Privacy Policy

EFFECTIVE 15 AUGUST 2026

THE SHORT VERSION

We collect the minimum needed to run an FPL analytics service: your email if you make an account, the FPL team id or squad you choose to give us, and usage analytics so we can see what is broken and what is worth building. Payments go through Stripe — we never see your card number. We do not sell your data. You can delete your account, and everything with it, whenever you like.

This policy explains what Onside Arena (“we”) — the operator of onsidearena.com — collects, why, and what your rights are. It applies to the website, the mobile app shell and our APIs.

1. What we collect

Account basics. If you create an account: your email address, and — if you sign in with Google, Apple or Meta — the stable account identifier and basic profile (name, verified email) those providers share. If you set a password we store only a strong hash of it, never the password itself.

Your FPL data. The FPL team id you submit is a public identifier of a fantasy team, and the squads we read from it come from the official public FPL API. If you use the screenshot import, the image is used to transcribe your squad and the resulting player list is what we keep. We also store product state you create: coach preferences, saved predictions, streaks, league chat messages.

Payments. Handled entirely by Stripe (or the app store on mobile). We store your subscription tier and Stripe customer/subscription ids. Your card details never touch our servers.

Usage and attribution. Pageviews, clicks and product events (analytics), plus first-touch attribution data — UTM parameters, Google Ads click id (gclid), referrer and landing page — stored in a cookie and, if you sign up, on your account row, so we can measure which marketing actually works.

Country, from IP, not stored. To pick a sensible default language we read the country code our CDN (Cloudflare) derives from your IP address (CF-IPCountry). The answer is used in your browser and is not stored on our servers.

2. Why we use it

To provide the service (accounts, ratings, the AI coach, emails you asked for); to improve it (analytics, error tracking, session replay as described below); to measure advertising (Google Ads conversion tracking, and a Reddit ads pixel when a campaign is running); and to meet legal obligations (billing records). Where UK GDPR asks for a lawful basis: performance of a contract for the service itself, legitimate interests for analytics and service protection, and consent where required (e.g. marketing emails, push notifications).

3. Session replay — an honest note

We use PostHog (EU-hosted) for product analytics, including session replay: for a sample of visitors who stay longer than about 50 seconds, we record how the pages were used — scrolling, clicks, navigation — so we can watch where real people get stuck (for example, in the squad importer). Replays are for internal debugging and product work only. Password fields are masked by the recorder. If you would rather not appear in analytics at all, browser tracker-blocking tools will stop it, and you can ask us to exclude you at the contact address below.

4. Cookies we actually set

COOKIEPURPOSELIFETIME
onside_sessionKeeps you signed in (secure, httpOnly authentication session).90 days
onside_attribFirst-touch attribution — remembers how you first arrived (UTM tags, Google Ads click id (gclid), referrer, landing page) so we can measure which marketing works.90 days
onside_langYour language choice (English / Arabic).1 year
onside_anonRandom anonymous id so events from the same browser can be counted as one visitor before you ever sign in. Not linked to your name or email unless you create an account.1 year
onside_signup_convOne-shot flag set at sign-up so the browser reports the sign-up conversion to Google Ads exactly once, then it is deleted.10 minutes (one-shot)
onside_oauth_state / onside_oauth_pkceSecurity tokens (CSRF / PKCE) that protect the Google, Apple and Meta sign-in flows.Minutes — deleted when sign-in completes
ph_* (PostHog)Product analytics and session replay (see below). Served first-party from our own domain.Up to 1 year
_ga / _ga_* (Google Analytics)Google Analytics 4 — visit and traffic-source measurement.Up to 2 years

A few additional short-lived or purely-functional values (e.g. UI preferences, “already saw this popup”) live in cookies or your browser’s local storage; none of them identify you.

5. Third parties we share data with

Only processors that run the service — we do not sell personal data:

  • Stripe — payment processing and subscription billing.
  • Google Analytics 4 — traffic measurement (GA4 property G-313VQC5KQT).
  • Google Ads — conversion tracking for our own ad campaigns.
  • PostHog (EU) — product analytics and session replay, as above.
  • Reddit Ads — conversion pixel, only while a Reddit campaign is configured.
  • Resend — sends our transactional and newsletter email.
  • Cloudflare — CDN, TLS and bot protection in front of the site.
  • Railway — hosting for the application and database.
  • Sentry — error monitoring, which can include request metadata when something crashes.

If you opt in to push notifications, your browser’s push endpoint is stored so we can deliver them (web-push); unsubscribe any time in your browser or account settings. Emails: transactional messages (sign-in links, receipts) are always sent; newsletter and digest cadence is your choice and every marketing email has an unsubscribe link.

6. Retention and deletion

Account data is kept while your account exists. Delete your account from the account page (or email us) and the row is deleted from our database along with its linked data — squads, preferences, subscriptions state, push subscriptions. Billing records are retained by Stripe as required by law. Analytics events age out per the retention settings of GA4/PostHog. Attribution cookies expire on the schedule in the table above.

7. Your rights (UK GDPR)

You have the right to access the personal data we hold about you, to have it rectified or erased, to receive a portable copy, to object to or restrict certain processing, and to withdraw consent where processing rests on consent. Email [email protected] and we will action it — deletion requests are honoured without drama. You can also complain to the UK Information Commissioner’s Office (ico.org.uk).

8. International transfers

We prefer UK/EU processing where offered (PostHog runs on its EU cloud). Some processors (e.g. Google, Stripe, Cloudflare, Railway) operate globally, including in the United States; transfers rely on the processors’ standard safeguards (UK IDTA / EU standard contractual clauses and adequacy frameworks).

9. Children

The service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

10. Changes and contact

We will update this policy as the product changes and flag material changes on the site or by email, with the effective date at the top. Controller: Onside Arena. Contact: [email protected] or the contact form.

See also the Terms of Service.