Giveaway Control
Last updated 27 September 2026

Your setup and payout information

Optional setup, optional account

You can enter ordinary giveaways in Twitch or Kick chat without creating a Giveaway Control account. Optional setup stores the platform IDs and usernames you authorise, connection dates and the relationship between linked accounts. A registered account additionally stores a username, email, password hash and account/security records.

Twitch and Kick handle their own login and permission screens. Giveaway Control does not ask for your platform password. For viewer identity linking, temporary OAuth credentials are used to identify the authorised account and are not kept as reusable viewer access or refresh tokens. Streamer integrations are separate and may need stored encrypted tokens to operate the connected channel.

Receiving addresses

Public receiving addresses you choose to save are encrypted in application storage and associated with your viewer setup. An address may still reveal financial activity on a public blockchain, so treat it as sensitive. Addresses are not added to standard entrant lists, ordinary reports, public lookup responses or normal application logs.

The organiser of a recorded winner selection can request access to the saved receiving address for the stated asset and network. The viewer must approve that request from their own setup before the address is disclosed. Approval lasts up to 24 hours; the organiser's access token is session-bound and lasts 15 minutes. Changing or removing the address invalidates the old approved address snapshot. Declining a request prevents further access through that request. It cannot remove a copy the organiser already received.

Organisers receive addresses only to arrange the relevant prize. Giveaway Control does not hold funds, send transactions or verify the organiser's manual “paid” record. Database recovery backups may contain encrypted payout records; ordinary giveaway exports do not contain full addresses.

Sessions and security records

Essential secure session cookies maintain login, protect forms and bind guest setup to its browser session. Random, expiring OAuth state values prevent an authorisation callback from being applied to another setup. Security records include event times, account and platform identifiers, rate-limit information and hashed identifiers used to investigate misuse. Payout audit events record what action happened and which asset/network it concerned, not a decrypted wallet address.

Do not share a setup session on a communal browser. Closing a browser may end access to a guest session; saved server information does not automatically disappear when a cookie is lost. Reconnect the original platform account(s) to regain guest access or use an optional Viewer login.

Why information is used

Setup and account information is used to provide requested linking, account management, giveaway identity matching, prize communication and recovery features. Security and limited audit records help protect users and investigate faults or abuse. Optional payout sharing is controlled by the viewer's approval for that specific request. Providing a wallet is not consent to marketing.

Twitch, Kick, the hosting provider, and services connected by the organiser process information necessary for their respective functions under their own terms. The organiser is separately responsible for how they use participant records and information they receive. Our support team may need limited account records to address a genuine request; full wallet addresses are not displayed in routine owner/admin lists.

Keeping and removing information

Linked setup and saved methods are retained so they can be used for future giveaways, until changed or removed or no longer needed to provide the service. You can remove saved payout methods in your setup and disconnect a platform. Disconnecting a platform is not the same as deleting historical giveaway records or closing an account.

Past giveaway, payment-confirmation and security records may need to be retained for resolving disputes, preventing abuse or meeting legal obligations. Restricted recovery backups are separate from live records. Contact the operator for access, correction, deletion, portability or restriction requests, or to ask about retention and the services used with your information. We may ask you to prove control of your account before acting. UK users may also raise a data-protection concern with the Information Commissioner's Office.

Contact

Use the Giveaway Control contact page to reach the operator about your information. Do not include private keys, seeds, passwords or recovery phrases. See also the payout responsibilities and Terms.