Privacy Policy Effective September 23, 2026.

Statasy Football ("we", "us") runs statasyfootball.com. This page explains what we collect, why, and what we do with it, in plain language. The short version: we keep as little as we can. Questions go to [email protected].

What we collect

Nothing, for most visitors. You can read every public page without an account, and we do not run analytics trackers, advertising pixels or fingerprinting scripts. The only traffic measurement is Cloudflare's aggregate metrics (request counts and countries), which do not identify individual visitors to us.

Your email address, if you sign in. We use it to send you the sign-in link and to know which account is yours. There is no password. Billing notices (receipts, failed payments) are sent by Stripe on our behalf to the same address.

A session cookie, after you sign in, so you stay signed in. It holds a random token and nothing else.

Billing details, handled by Stripe. If you subscribe, Stripe collects your card and billing information and processes the payment. We never see or store your full card number. We keep your Stripe customer and subscription IDs, your plan status (trial, active, past due, cancelled), the date it renews or ends, and whether you have asked to cancel, so the site knows what you have paid for. Stripe's handling of your data is covered by Stripe's privacy policy.

League connection is not live yet. If we add it, the league cookies you paste will stay in your browser and will only be forwarded to the league provider so the page can read your roster; we will update this policy to describe exactly what passes through our servers before the feature ships.

Suggestions sent through the Suggestions page are anonymous: we store the text you typed, the page you were on, and the time, nothing about you.

Cookies and local storage

NameWhereWhat it does
__Host-statasy_sessionCookie, this site only, HttpOnly, SecureKeeps you signed in after you use an email link. Set only when you sign in; removed when you sign out or it expires.
Theme preferenceBrowser localStorageRemembers your light or dark theme choice. Never leaves your browser.
Scoring preferenceBrowser sessionStorageRemembers the scoring format you picked (PPR and passing TD points) for the current tab. Never leaves your browser.

Stripe sets its own cookies on Stripe's checkout and billing pages, not on this site. We use no advertising or analytics cookies.

How we use it

To sign you in, to show you the plan you paid for, to bill you, to answer your support requests, and to keep the Service secure. That is all. We do not sell your data, rent it, or share it with advertisers, and we do not send marketing email.

Who we share it with

Only the services that run the site: Cloudflare (hosting, storage, aggregate metrics), Stripe (payments, receipts and failed-payment notices) and our email delivery provider (the sign-in email). Each receives only what it needs for its job. The pages also load their two typefaces from Google Fonts, so Google receives your IP address and the page address when the font files are fetched, as with any site that uses it. We will disclose information if the law requires it.

Retention

Sign-in links expire after 15 minutes and are deleted once used. Sessions expire 30 days after you sign in, whether or not you keep using the site, and end sooner when you sign out. Your email and plan record stay for as long as your account exists. Stripe keeps billing records for as long as tax and accounting rules require, which is outside our control.

Deleting your account

Email [email protected] from the address on the account and we will delete your email, sign you out on every device and delete your plan record within 30 days. Any active subscription is cancelled at the same time. We may keep records that we are legally required to keep, such as invoices.

Children

The Service is not for children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, email us and we will delete it.

Security

Sign-in is by single-use email link, session cookies are HttpOnly and Secure, and all traffic uses HTTPS. No system is perfectly secure; if we learn of a breach affecting your data we will tell you.

Changes

We may update this policy. When we do, we will change the effective date at the top of this page and, for material changes, notify account holders by email.

Contact

[email protected]. See also our Terms of Service.