Privacy policy
The short version: your squad lives in your browser, we never see your card, we only have your email if you give it to us, and there are no tracking cookies.
Last updated 9 August 2026 · FPL Receipts is run by Eddie Mackay ("we"), contact fplreceipt@gmail.com
What we hold, and why
| Data | Where it lives | Why (lawful basis) |
|---|---|---|
| Your squad, plans, receipts, drafts | Your own browser (localStorage). Nowhere else, unless you create an account | Running the tool (it doesn't work without somewhere to save) |
| The same data, synced | Supabase (EU — London), only if you sign in | Providing the account you asked for (contract) |
| Your email address | Supabase, only if you create an account or join the waitlist | Signing you in; delivering what you bought (contract) |
| Marketing consent | Supabase, a single yes/no you control | Only ever sent to if you ticked the box (consent) — unsubscribe is one click |
| Purchase record (email + what you bought) | Stripe or Gumroad, plus one row in Supabase | Delivering Pro and honouring refunds (contract, legal obligation) |
| Card details | We never see them. Payment is handled entirely by Stripe or Gumroad | — |
| Anonymous usage counts | Vercel Analytics, Google Analytics (both cookieless) and our own counters — event names like "visit", never who | Knowing whether features work (legitimate interest) |
| Public username and shared squad | Supabase — only if you choose a username / turn sharing on | You asked us to publish it; turning sharing off deletes it immediately |
Cookies
We don't set tracking cookies, which is why there's no cookie banner.
The browser storage we use is functional only: your squad data, and a session token if you sign in. Our analytics (Vercel Analytics, and Google Analytics in its cookieless consent mode — storage denied, so it receives only anonymous aggregate pings and sets no cookies) work without cookies or stored identifiers.
Who processes data for us
Supabase (database and sign-in, hosted in London), Stripe and Gumroad (payments), Resend (sending sign-in links and, with consent, updates), Vercel (hosting and cookieless analytics), Google Analytics (cookieless aggregate usage stats), Upstash (anonymous counters). Each only receives what its job needs. Player and fixture data comes from the official FPL API; nothing about you is sent to it — squad import uses only a public Team ID, never your FPL password.
How long, and your rights
Account data is kept while the account exists. Email us and we'll delete it.
You can ask for a copy of what we hold on you, ask us to correct it, or ask us to delete it — email fplreceipt@gmail.com from the address on the account and we'll do it within 30 days (purchase records may be kept longer where tax law requires). Clearing your browser removes the local copy yourself, and the app's Export button gives you a copy of your data at any time. If you're unhappy with how we've handled something, you have the right to complain to the ICO (ico.org.uk).