Privacy and analytics choices
This policy covers League Gazette at leaguegazette.com and Draft Room by League Gazette at draft.leaguegazette.com.
Cloudflare Web Analytics provides aggregate traffic and performance measurement on both products. Query strings are suppressed before transmission so league identifiers, payment-return flags, Draft Room configurations, and campaign parameters are not included.
PostHog product analytics is optional and starts only after explicit opt-in. It uses memory-only SDK persistence, no session replay, no autocapture, no automatic page views, no person profiles, and no IP or geolocation enrichment. We retain PostHog events for 30 days maximum.
If you opt in, we create a pseudonymous random identifier in the lg_analytics_id cookie and store your choice in the lg_analytics_consent cookie. Both cookies use the .leaguegazette.com domain and expire after one year so the same choice applies to both products. The identifier is not derived from your identity, league, payment, device fingerprint, or product data.
Optional analytics is limited to allowlisted product views, cross-product clicks, connection starts and completions, checkout starts, purchase completions, Draft Room funnel actions, and sanitized exceptions. Sanitized exceptions use enumerated error codes and query-free allowlisted paths; they never include raw messages, stacks, request bodies, or free text.
PostHog receives no personal or league data: no names, email addresses, league or team identifiers, manager or player data, imported labels, draft configurations or picks, Stripe identifiers, full URLs, queries, hashes, referrers, user agents, or IP-derived properties.
You can decline optional analytics or later opt out through Privacy & analytics choices. Opting out stops PostHog, deletes the shared pseudonymous identifier and PostHog cookies, and leaves only the denied consent choice. It does not delete essential storage such as recent leagues, saved Draft Room configurations, or draft progress.
Operational league, connection, payment, entitlement, support, security, and accounting data is separate from optional product analytics. Stripe, Supabase, Cloudflare, Google Cloud, and our storage providers process the operational data needed to connect leagues, take the one-time payment, provide seasonal access, generate results, prevent abuse, and administer the 30-day refund process. Analytics opt-out does not erase records that must be retained to provide access, refunds, security, or accounting.