Your privacy matters to us. This policy explains how we handle your information.
Last updated: September 7, 2026
SportPool ("we," "us," or "our") operates the website at sportpool.io and the SportPool mobile apps for iOS and Android (together, the "Service"). This Privacy Policy describes how we collect, use, and protect your personal information when you use our Service.
SportPool is a social prediction platform. You join or create a pool built around a competition — a tournament such as the FIFA World Cup, or a league season such as the Premier League — and make predictions that are scored against real results. Different pools run different games (Pick'em, Predict the Table, Last Man Standing, and Showdown head-to-head duels), and the information we hold about you depends in part on which of them you play.
By using SportPool, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
When you create an account, we collect your full name, email address, and username. Your password is securely handled by our authentication provider and is not stored in plain text.
We collect data related to your use of the Service. Depending on the pools you join, this includes:
Pools can be upgraded to a paid tier. Checkout is handled entirely by Paddle, which acts as the merchant of record and is the legal seller of the transaction. You are sent to Paddle's hosted checkout to pay, and your card, bank, and billing details are entered on Paddle's systems, not ours.
We never see, receive, or store your card number, CVV, or bank details. What we do store is a record of the purchase: the Paddle transaction and customer identifiers, the price identifier and tier purchased, the amount and currency, the pool it applied to, the account that bought it, and the date. We use that record to unlock the tier, to support you if something goes wrong, and to keep accurate financial records.
Paddle's own handling of your payment data is governed by Paddle's privacy policy. See our Refund Policy for how purchases and refunds work.
Separately from any purchase made through SportPool, pool administrators may track whether members have paid an entry fee to that pool. If an admin marks your entry as paid, we store a paid/unpaid flag and the date it was recorded. SportPool does not collect, process, or hold entry fees, prize money, or payouts, and no card, bank, or payment-processor data is collected or stored for them. Any actual collection of those fees happens between you and your pool administrator, outside the Service.
We may collect technical information such as your IP address, browser type and version, device information, and user agent string. This data is collected when you accept our Terms of Service and when you interact with certain features of the Service.
We use cookies and similar technologies to keep you signed in and, where enabled, to understand how visitors use the Service. See Section 4 for the full list and purpose of each cookie.
So that pool members can see who is around, we record and keep a short presence record for your account: when you were last seen, whether you are currently active, which pool you are currently viewing, and whether you are on the web or in the mobile app. The mobile app updates this roughly every 25 seconds while it is open on screen, and marks you inactive as soon as it is backgrounded. Other members of a pool you share can see that you are online and in that pool. Typing indicators are transmitted live to the members of the pool you are typing in and are not stored.
On the web, we store a small amount of data in your browser's local storage: your light/dark color-mode preference (sport-pool-color-mode), and temporary backups of in-progress predictions (predictions_backup_*) so you don't lose work if you go offline or refresh the page. This data lives on your device only and is cleared when you clear your browser data.
In the mobile app, your sign-in session is held in your device's secure keystore (Keychain on iOS, Keystore on Android) rather than in ordinary app storage, and the app keeps a local cache of pool, fixture, and leaderboard data so screens load quickly and work briefly offline. Both are removed when you sign out or delete the app.
Every pool has a group chat called Banter. When you take part, we store the text of your messages, who sent them and when, which pool they belong to, any members you @mention, the message you were replying to, emoji reactions and who added them, messages an admin has pinned, and how far through the conversation you have read.
Most Banter messages are not typed. The app posts share cards to the chat on your behalf when something happens worth sharing — a badge or level you have earned, a leaderboard update, or a prediction you chose to share. These are stored like any other message, and alongside the visible card we keep the structured detail behind it: for a badge card, your level, total experience points and the badges themselves; for a prediction card, what you predicted and what actually happened; for a leaderboard card, the standings at that moment, which can include the name of whoever was leading.
Banter messages cannot be edited or deleted — by you, by your pool admin, or by us through the app. Once a message is posted it stays in that pool's history. Please treat anything you send as permanent. You can remove an emoji reaction you added, and deleting your account removes your messages everywhere (see Section 8), but there is no way to take back a single message.
Banter history is visible to whoever is a member of the pool now. Someone who joins the pool later can read everything posted before they arrived. If you leave a pool, you lose access to its chat but the messages you already posted stay there and remain visible to the members who remain.
The mobile app can join a pool by scanning an invite QR code. If you choose that option, the app asks for camera permission and opens a live camera view solely to read the code in frame. No photo or video is captured, saved, or transmitted anywhere — the camera is read in memory, only the invite code is extracted, and the camera session is shut down as soon as you leave the scanner. You can join by typing a code instead and never grant camera access at all, and you can revoke the permission at any time in your device settings.
In Showdown pools you can generate a short video card of a duel — the reveal of who you were drawn against, or the result once it is settled. The card shows both members' display names and the score. Because the point of the card is to be shared outside the app, the rendered video file is stored on a public URL and can be viewed by anyone who has that link, without signing in. Only a member of the pool who is one of the two people in the duel can generate a card, but once generated the file itself is not access-controlled. Please treat these links as public.
When a pool admin or super admin takes an action that affects other users — such as removing a member, adjusting points, updating settings, or moderating chat — we record the action, the administrator, the affected user or entry, and a timestamp, so that actions remain auditable.
If you contact us through the contact form, we collect the name, email address, and message content you provide. We also store records of email notifications sent to you through the Service.
When you use the SportPool mobile app and grant notification permission, your device's operating system issues us a push notification token (an APNs device token on iOS or an Expo push token routed via Firebase Cloud Messaging on Android). We store this token, the platform it was issued for, and your per-category notification preferences so we can deliver pushes about pool activity, prediction deadlines, match results, leaderboard changes, mentions, and badges or level-ups you earn. You can revoke notification permission at any time in your device settings, and you can toggle individual categories off from your profile in the app — in either case we stop sending the affected pushes and remove invalid tokens automatically.
When enabled, the mobile app sends crash reports and error telemetry (stack traces, app version, device model, OS version) to Sentry so we can diagnose and fix bugs. No prediction content or personal pool data is sent to Sentry.
We use the information we collect to:
These cookies are required for the Service to function and are always set when you sign in:
sb-<project>-auth-token — a signed session token issued by our authentication provider (Supabase) that keeps you signed in across pages. It is marked HttpOnly, Secure, and SameSite=Lax.sb-<project>-auth-token-code-verifier — a short-lived PKCE code verifier used during the sign-in callback. It is removed automatically once you are signed in.cookieyes-consent — records the cookie choices you made in our consent banner, so we can honour them and stop asking. It stores a random consent identifier and a yes/no for each category, and nothing else about you.Theme and prediction-draft preferences are stored in your browser's local storage, not in cookies (see Section 2). The mobile app does not use cookies.
On your first visit, a consent banner (provided by CookieYes) asks how you want non-essential cookies handled. You can Accept All, Reject All, or Customise per category. Nothing but the essential cookies above is set until you choose, and rejecting is a single click that is honoured in every region — not only where consent is legally required. You can reopen the banner and change your mind at any time.
We use Google Tag Manager and Google Analytics to collect aggregated usage data (pages visited, time on page, general interaction patterns). These cookies do not identify individual users to us.
The analytics tag loads in a consent-aware mode: until you accept the analytics category, it is denied permission to write or read any cookie, so no _ga, _gid, _gat, or _dc_gtm_* cookie is set and no analytics identifier is stored on your device. Those cookies appear only after you have accepted analytics, and disappear again if you withdraw that consent. Declining analytics does not affect any part of SportPool.
Web fonts are compiled into the Service and served from our own domain. Loading a SportPool page does not make a request to Google Fonts and does not expose your IP address to a font provider.
We do not use advertising cookies, marketing pixels, or cross-site tracking technologies, and we do not serve personalised advertising. Our consent banner lists an advertising category because it is a standard tool covering cookies a site of this kind might use; we set no cookies in it.
We use the following third-party services to operate SportPool:
Each of these services has their own privacy policies governing how they handle data. We encourage you to review their respective policies.
We do not sell, rent, or trade your personal information to third parties.
We share data only with the third-party service providers listed above, and only as necessary to operate the Service.
Within a pool, your username, entries, scores, leaderboard position, form and streak statistics, level and badges, and online presence are visible to the other members of that pool. Your email address is never shared with other users.
Your predictions become visible to other members only once they can no longer be changed. Picks are sealed until the relevant deadline — a match kickoff, a matchweek lock, or a table deadline — and are then shown to the pool. In Showdown pools, the opponent you have been drawn against is likewise hidden from you until the reveal for that matchweek.
Messages, reactions, pins, and @mentions you post in a pool's Banter chat are visible to every member of that pool, including members who join after you posted. They are delivered live to members who have the chat open at the time, and can trigger an email or push notification to the people you mention.
Pool admins and SportPool super admins can read chat content. To be clear about what that does and does not mean: an admin can pin a message, but no one using the app can edit or remove a message once it is sent. If something in a pool's chat needs to come down, please contact us and we will deal with it directly.
Video cards you generate are stored at public URLs and can be viewed by anyone holding the link, including people who are not SportPool members (see Section 2).
We may disclose your information if required by law, legal process, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Our database and authentication infrastructure are hosted in the United States (Supabase, us-east-1). Our other providers operate globally. If you use SportPool from outside the United States, your information will be transferred to and processed in the United States and in other countries where our providers operate, which may have different data protection laws than your own.
We retain your personal information for as long as your account is active or as needed to provide the Service.
When you delete your account, we delete your account record, your pool memberships and entries, all of your predictions and scores across every game mode, your experience points, levels and badges, your Banter messages and reactions, your presence record, your push tokens and notification preferences, your terms-acceptance record, and your sign-in credentials. Deletion is immediate and cannot be undone.
Deleting your account is the only way to remove Banter messages you have posted, and it removes them from every pool at once — they will disappear from the chat history other members see. Leaving a single pool does not remove them.
Two things are kept after deletion. Records of email we have already sent you are retained but stripped of your account identifier. Records of purchases made through Paddle are retained, unlinked from your account, because we are required to keep accurate financial and tax records; Paddle retains its own copy under its own policy.
Video cards already generated and shared remain at their public URLs until we remove them. If you want a card taken down, please contact us.
Contact form submissions are retained for as long as needed to resolve your inquiry. Some information may be retained in anonymized or aggregated form for analytical purposes.
You have the right to:
You can delete your account directly from your profile settings, or see our account deletion page for full instructions. One prerequisite applies: if you are the administrator of a pool, you must first transfer that role to another member, so that deleting your account does not leave their pool without an admin. We will tell you which pools this affects if you try.
To exercise any of the other rights above, please contact us.
The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us and we will promptly delete that information.
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.
We encourage you to review this policy periodically to stay informed about how we protect your information.
If you have any questions about this Privacy Policy or wish to exercise any of the rights described in Section 9, you can email us at privacy@sportpool.io or use our contact form.