Privacy Policy
Effective 9 October 2026
1. Who we are
Pitch Gaffer (pitchgaffer.com) is an independent fan-built tool for Fantasy Premier League managers, operated from Thailand. We are the data controller for the personal data described here. Contact: [email protected].
Pitch Gaffer is not affiliated with, endorsed by or connected to the Premier League or Fantasy Premier League.
2. What we collect and why
| Data | When | Why | Where it is stored |
|---|---|---|---|
| Your squad, settings and local history | Always | So the app remembers your team | Only in your own browser (local storage) |
| FPL Team ID you type in | If you import a team | To fetch your public FPL team, transfers and history from the FPL API on your behalf | Your browser; and your account if you are signed in |
| Name, email, profile photo and Google account ID | If you sign in with Google | To create your account and keep you signed in | Google Firebase Authentication |
| Saved team snapshots (history) and linked FPL Team ID | If you are signed in | To sync your history across devices | Google Cloud Firestore, London (europe-west2) |
| Subscription status: plan, renewal date, Stripe customer ID | If you subscribe to Pro | To unlock Pro features and let you manage your subscription | Cloudflare (key-value storage) |
| Payment details (card, billing address) | If you subscribe to Pro | To take payment | Stripe only — we never receive or store your card number |
| IP address and technical request data | Every visit | To deliver the site, prevent abuse and keep it secure | Cloudflare, our hosting provider |
Football data shown in the app (players, fixtures, prices) comes from public sources such as the official FPL API. We request it through our own server, so your IP address is not sent to those sources.
3. Legal bases (UK/EU GDPR)
- Contract — to provide your account and any Pro subscription you buy.
- Legitimate interests — to run, secure and improve the service and prevent fraud.
- Legal obligation — to keep payment and tax records.
For users in Thailand, we process data in line with the Personal Data Protection Act B.E. 2562 (PDPA) on the same bases.
4. Cookies and local storage
We do not use advertising or analytics cookies. We use only what the service needs to work:
- Local storage in your browser for your team, preferences and cached data.
- Google Firebase stores a sign-in session in your browser if you sign in.
- Stripe sets its own cookies on its checkout and billing pages for fraud prevention — see Stripe's privacy policy.
Because these are strictly necessary, we do not show a cookie banner. If we ever add analytics, we will ask for your consent first.
5. Who we share data with
We use these service providers (processors) only to run Pitch Gaffer:
- Google (Firebase) — sign-in and synced history.
- Cloudflare — hosting, security and subscription status storage.
- Stripe — payments, invoices and subscription management.
We do not sell, rent or share your personal data for advertising. We may disclose data if required by law.
6. International transfers
Our providers may process data outside your country, including in the United States. They rely on recognised safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.
7. How long we keep it
- Account data and history — until you delete your account or ask us to.
- Subscription and payment records — as long as required for tax and accounting law (typically up to 7 years).
- Data in your browser — until you clear it.
8. Your rights
You can ask to access, correct, export or delete your personal data, or object to or restrict how we use it. Email [email protected] from the address on your account and we will respond within 30 days. You can also complain to your local data protection authority — for example the UK ICO, your EU supervisory authority, or Thailand's PDPC.
9. Children
Pitch Gaffer is not intended for children under 16. Paid subscriptions require you to be an adult or to have permission from a parent or guardian.
10. Security
Data is encrypted in transit (HTTPS). Access to your synced data is limited to your own signed-in account by our database rules, and payment secrets are kept server-side only.
11. Changes
If we change this policy in a meaningful way, we will update the date above and let signed-in users know in the app.