Privacy Policy

Last updated: July 31, 2026

1. Introduction

Remontada ("we", "us", or "the Service") operates a fantasy football platform available to users worldwide. We respect your privacy and are committed to protecting your personal data in accordance with applicable data protection laws, including the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the CPRA, Brazil’s LGPD, Canada’s PIPEDA, Australia’s Privacy Act, and other comparable regional privacy frameworks.

This Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and the rights you have over it — wherever in the world you are located.

2. Data we collect

Account data: Your name, email address, display name, and avatar — provided when you register.

Device & network data (fraud prevention): To protect the integrity of our contests and help ensure one person cannot create multiple accounts, we automatically collect and process a device fingerprint (a hash derived from your browser and device configuration) and your public IP address when you complete onboarding. This is a legitimate interest measure under GDPR Article 6(1)(f) and a business purpose under the CCPA.

Usage data: Information about how you interact with the Service (contests joined, draft activity, scoring results) needed to run the game.

Optional phone number: If you choose to provide a phone number for identity verification, it is processed only for that purpose and stored securely.

3. Why we collect device & network data

We use device fingerprints and IP addresses solely to detect and prevent multi-accounting, fraud, and abuse so that contests remain fair for all participants. A device fingerprint match is treated as a strong signal that the same device may be linked to more than one account; a shared IP address is treated as a weak signal only (because IPs can be shared across networks, NATs, and VPNs) and never blocks access on its own.

We do not sell your personal data to third parties, and we do not use device fingerprints to track you across other websites or services.

4. Legal bases for processing (GDPR / UK GDPR)

We process your personal data under the following lawful bases:

  • Performance of a contract — to create and run your account and contests.
  • Legitimate interests — to prevent fraud, multi-accounting, and abuse.
  • Consent — for any optional data (such as a phone number) you explicitly provide.
  • Legal obligation — where we are required to retain data by law.

5. Third parties we rely on

We use trusted service providers that process limited data on our behalf under data processing agreements:

  • Hosting & infrastructure — to store and operate the Service.
  • IP lookup — a third-party endpoint (ipify) determines your public IP address at onboarding for fraud detection.
  • Email delivery — to send you account and contest notifications.

Where your data is transferred outside your region (for example, to providers in the United States), we rely on appropriate safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms recognized by your jurisdiction.

6. Data retention

We keep your account data for as long as your account is active. Device fingerprints and IP addresses collected for fraud prevention are retained for the lifetime of your account and for a reasonable period afterward to support ongoing abuse prevention, unless a shorter retention period is required by your local law.

7. Your rights

Depending on where you live, you may have some or all of the following rights:

  • Access / know: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure / deletion: Request deletion of your account and associated data, subject to legal exceptions.
  • Restriction & objection: Ask us to limit or stop certain processing.
  • Portability: Receive your data in a structured, machine-readable format.
  • Withdraw consent: Withdraw consent for optional processing at any time.
  • Opt-out of "sale" or "sharing" (CCPA/CPRA): We do not sell your data. You may still request that we not share it for cross-context behavioral advertising.
  • Lodge a complaint: With your local data protection authority (e.g. your national DPA in the EU/UK, or the California Attorney General).

To exercise any of these rights, contact us using the details in Section 9. We will respond within the timeframe required by your applicable law (generally 30 days).

8. Children’s privacy

The Service is not directed at children under the age of 16 (or the higher age required by your local law, such as 13 under COPPA where parental consent applies). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

9. Contact us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact Base44 support through the app’s support channel. We will verify your identity before acting on requests involving your personal data.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be posted here with an updated “Last updated” date. Where required by law, we will notify you of significant changes affecting your rights.