FPL Receipts 2026/27

Privacy policy

The short version: your squad lives in your browser, we never see your card, we only have your email if you give it to us, and there are no tracking cookies.

Last updated 9 August 2026 · FPL Receipts is run by Eddie Mackay ("we"), contact fplreceipt@gmail.com


What we hold, and why

Everything, in one table
DataWhere it livesWhy (lawful basis)
Your squad, plans, receipts, draftsYour own browser (localStorage). Nowhere else, unless you create an accountRunning the tool (it doesn't work without somewhere to save)
The same data, syncedSupabase (EU — London), only if you sign inProviding the account you asked for (contract)
Your email addressSupabase, only if you create an account or join the waitlistSigning you in; delivering what you bought (contract)
Marketing consentSupabase, a single yes/no you controlOnly ever sent to if you ticked the box (consent) — unsubscribe is one click
Purchase record (email + what you bought)Stripe or Gumroad, plus one row in SupabaseDelivering Pro and honouring refunds (contract, legal obligation)
Card detailsWe never see them. Payment is handled entirely by Stripe or Gumroad
Anonymous usage countsVercel Analytics, Google Analytics (both cookieless) and our own counters — event names like "visit", never whoKnowing whether features work (legitimate interest)
Public username and shared squadSupabase — only if you choose a username / turn sharing onYou asked us to publish it; turning sharing off deletes it immediately

Cookies

We don't set tracking cookies, which is why there's no cookie banner.

The browser storage we use is functional only: your squad data, and a session token if you sign in. Our analytics (Vercel Analytics, and Google Analytics in its cookieless consent mode — storage denied, so it receives only anonymous aggregate pings and sets no cookies) work without cookies or stored identifiers.

Who processes data for us

Supabase (database and sign-in, hosted in London), Stripe and Gumroad (payments), Resend (sending sign-in links and, with consent, updates), Vercel (hosting and cookieless analytics), Google Analytics (cookieless aggregate usage stats), Upstash (anonymous counters). Each only receives what its job needs. Player and fixture data comes from the official FPL API; nothing about you is sent to it — squad import uses only a public Team ID, never your FPL password.

How long, and your rights

Account data is kept while the account exists. Email us and we'll delete it.

You can ask for a copy of what we hold on you, ask us to correct it, or ask us to delete it — email fplreceipt@gmail.com from the address on the account and we'll do it within 30 days (purchase records may be kept longer where tax law requires). Clearing your browser removes the local copy yourself, and the app's Export button gives you a copy of your data at any time. If you're unhappy with how we've handled something, you have the right to complain to the ICO (ico.org.uk).