Following Personal Data Through a Lolajack Account

Last updated: 28 September 2026
Identify the data category and account event before sending a privacy request. Lolajack’s published information names [email protected] and [email protected] as contact routes and says registration and due diligence can involve identity, address, financial, source-of-funds and device information. A dated, specific request is easier to match to the correct record.

Data begins with registration

A customer supplies identity and contact details to create and operate an account. The profile becomes the reference point for later account and due-diligence checks.
Enter accurate information and update it through the approved route when it changes. Conflicting profile versions can make a rights request or account investigation harder to match.
The registration record should describe one person consistently across contact, payment and verification events.

Address and identity records

The published privacy information includes identity and address data among the categories that may be processed.
When Lolajack requests evidence, follow the stated submission route and provide material that answers the specific request. Avoid sending additional sensitive records through an unconfirmed channel.
Data minimisation starts with relevance: the document should prove the requested point, not expose unrelated information.

Financial and source-of-funds context

Financial and source-of-funds information can form part of due diligence. The published notice does not establish one fixed trigger or universal document list.
Keep transaction records that connect the account action, date and amount. If a request is unclear, ask support what category of evidence is required before sending it.
A precise request and response reduce the risk of repeated submissions containing more information than needed.

Device information

Device data can help operate and protect an online account. Browser sessions on desktop, Android and iOS may therefore form part of the account record.
Use a screen lock, protect the linked email account and sign out on shared devices. If an unfamiliar session appears, contact support with the time and device context.
Device information becomes useful when it can be compared with a clear report from the account holder.

Payment-page context

The public payments page asks for country and currency before displaying deposit and withdrawal views. The signed-in action can generate its own account and financial records.
Confirm the GBP account context and retain transaction confirmations. Do not treat a public logo as evidence that a particular method or condition applied to the account.
The privacy trail should match the actual cashier event rather than an assumption about availability.

Purpose and service use

The notice says account data may be used to provide the service, answer requests, improve products, prevent fraud and harmful behaviour, send marketing, resolve disputes, meet legal duties and protect service security.
When asking why a category was used, identify the event or request involved. General questions can produce general answers; a dated account event gives the privacy team something concrete to trace.
Purpose is easier to examine when the request names the data category and the account process.

Sharing and recipients

A player may want to know whether information was shared and which type of recipient received it. The notice names authorised group personnel, payment and financial providers, service providers, marketing partners, fraud-prevention agencies, game providers, analytics providers, law enforcement and regulatory or licensing authorities among the possible categories.
Address the question to [email protected] and specify the data, period and account event concerned. Ask for the applicable privacy explanation rather than assuming a recipient list.
The answer should come from the controller’s current records, not from an editorial guess.

Retention questions

The notice says personal data is kept while the account is maintained and for the stated purposes. It may be retained longer where legal obligations, including anti-money-laundering requirements, apply. When there is no remaining legal or business need after closure, the notice says data is deleted or anonymised.
Ask which category is retained, for what reason and how the period is determined. A closed account does not by itself prove that every record disappears immediately.
Separating account closure from data retention produces a clearer privacy request.

Rights and identity matching

A rights request must be matched to the correct account without exposing it to another person. The notice lists access, correction, erasure where no compelling reason remains, restriction, transfer, objection, withdrawal of consent and complaint to a supervisory authority.
Use the registered contact route where possible and describe the right or outcome sought. Follow the security instructions supplied in the response.
The request should be broad enough to cover the intended data but specific enough to identify the account and period.

Escalating a privacy concern

The published contacts are [email protected] and [email protected]. The data-protection address is the direct route for a privacy question.
Keep the message you sent, its date and any reference. If the concern began with support, include the earlier case details, so the privacy team can follow the same event.
A complete chronology helps distinguish a privacy issue from an unresolved customer-service question.

Marketing choices and consent

The notice identifies consent as a basis for direct marketing by email, SMS, phone, website or app notification, for personalised offers and for targeted advertising. It also says consent can be withdrawn without affecting processing that was lawful before withdrawal.
A useful request should name the channel to stop and distinguish marketing from messages needed to administer or secure the account. Keep the confirmation, so any later message can be compared with the preference date.

Cookies, security and international transfers

The notice distinguishes strictly necessary cookies from non-essential cookies that require consent. It also describes administrative, technical and physical safeguards while acknowledging that no internet transmission or storage system is completely secure.
For transfers outside the EU or EEA, it refers to adequacy decisions, Standard Contractual Clauses or other recognised safeguards. A person asking about a specific transfer should identify the service and date so the DPO can address the relevant recipient and safeguard.

Build a privacy request that can be answered

Start with one outcome: access to records, correction of a detail, deletion where applicable, restriction, transfer, objection, consent withdrawal or an explanation of sharing. Add the account identifier, relevant date range and data category. Do not attach identity or financial documents until the response explains the secure route and what is needed.
Send a product-account question to [email protected] and a data-protection request to [email protected]. Retain your message, its reference and the response. That compact chronology lets the recipient trace the right, record and account event without guessing what remedy is sought.
If the request concerns several rights, separate them into labelled outcomes rather than one broad complaint. This makes it easier to see which part has been answered, which identity check is still required and whether a later follow-up concerns access, correction or another right.