A random pick nobody can rig.
Everyone in the draw seals a random ticket they can't change. The winning number comes from a public randomness beacon that publishes only after sealing closes — and the beacon round is fixed in the deal before anyone seals, so nobody can pick the entropy last. One winner, a signed certificate, and a draw anyone can re-check.
One private link per person.
The link is the invitation and the only way in. Send each person their own, any way you like. We store only a hash of it, so a lost link cannot be recovered, not even by us.
Each person's browser generates their ticket locally when they seal — it never crosses the network unsealed. Once everyone has sealed and opened, the draw pins itself the moment the beacon round publishes; anyone's open page triggers it, and the result is identical for all.