Privacy Policy

Effective date: May 20, 2026

Last updated: May 20, 2026

Last reviewed: May 2026

The short version

  • We do not sell your personal information. We do not share it for cross-context behavioral advertising.
  • We store your fantasy provider credentials (OAuth tokens, ESPN session cookies) encrypted at rest using AES-256.
  • We collect the minimum we need to run the service: account info, your league data from connected providers, notification preferences, and basic product analytics.
  • You can export or delete your data from inside your account at any time.
  • If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or any other US state with a comprehensive privacy law, see the state-specific sections below for your rights.
  • RosterRush is offered only to residents of the United States and Canada. We do not knowingly offer the Service to residents of the European Economic Area or the United Kingdom.

1. Who we are

RosterRush is operated by RosterRush LLC, a Delaware limited liability company ("RosterRush," "we," "us," or "our"). This Privacy Policy explains what information we collect when you use rosterrush.com (the "Service"), how we use it, who we share it with, and the choices you have.

If you have a question about this policy or want to exercise a privacy right, contact us:

  • Email: [email protected]
  • Mailing address: [VIRTUAL_MAILBOX_PENDING — replace before launch]

2. Information we collect

2.1 Information you give us directly

  • Account information: your email address, name, password (stored hashed with bcrypt), timezone, and notification preferences.
  • Social login profile (optional): if you sign in with Google or Apple, we receive your name, email, and a provider-issued user ID. We do not receive your social account password.
  • Fantasy provider connections: the credentials you supply to let us read your fantasy leagues — Yahoo OAuth tokens, ESPN session cookies (SWID and espn_s2), and Sleeper username. OAuth tokens and ESPN session cookies are encrypted at rest (see Section 7).
  • Subscription and billing data: when you subscribe, our payment processor Stripe collects your payment details. Stripe shares limited information back to us (the last four digits of the card, brand, country, customer ID, and subscription state). We never see or store your full card number or CVV.
  • Support and feedback: messages you send us, including the email address you sent them from.

2.2 Information we collect automatically

  • Usage data: pages you visit, features you use, sync activity, and timing. We use this to operate the Service and improve it.
  • Product analytics: we use PostHog to understand how the Service is used. PostHog is opted out by default; if you click "Accept" on our cookie banner, PostHog captures pageviews and product interactions and we identify you to PostHog by your user ID, email, subscription tier, and founder status.
  • Error and performance data: when something breaks, our error tracker (Sentry) captures the exception, the request that produced it, and the user ID associated with it.
  • Device and connection data: IP address, browser type, operating system, and screen size. IP addresses pass through Cloudflare (our edge network) for DDoS protection and TLS termination.
  • Cookies: session cookies for authentication, a CSRF cookie for security, and (if you accept) analytics cookies for PostHog. See Section 8.

2.3 Information from your fantasy providers

When you connect ESPN, Yahoo, or Sleeper, we read fantasy data from those providers on your behalf:

  • Your leagues, teams, rosters, transactions, and free agent lists.
  • Your provider display name and user ID.
  • Public player information (statistics, ownership percentages, transaction trends).

We do not write back to those providers (we don't add, drop, or trade players on your behalf). We do not access your provider account for anything other than the leagues you connect.

2.4 Things we do not collect

  • Biometric data.
  • Precise geolocation.
  • Government identifiers (Social Security numbers, driver's licence numbers).
  • Information about your activity on other websites.
  • Children's data. The Service is for adults only — see Section 12.

3. How we use your information

We use the information we collect to:

  • Operate the Service: authenticate you, sync your fantasy leagues, monitor player availability, and deliver notifications to your inbox.
  • Bill you: process subscription payments through Stripe; manage gift code redemption; honor founder discounts.
  • Communicate with you: send transactional emails (sign-up confirmations, password resets, billing receipts, expiry warnings, player alerts) and respond to support requests.
  • Improve the product: understand which features are used and where users get stuck.
  • Prevent fraud and abuse: detect and stop credential stuffing, chargeback fraud, and Terms of Service violations.
  • Debug: investigate errors and performance problems via Sentry.
  • Comply with the law: respond to lawful requests, enforce our Terms, and meet our tax and accounting obligations.

We do not use your personal information to train artificial intelligence or machine learning models offered to third parties. Statistical features inside the Service (such as trend scoring) operate on public fantasy data, not on identifying information about you.

4. Who we share information with

We do not sell your personal information, and we do not share it with advertising networks. We do share it with the service providers ("subprocessors") that we need to run the Service. See our subprocessor list for the full list with links to each vendor's data processing terms.

4.1 Categories of recipients

  • Payment processor (Stripe): handles billing, subscription management, the customer portal, and (where applicable) sales tax calculation.
  • Edge network (Cloudflare): serves traffic, terminates TLS, provides DDoS protection and a web application firewall.
  • Error tracking (Sentry): receives exception data and the user ID of the affected user when something breaks.
  • Product analytics (PostHog): receives pageview and event data, tagged with your user ID, email, subscription tier, and founder status — only if you have accepted analytics cookies.
  • Transactional email (Resend): delivers the emails we send you.
  • Fantasy providers (ESPN, Yahoo, Sleeper): we send API requests on your behalf using the credentials you provided.

4.2 Legal disclosures

We may disclose information when we believe in good faith that the law requires it — for example, in response to a valid subpoena, court order, or government request. We may also disclose information to enforce our Terms, protect our rights or property, or protect users' safety.

4.3 Business transfers

If RosterRush is acquired, merged, or sells substantially all of its assets, your information may be transferred to the acquirer as part of that transaction. We will notify you by email at least 30 days before any such transfer takes effect, so you have time to export or delete your data first.

5. Subprocessors

The following vendors process personal information on our behalf. We have current data processing terms in place with each of them, or rely on their published terms where applicable.

Subprocessor Purpose Reference
Stripe Payment processing, subscription billing, customer portal, sales tax DPA
Cloudflare DNS, CDN, DDoS protection, web application firewall, TLS termination DPA
Sentry Application error tracking and performance monitoring DPA
PostHog Product analytics (opt-in via cookie banner) DPA
Resend Transactional email delivery DPA

Hosting: the Service runs on infrastructure operated directly by RosterRush in Toronto, Ontario, Canada, fronted by Cloudflare's global edge network. We do not use AWS, Google Cloud, or Microsoft Azure for application or database hosting.

6. How long we keep your information

Data Retention
Account record For as long as your account is active
Account record after a deletion request Deleted no later than 30 days after the request, with a recovery window during which you can email support to cancel the deletion
Fantasy provider credentials (OAuth tokens, ESPN cookies) Until you disconnect the provider, the credentials expire, or your account is deleted
Notification records 90 days for individual delivery records; aggregated counts indefinitely
Billing records (invoices, receipts, tax records) 7 years, as required by tax law
Error logs and analytics events Retained per Sentry and PostHog default retention (typically 30–90 days for free-tier accounts)
Support correspondence 2 years after the ticket is closed

If you delete your account, we retain billing records as described above (we are legally required to) but the records are dissociated from your active profile and used only for tax and accounting purposes.

7. How we protect your information

We follow the security practices we actually run, not the ones that sound impressive. As of the date of this policy:

  • Encryption in transit: all connections between your browser and the Service use TLS, terminated at Cloudflare's edge.
  • Encryption at rest for credentials: Yahoo OAuth access and refresh tokens and ESPN session cookies (SWID, espn_s2) are encrypted at rest using AES-256 keyed on our application secret. The plaintext never touches the database.
  • Password hashing: account passwords are hashed with bcrypt; we never store passwords in clear text.
  • Session cookies: issued with the HttpOnly and Secure flags; protected with CSRF tokens on state-changing requests.
  • Edge protection: Cloudflare's web application firewall and DDoS mitigation sit in front of all traffic.
  • Logging discipline: we do not log fantasy provider credentials, OAuth tokens, ESPN cookies, or full payment card data; this is enforced by automated tests in our codebase.
  • Restricted access: production database access is restricted to the founder; production secrets are stored in encrypted Kubernetes secrets, not in source control.

No system is perfectly secure. If you discover a vulnerability, please email [email protected] — we will respond and credit good-faith reports.

8. Cookies and tracking

We use a small number of cookies and similar technologies:

Cookie Purpose Duration
Session cookie Keeps you logged in Session, refreshed on use
XSRF token CSRF protection Session
Cloudflare cookies (`__cf_bm`, `cf_clearance`) Bot management and security Up to 30 minutes / up to 30 days
Theme preference (localStorage) Remembers your light/dark mode choice Until you clear browser storage
PostHog cookies (`ph_*`) Product analytics — only set after you accept Up to 1 year

Our cookie banner defaults PostHog to opted-out. PostHog only begins capturing once you click "Accept." You can change your mind at any time by clearing your browser storage for rosterrush.com and refreshing the page.

We do not use advertising cookies, retargeting pixels, or social media tracking pixels. We respect the Global Privacy Control (GPC) signal — if your browser sends GPC, we treat it as an opt-out of any "sale" or "sharing" of personal information for cross-context behavioral advertising (we don't do either, but this codifies it).

9. California privacy rights

This section applies if you are a California resident, under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").

9.1 Categories of personal information we collect

In the last 12 months we have collected the following categories of personal information about California residents:

  • Identifiers — name, email, account ID, IP address, device identifiers.
  • Customer records (Cal. Civ. Code § 1798.80(e)) — billing information held by our payment processor.
  • Commercial information — subscription tier, transaction history, gift code redemptions.
  • Internet or other electronic network activity — pages visited, features used, sync activity, error events.
  • Inferences — your effective subscription tier and engagement state, used to surface upgrade prompts.

The sources, purposes, and categories of recipients for each of these categories are described elsewhere in this policy.

9.2 We do not sell or share your personal information

We do not sell personal information for money or other valuable consideration. We do not share personal information for cross-context behavioral advertising. We have not done so in the past 12 months. For that reason, we do not display a "Do Not Sell or Share My Personal Information" link — there is nothing to opt out of. If this ever changes, this policy will be updated and a link will be added at least 30 days before any sale or sharing begins.

We do not knowingly collect or sell the personal information of consumers under the age of 16.

9.3 Your CCPA rights

  • Right to know what personal information we have collected about you, including the categories, sources, business purposes, and recipients.
  • Right to access a copy of the specific personal information we hold about you. Use the in-app export tool at Settings → Export My Data, or email us.
  • Right to delete your personal information, subject to limited exceptions (for example, billing records we are required to keep for tax purposes). Use Settings → Delete Account, or email us.
  • Right to correct inaccurate personal information. Most fields are editable directly in account settings.
  • Right to limit use of sensitive personal information. We do not use sensitive personal information for purposes beyond what is necessary to provide the Service, so this right does not currently change anything; we list it for completeness.
  • Right to non-discrimination — exercising your privacy rights will not get you charged more, denied service, or otherwise penalized.
  • Right to designate an authorized agent to make a request on your behalf. The agent must provide a signed permission and we may verify your identity directly.

9.4 California "Shine the Light"

California Civil Code § 1798.83 permits California residents to ask once per calendar year for a list of categories of personal information disclosed to third parties for those third parties' direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes, so a Shine the Light request to us will return an empty list.

10. Other US state privacy rights

If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, or any other US state with a comprehensive consumer privacy law, you have rights similar to those described above. In particular, you have the right to:

  • Confirm whether we are processing your personal data, and access it.
  • Correct inaccurate personal data.
  • Delete your personal data (subject to the same exceptions noted in Section 9.3).
  • Obtain a portable copy of your data.
  • Opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. We do not do any of those things, so opt-out requests return nothing to opt out of.
  • Appeal a decision we make about a privacy request.

To exercise any of these rights, email [email protected] with the request and the state you reside in. We will respond within 45 days. If we decline a request, you may appeal by replying to our decision; we will respond to the appeal within 60 days and, where required by your state's law, explain how to file a complaint with your state Attorney General.

11. Canadian residents (PIPEDA)

If you are a resident of Canada, the federal Personal Information Protection and Electronic Documents Act ("PIPEDA") and, where applicable, your provincial privacy law (Quebec's Law 25, BC's PIPA, Alberta's PIPA) apply. You have the right to:

  • Access the personal information we hold about you and have it corrected if it is inaccurate.
  • Know how we are using and disclosing your information.
  • Withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.
  • File a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca, or with your provincial regulator.

Our application and database servers are located in Toronto, Ontario. Some of our subprocessors (Stripe, Sentry, PostHog, Resend, Cloudflare) process data in the United States. By using the Service, you acknowledge that your personal information may be processed in jurisdictions outside of Canada and may be subject to lawful access requests by those jurisdictions' authorities.

Email [email protected] to make an access, correction, or withdrawal request.

12. EU and UK residents

RosterRush is offered only to residents of the United States and Canada. We do not market the Service to residents of the European Economic Area, the United Kingdom, or Switzerland, and we do not intend to operate as a "controller" or "processor" under the EU/UK General Data Protection Regulation.

If you are an EU, UK, or Swiss resident and you have nevertheless created an account, you may contact [email protected] to request access to or deletion of your personal information; we will honor those requests as a matter of policy. However, you should understand that the Service is not designed or operated for EU/UK use, we have not appointed an Article 27 EU Representative or a UK Representative, and we may decline to provide the Service to you. We reserve the right to terminate accounts that we determine are based in jurisdictions where we do not offer the Service.

13. Children's privacy

The Service is for users 18 years of age and older. We do not knowingly collect personal information from children under 13 (or under 16 for California residents). If you believe we have inadvertently collected information from a child, contact [email protected] and we will delete it promptly. This is consistent with the federal Children's Online Privacy Protection Act ("COPPA").

14. How to exercise your rights

You have three ways to exercise your privacy rights:

We will respond to most requests within 30 days. Complex requests may take up to 45 days (60 days for some state appeals), and we will let you know if we need additional time.

15. Security incidents

If we determine that a security incident has compromised the confidentiality, integrity, or availability of your personal information, we will notify affected users without unreasonable delay and, in any event, within 72 hours of confirming the breach, unless law enforcement asks us in writing to delay notification. Notice will be sent to the email address on file and will describe what happened, what information was involved, what we are doing about it, and what you can do to protect yourself. We will also notify the relevant state Attorneys General when required by law.

16. Changes to this policy

We will update this Privacy Policy from time to time. When we make a material change — for example, a new category of personal information, a new subprocessor that handles sensitive data, or a change in how we share information — we will send a notice to the email on file at least 30 days before the change takes effect. Non-material changes (typos, clarifications, updated subprocessor links) take effect when posted. The "Last updated" date at the top reflects the most recent revision.

If you do not agree to a change, you may export your data and close your account before the change takes effect.

17. Contact

Privacy questions and requests: [email protected]

Security reports: [email protected]

General support: [email protected]

RosterRush LLC

[VIRTUAL_MAILBOX_PENDING — replace before launch]

Delaware, United States

Last updated: May 20, 2026

© 2026 RosterRush LLC. All rights reserved.