
What data we collect
Come Sports collects the following data: (1) account data (mobile number, email, name), (2) KYC data (PAN, Aadhaar, address proof — only when required by regulation), (3) transaction data (deposits, withdrawals, contest entries), (4) usage data (app interactions, captain pick selections), (5) location data (country-level only, not GPS).
The data is collected at the signup step, the KYC step, the transaction step, and the app interaction step. The collection points are documented in the app’s privacy dashboard, with the dashboard showing what data is collected at each point.
Sensitive data is collected only when required by regulation, and the sensitive data is encrypted using AES-256 encryption. The encryption is the input that drives the data security, and the security is what separates Come Sports from less-secure fantasy platforms.
How we use your data
Come Sports uses the data to: (1) provide the platform service (account management, contest participation), (2) verify identity (KYC compliance), (3) process payments (deposits, withdrawals), (4) improve the platform (app features, captain pick AI), (5) communicate with you (notifications, support).
The data is not used for: (1) third-party advertising, (2) data sale or rental, (3) any purpose not disclosed in this privacy policy. The non-use commitments are documented in the privacy policy, with the policy being the input that drives the data ethics.

How we protect your data
Come Sports protects data using: (1) AES-256 encryption for data at rest, (2) TLS 1.3 encryption for data in transit, (3) PCI-DSS Level 1 certified payment gateways, (4) ISO 27001 certified data centers, (5) two-factor authentication for account access.
The platform undergoes annual security audits by independent third-party security firms. The audits are the input that drives the security validation, and the validation is what gives players the confidence that their data is safe.
Come Sports maintains a 24/7 security operations centre (SOC) that monitors for suspicious activity and responds to incidents within 15 minutes. The SOC is the input that drives the security incident response, and the response is what protects the platform from data breaches.
Frequently asked questions
What data does Come Sports collect?
Does Come Sports sell player data?
How do I delete my Come Sports account?
Data retention policies on Come Sports
The Come Sports data retention policy follows the Indian Information Technology Act and the SPDI Rules. Personal data is retained for as long as the account is active, with the data deleted within 90 days of account closure. The retention period is the input that drives the platform’s compliance with the Indian privacy laws.
Financial data (deposits, withdrawals, contest entries) is retained for 5 years for tax compliance, in line with the Income Tax Act 1961. The 5-year retention is the input that drives the platform’s ability to respond to tax authority inquiries, and the response capability is what separates Come Sports from less-compliant fantasy platforms.
The Come Sports data sharing and third-party policies
The Come Sports data sharing is limited to: (1) payment gateways for processing deposits and withdrawals, (2) KYC service providers for identity verification, (3) SMS/OTP providers for mobile verification, (4) cloud hosting providers for infrastructure. The 4 third parties are the input that drives the platform’s operations, and the operations are the input that drives the player experience.
Come Sports does not share player data with: (1) advertisers, (2) data brokers, (3) marketing partners, (4) any other third party not directly involved in the platform’s operations. The non-sharing commitments are the input that drives the player trust in the platform.
The third-party data sharing is governed by data processing agreements (DPAs) that comply with the Indian Information Technology Act. The DPAs are the input that drives the platform’s compliance, and the compliance is the input that drives the player trust.
The Come Sports player rights and choices
Players have the right to: (1) access their personal data, (2) correct inaccurate data, (3) request data deletion, (4) opt out of marketing communications, (5) withdraw consent. The 5 rights are the input that drives the platform’s compliance, and the compliance is the input that drives the player trust.
Players can exercise their rights via the in-app privacy dashboard, where they can view, edit, and delete their data. The dashboard is the input that drives the player self-service, and the self-service is the input that drives the rapid exercise of rights.
Players can also email [email protected] to exercise their rights. The email is the input that drives the manual exercise of rights, and the manual exercise is the input that drives the comprehensive coverage of rights.
The Come Sports data security infrastructure
The Come Sports Fantasy data security infrastructure is the input that drives the player data protection, and the protection is the input that drives the player trust in the platform. The infrastructure includes: (1) AES-256 encryption for data at rest, (2) TLS 1.3 encryption for data in transit, (3) PCI-DSS Level 1 payment gateways, (4) ISO 27001 certified data centers.
The platform also maintains a 24/7 security operations centre (SOC) that monitors for suspicious activity. The SOC responds to security incidents within 15 minutes, with the response being the input that drives the platform’s incident handling, and the incident handling is the input that drives the long-term platform resilience.
The platform undergoes annual security audits by independent third-party security firms. The audits are the input that drives the security validation, and the validation is the input that drives the player trust in the platform.
The Come Sports data breach notification policy
The Come Sports Fantasy data breach notification policy is: (1) within 72 hours of a confirmed breach, the platform notifies the affected players, (2) within 72 hours, the platform notifies the relevant Indian authorities, (3) the platform provides a clear explanation of the breach, (4) the platform provides a clear path to resolution. The 4 commitments are the input that drives the platform's compliance, and the compliance is the input that drives the long-term player trust.
The platform has not had a data breach in its 2-year history. The clean record is the input that drives the platform's security reputation, and the reputation is the input that drives the long-term player adoption rate.
In the event of a breach, the platform will: (1) contain the breach, (2) assess the scope, (3) notify the affected players, (4) implement the fix, (5) prevent the future breaches. The 5 steps are the input that drives the platform's incident response, and the response is the input that drives the long-term platform resilience.
The Come Sports data portability rights
Players have the right to request a copy of their personal data in a portable format. The portability right is the input that drives the platform's compliance, and the compliance is the input that drives the long-term player trust.
Players can request a copy of their data via the in-app privacy dashboard. The dashboard provides a downloadable JSON file with all the player's personal data, including: (1) account data, (2) KYC data, (3) transaction data, (4) usage data. The 4 categories are the input that drives the comprehensive data portability, and the comprehensiveness is the input that drives the long-term platform compliance.
The Come Sports privacy compliance certification
The Come Sports Fantasy platform is certified for: (1) ISO 27001 (Information Security Management), (2) PCI-DSS Level 1 (Payment Card Industry Data Security Standard), (3) SOC 2 Type II (Service Organization Control 2). The 3 certifications are the input that drives the platform's compliance, and the compliance is the input that drives the long-term player trust.
The platform is audited annually by independent third-party security firms. The audits are the input that drives the security validation, and the validation is the input that drives the long-term platform value.
The platform maintains a 24/7 security operations centre (SOC) that monitors for suspicious activity and responds to incidents within 15 minutes. The SOC is the input that drives the security incident response, and the response is the input that drives the long-term platform resilience.
The Come Sports privacy controls for parents
The Come Sports Fantasy platform provides privacy controls for parents who want to monitor their children's activity. The controls are the input that drives the family safety, and the safety is the input that drives the long-term platform value.
The parent controls include: (1) view the child's account activity, (2) set deposit limits on the child's account, (3) receive notifications about the child's contest entries, (4) request the child's account suspension. The 4 controls are the input that drives the family safety, and the safety is the input that drives the long-term platform value.
The parent controls are available via the parent's account, with the parent able to manage multiple child accounts from a single dashboard. The unified dashboard is the input that drives the family safety, and the safety is the input that drives the long-term platform value.
The Come Sports privacy education for players
The Come Sports Fantasy platform provides privacy education for players via: (1) in-app privacy tutorials, (2) email newsletters, (3) social media posts, (4) community webinars. The 4 education channels are the input that drives the player awareness, and the awareness is the input that drives the long-term player value.
The privacy education covers: (1) what data is collected, (2) how data is used, (3) player rights, (4) security measures. The 4 topics are the input that drives the comprehensive privacy awareness, and the awareness is the input that drives the long-term platform value.
The Come Sports privacy policy for international players
For international players (when the platform expands in 2026-2027), the privacy policy will be localised to comply with: (1) GDPR for European players, (2) CCPA for California players, (3) PDPA for Singaporean players. The 3 frameworks are the input that drives the international privacy compliance, and the compliance is the input that drives the long-term platform value.
The localisation includes: (1) translated privacy policies, (2) localised data retention policies, (3) regional data processing agreements. The 3 localisations are the input that drives the international player trust, and the trust is the input that drives the long-term platform value.
The Come Sports privacy policy summary
The Come Sports privacy policy summary: data collection (account, KYC, transaction, usage), data usage (platform, verification, payment, improvement, communication), data sharing (limited to 4 third parties), data retention (90 days post-closure, 5 years for financial), player rights (access, correct, delete, opt-out, withdraw). The 5 categories are the input that drives the comprehensive privacy, and the privacy is the input that drives the long-term player value.
The Come Sports privacy policy final notes
The Come Sports privacy policy is reviewed annually with the latest regulations and player feedback. The review is the input that drives the policy improvement, and the improvement is the input that drives the long-term platform value.