Flop Fantasy ("we", "the app") is a free fantasy football game run by an individual developer. This page explains exactly what data we collect, why, and what control you have over it. If you have any question, email privacy@flopfantasy.com.
1. Data we collect
We only collect what's strictly needed to make the game work:
- Account identity — your email address, and, if you sign in with Google or Apple, your name and avatar URL. We never see your password.
- Profile — a username (handle) and team name that you choose. You can change either at any time in Settings.
- Game state — the squad you pick each round, your captain / vice, chips played, leagues you join, and the points you score.
- Technical logs — your IP address and User-Agent are recorded by our hosts (Supabase and Vercel) for security and abuse prevention. These logs are auto-deleted after 30 days.
We do not collect: your phone number, location, contacts, payment info, or anything else. We don't run third-party analytics or ad trackers.
2. Why we collect it
- Email — to sign you in and notify you of major changes (e.g. a deadline change or a security incident). We will never send marketing emails.
- Profile — so other players can see who's leading the league.
- Game state — to score your squad and compute league standings.
- Logs — to detect abuse, fix bugs, and keep the service running.
3. How long we keep it
Your account data lives until you delete your account (see §6). Server logs are kept for 30 days then auto-purged. Deleted account data is permanently removed within 14 days of the deletion request, except where law requires us to retain a record (which we don't anticipate for this kind of game).
4. Who we share it with
We share data only with the infrastructure providers that run the app:
- Supabase (database + authentication) — they store your account, squad, and league data on EU servers. They are GDPR-compliant and cover us under their DPA.
- Vercel (web hosting) — serves the site and records traffic logs. GDPR-compliant.
- Google / Apple (sign-in) — only if you choose to use them as your login method. We receive only your email and basic profile.
We never sell your data. We never share it with advertisers. There is no advertiser; this is a hobby project.
5. Cookies and similar technologies
We use a small number of strictly-necessary cookies to keep you signed in (set by Supabase Auth). We don't use cookies for advertising or third-party tracking. Because these cookies are essential to the service, no banner consent is required under EU law.
6. Your rights
Under GDPR (EU), CCPA (California), and most other modern privacy laws, you have the right to:
- Access a copy of your data — Settings → Download my data
- Correct inaccurate data — Settings → edit handle / team name
- Delete your data — Settings → Delete my account
- Object to processing or restrict it — email us at privacy@flopfantasy.com
- Lodge a complaint with your local data-protection authority (e.g. the ICO in the UK, the CNIL in France) if you believe we've handled your data unlawfully.
We respond to all requests within 30 days.
7. Children
Flop Fantasy is not designed for children under 13 (US) or 16 (EU). If you believe a child has signed up, email us and we'll delete the account immediately.
8. Changes to this policy
If we change anything material we will notify you via email and update the "Last updated" date at the top. Continued use after the change means you accept the new policy.
9. Contact
For any privacy question, email privacy@flopfantasy.com. Operator: Mohamed Abdelkader, contactable at the same address.