Privacy Policy

Your privacy matters to us. This policy explains how we handle your information.

Last updated: April 18, 2026

1. Overview

Sport Pool ("we," "us," or "our") operates the website at sportpool.io (the "Service"). This Privacy Policy describes how we collect, use, and protect your personal information when you use our Service.

By using Sport Pool, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

2. Information We Collect

Account Information

When you create an account, we collect your full name, email address, and username. Your password is securely handled by our authentication provider and is not stored in plain text.

Activity Data

We collect data related to your use of the Service, including your match predictions, pool memberships, scores, leaderboard rankings, and pool settings you configure as an administrator.

Technical Data

We may collect technical information such as your IP address, browser type and version, device information, and user agent string. This data is collected when you accept our Terms of Service and when you interact with certain features of the Service.

Cookies & Analytics Data

We use cookies and similar technologies to keep you signed in and, where enabled, to understand how visitors use the Service. See Section 4 for the full list and purpose of each cookie.

Local Device Storage

To improve your experience, we store a small amount of data in your browser's local storage: your chosen theme (sport-pool-theme), your light/dark color-mode preference (sport-pool-color-mode), and temporary backups of in-progress predictions (predictions_backup_*) so you don't lose work if you go offline or refresh the page. This data lives on your device only and is cleared when you clear your browser data.

User-Generated Content

When you post in a pool's community chat, we store your messages, emoji reactions, pinned messages, @mentions, and transient signals such as typing indicators and online presence. This content is shown to other members of the same pool.

Entry-Fee Tracking

Pool administrators may track whether members have paid an entry fee. If an admin marks your entry as paid, we store a paid/unpaid flag and the date it was recorded. Sport Pool does not process payments, and no card, bank, or payment-processor data is collected or stored. Any actual collection of fees happens outside the Service.

Administrative Logs

When a pool admin or super admin takes an action that affects other users — such as removing a member, adjusting points, updating settings, or moderating chat — we record the action, the administrator, the affected user or entry, and a timestamp, so that actions remain auditable.

Communications

If you contact us through the contact form, we collect the name, email address, and message content you provide. We also store records of email notifications sent to you through the Service.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Create and manage your account
  • Calculate scores, update leaderboards, and process predictions
  • Deliver community features such as pool chat, reactions, and @mentions
  • Send you email notifications about pool activity, prediction deadlines, match results, leaderboard updates, and administrative events, subject to your notification preferences
  • Respond to your contact form inquiries
  • Maintain administrative audit logs so pool and super admin actions remain accountable
  • Improve the Service through analytics and usage patterns (where enabled — see Section 4)
  • Log your acceptance of our Terms of Service for legal compliance
  • Detect and prevent fraud, abuse, or unauthorized access

4. Cookies & Tracking

Essential Cookies

These cookies are required for the Service to function and are always set when you sign in:

  • sb-<project>-auth-token — a signed session token issued by our authentication provider (Supabase) that keeps you signed in across pages. It is marked HttpOnly, Secure, and SameSite=Lax.
  • sb-<project>-auth-token-code-verifier — a short-lived PKCE code verifier used during the sign-in callback. It is removed automatically once you are signed in.

Theme and prediction-draft preferences are stored in your browser's local storage, not in cookies (see Section 2).

Analytics Cookies

The Service may be configured to load Google Tag Manager and Google Analytics to collect anonymous, aggregated usage data (pages visited, time on page, general interaction patterns). When enabled, Google Analytics sets cookies such as _ga, _gid, _gat, and _dc_gtm_*. These cookies do not identify individual users to us.

Analytics are only loaded where we have a lawful basis to do so. We are currently rolling out a cookie consent banner that will let you accept or decline analytics cookies before they are set. Until that banner is live, analytics remain disabled in regions where consent is legally required.

No Advertising or Cross-Site Tracking

We do not use advertising cookies, marketing pixels, or cross-site tracking technologies.

5. Third-Party Services

We use the following third-party services to operate Sport Pool:

  • Supabase — Provides our database and authentication infrastructure. Your account information and activity data are stored securely on Supabase servers.
  • Google Analytics / Google Tag Manager — When enabled, collects anonymous usage analytics to help us understand how the Service is used. Subject to your cookie preferences and local law.
  • Resend — Handles email delivery for notifications, deadline reminders, and contact form messages. We also sync your email address to a Resend audience so that pool admins and Sport Pool can send you broadcast emails to which you are subscribed. Every broadcast email includes a one-click unsubscribe link.
  • Vercel — Hosts the Service. Vercel may collect standard server logs including IP addresses and request data.

Each of these services has their own privacy policies governing how they handle data. We encourage you to review their respective policies.

6. Data Sharing

We do not sell, rent, or trade your personal information to third parties.

We share data only with the third-party service providers listed above, and only as necessary to operate the Service. Within the Service, your username, predictions, and scores are visible to other members of the pools you join. Your email address is not shared with other users.

Messages, reactions, pins, and @mentions you post in a pool's community chat are visible to every member of that pool. Pool admins and Sport Pool super admins may also view chat content for moderation purposes.

We may disclose your information if required by law, legal process, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

7. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. If you delete your account, your personal data will be removed. Some information may be retained in anonymized form for analytical purposes, and certain records (such as terms acceptance logs) may be kept for legal compliance.

Contact form submissions are retained for as long as needed to resolve your inquiry.

8. Your Rights

You have the right to:

  • Access the personal information we hold about you
  • Correct any inaccurate or incomplete information
  • Delete your account and associated data from your profile settings
  • Manage which categories of email notifications you receive from your profile settings
  • Unsubscribe from broadcast emails using the unsubscribe link in any such email

To exercise any of these rights, please contact us. You can also delete your account directly from your profile settings.

9. Children's Privacy

The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us and we will promptly delete that information.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.

We encourage you to review this policy periodically to stay informed about how we protect your information.

11. Contact

If you have any questions about this Privacy Policy or wish to exercise any of the rights described in Section 8, you can email us at privacy@sportpool.io or use our contact form.