Privacy Policy

Last updated 6 September 2026 · Championship Analytics · champ-analytics.com

Stripe holds the email and purchase record needed to provide paid access. If you create an account, we keep the account information needed to sign you in. If you choose Connected Leagues, we also keep the normalized league settings and roster data needed to personalize the product. We keep a limited set of first-party usage events without player, roster, league, email, or access-token data. We do not sell or rent this information, do not hand it to advertisers, and never see your card.

What we collect

What we never see

Your card number. Payment happens on Stripe’s hosted checkout page. Card details are processed by Stripe and are never transmitted to or stored by Championship Analytics.

Your reusable fantasy-provider password. Provider credentials are not part of the Connected Leagues import flow. Your Championship Analytics password is different: it is submitted only to our first-party sign-in endpoint over HTTPS and is immediately checked or converted to a salted scrypt hash; the plaintext password is not stored.

Where your access lives

When you buy, we mint a signed access token and store it in your browser's local storage under ca_pass. It contains your email, your plan, an expiry date, and your Stripe customer id, signed so it cannot be altered. It is not a tracking cookie: it is only ever sent to us when you request the board.

If you sign in to a Championship Analytics account, the server also uses a random session value in a secure, HTTP-only cookie. The server stores only a hash of that session value. Account sessions use secure cookie settings, expire after 180 days of inactivity under the current rolling-session policy, and can be revoked. Resetting your username or password revokes other active account sessions.

Clear your browser storage and the browser-local paid pass disappears. Restore access can mint a fresh one. If you have an account, you can also sign back in with your account credentials or use the verified email recovery flow.

Account and Connected Leagues storage and control

Account and Connected Leagues records are stored by Netlify Blobs with encryption at rest and in transit and strong-consistency reads. Account records can include your email, username, salted password hash and salt, entitlement link, connected-league data, and account audit entries. Provider responses are normalized in memory; we do not keep a separate raw private payload archive.

Password setup and reset use a short-lived, single-use email verification. The verification token expires after 15 minutes. We keep only the server-side records needed to prevent reuse and authorize the short setup window.

You can disconnect a provider, delete one connected league, or delete all connected data from My Leagues. Connected deletion does not cancel Stripe or remove your existing paid-board pass. Clearing browser storage alone can make an anonymous connected identity inaccessible, so use the in-product delete control first if deletion is your intent.

To remember your last league and team between pages, this browser stores their display names, stable ids, and scoring format. It does not store the roster or available-player pool locally, and those details are not included in product analytics.

If you choose ESPN Sync, the optional Chrome extension reads the league and team identifiers, league settings, team and owner display names or identifiers, rostered player names and ESPN identifiers, and draft results visible in your own signed-in ESPN browser session and hands that normalized league data to Championship Analytics. This ordinary import does not read or send your ESPN password, cookies, or session values. The initial handoff is user-triggered, held temporarily in extension-session storage, and deleted after delivery. If you start the Live Draft Companion, the extension checks that open ESPN tab for draft changes and sends normalized league data while the companion remains active. A short-lived Championship Analytics capability scoped to that league is held in extension-session storage for up to eight hours; it is not an ESPN credential and expires automatically.

On ESPN draft pages, a small extension script loads before ESPN opens its live connection so it can observe that connection's status. Pick and undo signals are inspected only after you start the companion and stop when you close it. Only normalized draft information is passed to the companion; raw connection messages, connection URLs, and member identifiers from those messages are not forwarded or stored. The extension does not open a second draft connection or send draft commands. Chrome may request approval for ESPN site access when you install or update the extension.

Optional phone refresh. Where offered, you can separately authorize the extension to send an ESPN session directly to our server. We encrypt it with a separate server-held key and use it only to read the ESPN league you select when you request a refresh. The ESPN session itself is account access, not a league-scoped permission from ESPN. We do not collect your ESPN password or use the session to change your lineup or transactions. The session is not placed in URLs, analytics, ordinary imports, or extension storage. Its use ends at the earlier of the supplied expiration or 90 days; ESPN may invalidate it sooner. Turning off phone refresh, disconnecting the provider, deleting the league, or deleting your account removes the saved session. Initial setup and reconnecting currently require desktop Chrome. This option does not enable unattended roster polling.

Chrome Web Store Limited Use disclosure. Data received through ESPN Sync is used only to provide and improve the connection and the fantasy-football analysis you request. It is never sold, used for personalized advertising, or transferred for credit, lending, or unrelated profiling. A person may access it only with your explicit consent for support, when necessary for security or legal compliance, or after it has been aggregated and de-identified for internal product operations. Championship Analytics' use of information received through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Championship Analytics is not affiliated with or endorsed by ESPN.

Who we share it with

How long we keep it

Purchase records stay at Stripe as long as tax and accounting law requires. Account records, including an account email, username, and password hash if created, are kept until you ask us to delete the account or until they are otherwise removed under our retention practices. Replacing a password replaces its stored hash; we do not keep the old plaintext password. Pre-registration emails are deleted on request. Usage-event records follow the log retention available in the hosting account; they contain no Championship Analytics account or session identifier to retrieve as a personal activity history.

Connected storage keeps at most eight normalized snapshots and forty sync records per league, one hundred audit entries, and two hundred feedback records per identity. The secure browser session expires after 180 days under the current rolling-session policy. Connected records remain until you disconnect the league or delete them from My Leagues; they are not automatically deleted when a browser session expires.

Your rights

Wherever you live, you can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. If you are in the UK, EU, or California, you may also have those rights by statute. We honor the same requests from every user.

Deleting Connected Leagues data does not delete your Stripe purchase or existing paid-board access. Deleting a Stripe/customer record is a separate request and may be limited by tax and accounting retention duties.

Children

This site is not directed at anyone under 13 and we do not knowingly collect their data.

Contact

Email support@champ-analytics.com, reply to your Stripe receipt, or write to us at the address on it. Data requests are answered within thirty days.