Privacy Policy
Last updated: 2026-09-18
Draft for product use. Not a substitute for attorney review. Describes practices for Homefield Fantasy at https://homefieldfantasy.com.
This Privacy Policy explains what Homefield collects, how we use it, and the vendors that help run the product. Related documents: Terms of Service · Fantasy / DFS Disclaimer.
1. Who we are
Controller / operator: Homefield Fantasy (legal entity name TBD). Contact: support@homefieldfantasy.com.
2. What we collect
- Account & auth (Clerk): email, user id, session metadata, and profile fields you provide when you sign up or sign in.
- Billing (Stripe): customer and subscription identifiers, payment status, and invoice-related metadata. Card numbers are handled by Stripe — Homefield does not store full card PANs.
- Product settings: sport preference, Sleeper username, CBS league id, and similar preferences you save. We do not collect CBS passwords.
- League / CBS data: when you sync, we process roster, free-agent, scoring, and related snapshots needed to power Season advice. CBS session tokens you paste are kept in browser storage for free use and are sent to Homefield only in the moment of a sync/lookup request (proxy to CBS) — we do not persist host passwords or CBS session tokens in Neon. Pro may store non-secret league hints (e.g., league id / username) in our database.
- DFS uploads: salary CSVs and optimizer sessions you provide. Without an account, DFS CSV sessions typically remain in browser storage only.
- Recommendation & accuracy events: Homefield suggestions, your locked picks, and scored outcomes used for personal accuracy metrics when those features are enabled.
- Transactional email (Resend): welcome / weekly accuracy and similar product email when configured. Contacts are stored in our database (e.g., Neon), not a separate marketing CRM unless we disclose otherwise.
- AI processing: prompts and tool context may be sent to model providers (e.g., Hugging Face Inference; optional OpenAI fallback) to generate analyst answers. Do not paste secrets you do not want processed.
- Technical logs: IP address, user-agent, and request metadata may appear in hosting / edge logs (e.g., Vercel) for security and reliability.
3. Analytics
Homefield does not run third-party product analytics suites or ad pixels (e.g., Google Analytics, Meta Pixel) by default. We record limited first-party funnel events on our own servers (e.g., Neon when configured) so we can measure product steps such as league sync, locks, Ask, DFS CSV import/export, onboarding checklist progress, and free→Pro checkout. Those events use allowlisted names and non-identifying props (sport, provider, outcome, platform, step) — never CBS/Sleeper tokens, emails, usernames, league ids, Ask question text, player names, or CSV file contents. An anonymous session id may be stored in your browser localStorage solely to connect steps without an account. If we add analytics cookies or third-party SDKs later, we will update this Policy and, where required, obtain consent. Server and platform logs from hosting, auth, and payment vendors may still process limited technical data as described above.
4. How we use data
- Provide Season desks, DFS tools, accounts, and Pro features.
- Process payments and prevent fraud / abuse.
- Send transactional product email you request or that is necessary for the service.
- Improve reliability, safety, and recommendation quality.
- Comply with law and enforce the Terms.
5. Processors & third parties
- Clerk — authentication
- Stripe — payments and billing portal
- Resend — transactional email
- Neon (or equivalent) — application database when configured
- Vercel — hosting
- Hugging Face / optional OpenAI — AI inference
- Sleeper / CBS Sports — league data you choose to sync (subject to their terms)
Each vendor processes data under its own policies. Homefield does not sell your personal information.
6. Local-only free use
Without an account, league snapshots and DFS CSV sessions stay in your browser localStorage and are not kept as cloud history on Homefield. Sync still relays your host session token through Homefield to CBS/Sleeper for that request only — tokens are not written to our database. Signed-in / Pro features may persist settings and recommendation events as described above. Do not paste host tokens into Ask; the analyst refuses credential-shaped prompts.
7. Retention
We retain account, billing, and product records for as long as your account is active and as needed for legal, tax, and security purposes. You may request deletion of account-linked data subject to lawful retention needs (e.g., Stripe invoices).
8. Your choices
- Update or disconnect league settings in the product.
- Clear browser localStorage to remove local tokens / DFS sessions.
- Manage subscription and payment methods via Stripe Customer Portal when enabled.
- Email support@homefieldfantasy.com for access, correction, or deletion requests.
9. Children
The service is not directed to children under 13 (or under 16 where that is the applicable digital-consent age). Do not use Homefield if you are under the minimum age for fantasy / DFS in your jurisdiction.
10. International users
The product may be hosted in the United States. If you access it from elsewhere, you understand data may be processed in the U.S. and other locations where our vendors operate.
11. Changes
We may update this Policy. The “Last updated” date will change when we do. Material changes will be reflected on this page.
12. Contact
Privacy questions: support@homefieldfantasy.com