PRIVACY POLICY
PointStack Fantasy Hub, LLC ("PointStack," "we," "us," or "our") operates the PointStack web application. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
INFORMATION WE COLLECT
When you create an account and connect your fantasy platforms, we collect:
- Account information — your email address, password (hashed, never stored in plaintext), and optional display name
- Platform credentials — Sleeper username; ESPN session cookies (espn_s2, SWID); Yahoo OAuth access and refresh tokens; Fantrax Secret ID. These are stored so your platforms reconnect automatically when you log in.
- Payment information — we use Stripe to process payments. We store only your Stripe customer ID. Card numbers and billing details are handled entirely by Stripe and never touch our servers.
- Usage data — basic server logs (request timestamps, errors). We do not use analytics tracking cookies or third-party ad trackers.
If you sign up for the waitlist, we collect only your email address.
HOW WE USE YOUR INFORMATION
- To authenticate you and maintain your session
- To connect to your fantasy platforms and fetch your league, matchup, and roster data
- To process your one-time payment and verify your subscription status
- To send transactional emails (account confirmation, payment receipts, pre-season reminders). We do not send marketing email without your explicit opt-in.
HOW WE STORE YOUR INFORMATION
Account data and platform credentials are stored in Supabase, a managed database platform with encryption at rest and in transit. Platform credentials (cookies, tokens) are stored in your account record and transmitted only to our server-side proxy functions — they are never exposed in client-side code or browser storage.
Payments are processed by Stripe. Their privacy policy governs how they handle your billing information.
Transactional emails are sent via Resend. Your email address is passed to Resend solely for the purpose of delivering that message.
THIRD-PARTY FANTASY PLATFORMS
PointStack connects to Sleeper, ESPN, Yahoo Fantasy Sports, Fantrax, and CBS Sports Fantasy using credentials you provide. By connecting a platform, you authorize PointStack to access your fantasy data on that platform on your behalf.
PointStack is an independent tool and is not affiliated with, endorsed by, or sponsored by Sleeper, ESPN, Yahoo, Fantrax, CBS Sports, or any of their parent companies.
DATA SHARING
We do not sell, rent, or trade your personal information. We do not share your data with advertisers or data brokers. The only third parties that receive your data are the infrastructure services necessary to operate PointStack (Supabase, Stripe, Resend), and only to the extent required for those services to function.
DATA RETENTION
Your account data is retained while your account is active. If you delete your account, your data is removed within 30 days. Stripe retains payment records per their own retention policies and applicable financial regulations.
YOUR CHOICES
- Disconnect a platform — you can remove any platform connection at any time from the Manage Accounts panel. This deletes the stored credentials for that platform.
- Delete your account — email us at support@pointstack.app and we will delete your account and associated data.
- Access your data — you may request a copy of the data we hold about you by emailing us.
CHILDREN'S PRIVACY
PointStack is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
CHANGES TO THIS POLICY
We may update this policy as the service evolves. We will post the updated policy here with a revised date. Continued use of PointStack after changes constitutes acceptance of the updated policy.
CONTACT
Questions about this policy? Email us at support@pointstack.app.