Privacy Policy
Stripe holds the email and purchase record needed to provide paid access. If you create an account, we keep the account information needed to sign you in. If you choose Connected Leagues, we also keep the normalized league settings and roster data needed to personalize the product. We keep a limited set of first-party usage events without player, roster, league, email, or access-token data. We do not sell or rent this information, do not hand it to advertisers, and never see your card.
What we collect
- Saved work: when you sign in with an active plan, we sync your Watch list, recent players, comparisons, saved trade scenarios, and draft selections to your account. A separate local cache keeps edits available offline. View filters and league display preferences stay on the device. You can remove saved items; deleting your account data also removes its saved workspace.
- Connected-league data you choose to provide: league scoring and roster settings, teams, rosters, player mappings, draft/transaction/matchup data when available, sync timestamps, recommendations, fixed recommendation feedback, and provider stable IDs. This is stored under your Championship Analytics identity, which may begin as a random browser identity before you sign in.
- Provider authorization: Sleeper, manual import, and ESPN Sync require no provider password. Ordinary ESPN league imports do not read or send ESPN cookies or reusable session values. Phone refresh, when available, requires separate consent as described below.
- Your email address, when you buy, join the pre-registration list, create an account, sign in, or request an account-recovery link. Creating an account does not require payment information.
- Your Championship Analytics username, if you choose one. A normalized version is used as a unique sign-in alias for your account.
- A password verifier, not your password, if you create a password. Your password is processed only long enough to derive a salted, memory-hard scrypt hash. We store the random salt and resulting hash on the server; we do not store or recover the password itself.
- A record of your purchase — which plan, when, and whether it is active. This lives at Stripe.
- Limited first-party usage events — for example, a Draft tool open, a completed Season Comparison, a pricing view, or a Watch action. The event endpoint rejects free-form data and does not receive player names, roster contents, searches, email addresses, passwords, password hashes, or access tokens.
- Tracking exclusions: no cross-site pixels, advertising identifiers, fingerprinting, or analytics session ID. The optional Championship Analytics account session is described below.
What we never see
Your card number. Payment happens on Stripe’s hosted checkout page. Card details are processed by Stripe and are never transmitted to or stored by Championship Analytics.
Your reusable fantasy-provider password. Provider credentials are not part of the Connected Leagues import flow. Your Championship Analytics password is different: it is submitted only to our first-party sign-in endpoint over HTTPS and is immediately checked or converted to a salted scrypt hash; the plaintext password is not stored.
Where your access lives
When you buy, we mint a signed access token and store it in your browser's local storage under ca_pass. It contains your email, your plan, an expiry date, and your Stripe customer id, signed so it cannot be altered. It is not a tracking cookie: it is only ever sent to us when you request the board.
If you sign in to a Championship Analytics account, the server also uses a random session value in a secure, HTTP-only cookie. The server stores only a hash of that session value. Account sessions use secure cookie settings, expire after 180 days of inactivity under the current rolling-session policy, and can be revoked. Resetting your username or password revokes other active account sessions.
Clear your browser storage and the browser-local paid pass disappears. Restore access can mint a fresh one. If you have an account, you can also sign back in with your account credentials or use the verified email recovery flow.
Account and Connected Leagues storage and control
Account and Connected Leagues records are stored by Netlify Blobs with encryption at rest and in transit and strong-consistency reads. Account records can include your email, username, salted password hash and salt, entitlement link, connected-league data, and account audit entries. Provider responses are normalized in memory; we do not keep a separate raw private payload archive.
Password setup and reset use a short-lived, single-use email verification. The verification token expires after 15 minutes. We keep only the server-side records needed to prevent reuse and authorize the short setup window.
You can disconnect a provider, delete one connected league, or delete all connected data from My Leagues. Connected deletion does not cancel Stripe or remove your existing paid-board pass. Clearing browser storage alone can make an anonymous connected identity inaccessible, so use the in-product delete control first if deletion is your intent.
To remember your last league and team between pages, this browser stores their display names, stable ids, and scoring format. It does not store the roster or available-player pool locally, and those details are not included in product analytics.
If you choose ESPN Sync, the optional Chrome extension reads the league and team identifiers, league settings, team and owner display names or identifiers, rostered player names and ESPN identifiers, and draft results visible in your own signed-in ESPN browser session and hands that normalized league data to Championship Analytics. This ordinary import does not read or send your ESPN password, cookies, or session values. The initial handoff is user-triggered, held temporarily in extension-session storage, and deleted after delivery. If you start the Live Draft Companion, the extension checks that open ESPN tab for draft changes and sends normalized league data while the companion remains active. A short-lived Championship Analytics capability scoped to that league is held in extension-session storage for up to eight hours; it is not an ESPN credential and expires automatically.
On ESPN draft pages, a small extension script loads before ESPN opens its live connection so it can observe that connection's status. Pick and undo signals are inspected only after you start the companion and stop when you close it. Only normalized draft information is passed to the companion; raw connection messages, connection URLs, and member identifiers from those messages are not forwarded or stored. The extension does not open a second draft connection or send draft commands. Chrome may request approval for ESPN site access when you install or update the extension.
Optional phone refresh. Where offered, you can separately authorize the extension to send an ESPN session directly to our server. We encrypt it with a separate server-held key and use it only to read the ESPN league you select when you request a refresh. The ESPN session itself is account access, not a league-scoped permission from ESPN. We do not collect your ESPN password or use the session to change your lineup or transactions. The session is not placed in URLs, analytics, ordinary imports, or extension storage. Its use ends at the earlier of the supplied expiration or 90 days; ESPN may invalidate it sooner. Turning off phone refresh, disconnecting the provider, deleting the league, or deleting your account removes the saved session. Initial setup and reconnecting currently require desktop Chrome. This option does not enable unattended roster polling.
Chrome Web Store Limited Use disclosure. Data received through ESPN Sync is used only to provide and improve the connection and the fantasy-football analysis you request. It is never sold, used for personalized advertising, or transferred for credit, lending, or unrelated profiling. A person may access it only with your explicit consent for support, when necessary for security or legal compliance, or after it has been aggregated and de-identified for internal product operations. Championship Analytics' use of information received through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Championship Analytics is not affiliated with or endorsed by ESPN.
Who we share it with
- Stripe — processes payments and holds the customer record. Stripe's privacy policy.
- Netlify — serves this site, runs the first-party account and event endpoints, stores account and Connected Leagues records, and receives standard server logs, including IP addresses. Championship Analytics does not add IP addresses or user agents to its product event records. Netlify's privacy policy.
- Your selected fantasy provider: only when you choose to connect it. Manual import is processed by Championship Analytics. Sleeper uses its documented read-only API without provider authentication. Ordinary ESPN imports use the optional browser extension without collecting credentials. Separately authorized phone refresh is described above.
- Other parties: we do not share data with brokers or ad networks and do not resell analytics.
How long we keep it
Purchase records stay at Stripe as long as tax and accounting law requires. Account records, including an account email, username, and password hash if created, are kept until you ask us to delete the account or until they are otherwise removed under our retention practices. Replacing a password replaces its stored hash; we do not keep the old plaintext password. Pre-registration emails are deleted on request. Usage-event records follow the log retention available in the hosting account; they contain no Championship Analytics account or session identifier to retrieve as a personal activity history.
Connected storage keeps at most eight normalized snapshots and forty sync records per league, one hundred audit entries, and two hundred feedback records per identity. The secure browser session expires after 180 days under the current rolling-session policy. Connected records remain until you disconnect the league or delete them from My Leagues; they are not automatically deleted when a browser session expires.
Your rights
Wherever you live, you can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. If you are in the UK, EU, or California, you may also have those rights by statute. We honor the same requests from every user.
Deleting Connected Leagues data does not delete your Stripe purchase or existing paid-board access. Deleting a Stripe/customer record is a separate request and may be limited by tax and accounting retention duties.
Children
This site is not directed at anyone under 13 and we do not knowingly collect their data.
Contact
Email support@champ-analytics.com, reply to your Stripe receipt, or write to us at the address on it. Data requests are answered within thirty days.