v2.0 — Effective: May 15, 2026
v2.0 — pending counsel review. This is our best-effort compliance baseline. Operator must confirm with legal counsel before launch.
Los Floppers (“we,” “us,” or “our”) operates a soccer media platform that provides pre-game and post-game engines, Flop Ratings, Powder Keg Index scores, and live agree/disagree voting on editorial takes. This Privacy Policy describes how we collect, use, share, and protect information about you when you use our website or mobile application.
The data controller responsible for your personal data is:
Los Floppers Media
[Entity address — operator to fill before launch]
For any privacy-related questions, data access requests, or concerns, contact our Data Protection Officer:
We collect and process the following categories of data:
Anonymous usage. When you vote without an account, your IP address is used solely to enforce rate limits. IP addresses are processed in-memory via Redis and are not stored in our database or linked to any personal profile.
We partner with Google AdSense (web) and Google Ad Manager (mobile) to display advertisements. These networks may use cookies and device identifiers to serve ads based on your interests. Ad code only loads when you grant advertising consent via the cookie banner (or in-app settings on mobile).
We use a minimal set of cookies, all functional. Plausible Analytics is cookieless and does not set any cookies.
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
| sb-*-auth-token | Supabase | Authentication session (essential) | Session / 1 year |
| lf_consent | Los Floppers | Cookie consent preference storage (essential) | 1 year |
Supabase auth cookies use the naming pattern sb-[project-ref]-auth-token and may be chunked across multiple cookies. They are strictly essential for authentication and do not require consent.
| Data category | Retention period |
|---|---|
| Account data | Lifetime of your account + 30 days post-deletion |
| Engagement data | Lifetime of your account; deleted in cascade with account |
| Analytics (Plausible) | 24 months (Plausible default) |
| Error tracking (Sentry) | Per Sentry plan (typically 30 days — operator confirms) |
| Server logs (Railway) | 30 days (Railway default retention) |
| IP rate-limit counters (Redis) | Ephemeral — expires automatically per sliding window TTL; never written to permanent storage |
Server-side structured logs include a request_id and a hashed user_id (HMAC-SHA256). No email, IP address, or raw user ID appears in structured logs.
We share data with the following service providers to operate the platform. Each sub-processor processes data only as instructed and under appropriate safeguards.
| Provider | Company | Country | Purpose |
|---|---|---|---|
| Supabase | Supabase Inc. | US | Authentication + database |
| Vercel | Vercel Inc. | US | Web hosting |
| Railway | Railway Corp. | US | Backend hosting + server logs |
| Sentry | Functional Software Inc. | US | Error tracking (PII scrubbed) |
| Plausible | Plausible Insights OU | EE | Privacy-first analytics |
| Expo | Expo Application Services Inc. | US | Mobile push notifications |
| Google AdSense / Ad Manager | Google LLC | US | Display advertising (only with consent) |
You have the following rights regarding your personal data:
We will respond to all rights requests within 30 days. If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority.
We do not sell your personal informationto third parties. We do not share your personal information for cross-context behavioral advertising. California residents have the right to know, delete, and opt out of the sale of personal information. Since we do not sell personal data, no opt-out mechanism for “sale” is required. All other rights (access, deletion) are available as described in Section 9 above.
Most of our sub-processors are based in the United States (see Section 8). If you are located in the EU/UK/EEA, your data may be transferred to the US. We rely on Standard Contractual Clauses (SCCs) where applicable, as provided by each sub-processor. Plausible Analytics (based in Estonia, EU) processes analytics data within the EU.
Operator note: confirm that DPAs with SCCs are in place with each US-based sub-processor before launch.
We may update this Privacy Policy from time to time. When we make substantial changes, we will notify you via an in-app notification and update the version number at the top of this page.
Version history:
Our service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at dpo@losfloppers.com and we will delete it promptly.
For privacy questions, data access or deletion requests, or any other concerns, contact our Data Protection Officer at dpo@losfloppers.com or visit our contact page.