Privacy Policy

Last updated: August 25, 2026

This policy describes the system that exists, not an intention. We inventoried what the site actually collects before writing it, and what is here is what is running.

The honest summary: we keep what it takes to sign you in, let you read, and bill you correctly, plus what measures whether an ad worked. We do not sell your data. You can ask us to delete everything, and there is a procedure that genuinely does it.

1. Who we are and what this covers

This policy covers crenas.site and everything we run there: the free content, the paid subscription, the Arena, the personal tracker, our emails, and the Picks add-on.

Product
Coliseum
Business
Crenas
Contact
crenas.coliseum@gmail.com
Website
crenas.site
Charges appear as
COLISEUM CRENAS.SITE
Payments processed by
Stripe

Registered company details are being completed and will be published here as soon as they exist. Until then, crenas.coliseum@gmail.com is the channel for any privacy request, and it is answered.

2. The short version

  • We keep your account details so you can sign in, and your subscription status so the right content unlocks.
  • We record what happens on the site and in our emails, so we can tell what works and fix what breaks.
  • We share data with the companies that run payments, email and ad measurement for us. Section 11 names every one of them and says exactly what each receives.
  • We do not sell your data, and we do not buy lists.
  • You can ask for a copy of your data, or ask us to delete it. Section 15 explains precisely what deletion removes and what survives.

3. Data you give us

  • Account. Email address, a securely hashed password, username and display name. Optionally a bio or avatar.
  • Google sign-in, if you use it. Your Google account identifier, email, name and profile picture.
  • Payment. Handled by Stripe. We receive your email, name, country, and the last digits and brand of your card. We never receive or store the full card number.
  • Lead forms. If you give us your email or phone number on a landing page to receive something, we store what you typed.
  • Telegram, for the add-on. Your Telegram user id, username, first name and interface language, so we can link your account to the private room and remove access when the add-on ends.
  • Anything you write to us, including replies to our emails.

4. Data produced by using the Service

  • Server logs. Our web server records each request with an IP address, a timestamp, the page, and the user agent. From those logs we derive a visitor identifier by hashing the IP address together with the user agent, so we can count how many distinct people arrived from a campaign without keeping a list of IP addresses next to them. That identifier is pseudonymous, not anonymous, and we treat it as personal data.
  • Reading and account activity. Which analyses you opened, when you signed in, what you predicted in the Arena, your points and streaks, and your subscription state over time.
  • A customer timeline. For subscribers, we assemble the events above into one chronological view — signed up, paid, read this, cancelled — so we can answer support questions and understand where the product fails people.
  • Email activity. Whether a message was delivered, bounced, or opened. See section 10.
  • Abuse and integrity signals. A hash of your user agent, IP and language when you comment or vote, the IP address recorded on a poll vote or a failed gate attempt, and checks for repeated sign-ups. These exist to stop spam and stop one person taking a free trial many times.
  • Consent record. When you tick the box before paying, we store which version of the Terms you accepted, when, from which IP address and user agent. That record is what protects both of us if a charge is ever disputed.

5. Data we receive from others

  • Stripe tells us your subscription state, what was charged, whether a card was declined, the country of the card, and the reason you gave if you cancelled through them.
  • Meta tells us, in aggregate, how our ads performed. It does not tell us who you are.
  • Google gives us your basic profile if you chose Google sign-in.
  • Resend tells us what happened to each email we sent you.
  • We also infer a likely country and language from technical signals so the site opens in a language you read. It is a guess, and you can override it.

6. What we use it for

  • Running your account and giving you the access you paid for.
  • Taking payment, renewing your subscription, warning you before a charge, and handling refunds and failed payments.
  • Sending you what your subscription involves: billing notices, account emails, and the editorial emails you signed up for.
  • Measuring which campaigns and pages bring people who actually subscribe.
  • Understanding how the product is used so we can decide what to build and what to fix.
  • Preventing fraud, abuse, repeated free trials and spam.
  • Meeting our legal, tax and accounting obligations.
What we never do

We do not sell your personal data, we do not buy email lists, and we do not use your data to train models that we sell or share.

7. Our legal basis for each purpose

Where the GDPR or UK GDPR applies to you, these are the grounds we rely on:

Account, access, billing
Performance of our contract with you.
Security, fraud and abuse prevention
Our legitimate interest in keeping the Service working and paid for honestly.
Product analytics and measurement
Our legitimate interest in understanding and improving the Service. You can object.
Advertising cookies and ad measurement
Your consent, which you can withdraw at any time.
Marketing emails
Your consent, or our legitimate interest where you are already a customer. Every one carries an unsubscribe link.
Billing notices and service emails
Performance of our contract. These are not marketing and continue even if you unsubscribe from marketing.
Tax and accounting records
Compliance with a legal obligation.

8. Cookies and identifiers

The complete list of what we or our providers set in your browser:

arena_token
Keeps you signed in. Essential. Cleared when you sign out.
NEXT_LOCALE
Remembers whether you read in Portuguese or English. Essential.
coliseum_access
Access to campaign areas. Essential for anyone using those links.
coliseum_owners_pass, coliseum_friends_pass, coliseum_dashboard_pass
Internal, guest and admin gates. Last up to 30 days. Essential for anyone entering through them.
ab_us, ab_vid, ab_preview
Page version testing. Store a variant and a random identifier for up to 90 days so you always see the same version. Switched off since August 24, 2026.
_fbp, _fbc
Set by Meta to measure advertising. These are what connect a visit to an ad click. Advertising, not essential.

You can clear or block cookies in your browser. Blocking the essential ones means you cannot stay signed in. Section 14 explains how to refuse the advertising ones.

9. Advertising and measurement

We advertise on Meta platforms, and we measure whether those ads produce subscribers. That measurement happens in two ways, and the second is the one most policies leave out.

  • In your browser. The Meta Pixel loads on our pages and reports events such as a page view or a checkout being opened, along with the _fbp and _fbc cookies.
  • From our server. We also send the same events directly from our server to Meta. Those messages carry your email address in hashed form, and your IP address and user agent in the clear, so Meta can match the event to an account. We do this so a purchase is counted once and attributed correctly, not to build a profile of you.
  • Attribution. When a subscription is created, we send the order and the buyer details to Utmify to attribute the sale to the campaign that produced it. Section 11 states exactly which fields.
If you are in California

Sharing data with Meta for ad measurement counts as “sharing for cross-context behavioural advertising” under California law, even though no money changes hands. You have the right to opt out. Email crenas.coliseum@gmail.com with the subject “Do Not Share”, or block advertising cookies in your browser, and we will honour it.

10. Email

We send two kinds of email, and the difference matters for what you can turn off.

  • Service and billing emails — a receipt, a renewal notice before a charge, a declined card, a password reset. These are part of the contract and continue for as long as you have an account, whether or not you unsubscribe from marketing. If you want them to stop, close your account.
  • Editorial and marketing emails — every one has an unsubscribe link, and one click is enough.

We record whether you opened an email. Our provider embeds a small invisible image, and when your mail app loads it we record that the message was opened. We use it to see which emails are worth sending and to stop sending a sequence to someone who is clearly not reading it. If you would rather this did not happen, most mail apps have a setting to block remote images, and that setting stops it — or write to us and we will exclude your address.

11. Who we share data with

Every company that receives your personal data from us, and what each one gets:

Stripe
Payments and subscriptions. Receives your email, name and card details. We never see your full card number.
Meta (Facebook, Instagram)
Ad measurement. Receives your email in hashed form, and also your IP address and user agent in the clear, plus the _fbp and _fbc cookie identifiers.
Utmify
Sale-to-campaign attribution. Receives the buyer name, email, phone (when present) and country, along with the order amount.
Resend
Email delivery. Receives your address and reports back what happened to each message, including whether it was opened.
Telegram
Only for Picks add-on subscribers. Receives what is needed to link your account to the private room.
Google
Only if you choose Google sign-in. In that case we receive your Google account identifier, email, name and picture.
Infrastructure
Hosting and database, which store what is described here so the site can run.

We also disclose data where the law requires it, and we would disclose it to a buyer if the business were ever sold — in which case this policy would follow the data, and we would tell you before anything changed.

12. Where your data goes

The providers above operate internationally, so your data is processed outside the country you live in, including in the United States and the European Economic Area. Where the law requires a safeguard for that transfer, we rely on the mechanisms our providers put in place, such as Standard Contractual Clauses and adequacy decisions.

13. How long we keep it

Server logs, which contain IP addresses
14 days, deleted by automatic rotation.
Derived visitor identifiers
90 days from the last visit.
Email delivery and open records
12 months.
Lead details that never became an account
12 months from the last contact, then deleted.
Active account
For as long as the account exists.
Closed or cancelled account
24 months, then the identity is erased as described in section 15.
Consent records
For as long as the subscription lasts, plus 24 months.
Invoices, payments and tax records
5 years, because accounting law requires it. This is the one we cannot delete on request.

14. Your rights

Wherever you live, you can ask us to:

  • give you a copy of the data we hold about you,
  • correct anything that is wrong,
  • delete your data,
  • stop using it for a particular purpose, including advertising measurement,
  • export it in a portable form,
  • stop sending you marketing, which the unsubscribe link also does instantly.

Write to crenas.coliseum@gmail.com from the address on your account. We answer within 30 days, and we do not charge for it. We will not treat you worse for exercising any of these rights.

15. How deletion actually works

Most policies say “you may request deletion” and leave it there. Here is precisely what happens when you ask.

What is erased, and what remains

Erased: everything that points at a person — your email, name, phone number, IP addresses, city, photo, password, Telegram username, and the card fingerprint held against your account.

Kept: everything that points at a number — how much was paid, on which plan, how many days the subscription lasted, how many analyses were read, which campaign it came from, when it was cancelled. None of it carries your identity any more.

The consequence is that our revenue, conversion and churn figures do not move when we erase someone, because those figures never depended on anyone’s name. That is what lets us say yes to a deletion request without argument.

We also ask Stripe to redact its copy. What Stripe must keep for accounting law stays with Stripe under its own retention rules, and we cannot remove it for them.

16. How we protect it

Encrypted connections throughout, passwords stored only as a bcrypt hash and never in a readable form, card data never touching our servers, signed session tokens, and access to the database limited to what runs the Service. No system is perfect, and we will tell you and the relevant authority if a breach ever affects your data.

17. Your rights where you live

European Economic Area and United Kingdom

The rights in section 14 are your GDPR and UK GDPR rights: access, rectification, erasure, restriction, portability, and objection — including an absolute right to object to direct marketing. Where we rely on consent, you can withdraw it at any time without affecting what we did before. You may also complain to your national data protection authority, and in the UK to the Information Commissioner’s Office.

California

You have the right to know what we collect and why, to delete it, to correct it, and to opt out of the sharing described in section 9. We do not sell personal information for money. We do not knowingly collect data from anyone under 16. Exercise any of these by writing to crenas.coliseum@gmail.com, and we will not discriminate against you for it.

Other US states

If your state has a comprehensive privacy law — Virginia, Colorado, Connecticut, Utah, Texas and others — the same requests work, by the same email, and we honour them.

Australia

We handle your personal information consistently with the Australian Privacy Principles. You may ask for access and correction, and complain to the Office of the Australian Information Commissioner if we get it wrong.

Canada

Under PIPEDA you may access and correct your personal information and complain to the Office of the Privacy Commissioner of Canada.

Brazil

Under the LGPD you hold the rights in Article 18: confirmation of processing, access, correction, anonymisation, portability, deletion, information about who we share with, and the right to withdraw consent.

18. Under 18

Coliseum is for adults and you must be 18 to hold an account. We do not knowingly collect data from children. If you believe a minor has given us data, write to crenas.coliseum@gmail.com and we will remove it.

19. Changes and contact

When we add a provider, a cookie, or a new use of your data, this page changes with it. If a change materially affects you we will say so by email or in the product, not only by moving the date at the top.

Privacy questions, or any request in section 14: crenas.coliseum@gmail.com. See also our Terms of Service and Refund and Cancellation Policy.

Coliseum - UFC Fight Analysis & Predictions