 months from the date of your last communication, then permanently deleted from our systems.

Server logs: 90 days, which is the industry standard for security monitoring and debugging. After 90 days, logs are automatically purged.

Analytics cookies: _ga cookie expires after 2 years; _gid expires after 24 hours. See our Cookie Policy for the full list.

Affiliate tracking cookies: typically 30-90 days depending on the specific affiliate programme. These cookies are set by the betting operator or affiliate network, not by us.

Legally required data: stored for the applicable limitation period under relevant law (typically 3-6 years for tax and accounting purposes).

After the applicable retention period expires, data is either permanently deleted or irreversibly anonymised so that it can no longer be linked to any individual.

8. Your Rights Under GDPR

Right of access (Art. 15): you may request a copy of all personal data we hold about you. We must respond within 30 days of receiving your request.

Right to rectification (Art. 16): if any personal data we hold is inaccurate or incomplete, you may request its correction.

Right to erasure (Art. 17): you may request deletion of all personal data we hold about you — the "right to be forgotten". We will comply unless we have a legal obligation to retain the data.

Right to restriction of processing (Art. 18): you may restrict processing in certain circumstances, for example while we verify the accuracy of your data.

Right to data portability (Art. 20): you may receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV). You may also request that we transmit this data directly to another controller where technically feasible.

Right to object (Art. 21): you may object to processing based on legitimate interest at any time. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.

Right to withdraw consent: where processing is based on consent (e.g. analytics cookies), you may withdraw that consent at any time without affecting the lawfulness of prior processing.

Right to lodge a complaint: you may lodge a complaint with a supervisory authority. For EU users, contact your national data protection authority. For Indian users, the Data Protection Board of India will handle complaints once fully constituted under DPDPA 2023.

To exercise any of these rights, write to privacy@domain.com. We will confirm receipt within 72 hours and process your request within 30 days.

9. Data Security

All connections to our Site are encrypted with SSL/TLS (256-bit encryption) — you can verify this by checking that the URL begins with https://. We apply regular software updates and security patches to our server infrastructure to address known vulnerabilities. Access to any personal data (contact form submissions) is restricted to authorised editorial staff only — no third parties have access to our internal systems. All administrative accounts are protected with two-factor authentication (2FA). We maintain regular encrypted backups of site data stored in a separate geographic location. While no system can guarantee 100% security, we implement all reasonable technical and organisational measures to protect your data.

10. Children's Data

Our Site is intended exclusively for persons aged 18 years or older. We do NOT knowingly collect personal data from children or minors. Our content relates to cricket betting analysis, which is an adult topic — we do not target or market to anyone under 18. If we discover that we have inadvertently collected data from a minor, we will delete it immediately and without delay. If you believe your child has provided us with personal data, please contact us at privacy@domain.com and we will take prompt action.

11. Indian Data Protection

For users in India, we additionally comply with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. These rules require us to implement reasonable security practices for any sensitive personal data we process — in practice, we collect very limited data from Indian users (primarily IP addresses via analytics).

The Digital Personal Data Protection Act, 2023 (DPDPA) has been enacted by the Indian Parliament. We are committed to complying with its provisions as the implementing rules are notified and the Data Protection Board of India becomes operational. We implement reasonable security practices as required under Indian IT law, including encryption, access controls and data minimisation. For data protection queries from Indian users, contact: privacy@domain.com.

12. Changes to This Policy

We reserve the right to update this Privacy Policy as laws change or our data practices evolve. The "Last updated" date is always shown at the top of this page. Substantial changes (new data categories, new third-party processors, new legal bases) will be highlighted with a notification on the Site. Continued use of the Site after an update constitutes acceptance of the updated policy. We recommend periodically reviewing this page.