Privacy Policy
This policy describes what SharpFooty Analytics ("we") stores and why.
What we collect
Members: your email address (sign-in is by emailed magic link — we never hold a password), your alert and league preferences, your subscription status, and page-view analytics linked to your account (pages visited and when), used to improve the product. If you use the bet log or set decision alerts, we also store what you enter there — stakes, prices taken, results, notes and the fixtures and thresholds you watch. That data is private to your account, never aggregated into any public number, and is deleted with your account. Visitors: anonymous page counts only — IP addresses are one-way hashed and no visitor cookies are set.
The partner programme
If you arrive through a creator's partner link we record the click (the landing page, a one-way hashed IP address, a coarse device class and the referring site — no name, no account) and, only if you accept cookies, a referral token for 30 days. If you then create an account within that window, your account is linked to that creator. The creator sees you only as an opaque reference such as SF-3A7E9, the month you joined and whether a membership payment occurred — never your email, name or payment details. Unlinked clicks are deleted after 90 days; a click that led to an account is kept as the record behind a commission with its hashed IP and referrer removed. Deleting your account removes the link to the creator. If you become a partner yourself, your application, contact details, payout details and ledger are processed to run the programme and pay you, and are retained as financial records after you leave it, with your account link removed.
Processors
Email delivery is handled by Resend; payments by Stripe (card details never touch our servers); the site is served through Cloudflare. Each processes data under its own policy.
What we never do
We do not sell or share personal data, run advertising trackers, or send email beyond sign-in links and the alerts you switch on.
Sessions
Sign-in sessions are long-lived by design: you stay signed in on a device until you sign out there (the session cookie renews on each visit rather than expiring on a timer). Signing out invalidates that device's session immediately; clearing your browser cookies has the same effect.
Retention & your rights
Data is kept while your account is active. You can delete your account yourself at any time from your account page; this removes your account record, sessions, your bet log and decision alerts, saved views, watchlist, alert preferences, notification history and any push registrations. Aggregate usage counts are retained but no longer identify you. Billing audit records are retained de-identified: payment webhook events keep their pseudonymous Stripe identifiers for dispute and audit purposes but lose the link to your account. A bounded administrative grant log (admin actions) is retained as an operational audit record. Magic-link sign-in tokens are pruned 30 days after they expire. Deleting your account does not cancel a payment-provider subscription — cancel that in the billing portal first, and deletion becomes available once it has ended. For access to a copy of your data, contact us from the email address on your account.