PPR
Points Per RivalPPR
RivalsLeaguesLog inGet Access
Terms & ConditionsPrivacy PolicyTruth
PPR

© 2026 Points Per Rival

HomeRivalsLeaguesLog in

Legal

Privacy Policy

Last updated May 29, 2026

This Privacy Policy explains what information Points Per Rival ("PPR", "we", "us") collects, how we use it, and the choices you have. It applies to pointsperrival.com and related services.

1. Information We Collect

Account information

When you register or claim a team, we store your email address, username, display name, and a securely hashed version of your password. We never store your password in plain text.

Profile & league content

We store profile details you choose to add (such as a bio or avatar) and the fantasy data entered into PPR — team names, weekly scores, rosters, standings, and league history.

Technical & usage data

To operate and secure the service we log technical information such as IP address, timestamps, and basic request metadata. Failed authentication attempts are logged with IP and timestamp for abuse prevention.

2. How We Use Information

  • To provide, maintain, and improve the PPR service and your league experience.
  • To authenticate you and keep your account and the service secure.
  • To prevent fraud, abuse, and unauthorized access (including rate limiting).
  • To communicate with you about your account, invites, and service updates.

We do not sell your personal information.

3. Cookies & Sessions

PPR uses a single essential, httpOnly session cookie to keep you signed in. It is not used for advertising or cross-site tracking. Disabling it will prevent you from logging in.

4. Third-Party Services

We rely on a small set of trusted providers that process data on our behalf. Each is bound by its own terms and privacy practices:

  • Vercel — application hosting and content delivery.
  • Supabase — managed PostgreSQL database that stores your account and league data.
  • Sleeper API — used to import league, roster, and NFL player data when you connect a league.
  • Resend — sends transactional email (such as password-reset links) from admin@pointsperrival.com.

As features roll out, we may also use an NFL scores provider (for live scoring) and Anthropic's Claude AI (to generate optional matchup recaps). This policy will be updated as those services go live.

5. Data Retention

We keep your information for as long as your account is active or as needed to provide the service. You may request deletion of your account and associated personal data at any time (see Your Rights). Some records may be retained where required for security or legal reasons.

6. Security

We protect data with scrypt password hashing plus a server-side pepper, httpOnly session cookies, database-backed rate limiting on sensitive endpoints, audit logging of sensitive actions, and security headers including a content security policy. No system is perfectly secure, but we work to safeguard your information.

7. Your Rights

You may request access to, correction of, or deletion of your personal data. To exercise these rights, contact admin@pointsperrival.com from the email associated with your account.

8. Children's Privacy

PPR is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will remove it.

9. Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above. Continued use of PPR after an update constitutes acceptance of the revised policy.

10. Contact

Questions about your privacy? Reach us at admin@pointsperrival.com.