Footy26
Privacy Policy
Last updated May 19, 2026 · This document is available in English only.
Footy26 (“Footy26,” “we,” “our,” or “us”) is operated by Lilico LLC, a Delaware limited liability company with its principal place of business in California. This Privacy Policy explains what information we collect when you use footy26.com, why we collect it, and the choices you have. By using Footy26 you agree to this policy.
1. Information we collect
1.1 Account information (Google Sign-In)
Footy26 uses Google as the only sign-in option, via the OAuth 2.0 / OpenID Connect flow managed by Supabase. When you sign in we receive from Google:
- your Google account email address,
- your display name,
- your Google account profile picture (avatar URL).
We store a stable user identifier (Supabase auth.uid), display name, and avatar URL. We do not store your Google password.
1.2 Game data
We store the predictions you make (“picks”), the leagues you create or join, and any custom display name you set. Your picks remain private to you until the tournament begins; once the bracket locks, your league members can see your picks for the purpose of scoring and ranking.
1.3 Tip information (Stripe)
If you choose to send a voluntary tip, payment is processed by Stripe, Inc. Footy26 never sees your card number, CVV, or full bank details. We receive only a Stripe session identifier, the amount tipped, and a confirmation that payment succeeded. We then store a record that you have tipped so we can thank you and keep you from being shown a tip prompt repeatedly.
1.4 Technical and usage data
To run the service securely we automatically collect:
- your IP address, browser user-agent, and approximate region (used by Vercel and Supabase to route requests, prevent abuse, and resolve incidents),
- aggregated usage events (pages visited, buttons clicked, and similar) recorded by PostHog. We strip personal identifiers before they leave your browser, so events are tied to a random visitor identifier rather than your name or email,
- error and performance traces recorded by Sentry. Our Sentry configuration removes email, username, and IP address from every event before it is sent.
1.5 Push notification tokens
If you turn on browser push notifications inside Footy26, your browser generates a Web Push subscription token tied to the Footy26 origin. We store this token so we can send you alerts (e.g. goal in your bracket, kickoff reminder). You can revoke this any time in your browser settings or by turning notifications off in Footy26 settings.
2. How we use your information
- to operate the service: authenticate you, save your bracket, score your picks,
- to keep your account secure and prevent abuse,
- to send the push notifications you have explicitly opted into (we never push without consent),
- to understand which features people use, in aggregate, so we can fix bugs and improve the product,
- to process voluntary tips, as we describe on the tip page,
- to communicate operational messages with you (a sign-in confirmation, a notice that this policy has changed). We do not send marketing email.
3. Advertising
Footy26 does not display third-party advertising. We do not run Google AdSense, advertising networks, or behavioral ad cookies. We do not sell or share your personal information for cross-context behavioral advertising as defined under the California Consumer Privacy Act (CCPA/CPRA).
4. Who we share information with
We share information only with the third parties needed to run Footy26:
- Google LLC: identity provider for sign-in.
- Supabase, Inc.: database, authentication, and edge functions.
- Vercel Inc.: application hosting and content delivery.
- Stripe, Inc.: payment processing for voluntary tips.
- PostHog Inc.: product analytics, with personal identifiers stripped client-side before transmission.
- Functional Software, Inc. (Sentry): error monitoring, with personal identifiers stripped before transmission.
We may also disclose information if we are legally required to (a valid subpoena, court order, or applicable regulation), or if we reasonably believe disclosure is necessary to protect the safety of users or the public. We will not voluntarily hand over your information.
5. Cookies and similar technologies
Footy26 uses two categories of cookies and similar storage: strictly necessary cookies that keep you signed in and remember your language and theme, and an opt-in analytics category (PostHog) for understanding which features people use. Analytics cookies are off by default and are only set after you explicitly accept them on the cookie banner or in the preferences modal.
Because we do not run advertising, we do not set advertising or cross-site tracking cookies. We respect the Global Privacy Control (GPC) signal: if your browser sends GPC, analytics stays off until you explicitly opt in.
For the full list of cookies (names, purposes, retention), the third-party processors that set them, and instructions for managing them at the browser level, see our Cookie Policy. You can change your choices any time: visit /cookies and click “manage cookie preferences,” or go to Settings → Preferences → Cookie preferences.
6. International data transfers
Footy26 is operated from the United States, and our service providers above are primarily located in the United States. If you visit Footy26 from outside the United States your information will be transferred to and processed in the United States, which may have different data-protection laws than your home country.
7. How long we keep your information
We keep your account information for as long as your account is active. If you delete your account from the Settings page, we delete your profile, picks, league memberships, and push subscription tokens within a reasonable period. We may retain limited anonymous, aggregated data (e.g. how many people picked each match outcome) for historical purposes after deletion. We retain Stripe-side tip records as long as applicable tax and accounting laws require.
8. Your rights and choices
Wherever you live, you can sign in to Settings and:
- edit your display name,
- turn push notifications on or off,
- delete your account permanently.
8.1 California residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect about you, to request a copy, to ask us to correct or delete it, and to limit the use of any sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising, so a “Do Not Sell or Share” signal does not change anything we do. To exercise any of these rights, email eric@lilicollc.com.
8.2 European Economic Area, United Kingdom, Switzerland
If you are located in the EEA, the UK, or Switzerland, you have the right to access, correct, delete, restrict, or object to our processing of your personal data, and to receive your data in a portable format. The legal bases on which we rely are performance of a contract (operating the service for you), our legitimate interest in running and improving the service, and your consent (push notifications, optional analytics). To exercise these rights, email eric@lilicollc.com. You also have the right to complain to your local data-protection authority.
9. Children
Footy26 is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at eric@lilicollc.com and we will delete it.
10. Security
We use industry-standard practices to protect your information: encryption in transit, row-level security on the database, and least-privilege access to production systems. No service is one hundred percent secure. If you discover a security issue please email eric@lilicollc.com rather than disclosing it publicly.
11. Changes to this policy
We may update this policy from time to time. If we make a material change we will update the “Last updated” date at the top of the page and, where the change is significant, surface a notice in the app the next time you sign in. Your continued use of Footy26 after the change takes effect constitutes acceptance of the revised policy.
12. Contact
Questions about this Privacy Policy or your information? Email eric@lilicollc.com.
Lilico LLC