Privacy Policy

Last Updated
August 18, 2026

This policy explains what personal data Fantasy Global collects when you use our website and mobile apps, the legal bases for processing, who we share data with, and how you can exercise your rights. The operator is Aykut Silan, a natural person who lives in Poland; there is no company.

1. Data Controller

This Privacy Policy applies to the Fantasy Global / Global Fantasy Football website (globalfantasyfootball.com) and our iOS and Android apps (the “Service”).

The Service is operated by Aykut Silan, a natural person residing in Poland (“we”, “us”, “our”), not by a company. A home address is not published. Use the contact page for legal notices and privacy requests; a postal address will be provided on request where a court, a data-protection authority, or the law requires it.

For privacy questions, access requests, and deletion requests, use the contact form on globalfantasyfootball.com.

2. Data We Collect

The categories below reflect the account, gameplay, billing, and support flows in our systems. If you do not provide data that a feature requires, that feature may not work.

  • Account and profile data: name, email address, username, global team name, bcrypt-hashed password, Premium status and expiry, and logo configuration (generated SVG parameters or, for Premium users, a custom logo stored as JSON/base64 in PostgreSQL, not in a separate object store).
  • Gameplay data: league and cup names, memberships, squads, captain and bench selections, draft order and picks, transfers, trades, auction bids, FAAB bids, scores, fixture results, and in-app notifications.
  • User-generated content: league chat messages, direct messages, product suggestions, player-value suggestions, optional contact preference and contact details, bug-report text and optional screenshots, and contact-form messages.
  • Purchase and subscription records: plan interval (monthly or yearly), billing provider (Stripe, Apple, or Google), transaction and subscription identifiers, customer IDs, period start and end, auto-renewal and cancellation status, and billing-event logs.
  • Cash-prize and payout records: league or pyramid entry-fee amounts and status, prize-pool records, Stripe Checkout session and PaymentIntent IDs, Stripe Connect account ID, and payout-readiness flags. We do not store full card numbers, IBAN, or identity-document images; identity verification is handled by Stripe.
  • Device and push data: iOS or Android platform, device ID, APNs or FCM token, app version, build number, and permission status. Tokens are stored so we can send gameplay and announcement notifications to devices that granted permission.
  • Session and security data: httpOnly authentication cookies (JWT session token and email cookie), a maintenance-access cookie, an admin MFA step-up cookie on administrator accounts, and language or UI preferences stored in the browser. The localStorage user cache may include email and username. IP addresses are used temporarily for registration and password-reset rate limiting and are not stored as a permanent field on the user record. Server and error logs may include IP address, user agent, timestamps, and request path.
  • Analytics (if configured): Google Analytics 4 may collect page path and device or browser signals. If no GA measurement ID is configured, this tracking is not loaded.

3. Legal Bases for Processing (GDPR)

If you are in the European Economic Area, the United Kingdom, or a similar regime, we process personal data on these bases:

  • Performance of a contract: creating and signing into an account, running leagues, drafts, scoring, trades, messaging, Premium access, collecting entry fees, and paying prizes.
  • Legitimate interests: preventing fraud, multi-accounting, cheating, and abuse; securing the Service; improving the product; and, if configured, limited first-party analytics. You may object to processing based on legitimate interests.
  • Legal obligation: accounting, tax, payment-services, dispute, and legal-claim requirements.
  • Consent: we do not send marketing newsletters. Contact-form, bug-report, and optional suggestion contact details are communications you initiate. Push tokens depend on your device permission. You can restrict cookies, analytics, and notifications in your browser or operating-system settings.

4. How We Use Data

  • To operate your account, reset passwords, and keep you signed in. A mandatory email-verification flow is not currently live.
  • To run leagues, pyramids, official leagues, drafts, auctions, transfers, trades, cups, and scoring.
  • To provide chat, direct messages, logos, suggestions, and support, and to investigate abuse.
  • To verify, restore, and update Premium access through Stripe, the Apple App Store, or Google Play Billing.
  • To collect or hold entry fees in cash-prize leagues, apply the platform fee, and pay winners through Stripe Connect.
  • To send transactional email (welcome, password reset, league or draft notices, and payment notices). We do not operate a marketing list. Contact-form and bug-report messages are emailed via Resend to our support inbox and are not written to the database.
  • To store device tokens and send push notifications (drafts, trades, transfers, messages, and admin announcements). FAAB/waiver events are in-app only. You can disable notifications in your device settings.
  • To protect accounts, apply rate limits, enforce rules, and comply with law.

5. Messages, Uploads, and Gameplay Content

League chat, direct messages, team logos, league names, suggestions, and bug-report attachments may be processed and stored to provide the feature, preserve other users’ league history, maintain security, and investigate abuse. League chat is visible to members who can access that league.

Squads, draft picks, scores, and similar gameplay records are stored with your account and the leagues you join. Other managers in a league can see your username, team name, logo, and public gameplay information.

6. Payments, Subscriptions, and Cash Prizes

Web Premium payments and league or pyramid entry fees are processed by Stripe. iOS in-app subscriptions are processed by Apple. Android in-app subscriptions are processed by Google Play Billing. Cash-prize entry fees are not offered in the Play Store app. We do not receive your full payment-card or bank-account numbers.

Users who want to receive cash prizes complete Stripe Connect Express identity verification. Stripe may collect identity and bank details to meet its legal obligations. We store the Stripe Connect account ID and payout-readiness flags.

After account deletion, billing, entry-fee, and prize records may be retained in anonymized or identifier-limited form for accounting, tax, fraud prevention, and league history. Apple or Google subscriptions must be cancelled separately in the relevant store account.

7. Cookies, Sessions, and Local Storage

Essential cookies and similar technologies keep you signed in and help secure the Service. We do not currently display a separate cookie-consent banner. Analytics scripts load only if a measurement ID is configured.

  • token: httpOnly JWT session cookie, about 7 days. Authenticates your session.
  • userEmail: httpOnly cookie, about 7 days. Helps resolve the signed-in user. During native-to-web session handoff this cookie may not be httpOnly.
  • admin_stepup: httpOnly cookie for administrator MFA step-up (about 2 hours). Used only on admin accounts.
  • maintenance_bypass: httpOnly cookie used for authorized maintenance access (up to 30 days).
  • Local storage: language preference, a user cache that may include email, username, name, team name, and Premium status, and some UI “dismiss” flags (for example, the suggestions banner or FAAB rules).
  • Google Analytics (if configured): Google first-party analytics cookies (for example, _ga). You can block these in your browser.

8. Subprocessors and Third Parties

We use the following categories of providers to operate the Service. They process data under their own privacy terms. We do not sell personal data and we do not share it for cross-context behavioral advertising.

  • Stripe, Inc.: web payments, subscriptions, entry-fee collection and authorization holds, refunds, and Stripe Connect prize transfers.
  • Apple Inc.: iOS in-app purchase, subscription, and restore flows.
  • Google LLC (Google Play Billing): Android Premium subscriptions, verification APIs, and Play real-time developer notifications.
  • Resend: transactional and support email (welcome, password reset, contact form, bug reports, and admin alerts). Contact and bug-report content is not written to the database; it is delivered to our support inbox.
  • API-Football / API-Sports (api-sports.io): match, squad, statistics, and live-score data feeds; player and team images via media.api-sports.io. This feed is not used to share your account with third parties for marketing.
  • Google Analytics 4 (only if enabled on the site): page-usage measurement.
  • Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM): storage of device tokens and delivery of push notifications.
  • Self-hosted PostgreSQL and application servers: Hetzner with Docker/Coolify. Backups may be stored in the same environment.
  • flagcdn.com: country-flag images in the language switcher.
  • Transfermarkt and similar public football sources: server-side scraping to update club-transfer information. This does not send your account to those sites.

9. International Transfers

Some providers are established outside the European Economic Area (for example, in the United States). Data may be transferred with appropriate safeguards such as Standard Contractual Clauses or the provider’s then-current transfer mechanism. The operator resides in Poland; the lead supervisory authority is the Polish Data Protection Office (UODO).

10. Retention

We keep account, gameplay, and message data while your account is active. Account deletion is anonymization, not full erasure: sign-in credentials are removed; name, username, email, and logo are overwritten. League chat, direct messages, suggestions, billing events, Stripe customer/Connect IDs, and gameplay history may remain linked to the anonymized user ID.

Password-reset tokens are hashed and short-lived (about one hour). Push-device records are deleted when you delete your account or when a device registration is revoked. Server logs are kept for a limited operational period.

11. Security

Passwords are stored with bcrypt. Session tokens are carried in httpOnly cookies. Administrator accounts may use optional TOTP multi-factor authentication. Payment-card data remains with Stripe, Apple, or Google. No method of transmission or storage over the internet is completely secure.

12. Your Rights (GDPR, CCPA/CPRA, and similar laws)

Depending on applicable law, you may have the rights below. We will honour requests after identity verification, subject to legal exceptions.

  • Access and portability: request a copy of the personal data we hold about you.
  • Rectification: update name, team name, logo, and similar fields in the app, or contact us for other corrections.
  • Deletion (right to be forgotten): use the in-app account deletion steps below, or write to us through the contact form.
  • Restriction or objection, including for legitimate-interest analytics and security processing.
  • CCPA/CPRA: you have the right to opt out of sale or sharing of personal information for cross-context behavioral advertising. We do not sell personal data and we do not share it for that purpose. You may exercise rights without discriminatory treatment.
  • Complaint: you may lodge a complaint with your local data-protection authority. Because the operator is in Poland, the lead authority is UODO (uodo.gov.pl). In the EU you may also complain to your own supervisory authority.

13. In-App Account and Data Deletion

Consistent with Apple App Store and Google Play account-deletion guidelines, you can delete your account from the app or website.

  • Sign in and open the Profile page.
  • Scroll to Delete Account.
  • Enter your current password and type DELETE in the confirmation field.
  • Confirm Permanently Delete My Account. You will be signed out. Sign-in credentials are removed; name, username, email, and logo are anonymized; push devices are deleted.
  • This is not a hard erase. League chat, direct messages, suggestions, gameplay history, Stripe identifiers, and billing records may remain linked to the anonymized user ID so other users’ league history and legal or accounting obligations are preserved.
  • If you have an App Store or Google Play subscription, cancel it separately in your Apple or Google account settings. Uninstalling the app does not delete your account or cancel a subscription.
  • If you cannot access the app, use the contact form to make the same request.

14. Children’s Privacy

The Service is not directed to children under 16. Cash-prize, entry-fee, and payout features are for users aged 18 or older. If we learn that an account belongs to a child under 16, we will delete or anonymize it. Parents may contact us through the contact form.

15. No Sale of Personal Data

We do not sell personal data. We do not use third-party advertising networks. We do not share personal data for cross-context behavioral advertising or cross-app advertising tracking. Google Analytics, if enabled, is optional first-party usage measurement, not a sale of data for advertising.

16. Policy Updates

We may update this policy from time to time. When changes are material, we will update the date on this page and provide additional notice where appropriate. Continued use of the Service after an update means you accept the policy then in effect.

17. Contact

Data controller: Aykut Silan, a natural person residing in Poland. A home address is not published. Use the contact page for privacy and deletion requests. Governing law: Poland, together with the GDPR and any mandatory consumer rules.

Contact form: contact page. Terms of Use: Terms of Use.