Privacy Policy
What FPLMan collects, why it collects it, and what you can ask us to do with it.
Last updated
Who we are
FPLMan is an independent Fantasy Premier League companion at fplman.com, built and run by a solo developer. FPLMan is the controller of the personal data described on this page.
For anything about your data, email support@fplman.com.
FPLMan is not affiliated with or endorsed by the Premier League or Fantasy Premier League.
Information you give us
When you create an account and use FPLMan, we store:
- Your email address — it identifies your account, and it is where account and gameweek emails go.
- Your password, hashed — held as a one-way bcrypt hash. We never store or see the password itself. Accounts created through Google have no password at all.
- A team name, if you enter one at signup. It is a label; it can be blank.
- Your FPL manager ID, if you add one. This is what lets FPLMan fetch your squad — see below.
- Your email notification settings — whether gameweek emails are on, and which sections you want in them.
- Anything you send us by email, including support and billing correspondence.
We also keep a record that your email address has been given the free trial. That record is a one-way hash of the address, not the address itself, and it is the one thing that deliberately outlives your account — see how long we keep things.
Your light/dark theme choice is stored by your browser (in local storage) and is never sent to us.
Signing in with Google
You can create an account or sign in with Google instead of a password. FPLMan requests two OAuth scopes only — openid and email — so what Google returns to us is:
- your Google account identifier (the stable sub value), which we store so you keep the same FPLMan account even if you change your Google email;
- your email address, and whether Google has verified it. We only accept a verified address.
We do not request or receive your name, profile picture, contacts, calendar, Google Drive files or anything else from your Google account, and we never receive your Google password. If you later change the email on your Google account, we match you by the account identifier rather than creating a second account.
Google processes your sign-in under its own privacy policy, which you can read at policies.google.com/privacy (opens in a new tab).
Your FPL squad data
If you give FPLMan your FPL manager ID, we send that ID to the official Fantasy Premier League API to read the information attached to that public profile. What we fetch and keep is:
- Your squad for the relevant gameweek — the players, who is on the bench, and your captain and vice-captain picks.
- Your money and transfer state — bank balance, squad value, and the number of free transfers you have, which we work out from your gameweek history.
- Which chips you have played, and in which gameweek.
- Your gameweek history, which is read to derive the two items above.
When you open your mini leagues, FPLMan reads your league memberships and their standings from the FPL API while the page renders. Nothing from those pages is stored — including the other managers in your leagues.
This data comes from Fantasy Premier League, which is operated by the Premier League and is not connected to FPLMan in any way. Sending your manager ID to their API is a request for information they already publish about that entry.
Payments through Stripe
Season Passes are sold and processed by Stripe. Checkout happens on Stripe's own hosted page, not on FPLMan.
What Stripe sends back to us, and what we store against your account, is:
- your Stripe customer ID, so repeat purchases and any refund can be matched to the right account;
- the identifier of the payment that paid for your pass, and the checkout session identifier;
- whether the payment succeeded, failed, was refunded or was disputed, and the date access was taken back if it was;
- the date your Pro access runs to, and how it was granted (trial, paid pass, or complimentary).
We also record the identifiers of the Stripe events we have already processed, so that a repeated notification from Stripe cannot be applied twice. Those records are not linked to an account.
Stripe processes your payment and billing details, and device and fraud-prevention signals, as its own controller and under its own privacy policy — stripe.com/privacy (opens in a new tab). Anything we do not receive, including your card details, we cannot help with; those questions go to Stripe.
Cookies and similar technologies
Strictly necessary — always set, and not optional:
- a session cookie (JSESSIONID), which keeps you signed in and holds the token that protects forms against cross-site request forgery. It is deleted when you sign out;
- Google's own cookies, set on Google's domains while you complete a Google sign-in;
- Stripe's own cookies, set on Stripe's domain while you complete checkout, including for fraud prevention;
- a consent cookie (fplman_consent), which remembers your answer to the cookie banner for 180 days so you are not asked again;
- your browser's local storage, for the light/dark theme setting. Not a cookie, and never sent to us. One more thing is stored there once you accept the optional cookies below — see that section.
Optional — only after you accept them in the cookie banner:
- A note of what has already been counted. Once you have accepted either group, your browser also stores a short list of the one-off events it has already reported — a purchase confirmation re-opened, a trial ending — so the same thing is not counted twice. It is local storage rather than a cookie, it is written only after something has actually been reported, and it is never sent to us or to anyone else.
- Analytics. Google Analytics 4, loaded through Google Tag Manager, so we can see which pages and features get used and how people move through the site. Like the pixel below, it is not loaded at all unless you accept analytics cookies — decline, and your browser never contacts Google. What is sent is anonymous usage data: the page path, the page title, and named events such as a squad being synced or a checkout being started. Never your email address, your username, your account or FPL manager id, or the players and teams in your squad — the analytics code carries a fixed list of properties it is allowed to send, and drops anything else. The one exception to "no identifiers" is a purchase, which carries a scrambled one-way code standing for the checkout, so that re-opening the confirmation page is not counted as a second sale. It cannot be turned back into your order, your payment or you;
- Marketing. The Meta (Facebook) pixel, which lets us measure and target the advertising that brings people to FPLMan. It is not loaded at all unless you accept marketing cookies — decline, and your browser never contacts Meta.
Loading either of these means a request to Google or Meta, and any request to another company's servers carries your IP address and browser details to them — the same as the font request named below. Declining is what prevents it: nothing is requested at all.
Until you answer the banner, both groups are switched off: we run Google's Consent Mode with analytics storage, ad storage, ad user data and ad personalisation all set to denied, and the events described above are held back rather than sent. Closing the banner without choosing counts as declining everything optional.
You can change your mind at any time — Cookie preferences at the bottom of every page reopens the choice, and turning a group off applies from that moment.
One thing worth naming: the site loads its typefaces from Google Fonts, so your IP address and browser details reach Google when a page loads its fonts. No cookie is set for this, but it is a request to a third party.
Technical and usage information
Running the service produces some data about requests rather than about you directly:
- Server and proxy logs — the request path, the response status, timings, and the IP address and browser identification the request arrived with.
- Error logs, including stack traces, when something fails.
- Authentication and security events — sign-ins, failed sign-ins, verification and password activity.
- Aggregate product counts — how many accounts exist, how many have linked a manager ID, how many hold a pass. These are counts only; no account details pass through them.
- A cookieless visitor count. To know roughly how many people are on the site, FPLMan keeps a salted one-way hash of IP address plus browser identification, with a salt that is thrown away and replaced every day. The hash cannot be reversed and cannot be matched across days, it is held only in memory, and it is not linked to your account.
Logs and aggregate counts are sent to our monitoring provider so problems can be diagnosed.
What we use it for
- Creating and running your account, and signing you in.
- Fetching and keeping your FPL squad in sync.
- Producing the projections, suggestions and other features, free and Pro.
- Taking Season Pass payments and opening or closing Pro access accordingly.
- Sending the gameweek emails you have switched on, and account emails such as address verification.
- Answering your support and billing emails.
- Keeping the free trial to one per person, and preventing abuse of Pro access.
- Protecting the service against attacks and unauthorised access.
- Finding and fixing errors, and keeping the site up.
- Meeting legal, accounting and tax obligations.
- Measuring how the site is used, and — if you accept marketing cookies — measuring and targeting the advertising that brings people to FPLMan.
We do not sell your data, and we do not send marketing email.
Nothing you have given us — your account, your email address, your squad — is used for advertising or sent to an advertising platform. What the optional cookies described above send is anonymous browsing activity on this site, and only if you accept them: with marketing cookies accepted, Meta learns that a visitor it recognises took an action here, and may use that for ad targeting and measurement. Decline them and none of it happens.
Legal bases (GDPR)
Where the GDPR applies, we rely on:
- Performance of a contract — running your account, signing you in, syncing your squad, providing free and Pro features, taking payment and granting the access you bought, and sending the gameweek emails that are part of the product.
- Legitimate interests — security and abuse prevention, keeping the trial to one per person, operational logging, error diagnosis, reliability, and aggregate counts of how the product is used. We have kept each of these to what the job needs: the visitor count is a rotating one-way hash rather than a profile, and product metrics are counts rather than records.
- Legal obligation — payment, accounting and tax records.
Consent is the basis for one thing, and one thing only: the optional analytics and marketing cookies. Nothing in either group is set, and no data is sent to Google Analytics or Meta, until you accept it in the cookie banner. You can withdraw that consent at any time from Cookie preferences in the footer, and withdrawing it applies from that moment — it does not undo what was already sent.
Everything else the site does is covered by the bases above. The email settings let you switch product emails off rather than opting into extras, and we send no marketing email.
How long we keep things
- Your account and everything attached to it — for as long as your account exists. Deleting your account deletes it: your account record, saved squads, transfer plans, chip history, email settings, email log and payment references all go with it, in one operation.
- The one-way hash of your email address that records the trial having been given — kept indefinitely, on purpose. Without it, deleting an account and signing up again would reset the free trial for ever. It is a hash with no account attached, so it can answer "has this address had a trial?" and nothing else.
- Payment records — held by Stripe under its own retention rules and applicable accounting law, and not removed by deleting your FPLMan account. Stripe's records are how a payment can still be traced, refunded or evidenced after the account is gone.
- Processed payment-event identifiers — kept indefinitely. They are identifiers with no account link, and discarding them would let a repeated notification be applied twice.
- The visitor hash — discarded daily when the salt rotates, and on any restart.
Logs and monitoring data are kept for a limited period, for diagnosis and security, and then discarded. We have not yet fixed a single retention window for them across the hosting and monitoring providers; when we do, it will be stated here. If you want to know what is currently held about a specific request or period, ask us.
Who else processes your data
FPLMan uses a small number of providers. Each is used for one job:
- Google — sign-in, serving the site's typefaces, and — only with your consent — Google Tag Manager and Google Analytics, which measure how the site is used (privacy policy (opens in a new tab)).
- Meta — the advertising pixel, and only with your consent to marketing cookies. Without that consent it is never loaded and your browser never contacts Meta (privacy policy (opens in a new tab)).
- Stripe — payment processing (privacy policy (opens in a new tab)).
- Mailgun — sending email. Your address and the contents of the email pass through it (privacy policy (opens in a new tab)).
- Hetzner Online — hosting. The application and its database run on Hetzner servers in the EU (privacy policy (opens in a new tab)).
- Grafana Labs — where logs and aggregate metrics are sent for monitoring (privacy policy (opens in a new tab)).
- Fantasy Premier League — the source of all football and squad data. Your manager ID is sent to their API to read your entry.
Two more providers are worth naming for completeness, because they process content rather than anything of yours: AssemblyAI transcribes public podcast episodes, and Anthropic analyses those transcripts and public news articles into per-player summaries. Your account data, your email address and your squad are never sent to either.
Where your data goes
The application, its database and your account data are hosted in the EU. Some of the providers above are based outside the EEA, or may process data outside it — Stripe, Google, Meta, Mailgun and Grafana are all US-headquartered — so using FPLMan involves transfers out of the EEA.
The optional analytics and marketing cookies are the part of that you control: decline them and nothing is sent to Google Analytics or Meta at all.
Those providers publish the safeguards they rely on for such transfers, typically the European Commission's standard contractual clauses or a Data Privacy Framework certification. We have not yet reviewed and recorded each provider's mechanism individually, so this policy does not claim more than that. Ask us and we will tell you what we know about a specific provider.
Your rights
If the GDPR applies to you, you have the right to ask for access to the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable form. Where we ever rely on consent, you can withdraw it at any time.
Email support@fplman.com from the address on your account and say what you want. We will not charge you for it, and we will come back to you within one month. If we cannot do what you asked, we will explain why.
You also have the right to complain to a data protection authority. You can complain to the one in the country where you live or work.
Deleting your account
You can delete your account yourself, at any time, from your settings page. It asks you to type your email address to confirm, and your password as well if your account has one. There is no waiting period and no email to us required — the account and its data are removed immediately.
Two things survive that, and both are deliberate:
- the one-way hash that records the free trial having been used, so the trial stays one per person;
- the payment records held by Stripe, which are financial records rather than application data.
If you delete your account while you still hold a Season Pass, you give up whatever is left of it. If you would rather ask us to do it, or want to check what would be removed first, email support@fplman.com.
Children
FPLMan is not designed for children and you need to be at least 16 to have an account. We do not knowingly collect data from anyone younger. If you believe a child has created an account, email support@fplman.com and we will remove it.
Changes to this policy
If this policy changes we will update the page and move the "last updated" date at the top. If a change materially affects how we use your data, we will tell account holders by email before it takes effect rather than relying on you noticing the date.
Questions, corrections and complaints all go to support@fplman.com.