Privacy policy

Last updated 30 September 2026

Who we are

Mihailo Todosić operates Table Pundit (tablepundit.com). Contact us at hello@tablepundit.com. We are the controller of personal data for this service.

What we collect

When you use Table Pundit, we process:

  • Your email address and display name, to create and run your account.
  • Your predictions, chip and weekly swap use, and mini-league names and memberships, to run the game.
  • Login codes (stored as a hash, and they expire after 10 minutes) and a session cookie after you verify.
  • Your email address and the IP address supplied by our trusted proxy are used to prevent abuse of login codes and anonymous notification analytics. We store only short-lived HMAC-derived pseudonymous rate-limit subjects, counters, and reset times; we do not store the raw email address or IP address in the rate-limit table.
  • When you are signed in, the date and time you enter the app, recorded once per reporting day, so we can understand aggregated usage. We do not record every page view or session duration.
  • Your optional country, if you choose to provide it in Account. If the service is configured with a trusted hosting-country header, we may save a best-effort country code when you first create an account; you can correct or clear it.
  • If you first arrive through a campaign or referral, first-touch attribution such as UTM source, medium, campaign, referring hostname, landing path, and capture time. We hold this in first-party browser storage until signup or browser storage is cleared, then attach it to a new account. Invite codes are stored separately; we do not store full referrer URLs, IP addresses, or browsing history.
  • PWA signals: when a browser confirms an installation, and when a signed-in app opens in standalone mode, and whether an install recommendation was dismissed. These are separate from push-notification subscriptions.
  • Limited first-party product events, such as signup completion, tournament selection and viewing, valid invite-page opens, first save of a table, mini-league creation or joining, PWA prompt outcomes, push-permission outcomes, and notification clicks. We use an allow-list and small safe metadata values; we do not store raw email addresses, IP addresses, full URLs, or browser fingerprints in these events.

We do not take payments, run ads, use tracking pixels, or send your activity to a third-party product-analytics company.

If the app crashes, we send a technical error report (stack trace, page URL, and browser/runtime details) to our error-monitoring provider so we can fix the bug. We do not send login codes, and we do not record your session.

Why we use it

We use this information to run your account, the prediction game, and mini-leagues, to stop abuse of login codes, diagnose crashes, and understand whether the game is being used. We also look at aggregated game and product stats (signups, saved tables, app-entry activity, tournament participation, mini-league growth, PWA and push reach, notification clicks, acquisition sources, weekly swap, chip use, and broad country totals) to run the service and understand its audience. That is needed to provide and improve the service you asked for, and to keep it secure. We do not send those stats to advertising or product-analytics companies.

What is public

Your display name, points, and predicted table can appear on leaderboards and on a public player-table page for anyone who has the link. If you have no display name, we show the part of your email before @. Mini-league members see the same.

Who else sees data

  • Our hosting provider holds the app and database.
  • Our email provider sends our emails, such as login codes, reminders, and recaps.
  • Sentry receives crash reports so we can keep the service working. We do not enable session recordings.
  • We load live football standings and fixtures from football-data.org, and live basketball standings and games from Euroleague Basketball. We do not send your email or account to them. Football data provided by the Football-Data.org API.

We do not sell your data. We may disclose it if the law requires it.

Our email provider is based in the United States, so your email address may be processed there. It is certified under the EU-U.S. Data Privacy Framework.

Cookies

We set one first-party session cookie (NextAuth) so you stay logged in. It is strictly necessary for the service. We also use first-party browser storage for attribution and install-flow state; it is not an advertising or analytics cookie. We do not use advertising or third-party analytics cookies, and we do not show a cookie consent banner.

How long we keep it

We keep your account, game, and account-linked app-entry, attribution, PWA, and product event data until you ask us to delete them. Deleting your account hides you from the Global and mini-league boards immediately. We delete the account and those linked analytics rows 30 days later. Sign in before that date to keep your table. Mini-leagues you created stay up for the other players. Anonymous product events, such as an invite-page open before sign-in, are automatically deleted after 90 days. Login codes expire after 10 minutes. Rate-limit buckets stop affecting requests when their reset window expires and are eligible for routine cleanup. Crash reports are kept in Sentry according to that service’s retention settings.

Your rights

When signed in, you can delete your account from Account. Sign in before the deletion date to keep it. You can also email hello@tablepundit.com to ask for a copy of your data, to correct it, or to delete your account. Write from the email on the account so we can match the request.

Children

This service is not aimed at children under 16.

Changes

We update this page when the product changes. The “Last updated” date at the top is the source.

PrivacyTermsContact

© 2026 Table Pundit

Table Pundit is not affiliated with, endorsed by, or connected to any league, club, or governing body.