Privacy Policy
Stripe holds the email and purchase record needed to provide paid access. If you choose Connected Leagues, we also keep the normalized league settings and roster data needed to personalize the product. We keep a limited set of first-party usage events without player, roster, league, email, or access-token data. We do not sell or rent this information, do not hand it to advertisers, and never see your card.
What we collect
- Connected-league data you choose to provide: league scoring and roster settings, teams, rosters, player mappings, draft/transaction/matchup data when available, sync timestamps, recommendations, fixed recommendation feedback, and provider stable IDs. This is stored under a random browser identity.
- Provider authorization: Sleeper, manual import, and ESPN Sync require no provider password. ESPN Sync never reads or sends ESPN cookies or reusable session values.
- Your email address, when you buy, join the pre-registration list, or create an account through email sign-in. Creating an account does not require payment information.
- A record of your purchase — which plan, when, and whether it is active. This lives at Stripe.
- Limited first-party usage events — for example, a Draft tool open, a completed Season Comparison, a pricing view, or a Watch action. The event endpoint rejects free-form data and does not receive player names, roster contents, searches, email addresses, or access tokens.
- Tracking exclusions: no cross-site pixels, advertising identifiers, fingerprinting, or analytics session ID. The optional Connected Leagues session is described below.
What we never see
Your card number. Payment happens on Stripe’s hosted checkout page. Card details are processed by Stripe and are never transmitted to or stored by Championship Analytics.
Where your access lives
When you buy, we mint a signed access token and store it in your browser's local storage under ca_pass. It contains your email, your plan, an expiry date, and your Stripe customer id, signed so it cannot be altered. It is not a tracking cookie: it is only ever sent to us when you request the board.
Clear your browser storage and it disappears. That is the only copy on your device. Restore access mints a fresh one.
Connected Leagues storage and control
Connected Leagues uses a random session in a secure, HTTP-only cookie. The server stores only a hash of that session key. Normalized connected data is stored by Netlify Blobs with encryption at rest and in transit and strong-consistency reads. Provider responses are normalized in memory; we do not keep a separate raw private payload archive.
You can disconnect a provider, delete one connected league, or delete all connected data from My Leagues. Connected deletion does not cancel Stripe or remove your existing paid-board pass. Clearing browser storage alone can make an anonymous connected identity inaccessible, so use the in-product delete control first if deletion is your intent.
To remember your last league and team between pages, this browser stores their display names, stable ids, and scoring format. It does not store the roster or available-player pool locally, and those details are not included in product analytics.
If you choose ESPN Sync, the optional Chrome extension reads the league and team identifiers, league settings, team and owner display names or identifiers, rostered player names and ESPN identifiers, and draft results visible in your own signed-in ESPN browser session and hands that normalized league data to Championship Analytics. It never reads or sends your ESPN password, cookies, or session values. The handoff is user-triggered, held temporarily in extension-session storage, deleted after delivery, and must be run again whenever you want updated ESPN data.
Chrome Web Store Limited Use disclosure. Data received through ESPN Sync is used only to provide and improve the connection and the fantasy-football analysis you request. It is never sold, used for personalized advertising, or transferred for credit, lending, or unrelated profiling. A person may access it only with your explicit consent for support, when necessary for security or legal compliance, or after it has been aggregated and de-identified for internal product operations. Championship Analytics' use of information received through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Championship Analytics is not affiliated with or endorsed by ESPN.
Who we share it with
- Stripe — processes payments and holds the customer record. Stripe's privacy policy.
- Netlify — serves this site, runs the first-party event endpoint, and receives standard server logs, including IP addresses. Championship Analytics does not add IP addresses or user agents to its product event records. Netlify's privacy policy.
- Your selected fantasy provider: only when you choose to connect it. Manual import is processed by Championship Analytics. Sleeper uses its documented read-only API without provider authentication. ESPN Sync uses the optional user-triggered browser extension described above and stores no ESPN credential.
- Other parties: we do not share data with brokers or ad networks and do not resell analytics.
How long we keep it
Purchase records stay at Stripe as long as tax and accounting law requires. An account email is kept until you ask us to delete it. Pre-registration emails are deleted on request. Usage-event records follow the log retention available in the hosting account; they contain no Championship Analytics account or session identifier to retrieve as a personal activity history.
Connected storage keeps at most eight normalized snapshots and forty sync records per league, one hundred audit entries, and two hundred feedback records per identity. The secure browser session expires after 180 days. Connected records remain until you disconnect the league or delete them from My Leagues; they are not automatically deleted when the browser session expires.
Your rights
Wherever you live, you can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. If you are in the UK, EU, or California, you may also have those rights by statute. We honor the same requests from every user.
Deleting Connected Leagues data does not delete your Stripe purchase or existing paid-board access. Deleting a Stripe/customer record is a separate request and may be limited by tax and accounting retention duties.
Children
This site is not directed at anyone under 13 and we do not knowingly collect their data.
Contact
Email support@champ-analytics.com, reply to your Stripe receipt, or write to us at the address on it. Data requests are answered within thirty days.