Skip to content
Footy League 2026 EngineExplore live demo

Privacy Policy

Last updated: September 2026

This Privacy Policy explains how Footy League processes personal data on the apex platform at footyleague.app. Tenant league sites have their own controller-facing policy.

We process personal data under UK GDPR and the Data Protection Act 2018. This operational update covering advertising pixels and conversion APIs should receive external UK privacy review before the tracking master switch is enabled.

Controller and contact

Footy League is the controller for apex marketing, owner accounts, platform subscriptions, referrals, and platform administration. Contact Footy League through the published platform contact route to exercise a privacy right or ask a question.

Information we process

  • Account details, including name, email, authentication identifiers, and account status.
  • League ownership and setup progress needed to provide the service.
  • Stripe customer, subscription, invoice, refund, and dispute identifiers and status. Footy League does not store full card details.
  • First-touch campaign and referral parameters supplied in links.
  • With advertising consent, Google/Meta/TikTok/LinkedIn click and first-party advertising identifiers, conversion actions, event IDs, plan, value, currency, and timestamps.
  • Operational security, diagnostic, and email-delivery records.

We do not place form values, passwords, league names, phone numbers, or sensitive league operational data in advertising events.

Purposes and lawful bases

  • Providing accounts, subscriptions, and owned league sites: contract and steps requested before entering a contract.
  • Security, fraud prevention, service reliability, limited first-touch attribution, and product administration: legitimate interests, balanced against user rights.
  • Optional Google Analytics, advertising pixels, conversion APIs, Sentry, and YouTube media: consent controlled through the cookie banner.
  • Legal, tax, dispute, and regulatory obligations: legal obligation or legitimate interests as applicable.

Advertising consent is separate from analytics consent. Refusing it does not prevent use of Footy League. Signed-in consent is recorded so server-side renewal events stop after withdrawal; absence of a current affirmative record fails closed.

Advertising measurement

When advertising consent is active, Footy League may share conversion data with Google, Meta, TikTok, and LinkedIn. Server conversion matching uses a normalized SHA-256 hash of the owner email rather than the raw email, plus consented click identifiers where available. Hashing reduces direct exposure but remains personal-data processing because providers may match it to their users.

Browser and server conversion copies use a common event or transaction ID for deduplication. Stripe's verified invoice.paid event supplies the authoritative payment amount and invoice ID. Renewals may be sent server-side while consent remains active.

Advertising attribution identifiers stored by Footy League expire after 90 days. Delivery records retain event type, status, provider, timestamps, transaction/event IDs, and sanitized errors for operational audit and retry; they do not contain raw email addresses.

Suppliers and international transfers

Key suppliers include Supabase for authentication/database/server functions, Stripe for subscription billing, Resend for operational email, Sentry for consented error reporting, and Google, Meta, TikTok, and LinkedIn for consented analytics/advertising measurement.

These suppliers may process information outside the UK. We rely on the supplier terms, data-processing agreements, UK-approved transfer mechanisms, and applicable adequacy arrangements appropriate to each relationship. Provider privacy notices explain their independent use of data received through advertising products.

Retention and security

We keep account, subscription, tax, dispute, and security records only as long as needed for the service and applicable obligations. Advertising click identifiers expire after 90 days. Consent is retained until superseded or no longer needed to demonstrate the preference applied.

Access to tracking configuration and delivery health is restricted to the platform administrator. Provider access tokens remain server secrets and are never returned to the browser or stored in the public configuration.

Your rights

Subject to applicable exemptions, UK data-protection rights can include access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You can withdraw optional tracking through Cookie settings. You may complain to the Information Commissioner's Office.

Changes

We may update this policy as the service or provider requirements change. A material optional-tracking change causes the consent banner to ask again.