Privacy Policy
Who we are
Sales Bingo is a sales-motivation web application operated by Appolo. Throughout this policy, "we", "us" and "the Service" mean Sales Bingo; "you" means a person using it.
For any question about this policy or about your personal data, write to [email protected]. We aim to answer every privacy request within 30 days.
Controller and processor
Sales Bingo is sold to organisations, not to individuals. That distinction decides who is responsible for what.
- Your employer is the data controller. They decide to run the game, they choose the twenty-five goals, they invite the people, and they decide what a credit is worth.
- We are the data processor. We host the Service and process data on your employer's instructions.
- If you are an administrator setting up an organisation yourself, your organisation is the controller and you are acting for it.
If you want your data corrected or deleted and you use Sales Bingo through your employer, ask your administrator first — they control the account. If they cannot help, write to us at [email protected] and we will act on the controller's instruction.
What we collect
We collect the minimum the game needs to work. Nothing else.
| Category | Fields | Where it comes from |
|---|---|---|
| Identity | Name, email address, profile picture URL, country, region, solution areas, role | You, your administrator, or your Google or Microsoft account when you sign in with it |
| Authentication | A password hash (bcrypt), a Google or Microsoft account identifier, email-verification and password-reset tokens | You or your identity provider |
| Game activity | Which squares you banked and when, verification status and reviewer notes, credits earned and redeemed, teams, duels, activity-feed entries | Generated as you use the Service |
| Commercial evidence | Client name, deal or job code, deal value and currency, the person you met, your note | Entered by you when you bank a square |
| Administration | Audit log of role changes, verifications, exports and card edits; IP address recorded against those actions | Generated by administrator and controller actions |
| Billing | Organisation name, plan, seat count, payment status and payment identifiers | Your administrator and our payment processor |
We do not collect special category data — nothing about health, beliefs, ethnicity, political opinion, trade-union membership, biometrics or sexual orientation. Please do not enter any of it into a free-text field. We never ask for card numbers: payment details go directly to our payment processor and never touch our servers.
Why we process it
Our lawful basis is the contract between us and your organisation, and our legitimate interest in running a secure and functioning service.
- To run the game — build your card, count points, rank leaderboards, award credits.
- To verify entries — a nominated controller checks what you submitted against real commercial evidence.
- To send the daily summary — one email a day while a season is running. You can switch it off in your profile at any time.
- To keep the Service secure — rate limiting, abuse prevention and an audit log of administrative actions.
- To bill your organisation — seat counts and payment status.
This is recognition, not performance management. Sales Bingo is deliberately built so that its data does not flow into HR, payroll or appraisal systems, and we do not use your game data to profile you or to make any automated decision that affects you.
How we protect it
- Commercial evidence is encrypted at rest. Client names, deal codes and deal values are encrypted with AES-256-GCM before they are written to the database, and are decrypted only for a controller or an administrator. If the encryption key is not configured, the Service refuses to accept those fields rather than storing them in the clear.
- Everything is behind authentication. There is no anonymous access to any organisation's data, and every endpoint checks authorisation on every request.
- Passwords are hashed with bcrypt and are never stored or logged in readable form.
- Roles are re-read from the database on every request, so a revoked permission takes effect on the next click rather than when a session expires.
- Country scoping is enforced on the server. A controller sees only their own market's submissions, in the interface and in every export.
- Administrative actions are logged — who verified, rejected, changed a role, or ran an export.
- Data is encrypted in transit with TLS.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to you, we will notify the controller without undue delay and within 72 hours of becoming aware of it.
How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While your account is active, then 90 days after your organisation deletes it |
| Commercial evidence (client, code, value) | Until the end of the season plus 12 months, or sooner if your organisation purges it |
| Scores, credits and leaderboards | Kept as an archive of the season; can be anonymised on request |
| Audit log | 24 months |
| Billing records | As required by tax and accounting law, typically 7 years |
| Password reset and verification tokens | 1 hour and 14 days respectively |
Sales Bingo is designed to run as a fixed-term campaign. We encourage every organisation to agree a purge date for raw commercial evidence when the season closes, keeping only the archived leaderboard.
Your rights
If you are in the European Economic Area or the United Kingdom, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing, and to receive it in a portable format.
- You can see and correct your own profile in the app at any time.
- You can see every entry you have submitted and every credit you have earned.
- You can switch off the daily email from your profile.
- For anything else, contact your administrator, or write to [email protected].
You also have the right to lodge a complaint with your local supervisory authority. In Portugal, that is the Comissão Nacional de Proteção de Dados (CNPD).
International transfers
Our infrastructure may process data outside your country. Where data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses or on an adequacy decision. Your organisation can ask us about data residency options as part of an Enterprise agreement.
Children
Sales Bingo is a workplace tool. It is not directed at anyone under 16 and we do not knowingly collect data from children. If you believe a child has an account, write to [email protected] and we will remove it.
Changes and contact
We will update this policy when the Service changes. The version and date at the top of this page always tell you which text is current. If a change materially affects how we handle your data, we will notify the controller before it takes effect.
Questions, requests and complaints: [email protected].