Privacy
Privacy Policy
This policy explains what data HottestData holds about sweepstakes entrants and about business buyers, where it comes from, who it is shared with, and how anyone can have their details corrected or removed.
Last updated 10 August 2026
1. Who we are
HottestData is a business-to-business data company. We compile and license marketing lead files made up of consumers who entered sweepstakes and lottery-style promotional campaigns and gave express opt-in permission to be contacted by the sponsor and its marketing partners. Some of those records are additionally qualified with luxury purchase history supplied by our networking and distribution partners.
We are the controller of the data we compile and license. Each buyer becomes an independent controller of the records it licenses and of the campaigns it runs with them.
All privacy correspondence is handled by email at hottestdata@proton.me.
2. Consumer data we hold and where it comes from
We do not run consumer-facing sweepstakes ourselves. Records reach us from campaign operators, publishers, networking partners and distribution partners who collected them directly from the consumer. For each record we may hold:
- Identity and contact details: first and last name, email address, postal address, phone number.
- Entry metadata: campaign name and identifier, entry page source URL, submission date and time, IP address at the moment of entry, and the verbatim consent wording that was displayed.
- Self-reported profile answers given on the entry form, such as age bracket, household interests or product preferences.
- Luxury purchase indicators supplied by partners: purchase category, approximate spend band, purchase recency, partner or distribution source and buyer tier. We do not receive or store card numbers, bank details or full transaction records.
- Hygiene and suppression signals: deliverability status, bounce history, unsubscribe and do-not-contact flags, complaint records.
3. Consent as our basis for processing
Consumer records are only accepted into our files where the entry form showed a clear, affirmative opt-in naming the sponsor and its marketing partners and identifying the channels the consumer may be contacted through — typically email, telephone, SMS or postal mail. Consent must be an action the consumer took, never a pre-ticked box or an assumption made from a purchase.
Where our processing is assessed under the UK or EU GDPR, we rely on the consumer's consent for marketing contact and on legitimate interests for the operational parts of running a B2B data business, such as fraud screening, suppression management and record keeping. Purchase history from partners is used only to qualify and segment a record; it never substitutes for the sweepstakes opt-in that permits partner contact.
Consent can be withdrawn at any time. See section 8 for how, and see our consent and compliance standards for the evidence we retain.
4. How we use consumer data
- Verifying that a valid opt-in exists and that the evidence attached to a record is complete.
- Cleaning, de-duplicating and validating files, and removing junk or fraudulent submissions.
- Segmenting records by geography, vertical, campaign, purchase category and buyer tier so buyers receive only the audience they licensed.
- Licensing records to vetted business buyers for lawful direct marketing consistent with the consent given.
- Maintaining suppression, unsubscribe and do-not-contact lists so removed records are not supplied again.
We do not sell consumer data to individuals, and we do not knowingly compile data about children. Records that appear to relate to a minor are removed.
6. Data about buyers and site visitors
If you submit an inquiry form or email us, we hold the details you provide — name, work email, company, phone, and the campaign requirements you describe — so we can respond and keep a record of the commercial relationship. Inquiry submissions are also screened for spam and abuse, which involves a short-lived, hashed record of the connection making the request. We do not use these details for unrelated marketing and we do not sell them.
7. Retention and security
Consumer records and their consent evidence are retained while the record remains commercially usable and consent has not been withdrawn, and thereafter only as long as needed to prove that a lawful opt-in existed at the time of supply. Suppression entries are kept indefinitely by design — that is what stops a removed record from re-entering a file. Buyer correspondence and licensing records are kept for the period required for tax, accounting and dispute purposes.
Access to our files is restricted to the people who need it, transfers are encrypted, and deliveries are issued through expiring links rather than open attachments.
8. Your rights, removal and opt-out
Depending on where you live you may have the right to access the data we hold about you, to have it corrected or deleted, to withdraw consent, to object to or restrict processing, to request a portable copy, and to opt out of the sale or sharing of your personal information. We do not discriminate against anyone who exercises these rights.
To exercise any of them, email hottestdata@proton.me from, or quoting, the email address or phone number concerned and tell us what you want done. We respond within 30 days, and sooner where the law requires it. Removal requests are actioned at source and added to suppression so the record is not supplied again. We may ask for limited additional detail purely to confirm we are acting on the right record.
9. Changes to this policy
We update this policy when our practices or legal obligations change, and revise the date at the top of the page. Material changes will be reflected here before they take effect. This policy is provided for transparency and is not legal advice.
Questions about how your data is handled?
Consumers can request removal and buyers can request our consent evidence pack by email — we reply to every privacy request.
hottestdata@proton.me