Privacy Policy

Effective date: 30 August 2026

This Privacy Policy explains how Fipster (“Fipster”, “we”, “us”) collects, uses, shares, and protects information about visitors and registered users of our two products: the fipster.com website and any related sub-domains, and the Fipster iOS app (together, the “Service”). It also sets out your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using the Service you agree to the collection and use of information in accordance with this policy.

Scope — which parts of this policy apply to you

The website and the app are not the same product and do not behave the same way, so this policy is scoped explicitly rather than written as one blended document:

  • The fipster.com website is ad-supported. It serves advertising, uses analytics and advertising cookies, and presents a consent banner where consent is required. Every section below that is marked “website only” — including all advertising, cookie and consent-management provisions — describes the website and nothing else.
  • The Fipster iOS app carries no advertising and does not track you. It contains no advertising SDK, no advertising or attribution identifiers, no cookies and no consent management platform. The “Mobile app (iOS)” section immediately below states in full what the app does and does not do, and it governs the app wherever the rest of this policy differs.
  • Sections that carry no scope label — who we are, legal bases, your rights, retention, international transfers, children, security, changes, and contact — apply to both products.

Mobile app (iOS)

This section applies to the Fipster iOS app. Where it differs from the rest of this policy, this section governs the app — the advertising, cookie and consent-banner provisions elsewhere in this policy describe the fipster.com website only and have no application to the app.

The app shows no advertising. It contains no advertising SDK and no ad network. It does not use Google AdSense, Google Analytics, Firebase, the Meta Pixel, or any advertising or attribution SDK, and it does not use cookies or a consent management platform.

The app does not track you. We do not collect or use the Advertising Identifier (IDFA), we do not perform advertising attribution or ad measurement of any kind, we do not link your data with third-party data for advertising, and we do not share your data with data brokers or any other advertising business. Because the app does not track you, it does not ask for App Tracking Transparency permission and does not show any permission-style prompt about tracking or advertising.

What the app collects — only the following, and it is off by default:

  • Product-usage analytics (PostHog, hosted in the European Union on our own project) — which screens and features are used. This is first-party analytics for our own product decisions: it is not shared with any third party, is never combined with data from other companies, and is never used for advertising. Events contain only stable identifiers and predefined values, never free text, never your email, never a device or advertising identifier, and session recording is disabled. This may include an approximate, city-level location derived from your IP address for analytics; it is not precise, is never shared, and is never used for advertising.
  • Crash and diagnostic data (Sentry) — to find and fix stability problems; diagnostic reports are stripped of personal data before they are sent, and they are used for engineering purposes only, never for advertising.

Neither begins until you turn on “Share anonymous usage data” in the app’s menu, and you can turn it off again at any time in the same place, which stops collection immediately.

Sign-in and purchases. If you sign in, your email address is used solely to authenticate you; it is never sent to our analytics or crash-reporting tools. If you buy credit packs, the purchase is processed by Apple’s App Store, with RevenueCat used to validate and record entitlements. Neither is used for advertising.

No web content is rendered inside the app. Links to this policy and our other pages open in your own browser, so no website cookies or advertising tags are ever set from within the app. If you open fipster.com in your browser, the website’s own terms — including its advertising and consent banner — apply to that browser session, not to the app.

1. Who we are

Fipster is an independent football-prediction service that combines public match data with statistical models and large-language-model analysis. The data controller for personal information processed through the Service is the Fipster team. Questions about this policy or about how your data is processed can be sent via the Contact page.

2. Information we collect

We collect the following categories of information:

  • Information you give us. If you create an account or use Fantasy Fipster, we store your email address, a hashed password (or OAuth-provider id), your display name, and any picks or predictions you submit. If you contact us by email we keep the message and our reply. This applies to both the website and the app.
  • Information collected automatically. When you use the Service we log standard request metadata: IP address (truncated where possible), user-agent, referrer, the page or endpoint path, and a request id. This is used to operate the service, debug errors, and detect abuse. It is not used for advertising.
  • Cookies and similar technologies (website only). On the website we set a small number of first-party cookies for session management and theme preference. Third-party cookies may be set by the website providers listed in section 5 below — analytics, advertising, and consent management — and only with your consent where required. The app uses no cookies at all.
  • Payment information. If you buy chat credits on the website, your payment is processed by Stripe (see section 5). In the app, credit-pack purchases are processed by Apple’s App Store. In both cases we never receive or store your full card number, CVC, or bank credentials. We do receive (and store) a transaction reference, the credit-pack identifier, the purchase amount and currency, and the account identifier that the purchase should be credited to.

3. How we use your information

  • To deliver the Service: rendering predictions, fixtures, and league data.
  • To operate accounts and Fantasy Fipster: storing picks, scoring rounds, and displaying leaderboards.
  • To improve prediction quality: aggregated, de-identified usage signals are used to evaluate which models and prompts perform best.
  • Website only: to serve relevant advertising via Google AdSense on fipster.com, where you have given consent (or where consent is not required by your jurisdiction). We do not use your information to serve advertising in the iOS app, which carries no advertising.
  • To detect abuse, debug errors, and keep the Service available and secure.
  • To respond to you when you contact us, and to comply with legal obligations.

4. Legal bases for processing

Under UK GDPR we rely on the following legal bases: (a) contract, for the processing required to operate your account and Fantasy Fipster picks; (b) legitimate interests, for security, abuse prevention, error logging, and aggregate analytics that do not identify you individually; (c) consentwebsite only — for advertising cookies, personalised advertising, and any website analytics cookie that is not strictly necessary, and, in the app, for the optional product analytics and crash diagnostics described in the “Mobile app (iOS)” section, which are off until you switch them on; (d) legal obligation, where we are required to retain or disclose data by law.

5. Third-party processors

Operating Fipster requires sharing limited information with the following processors. Each is bound by their own terms and privacy policy. Entries marked website only are not present in, and are never loaded by, the iOS app.

  • Google Analytics 4 (GA4) — website only. Aggregate measurement of page views, audience reach, and traffic sources on fipster.com. GA4 is initialised in Google Consent Mode v2 default-deny; nothing is sent until you grant the “Analytics” consent category. You can revoke at any time from the “Manage consent” link in the footer. GA4 is not present in the iOS app.
  • Google AdSense — website only. Advertising and ad measurement on fipster.com. Subject to your consent under the “Advertising” category in jurisdictions that require it. Where consent has not been granted in a jurisdiction that requires it, AdSense serves only non-personalised ads (“NPA mode”). AdSense is not present in the iOS app, and the app displays no advertising.
  • Google Funding Choices — website only. Our Consent Management Platform (CMP) for website visitors in the United Kingdom, European Economic Area, and Switzerland. Funding Choices is registered with the IAB Europe Transparency & Consent Framework (TCF v2.2) and serves the consent banner you see on your first visit to fipster.com. It records your choice in a small set of first-party cookies and in your browser’s local storage for up to thirteen months, after which you will be asked to confirm again. The full TCF v2.2 vendor list is accessible from the banner’s “Manage options” control. You can revoke or change your consent at any time from the “Manage consent” link in our footer or by visiting our Cookie Policy. There is no consent management platform, and no consent banner, in the iOS app.
  • PostHog — first-party product analytics, hosted in the EU on our own project, never shared onward and never used for advertising. On the website it records page views and click and form interactions, and is loaded only after you grant the “Analytics” consent category, stopping immediately when you revoke. In the app it is off until you turn on “Share anonymous usage data”, as described in the “Mobile app (iOS)” section. Session recording is disabled on both.
  • Sentry — crash and diagnostic reporting, used to find and fix stability problems. Reports are stripped of personal data before they are sent and are never used for advertising.
  • Sports data feeds — third-party providers of fixture, lineup, and statistical data. We send no personal data to them; we only consume their feeds.
  • Sanity — content management for blog posts, prediction articles, and editorial pages.
  • Anthropic and OpenAI — large-language-model providers used by our chatbot and prediction-summary pipeline. When you use the chatbot, the message text is sent to the chosen provider; we do not send your account email or other identifiers.
  • Stripe — website only. Stripe Payments Europe Ltd. and its affiliates process credit-pack purchases made on fipster.com. When you buy a credit pack we redirect you to a Stripe-hosted checkout page; Stripe collects and processes your card or wallet credentials, performs fraud checks, calculates any applicable tax (where Stripe Tax is enabled), and notifies us when the payment has succeeded. We send Stripe the credit-pack price, the credit-pack identifier, and an internal account identifier so the purchase can be attributed back to your account. Stripe sets its own cookies on the checkout page; those are governed by Stripe’s privacy notice (stripe.com/privacy) and Stripe’s cookie policy (stripe.com/cookies-policy/legal).
  • Apple and RevenueCat — app only. Credit-pack purchases made in the iOS app are processed by Apple’s App Store under Apple’s own privacy policy. RevenueCat validates the App Store receipt and records which credit pack you are entitled to. Neither is used for advertising, advertising measurement or attribution.
  • Hosting and infrastructure — virtual private servers operated on our behalf, which process request logs and database content as part of running the Service.

6. Cookies and similar technologies (website only)

This section describes the fipster.com website only. The Fipster iOS app sets no cookies, uses no similar technologies, shows no consent banner, and does not track you — see the “Mobile app (iOS)” section above.

On the website we group cookies and similar technologies into four categories:

  • Strictly necessary — session, authentication, and theme cookies. These are required for the website to function and do not require consent.
  • Analytics — used to understand which pages are popular and to find and fix bugs. Loaded only with your consent in regions where consent is required.
  • Advertising — used by Google AdSense to serve relevant ads on the website and measure their performance. Loaded only with your consent in regions where consent is required.
  • Payment processing (Stripe) — when you buy chat credits on the website, Stripe sets strictly necessary cookies on its checkout page to keep your session secure and to detect fraud. These are set by Stripe on Stripe’s domain and only when you initiate a purchase; they do not load while you are browsing fipster.com. Stripe’s cookie policy is available at stripe.com/cookies-policy/legal.

Where consent is required (UK, EEA, Switzerland) we present, on the website only, an IAB TCF v2.2 registered Consent Management Platform (Google Funding Choices) that lets you accept, reject, or customise non-essential cookies before they load. Your choice is stored for up to thirteen months in line with the TCF v2.2 specification. You can change your choice at any time from the “Manage consent” link in the footer, or read the full breakdown of consent-related cookies on our Cookie Policy page.

7. Data retention

  • Account data — kept for the lifetime of the account and for up to 6 years after closure to satisfy tax, accounting, and dispute-resolution requirements.
  • Chatbot conversations — retained for up to 90 days for quality evaluation, then deleted or anonymised.
  • Request and error logs — retained for up to 30 days then rotated.
  • Analytics — Google Analytics (website only) retention is set to 26 months.
  • Consent records (website only) — the consent decision you make through our website CMP is stored on your device for up to 13 months. After that period your browser re-prompts and you can confirm or change your choice. The app stores no consent record of this kind; your “Share anonymous usage data” preference is simply an app setting you can change at any time.
  • Fantasy Fipster picks — retained for the lifetime of the season and archived afterwards for historical leaderboards.

8. Your rights

Under UK GDPR you have the right to: access the personal data we hold about you; request that inaccurate data is corrected; request that your data is erased (“right to be forgotten”) where there is no overriding legitimate basis to retain it; object to processing based on legitimate interests; restrict processing in certain circumstances; and request that we provide your data in a portable format. You can exercise any of these rights by emailing us via the Contact page. We will respond within one calendar month.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk if you believe your rights have been infringed.

9. International transfers

Some of our processors (notably Google, Anthropic, and OpenAI) operate in the United States. Where personal data leaves the UK we rely on the UK Data Bridge, the EU-US Data Privacy Framework, or Standard Contractual Clauses to provide an adequate level of protection.

10. Children

Fipster is not directed at children under 13 and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data to the Service, please contact us and we will delete it promptly.

11. Security

We use industry-standard measures to protect your data, including TLS in transit, encrypted password hashes, isolated production credentials, and least-privilege access. No system is perfectly secure; if you suspect your account has been compromised please contact us immediately.

12. Changes to this policy

We may update this policy from time to time. The effective date at the top of the page reflects the latest revision. Material changes will be highlighted in the footer or, where you have an account, by an email or in-app notice.

13. Contact

For privacy questions, data-subject requests, or to withdraw consent, please use the Contact page.