← Back to Tactixity
Privacy Policy
Last updated: August 17, 2026
1. Who We Are
Tactixity is operated by FAMPARS. We offer three independent fantasy sports products — FPL, NFL, and NBA. This policy explains what data we collect, how we use it, who we share it with, and how you can contact us. Contact: [email protected]
2. Data We Collect
- Account and sign-in: your email address; if you sign in with Google, your Google account identifier and verified email address (we do not store your Google sign-in token itself)
- FPL Manager ID — a public identifier you provide, used to look up your public FPL data. We do not persistently store your FPL data on our servers beyond a short, temporary cache measured in minutes. A Manager ID tied to your account may also be remembered in your own browser so you don't need to re-enter it.
- Sleeper username and league data (NFL/NBA) — entered by you, used to fetch your public roster, matchup and league information from Sleeper's API
- Billing identifiers — customer, subscription and transaction references from Paddle, our payment processor, plus your subscription status and relevant billing dates. We never receive or store your card number.
- Chat messages and display name — if you use community chat, your chosen display name and message content are stored so chat history can be shown to other members of that product's chat room
- Support messages — if you contact Support, your message, our response, and related status information, linked to your account
- Measurement data (only with your permission) — if you select "Allow measurement" in Privacy Choices, we store an anonymous/session identifier and campaign data such as UTM parameters, ad click identifiers (e.g. gclid), referrer and landing page. This is never collected if you have not allowed it, or after you reject it.
- Push notification data — if you enable push notifications, your Manager ID and the push subscription details your browser provides
- Basic technical data — collected automatically by our web server (see Section 13)
3. How We Use Data
- To provide chip, captain and transfer recommendations (FPL), and start/sit, waiver, and trade recommendations (NFL/NBA)
- To manage your account, subscription, and billing
- To operate community chat (message history, moderation, and abuse prevention)
- To provide Support and respond to your requests
- With your permission, to measure which campaigns and referrals bring visitors to Tactixity and improve the product
- To send push notifications you have opted into
- To maintain security and prevent abuse of the service
4. Sign-In and Sessions
You can sign in with Google or, in limited legacy cases, with an emailed sign-in link.
- When you sign in with Google, we verify the identity token Google gives us and store your Google account identifier, your verified email, and the fact it was verified. We never store the Google token itself.
- A Google-authenticated session is kept in a secure, HttpOnly cookie — not readable by page scripts, sent only over an encrypted connection, and valid for seven days.
- A limited legacy sign-in method (an emailed link) instead keeps a sign-in token in your browser's local storage.
- If you link a Google account to an existing Tactixity account, we require proof of ownership of both accounts first — this protects against someone else linking your account without your consent.
- Signing out clears your session cookie and any local sign-in token stored in that browser.
5. Measurement and Privacy Choices
Some browser storage is necessary for Tactixity to work at all: staying signed in, remembering your Manager ID, your theme preference, free-tool usage limits, and completing checkout. This necessary storage is never subject to a choice.
Separately, we use optional storage only to measure which campaigns and referrals bring visitors to the site — an anonymous/session identifier, UTM parameters, ad click identifiers (gclid), referrer, and landing page. This is off by default:
- It is only created if you select "Allow measurement" in the Privacy Choices banner or footer link.
- If you select "Reject non-essential," we do not create or send this measurement data, and any measurement data already stored is cleared immediately.
- Rejecting measurement never blocks you from using the product, previewing your team, or completing checkout — a rejected checkout simply excludes this measurement data from what we send to our payment processor.
- You can change your choice at any time using "Privacy choices" in the site footer.
We keep a record of your choice itself (accepted or rejected, with a timestamp) so we can remember and respect it on later visits.
6. Payments and Paddle
All checkout and billing is handled by Paddle, our payment processor and merchant of record. Paddle collects your payment details directly — we never see or store your card number or other raw payment credentials.
- We store the payment-related identifiers Paddle provides (customer, subscription, and transaction references), your subscription status, and relevant billing dates, so we can grant and manage your access.
- At checkout, we send Paddle the product/plan you're purchasing and a secure, one-time reference that lets us confirm the purchase belongs to your account. If you have allowed measurement (Section 5), we also send the campaign data described there; if you have not, we don't.
- Paddle's checkout only loads when you start a trial or purchase — not before. As part of operating checkout, Paddle automatically loads its own bundled billing/subscription analytics service (part of Paddle's "Retain" product). We do not separately initialize, configure, or send extra data to this service ourselves. Paddle Checkout itself is what's required to process your purchase; ProfitWell/Retain is loaded by Paddle as part of that checkout integration, and loads regardless of your measurement choice.
Paddle's own privacy policy governs how Paddle itself handles your payment data: paddle.com/legal/privacy
7. AI Processing
Anthropic (Claude) is the only AI provider we use in production.
- FPL narration (paid feature): we send only the minimum sport data needed to write the explanation — deterministic chip recommendations and squad performance figures. We do not send your FPL Manager ID, team name, or email to Anthropic for this.
- NFL/NBA narration (paid feature): we send matchup, waiver, trade, or streaming output already produced by our own recommendation engine — not an account identifier.
- Support: we send the text of your Support message so the AI can help answer it. We do not automatically add your email, user ID, or Manager ID to that request — only the message text itself. If you choose to include personal information in your message, that text is included, because you wrote it.
A small number of routine Support questions (such as "where do I find my Manager ID") are answered automatically without any AI call. AI-assisted Support responses are stored as part of your Support history (Section 8); sport narration responses are shown to you and are not kept as a separate history.
Anthropic's own privacy policy governs how Anthropic processes this data: anthropic.com/legal/privacy
8. Support
If you contact Support, we store your message, our response (AI-assisted or from our team), a category and priority, status, and related timestamps, linked to your account so we can maintain your support history and respond to you.
- A high-priority ticket may trigger an internal alert to our team — this alert contains only a ticket reference, category, priority, and timestamp, never your message content, email, or Manager ID.
- Support messages currently have no fixed automatic deletion period; we keep them while reasonably needed to provide support, resolve disputes, and meet legal obligations, subject to your rights in Section 14.
- Support is available to signed-in users.
9. Community Chat
- If you use community chat, we store your account, the sport/product room, your chosen display name, your message, its moderation status, and when it was sent.
- Chat rooms are separated by product, and joining one requires an active subscription to that product.
- Chat messages are automatically deleted once they are more than 90 days old, or once a room holds more than 500 messages — whichever happens first — except while a message is held under an active moderation report.
- We may retain reports, bans, and other moderation records for as long as reasonably needed for safety and abuse prevention.
10. Push Notifications
If you enable push notifications (FPL), we store your Manager ID together with the push subscription details your browser provides, so we can send you the notifications you asked for. Turning notifications off in your browser stops delivery to that browser, but does not by itself delete the stored subscription record on our servers — that record is removed via a verified privacy request or routine operational cleanup.
11. External Services and Data Sharing
We do not sell your data. We share data only as needed to provide the product, with the following providers — each of which also processes data under its own privacy terms:
- Google (Google Identity Services) — for sign-in
- Paddle, including its bundled ProfitWell/Retain billing-analytics service — for payments, subscriptions, and billing
- Anthropic — for AI-assisted narration and Support (Section 7)
- The official Fantasy Premier League API — to fetch the public FPL data tied to the Manager ID you provide
- Sleeper's public API — to fetch the public roster/league data tied to the username and league you provide (NFL/NBA)
- Telegram — for sanitized, internal critical-alert notifications to our own team only (Section 8)
FAMPARS operates Tactixity directly. FAMPARS is not a separate outside company we share your data with — it is us.
12. Data Retention
- Chat messages: up to 90 days or 500 messages per room, whichever comes first, except while held for an active moderation report.
- Technical/security logs: our web server's access logs are currently kept approximately 14 days under our log rotation; application logs are limited by size and rotation.
- Account and subscription information: kept while your account or subscription is active, and afterward as needed for security, dispute resolution, or legal obligations.
- Support messages and measurement/attribution records: we currently have no fixed automatic deletion period for these. We keep them while reasonably needed for support, security, product measurement, fraud prevention, dispute resolution, and business records, subject to a manual privacy request (Section 14) and any legal obligations.
- Push subscription data: kept while your subscription is active, or until removed via a verified privacy request or routine operational cleanup.
- Paddle billing records: controlled by Paddle under its own retention and legal obligations, separate from our own records.
13. Security and Technical Logs
- All data in transit is encrypted via HTTPS.
- Our web server automatically logs routine technical request information — such as IP address, requested page, referrer, and browser/user agent — for security and troubleshooting, kept per Section 12.
- We do not intentionally log your authentication tokens, session cookies, or full request contents. We do not claim our internal logs are entirely free of any internal reference used for troubleshooting.
- Payments are handled by Paddle under PCI DSS compliance.
14. Your Choices and Rights
- Privacy Choices: allow or reject optional measurement storage at any time using "Privacy choices" in the site footer (Section 5).
- Access, correction, export, or deletion: you can request any of these at any time by emailing [email protected]. We do not currently have a self-service deletion or export tool, so these requests are handled manually by our team.
- Before acting on a request, we verify it genuinely comes from you — for example, through your signed-in account or another way of confirming account ownership. We do not act on a request based only on an unverified email claiming to be you.
- Some information may need to be retained even after a deletion request — for example, minimum billing, security, or legal records we're required to keep, and billing records that remain under Paddle's own control.
- We aim to respond to and complete verified requests promptly, but we do not promise instant or unconditional deletion, particularly where a legal, security, or billing obligation applies.
- Some data lives only in your own browser — such as a remembered Manager ID or your Privacy Choices selection. Deleting your account on our servers does not remotely clear that browser's local storage; you can clear it yourself using Privacy Choices or your browser's "clear site data" option.
This policy describes our actual data practices. It is not a guarantee of compliance with any specific law in every jurisdiction.
15. Contact
[email protected]