Privacy Policy

Your privacy matters to us. This policy explains how we handle your information.

Last updated: September 7, 2026

1. Overview

SportPool ("we," "us," or "our") operates the website at sportpool.io and the SportPool mobile apps for iOS and Android (together, the "Service"). This Privacy Policy describes how we collect, use, and protect your personal information when you use our Service.

SportPool is a social prediction platform. You join or create a pool built around a competition — a tournament such as the FIFA World Cup, or a league season such as the Premier League — and make predictions that are scored against real results. Different pools run different games (Pick'em, Predict the Table, Last Man Standing, and Showdown head-to-head duels), and the information we hold about you depends in part on which of them you play.

By using SportPool, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

2. Information We Collect

Account Information

When you create an account, we collect your full name, email address, and username. Your password is securely handled by our authentication provider and is not stored in plain text.

Activity Data

We collect data related to your use of the Service. Depending on the pools you join, this includes:

  • Your pool memberships, entries, and any pool settings you configure as an administrator
  • Your predictions — match scorelines and bracket picks, predicted final league tables, Last Man Standing club selections, and any other picks a pool's game asks for
  • Your scores, points breakdowns, leaderboard rankings, and weekly movement
  • In Showdown pools, the opponent you were drawn against each matchweek, the result of that duel, and your running head-to-head record
  • In Last Man Standing pools, whether you are still in and the round in which you were eliminated
  • Derived statistics about how you play — your recent form, streaks, hit rate, exact-score count, and how your picks compare with the rest of your pool
  • Experience points, levels, and badges you unlock, and whether you have seen the notification for each

Purchases and Pool Upgrades

Pools can be upgraded to a paid tier. Checkout is handled entirely by Paddle, which acts as the merchant of record and is the legal seller of the transaction. You are sent to Paddle's hosted checkout to pay, and your card, bank, and billing details are entered on Paddle's systems, not ours.

We never see, receive, or store your card number, CVV, or bank details. What we do store is a record of the purchase: the Paddle transaction and customer identifiers, the price identifier and tier purchased, the amount and currency, the pool it applied to, the account that bought it, and the date. We use that record to unlock the tier, to support you if something goes wrong, and to keep accurate financial records.

Paddle's own handling of your payment data is governed by Paddle's privacy policy. See our Refund Policy for how purchases and refunds work.

Entry-Fee Tracking

Separately from any purchase made through SportPool, pool administrators may track whether members have paid an entry fee to that pool. If an admin marks your entry as paid, we store a paid/unpaid flag and the date it was recorded. SportPool does not collect, process, or hold entry fees, prize money, or payouts, and no card, bank, or payment-processor data is collected or stored for them. Any actual collection of those fees happens between you and your pool administrator, outside the Service.

Technical Data

We may collect technical information such as your IP address, browser type and version, device information, and user agent string. This data is collected when you accept our Terms of Service and when you interact with certain features of the Service.

Cookies & Analytics Data

We use cookies and similar technologies to keep you signed in and, where enabled, to understand how visitors use the Service. See Section 4 for the full list and purpose of each cookie.

Presence and Activity Signals

So that pool members can see who is around, we record and keep a short presence record for your account: when you were last seen, whether you are currently active, which pool you are currently viewing, and whether you are on the web or in the mobile app. The mobile app updates this roughly every 25 seconds while it is open on screen, and marks you inactive as soon as it is backgrounded. Other members of a pool you share can see that you are online and in that pool. Typing indicators are transmitted live to the members of the pool you are typing in and are not stored.

Local Device Storage

On the web, we store a small amount of data in your browser's local storage: your light/dark color-mode preference (sport-pool-color-mode), and temporary backups of in-progress predictions (predictions_backup_*) so you don't lose work if you go offline or refresh the page. This data lives on your device only and is cleared when you clear your browser data.

In the mobile app, your sign-in session is held in your device's secure keystore (Keychain on iOS, Keystore on Android) rather than in ordinary app storage, and the app keeps a local cache of pool, fixture, and leaderboard data so screens load quickly and work briefly offline. Both are removed when you sign out or delete the app.

Banter (Pool Chat)

Every pool has a group chat called Banter. When you take part, we store the text of your messages, who sent them and when, which pool they belong to, any members you @mention, the message you were replying to, emoji reactions and who added them, messages an admin has pinned, and how far through the conversation you have read.

Most Banter messages are not typed. The app posts share cards to the chat on your behalf when something happens worth sharing — a badge or level you have earned, a leaderboard update, or a prediction you chose to share. These are stored like any other message, and alongside the visible card we keep the structured detail behind it: for a badge card, your level, total experience points and the badges themselves; for a prediction card, what you predicted and what actually happened; for a leaderboard card, the standings at that moment, which can include the name of whoever was leading.

Banter messages cannot be edited or deleted — by you, by your pool admin, or by us through the app. Once a message is posted it stays in that pool's history. Please treat anything you send as permanent. You can remove an emoji reaction you added, and deleting your account removes your messages everywhere (see Section 8), but there is no way to take back a single message.

Banter history is visible to whoever is a member of the pool now. Someone who joins the pool later can read everything posted before they arrived. If you leave a pool, you lose access to its chat but the messages you already posted stay there and remain visible to the members who remain.

Camera Access (Mobile App Only)

The mobile app can join a pool by scanning an invite QR code. If you choose that option, the app asks for camera permission and opens a live camera view solely to read the code in frame. No photo or video is captured, saved, or transmitted anywhere — the camera is read in memory, only the invite code is extracted, and the camera session is shut down as soon as you leave the scanner. You can join by typing a code instead and never grant camera access at all, and you can revoke the permission at any time in your device settings.

Shareable Video Cards

In Showdown pools you can generate a short video card of a duel — the reveal of who you were drawn against, or the result once it is settled. The card shows both members' display names and the score. Because the point of the card is to be shared outside the app, the rendered video file is stored on a public URL and can be viewed by anyone who has that link, without signing in. Only a member of the pool who is one of the two people in the duel can generate a card, but once generated the file itself is not access-controlled. Please treat these links as public.

Administrative Logs

When a pool admin or super admin takes an action that affects other users — such as removing a member, adjusting points, updating settings, or moderating chat — we record the action, the administrator, the affected user or entry, and a timestamp, so that actions remain auditable.

Communications

If you contact us through the contact form, we collect the name, email address, and message content you provide. We also store records of email notifications sent to you through the Service.

Mobile Push Notifications

When you use the SportPool mobile app and grant notification permission, your device's operating system issues us a push notification token (an APNs device token on iOS or an Expo push token routed via Firebase Cloud Messaging on Android). We store this token, the platform it was issued for, and your per-category notification preferences so we can deliver pushes about pool activity, prediction deadlines, match results, leaderboard changes, mentions, and badges or level-ups you earn. You can revoke notification permission at any time in your device settings, and you can toggle individual categories off from your profile in the app — in either case we stop sending the affected pushes and remove invalid tokens automatically.

Crash and Error Reports

When enabled, the mobile app sends crash reports and error telemetry (stack traces, app version, device model, OS version) to Sentry so we can diagnose and fix bugs. No prediction content or personal pool data is sent to Sentry.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Create and manage your account
  • Calculate scores, update leaderboards, settle duels and rounds, and process predictions
  • Run the games a pool has chosen — including drawing Showdown opponents, tracking Last Man Standing survival, and scoring predicted league tables
  • Show you and your fellow members how you are playing, including form, streaks, levels, and badges
  • Deliver community features such as Banter chat, reactions, @mentions, and online presence
  • Complete pool upgrade purchases, unlock the tier you bought, handle refund requests, and keep accurate financial and tax records
  • Generate the shareable video cards you ask for
  • Send you email notifications about pool activity, prediction deadlines, match results, leaderboard updates, and administrative events, subject to your notification preferences
  • Send push notifications to your mobile device about the same categories of events when you use the SportPool mobile app and have granted notification permission, subject to your per-category notification preferences
  • Respond to your contact form inquiries
  • Maintain administrative audit logs so pool and super admin actions remain accountable
  • Diagnose crashes and errors, and improve the Service through analytics and usage patterns (where enabled — see Section 4)
  • Log your acceptance of our Terms of Service for legal compliance
  • Detect and prevent fraud, abuse, or unauthorized access

4. Cookies & Tracking

Essential Cookies

These cookies are required for the Service to function and are always set when you sign in:

  • sb-<project>-auth-token — a signed session token issued by our authentication provider (Supabase) that keeps you signed in across pages. It is marked HttpOnly, Secure, and SameSite=Lax.
  • sb-<project>-auth-token-code-verifier — a short-lived PKCE code verifier used during the sign-in callback. It is removed automatically once you are signed in.
  • cookieyes-consent — records the cookie choices you made in our consent banner, so we can honour them and stop asking. It stores a random consent identifier and a yes/no for each category, and nothing else about you.

Theme and prediction-draft preferences are stored in your browser's local storage, not in cookies (see Section 2). The mobile app does not use cookies.

Your Cookie Choices

On your first visit, a consent banner (provided by CookieYes) asks how you want non-essential cookies handled. You can Accept All, Reject All, or Customise per category. Nothing but the essential cookies above is set until you choose, and rejecting is a single click that is honoured in every region — not only where consent is legally required. You can reopen the banner and change your mind at any time.

Analytics Cookies

We use Google Tag Manager and Google Analytics to collect aggregated usage data (pages visited, time on page, general interaction patterns). These cookies do not identify individual users to us.

The analytics tag loads in a consent-aware mode: until you accept the analytics category, it is denied permission to write or read any cookie, so no _ga, _gid, _gat, or _dc_gtm_* cookie is set and no analytics identifier is stored on your device. Those cookies appear only after you have accepted analytics, and disappear again if you withdraw that consent. Declining analytics does not affect any part of SportPool.

Fonts

Web fonts are compiled into the Service and served from our own domain. Loading a SportPool page does not make a request to Google Fonts and does not expose your IP address to a font provider.

No Advertising or Cross-Site Tracking

We do not use advertising cookies, marketing pixels, or cross-site tracking technologies, and we do not serve personalised advertising. Our consent banner lists an advertising category because it is a standard tool covering cookies a site of this kind might use; we set no cookies in it.

5. Third-Party Services

We use the following third-party services to operate SportPool:

  • Supabase — Provides our database and authentication infrastructure. Your account information and activity data are stored securely on Supabase servers.
  • Vercel — Hosts the Service. Vercel may collect standard server logs including IP addresses and request data. We also use Vercel Blob to store rendered video cards (see Section 2) and Vercel's ephemeral compute sandboxes to render them.
  • Paddle — Merchant of record for pool upgrade purchases. Paddle collects and processes your payment and billing information directly, handles any sales tax or VAT due in your country, and returns to us only the transaction record described in Section 2.
  • Resend — Handles email delivery for notifications, deadline reminders, and contact form messages. We also sync your email address to a Resend audience so that pool admins and SportPool can send you broadcast emails to which you are subscribed. Every broadcast email includes a one-click unsubscribe link.
  • Google Analytics / Google Tag Manager — Collects aggregated usage analytics to help us understand how the Service is used. Subject to your cookie preferences and local law.
  • CookieYes — Provides the cookie consent banner and records your choices. It receives your consent selections and standard connection data such as your IP address in order to log that consent.
  • Apple Push Notification service (APNs) — Used to deliver push notifications to iOS devices. Apple receives the encrypted notification payload and your APNs device token in order to route the notification to your device.
  • Expo Push Service & Firebase Cloud Messaging (FCM) — Used to deliver push notifications to Android devices. Expo's hosted service relays the notification payload and your Expo push token to Google's Firebase Cloud Messaging, which then delivers the notification to your device.
  • Expo (EAS Update) — Delivers over-the-air updates to the mobile app. When the app checks for an update, Expo receives technical details about your installation such as the app version, platform, and update channel. No account or pool data is sent.
  • Sentry — When enabled in the SportPool mobile app, collects anonymized crash reports and error telemetry (stack traces, app version, device model, OS version) so we can diagnose and fix bugs. No prediction content or personal pool data is sent to Sentry.
  • API-Football — Supplies the fixtures, results, standings, line-ups, and match statistics that the Service scores against. This is a one-way feed into SportPool: no member data of any kind is sent to them.

Each of these services has their own privacy policies governing how they handle data. We encourage you to review their respective policies.

6. Data Sharing

We do not sell, rent, or trade your personal information to third parties.

We share data only with the third-party service providers listed above, and only as necessary to operate the Service.

Within a pool, your username, entries, scores, leaderboard position, form and streak statistics, level and badges, and online presence are visible to the other members of that pool. Your email address is never shared with other users.

Your predictions become visible to other members only once they can no longer be changed. Picks are sealed until the relevant deadline — a match kickoff, a matchweek lock, or a table deadline — and are then shown to the pool. In Showdown pools, the opponent you have been drawn against is likewise hidden from you until the reveal for that matchweek.

Messages, reactions, pins, and @mentions you post in a pool's Banter chat are visible to every member of that pool, including members who join after you posted. They are delivered live to members who have the chat open at the time, and can trigger an email or push notification to the people you mention.

Pool admins and SportPool super admins can read chat content. To be clear about what that does and does not mean: an admin can pin a message, but no one using the app can edit or remove a message once it is sent. If something in a pool's chat needs to come down, please contact us and we will deal with it directly.

Video cards you generate are stored at public URLs and can be viewed by anyone holding the link, including people who are not SportPool members (see Section 2).

We may disclose your information if required by law, legal process, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

7. Where Your Data Is Stored

Our database and authentication infrastructure are hosted in the United States (Supabase, us-east-1). Our other providers operate globally. If you use SportPool from outside the United States, your information will be transferred to and processed in the United States and in other countries where our providers operate, which may have different data protection laws than your own.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service.

When you delete your account, we delete your account record, your pool memberships and entries, all of your predictions and scores across every game mode, your experience points, levels and badges, your Banter messages and reactions, your presence record, your push tokens and notification preferences, your terms-acceptance record, and your sign-in credentials. Deletion is immediate and cannot be undone.

Deleting your account is the only way to remove Banter messages you have posted, and it removes them from every pool at once — they will disappear from the chat history other members see. Leaving a single pool does not remove them.

Two things are kept after deletion. Records of email we have already sent you are retained but stripped of your account identifier. Records of purchases made through Paddle are retained, unlinked from your account, because we are required to keep accurate financial and tax records; Paddle retains its own copy under its own policy.

Video cards already generated and shared remain at their public URLs until we remove them. If you want a card taken down, please contact us.

Contact form submissions are retained for as long as needed to resolve your inquiry. Some information may be retained in anonymized or aggregated form for analytical purposes.

9. Your Rights

You have the right to:

  • Access the personal information we hold about you
  • Correct any inaccurate or incomplete information
  • Delete your account and associated data from your profile settings
  • Manage which categories of email and push notifications you receive from your profile settings, and revoke push notification permission at any time in your device's system settings
  • Revoke camera permission for QR scanning at any time in your device's system settings
  • Unsubscribe from broadcast emails using the unsubscribe link in any such email

You can delete your account directly from your profile settings, or see our account deletion page for full instructions. One prerequisite applies: if you are the administrator of a pool, you must first transfer that role to another member, so that deleting your account does not leave their pool without an admin. We will tell you which pools this affects if you try.

To exercise any of the other rights above, please contact us.

10. Children's Privacy

The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us and we will promptly delete that information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.

We encourage you to review this policy periodically to stay informed about how we protect your information.

12. Contact

If you have any questions about this Privacy Policy or wish to exercise any of the rights described in Section 9, you can email us at privacy@sportpool.io or use our contact form.