1. Information you provide
Account information
When you create an account, we collect your email address and password. LeagueBeacon stores a one-way cryptographic hash of your password, not the plaintext password. We also create internal account, workspace, session, verification, and password-reset identifiers and record related timestamps.
Preferences and saved activity
We store preferences and content you choose to save, such as a preferred league, team, and position; connected leagues; saved trade ideas; draft watchlists stored in your browser; and account or subscription preferences.
Feedback and support
If you submit feedback or contact support, we receive the information you provide. Product feedback may include ratings, comments, the feature and league context associated with the feedback, and an optional screenshot. Support email sent to [email protected] is routed through Cloudflare Email Routing to LeagueBeacon’s monitored inbox.
2. Sleeper and fantasy football data
LeagueBeacon uses Sleeper’s public, read-only APIs and public profile information. Depending on the feature you use, we may retrieve and process:
- Sleeper username, immutable user ID, display name, and avatar reference;
- league IDs, names, seasons, status, roster settings, scoring settings, and draft settings;
- teams, managers, rosters, starters, reserve designations, and player identifiers;
- matchups, weekly results, and NFL state information;
- transactions, trades, waivers, traded picks, drafts, and draft selections; and
- public trade-block information where available.
You can analyze a public Sleeper league by entering a username or league ID. Connecting a Sleeper profile personalizes LeagueBeacon but does not authenticate ownership through Sleeper OAuth. LeagueBeacon does not request or store Sleeper passwords and does not change anything on Sleeper.
LeagueBeacon also processes public player and historical football statistics used to generate rankings, projections, trends, and other analysis, including nflverse data distributed through GitHub.
3. Payment and subscription information
Stripe processes payment details and hosts LeagueBeacon’s checkout and billing-management experiences. LeagueBeacon does not directly store complete payment-card numbers.
We receive and store billing information needed to administer access, such as Stripe customer, subscription, price, checkout-session, invoice, and event identifiers; plan and subscription status; billing-period and cancellation information; payment-status timestamps; and founding-offer reservation or eligibility records. Stripe may collect billing contact, payment method, tax, device, and transaction information under its own privacy policy.
4. Information collected automatically
Cookies
When you sign in, LeagueBeacon uses a session cookie to keep you authenticated and a separate security cookie to help protect state-changing requests. These cookies are necessary for account and security functions and are configured for a lifespan of up to 30 days. Signing out clears them from the browser.
Browser storage
LeagueBeacon uses localStorage and sessionStorage for an anonymous workspace identifier, local workspace preferences, saved trades, draft watchlists, rating-prompt state, tab navigation state, feedback-prompt state, and an opaque analytics session ID. Browser storage can persist on your device until it expires, is cleared by the product, or is removed through browser controls, depending on the item.
First-party usage analytics
For signed-in users, LeagueBeacon records product sessions and meaningful interactions such as page or feature views, navigation, signal interactions, trade and waiver actions, saved trades, player views, and feedback actions. These records may include internal user and session IDs, timestamps, current and previous views, navigation source, league ID, team name, application version, and limited event context. The analytics implementation is designed to omit passwords, authentication tokens, cookies, raw IP addresses, and browser or device fingerprints.
Reddit Pixel
The main LeagueBeacon application uses Reddit Pixel for page-visit and account-signup conversion measurement. LeagueBeacon does not send account email addresses, LeagueBeacon user IDs, or other authenticated customer identifiers to Reddit for advanced matching. Reddit’s pixel technology may process or derive information such as IP or network information, browser or device data, cookie or similar identifiers, page activity, and advertising-interaction data under Reddit’s own privacy practices.
Logs and security data
LeagueBeacon and its hosting or network providers may process request information such as IP address, browser or device information, request path, timestamps, response status, and diagnostic details in server or infrastructure logs. LeagueBeacon uses a one-way hash derived from IP address and email for authentication rate limiting; it does not store the raw IP address in that rate-limit record. Application logs also record operational events and internal identifiers needed to troubleshoot, secure, and administer the service.
5. How we use information
We use information to:
- create, authenticate, recover, and secure accounts;
- connect public Sleeper profiles and import or refresh league data;
- produce league-aware rankings, projections, trade analysis, waiver analysis, draft tools, signals, and other requested features;
- save workspaces, preferences, connected leagues, and trade ideas;
- process subscriptions, determine entitlements, manage promotions, and provide billing support;
- measure product usage, advertising results, and feature performance;
- receive feedback, provide support, troubleshoot, and improve LeagueBeacon;
- prevent fraud, abuse, and unauthorized access; and
- comply with law and protect users, LeagueBeacon, and others.
6. When we disclose information
We disclose information as needed to operate LeagueBeacon, including to these categories of recipients:
- Sleeper: LeagueBeacon sends public usernames, user IDs, league IDs, or similar request parameters to retrieve public fantasy data.
- Stripe: payment processing, checkout, customer portal, subscription administration, fraud prevention, and related billing operations.
- Render: application hosting, persistent storage, network delivery, and operational logging.
- Reddit: advertising measurement, including basic page-visit and signup conversion events. LeagueBeacon does not provide authenticated email addresses, LeagueBeacon user IDs, or other authenticated customer identifiers for advanced matching.
- Email providers: delivery of verification and password-reset emails. Cloudflare Email Routing also routes messages sent to the public LeagueBeacon support address.
- Professional advisers, authorities, or transaction participants: when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or complete a business transaction involving LeagueBeacon.
Public football data sources such as nflverse and GitHub provide data used by the service. Server-side retrieval of those datasets ordinarily does not require sending your LeagueBeacon account information to those sources.
7. Sale and advertising-related sharing
LeagueBeacon does not sell personal information for money. We do disclose information to service providers for the business purposes described above.
LeagueBeacon’s use of Reddit Pixel for advertising measurement may be considered “sharing,” “targeted advertising,” or a similar activity under some privacy laws even though no money is exchanged for the information. You may use browser privacy controls or content-blocking tools to limit pixel activity and may contact us about a privacy request. LeagueBeacon does not currently provide an automated advertising opt-out control.
8. Retention
We retain information for as long as reasonably needed to provide and secure LeagueBeacon, maintain account and subscription records, preserve saved work, resolve disputes, meet legal or accounting obligations, and support legitimate operational needs. Retention varies by data type and account lifecycle.
Expired sessions, temporary tokens, and promotion reservations have application-specific expiration rules. Operational database backups are created on a schedule and the current configuration prunes those backup files after 14 days. Some records may remain longer where needed for billing, fraud prevention, security, legal compliance, or backup integrity. We do not promise a specific deletion period for every record.
9. Security
We use reasonable administrative and technical safeguards designed to protect information. Current controls include one-way password hashing, hashed authentication tokens, access controls for administrative features, request-security protections, transport-security settings in production, and limited handling of payment data through Stripe. No internet service or storage system can guarantee perfect security.
10. Your choices and requests
- You can update certain preferences and disconnect a connected Sleeper profile through LeagueBeacon.
- You can manage or cancel an eligible paid subscription through the Stripe customer portal available from My Account.
- You can sign out to clear LeagueBeacon authentication cookies and use browser settings to clear cookies or browser storage.
- You can use browser privacy settings or content-blocking tools to limit third-party tracking.
- You can contact [email protected] to ask about access, correction, deletion, or another privacy request. We may need to verify the request and may retain information where permitted or required by law.
LeagueBeacon does not currently offer an automated account-deletion tool.
11. Third-party links and services
LeagueBeacon links to or works with third-party services. Their collection, use, and protection of information are governed by their own terms and privacy policies. We encourage you to review those policies before using the third-party service.
12. Children’s privacy
LeagueBeacon is intended only for users who are at least 18 years old and is not intended for anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided personal information to LeagueBeacon, contact us so we can review the situation and take appropriate action.
13. Changes to this Privacy Policy
We may update this Privacy Policy as LeagueBeacon or applicable requirements change. We will post the updated policy on this page and change the effective date. Where appropriate, we may provide additional notice of material changes.
14. Contact
LeagueBeacon is operated by KS Quality Trail LLC, doing business as LeagueBeacon.
Questions or privacy requests may be sent to [email protected].