Skip to content

Legal

Privacy Policy

What we collect, why, and what you can do about it. The short version: we collect what the product needs to work, we do not sell it, and we do not run advertising or third-party tracking.

Last updated July 28, 2026

We do not sell or share your personal information, and we do not use it for cross-context behavioural advertising. There are no advertising trackers, no analytics pixels and no data brokers involved.

What we collect

When you create an account: your email address and password. The password is hashed by our login provider and is never visible to us.

When you use the site: a display name and timezone if you set them, plus your subscription state and, if you subscribe, an identifier linking you to your Stripe customer record.

To stop repeat free trials: a one-way hash of your IP address and of a random browser id. These are keyed hashes, so the stored value cannot be turned back into your IP address. We keep them to enforce one trial per person and for nothing else.

When you pay: Stripe collects and holds your card details directly. We never receive or store your full card number. We see only what Stripe reports back: your customer id, the plan, the status, and the renewal date.

Automatically: ordinary server and CDN logs, including IP address, browser type and the pages requested, for security and debugging.

Why we collect it

  • To give you an account, keep you signed in, and show you the product.
  • To take payment, manage your subscription and send billing email.
  • To enforce one free trial per person and prevent abuse.
  • To keep the service secure, diagnose faults and prevent fraud.
  • To meet our legal and tax obligations.

We do not use your personal information to train the prediction model. The model runs on match data from our data providers, not on anything about you.

Who processes it for us

These companies handle data on our behalf under contract. We do not sell data to anyone.

ServiceRoleData involved
SupabaseDatabase and loginAccount, profile and subscription records
StripePaymentsCard details, billing address, payment history
ResendTransactional emailYour email address and message contents
RenderHostingRequests to the site, server logs
CloudflareCDN and securityIP address, request metadata

We may also disclose information if the law requires it, or to protect our rights, users or the security of the service.

Cookies

We use a small number of first-party cookies and no third-party advertising or analytics cookies.

sb-* (Supabase auth)

Strictly necessary

Keeps you signed in. Without it you would have to log in on every page.

Kept for: Until you sign out or the session expires

fhs_did

Anti-abuse

A random first-party id used to spot the same browser signing up for repeated free trials. It holds no personal data and is not used for advertising, analytics or tracking you across other sites.

Kept for: About 13 months

You can clear or block these in your browser. Blocking the login cookie will stop you being able to sign in. Blocking the anti-abuse cookie does not affect your access.

How long we keep it

  • Account and profile data: while your account is open, then deleted or anonymised within 90 days of closure.
  • Billing records: as long as tax and accounting law requires, typically seven years. Stripe holds the payment records themselves.
  • Trial anti-abuse hashes: retained after an account closes, because deleting them would let the same person take another free trial. They contain no readable personal data.
  • Server and CDN logs: a short rolling window, typically under 30 days.

Your choices

You can, at any time:

  • See and change your name and timezone, and change your password, from Settings.
  • Cancel your subscription from the billing page.
  • Ask us for a copy of the personal information we hold about you.
  • Ask us to correct anything that is wrong.
  • Ask us to delete your account and personal information.
  • Opt out of non-essential email. Billing and account emails are part of the service and cannot be switched off while you have an active subscription.

Email support@firsthalfscore.com for any of these and we will respond within 30 days. Depending on where you live you may have additional rights under local privacy law, including the right to complain to a regulator. We will not treat you differently for exercising any of them.

Security

Access to the database is restricted by row-level security and column-level privileges, so the application can only read and write what it needs. Passwords are hashed, card data never touches our servers, and traffic is encrypted in transit. No system is perfectly secure, but if a breach affects your personal information we will tell you and any regulator that requires it.

Children

The service is for adults aged 18 and over. We do not knowingly collect information from children. If you believe a child has created an account, email us and we will remove it.

Changes to this policy

If we change this policy materially we will update the date at the top and, where the change affects you, email you or show a notice on the site.

Who is responsible for your data

First Half Score is operated by Vincent Ploum, a sole proprietor based in New York, United States. That is who decides what personal information is collected here and why, and who is accountable for the choices described on this page.

Data is stored and processed in the United States. If you use the service from outside the US, your information is transferred there.

Contact

Email support@firsthalfscore.com with any privacy question, or use the contact page.

Questions about any of this? Email support@firsthalfscore.com. See also our Terms, Privacy Policy and Cancellation and Refunds.