Privacy Policy

Effective date: 18 May 2026

This Privacy Policy explains how Fipster (“Fipster”, “we”, “us”) collects, uses, shares, and protects information about visitors and registered users of fipster.com and any related sub-domains (collectively, the “Service”). It also sets out your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using the Service you agree to the collection and use of information in accordance with this policy.

1. Who we are

Fipster is an independent football-prediction service that combines public match data with statistical models and large-language-model analysis. The data controller for personal information processed through the Service is the Fipster team. Questions about this policy or about how your data is processed can be sent via the Contact page.

2. Information we collect

We collect three categories of information:

  • Information you give us. If you create an account or use Fantasy Fipster, we store your email address, a hashed password (or OAuth-provider id), your display name, and any picks or predictions you submit. If you contact us by email we keep the message and our reply.
  • Information collected automatically. When you visit the Service we log standard request metadata: IP address (truncated where possible), user-agent, referrer, the page path, and a request id. This is used to operate the service, debug errors, and detect abuse.
  • Cookies and similar technologies. We set a small number of first-party cookies for session management and theme preference. Third-party cookies may be set by the providers listed in section 5 below — analytics, advertising, and consent management — and only with your consent where required.
  • Payment information. If you buy chat credits, your payment is processed by Stripe (see section 5). We never receive or store your full card number, CVC, or bank credentials. We do receive (and store) a transaction reference, the credit-pack identifier, the purchase amount and currency, and the account identifier that the purchase should be credited to.

3. How we use your information

  • To deliver the Service: rendering predictions, fixtures, and league data.
  • To operate accounts and Fantasy Fipster: storing picks, scoring rounds, and displaying leaderboards.
  • To improve prediction quality: aggregated, de-identified usage signals are used to evaluate which models and prompts perform best.
  • To serve relevant advertising via Google AdSense, where you have given consent (or where consent is not required by your jurisdiction).
  • To detect abuse, debug errors, and keep the Service available and secure.
  • To respond to you when you contact us, and to comply with legal obligations.

4. Legal bases for processing

Under UK GDPR we rely on the following legal bases: (a) contract, for the processing required to operate your account and Fantasy Fipster picks; (b) legitimate interests, for security, abuse prevention, error logging, and aggregate analytics that do not identify you individually; (c) consent, for advertising cookies, personalised advertising, and any analytics cookie that is not strictly necessary; (d) legal obligation, where we are required to retain or disclose data by law.

5. Third-party processors

Operating Fipster requires sharing limited information with the following processors. Each is bound by their own terms and privacy policy.

  • Google Analytics 4 (GA4) — aggregate measurement of page views, audience reach, and traffic sources. GA4 is initialised in Google Consent Mode v2 default-deny; nothing is sent until you grant the “Analytics” consent category. You can revoke at any time from the “Manage consent” link in the footer.
  • PostHog — product analytics (page views, click and form interactions, retention). Hosted in the EU. Loaded only after you grant the “Analytics” consent category and stops capturing immediately when you revoke. Session recording is disabled.
  • Google AdSense — advertising and ad measurement. Subject to your consent under the “Advertising” category in jurisdictions that require it. Where consent has not been granted in a jurisdiction that requires it, AdSense serves only non-personalised ads (“NPA mode”).
  • Google Funding Choices — our Consent Management Platform (CMP) for visitors in the United Kingdom, European Economic Area, and Switzerland. Funding Choices is registered with the IAB Europe Transparency & Consent Framework (TCF v2.2) and serves the consent banner you see on your first visit. It records your choice in a small set of first-party cookies and in your browser’s local storage for up to thirteen months, after which you will be asked to confirm again. The full TCF v2.2 vendor list is accessible from the banner’s “Manage options” control. You can revoke or change your consent at any time from the “Manage consent” link in our footer or by visiting our Cookie Policy.
  • Sports data feeds — third-party providers of fixture, lineup, and statistical data. We send no personal data to them; we only consume their feeds.
  • Sanity — content management for blog posts, prediction articles, and editorial pages.
  • Anthropic and OpenAI — large-language-model providers used by our chatbot and prediction-summary pipeline. When you use the chatbot, the message text is sent to the chosen provider; we do not send your account email or other identifiers.
  • Stripe — Stripe Payments Europe Ltd. and its affiliates process credit-pack purchases on our behalf. When you buy a credit pack we redirect you to a Stripe-hosted checkout page; Stripe collects and processes your card or wallet credentials, performs fraud checks, calculates any applicable tax (where Stripe Tax is enabled), and notifies us when the payment has succeeded. We send Stripe the credit-pack price, the credit-pack identifier, and an internal account identifier so the purchase can be attributed back to your account. Stripe sets its own cookies on the checkout page; those are governed by Stripe’s privacy notice (stripe.com/privacy) and Stripe’s cookie policy (stripe.com/cookies-policy/legal).
  • Hosting and infrastructure — virtual private servers operated on our behalf, which process request logs and database content as part of running the Service.

6. Cookies and tracking

We group cookies and similar technologies into three categories:

  • Strictly necessary — session, authentication, and theme cookies. These are required for the Service to function and do not require consent.
  • Analytics — used to understand which pages are popular and to find and fix bugs. Loaded only with your consent in regions where consent is required.
  • Advertising — used by Google AdSense to serve relevant ads and measure their performance. Loaded only with your consent in regions where consent is required.
  • Payment processing (Stripe) — when you buy chat credits, Stripe sets strictly necessary cookies on its checkout page to keep your session secure and to detect fraud. These are set by Stripe on Stripe’s domain and only when you initiate a purchase; they do not load while you are browsing fipster.com. Stripe’s cookie policy is available at stripe.com/cookies-policy/legal.

Where consent is required (UK, EEA, Switzerland) we present an IAB TCF v2.2 registered Consent Management Platform (Google Funding Choices) that lets you accept, reject, or customise non-essential cookies before they load. Your choice is stored for up to thirteen months in line with the TCF v2.2 specification. You can change your choice at any time from the “Manage consent” link in the footer, or read the full breakdown of consent-related cookies on our Cookie Policy page.

7. Data retention

  • Account data — kept for the lifetime of the account and for up to 6 years after closure to satisfy tax, accounting, and dispute-resolution requirements.
  • Chatbot conversations — retained for up to 90 days for quality evaluation, then deleted or anonymised.
  • Request and error logs — retained for up to 30 days then rotated.
  • Analytics — Google Analytics retention is set to 26 months.
  • Consent records — the consent decision you make through our CMP is stored on your device for up to 13 months. After that period your browser re-prompts and you can confirm or change your choice.
  • Fantasy Fipster picks — retained for the lifetime of the season and archived afterwards for historical leaderboards.

8. Your rights

Under UK GDPR you have the right to: access the personal data we hold about you; request that inaccurate data is corrected; request that your data is erased (“right to be forgotten”) where there is no overriding legitimate basis to retain it; object to processing based on legitimate interests; restrict processing in certain circumstances; and request that we provide your data in a portable format. You can exercise any of these rights by emailing us via the Contact page. We will respond within one calendar month.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk if you believe your rights have been infringed.

9. International transfers

Some of our processors (notably Google, Anthropic, and OpenAI) operate in the United States. Where personal data leaves the UK we rely on the UK Data Bridge, the EU-US Data Privacy Framework, or Standard Contractual Clauses to provide an adequate level of protection.

10. Children

Fipster is not directed at children under 13 and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data to the Service, please contact us and we will delete it promptly.

11. Security

We use industry-standard measures to protect your data, including TLS in transit, encrypted password hashes, isolated production credentials, and least-privilege access. No system is perfectly secure; if you suspect your account has been compromised please contact us immediately.

12. Changes to this policy

We may update this policy from time to time. The effective date at the top of the page reflects the latest revision. Material changes will be highlighted in the footer or, where you have an account, by an email or in-app notice.

13. Contact

For privacy questions, data-subject requests, or to withdraw consent, please use the Contact page.