Privacy Policy

Last updated: August 2026

This Privacy Policy describes how NFL Records Pool (“we,” “us,” or “our”) collects, uses, and handles personal information when you use nflrecordspool.com (“the Platform”). By accessing or using the Platform, you agree to the practices described here. For details on how your pick submission data is used within the pool itself, see our Terms of Data Use.

1

Information We Collect

Information you provide directly.

When you create an account or join a league, we collect your name, email address, and display name. If you were invited by a league commissioner, your email address was used to generate your invitation link.

Activity data.

We collect data generated through your use of the Platform, including pick submissions, projection history, scoring results, and participation in pool features such as Survivor and Season Points.

We also record the date and time you last visited the Platform. The commissioner sees this as an approximate value (for example “Today,” “3d,” or “2w”) alongside whether your entry is complete, so that reminders go to people who still need to submit and not to people who already have. This is visible only to the commissioner and is never shown to other participants.

Automatically collected data.

When you visit the Platform, we and our third-party service providers automatically collect certain technical information, including your IP address, browser type, device type, pages visited, and referring URLs. This data is collected via cookies and similar tracking technologies described in Section 3.

2

How We Use Your Information

We use the information we collect to:

  • Operate the Platform and manage your account and league participation
  • Calculate standings, scores, and results in real time
  • Send account and pool-related notifications to your email address
  • Analyze usage patterns to improve the Platform
  • Detect and prevent abuse or unauthorized access

We do not use your information for advertising or sell it to third parties. See our Terms of Data Use for additional detail on how pick submission data is used in pool modeling.

3

Cookies and Tracking Technologies

Authentication session cookie.

When you sign in, we store a session cookie in your browser to keep you authenticated. This cookie is essential for the Platform to function and cannot be opted out of while signed in.

Product analytics (PostHog) — linked to your account.

We use PostHog to understand how the Platform is used. It records page views, clicks and other interactions with the interface, and session duration.

While you are signed in, this activity is not anonymous. We pass your account identifier and your email address to PostHog so that usage events are attributed to your account. This means the commissioner can see the activity of a named, signed-in participant — for example, which pages you visited and when. We use this to find where players get stuck, not to monitor individuals. While you are signed out, no user profile is created and events are not associated with you.

PostHog may also capture session replay — a reconstruction of your interactions with a page — for the same product-improvement purpose. Text you type into form fields is masked by PostHog's default input masking.

PostHog processes this data on servers in the United States, in accordance with PostHog's Privacy Policy. If you would like your analytics data disassociated from your account or deleted, contact the commissioner via the feedback form and we will action it.

Traffic analytics (Vercel) — anonymous.

We use Vercel Web Analytics for aggregate traffic statistics. Unlike PostHog, this one genuinely is anonymous: it sets no cookies, does not receive your email address or account identifier, and identifies visitors only by a temporary hash that is discarded after 24 hours. It is processed in accordance with Vercel's Privacy Policy.

Administrative testing cookie (commissioner only).

The Platform includes an administrative feature that allows the commissioner to temporarily adopt a test context — simulating a specific league member's view of the Platform for support and verification purposes. This is a read-only simulation used exclusively by the commissioner; it does not modify another user's account, data, or picks, and is not used to act on another user's behalf without their knowledge. This session state is stored as a short-lived cookie scoped to the commissioner's browser session.

4

Administrative Access to User Data

The Platform commissioner (site administrator) has elevated access to participant data for the purpose of operating the pool. This includes:

  • Viewing all participant pick submissions and scoring history
  • Editing a participant's picks on their behalf (e.g., to correct a submission error at a participant's request)
  • Managing account details, league assignments, and invitation links
  • Viewing anonymized pick distribution data across all participants
  • Viewing an approximate last-visit date, entry completion status, saved-but-unsubmitted drafts, and reminder-email history, in order to follow up with participants who have not finished entering

Administrative access is limited to the commissioner and is used solely to operate and maintain the pool. Administrative actions that modify participant data are taken only at the request of or with the knowledge of the affected participant.

5

Third-Party Services

The Platform is built on and integrates with the following third-party services, each of which processes some portion of your data:

  • Supabase — database storage and authentication. Your account credentials and all pick data are stored in Supabase.
  • Vercel — hosting and edge delivery. Your requests to the Platform are served through Vercel's infrastructure.
  • PostHog — product analytics, hosted in the United States. Usage events are sent to PostHog, and while you are signed in they carry your account identifier and email address. See Section 3.
  • Vercel Web Analytics — anonymous aggregate traffic statistics. No cookies, no email address, no account identifier.
  • Resend — delivery of sign-in links and pool notification emails to your email address.
6

Data Retention and Security

We retain your account data and submission history for the duration of your account. You may request deletion of your account and associated data by contacting the commissioner or using the feedback form.

We take reasonable technical measures to protect your data, including HTTPS encryption in transit and database-level access controls through Supabase's row-level security policies. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

7

Your Rights

Depending on your jurisdiction, you may have rights regarding your personal data, including the right to access, correct, or request deletion of your information. To exercise any of these rights, contact us via the feedback form or reach out through your account email.

California residents may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected and the right to request deletion.

8

Changes to This Policy

We may update this policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Continued use of the Platform after changes are posted constitutes acceptance of the revised policy.

9

Contact

Questions about this Privacy Policy? Use the feedback form or reach out through the contact information in your account settings.