Riser — Privacy Policy
Last updated: August 21, 2026
Riser is a fantasy hockey pool platform: a website and a mobile app that let you create a pool with friends, draft NHL players, and track standings through the season. This policy explains, in plain language, what personal information we collect, why, where it goes, and how you can delete it.
Person in charge of the protection of personal information (privacy officer): William Paquin-Brien — support@riserpool.com.
1. What we collect
When you create an account:
- Your email address and a password (the password is handled by our authentication provider, Supabase, and is never visible to us in readable form).
- A display name you choose. If you don't set one, we use the part of your email before the "@".
- If you sign up or sign in with Google (available on the web), Google sends us your name and email address. We do not receive your Google password or contacts.
When you use Riser:
- An optional profile photo (avatar) if you choose to upload one from your device's photo library.
- Your language preference (English or French) and your notification preferences (which emails and push notifications you want).
- Your pool activity: team name, rosters, draft picks, trades, waiver claims, lineup moves, and standings. This is the substance of the game and is visible to the other members of your pools.
- Your messages: pool chat messages and direct messages to other members.
If you enable push notifications (mobile):
- A push notification token issued by Expo (our notification delivery service), plus your device platform (iOS or Android) and device name. We only ask for this permission from the notification settings screen or a one-time prompt after you join your first pool, and the token for a device is deleted when you sign out on that device.
Automatically, for reliability:
- Error reports. When something breaks, our error-monitoring service (Sentry) receives a technical report. It can include your account's internal identifier (a random ID, not your email), the pool involved, and — on the website — a replay of what the screen looked like when the error occurred. We do not send Sentry your email address.
- Hosting logs. Our hosting providers (Vercel and Supabase) keep standard technical logs (such as IP address and request time) to operate and secure the service.
What we do not collect: date of birth, home address, phone number, or any payment information. Riser handles no money (see the Terms of Service). We use no advertising trackers.
2. What we use it for
- To run the service: accounts, pools, drafts, scoring, standings, chat.
- To send you the notifications you have opted into (email and/or push).
- To answer you when you contact support.
- To find and fix bugs (error reports).
- To keep the service secure.
We do not sell or rent your personal information. We do not use it for advertising.
3. Analytics
Riser's mobile app and website use PostHog, a product analytics service, to understand how Riser is used: how many people sign up and come back, which screens they spend time on, which features they use, and where flows like pool creation lose people. We use this to decide what to improve. We do not use it for advertising, and we do not sell or share this data.
Screens. The app records which screens you visit and how long you stay on each. Screens are recorded by their generic type — "the roster screen", "a direct-message conversation screen" — never by any content identifier: the record of visiting a conversation screen contains no conversation, no participant, and no message information of any kind. The website records page views the same way, by the generic shape of the page's address ("a pool's roster page", "a direct-message conversation page"): identifiers, invite codes, and everything after the "?" in an address are removed in your browser before anything is sent.
Feature usage. The app records a fixed list of feature interactions — for example: switching tabs, creating or joining a pool (with its settings choices only — never its name), viewing the steps of the pool-creation wizard (including where it was abandoned), entering the draft room, adding a player to a draft queue, making a pick, opening the draft board, proposing and completing trades, participating in claim windows, viewing head-to-head pages, changing app settings (which setting, such as language or a notification toggle), and the outcome of the system notification-permission prompt. The complete list is fixed in code; nothing outside it is captured.
Messaging — what we deliberately do not record. We record that messaging features are used — chat opened, a direct-message screen opened, a message sent, and from which part of the app — and never message content, message length, who you message, or which conversation it was. There is no general "tap recording" in the app: every recorded interaction is individually and explicitly coded, and no recorded event may carry text you or other members wrote (names, messages, searches).
Each event carries your account's internal identifier (the same random ID used in our error reports — never your email or your name; on the website, page views while you are signed out carry only a random browser identifier instead), the pool's internal identifier on pool-scoped events, a timestamp, and basic technical context attached by the analytics library (app version, device platform and operating system, language; on the website, browser type and screen size).
What we never send to analytics: your email, your display name, pool names, team names, chat or direct messages (content, length, or participants), player searches — and no screen recording or session replay of any kind.
Where it goes. PostHog processes this data in the United States (US Cloud) — the same jurisdiction as our database host (see §4).
How long it is kept. Under PostHog's current terms, event data on our plan is guaranteed to be retained for one year; data older than that may be deleted or moved to slower storage by PostHog. If we change plans in a way that changes retention, we will update this section.
Your choice. Analytics is off by default and runs only if you turn it on in Settings ("Help improve Riser"), separately in the mobile app and on the website (the website remembers your choice in your browser; the app, on your device). Nothing is collected unless you turn it on, and on the website the PostHog analytics library is not even downloaded until you do. You can change your mind at any time in the same place; turning it off stops collection immediately. To have the analytics data already collected for your account deleted, write to support@riserpool.com (see §8, Your rights).
4. Where your information is stored
Your account and pool data are stored with Supabase, our database and authentication provider, in the United States (AWS us-east-1, Northern Virginia). Our other providers (below) also process data on servers that may be located outside Québec and outside Canada.
5. Who we share it with
We share personal information only with the service providers (processors) that make Riser work:
| Provider | What they do for us | What they receive |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime updates | All account and pool data; your password (in protected form); avatar images |
| Vercel | Hosts the website and scheduled jobs | Standard web traffic and logs |
| Sentry | Error monitoring | Error reports: internal account ID, pool ID, technical context; screen replays on website errors |
| Resend | Sends our notification emails | Your email address, display name, and the content of the notification (which can include pool names, team names, and message previews) |
| Expo, Apple (APNs), Google (FCM) | Deliver push notifications | Your push token and the notification content (which can include direct-message text and mentions) |
| PostHog | Product analytics (mobile app and website) | Usage events identified by your account's internal ID (or, while signed out on the website, a random browser identifier) — never your email, name, or any message content (see §3) |
| Optional "Sign in with Google" | Handles your Google login; sends us your name and email |
These providers process personal information only to provide their service to us, and we require that each of them protect it with the same or an equivalent level of protection as described in this policy.
We also fetch public NHL player data (names, statistics, salary figures, photos) from the NHL's public API and CapWages. No personal information about you is sent to those sources.
Other members of your pools can see your display name, avatar, team name, rosters, transactions, and the messages you post. That is the nature of a pool. Choose your display name and avatar accordingly.
Avatar images note: avatar files are stored in a publicly addressable storage bucket — anyone who has the exact image link can view the image without logging in.
We would disclose personal information to authorities only if required by law.
6. How long we keep it
- Chat and direct messages are automatically and permanently deleted after 30 days, subject to the exceptions below. A scheduled job runs daily and removes messages older than 30 days.
- Exception — demonstration and review accounts: a small number of pools and accounts that we operate ourselves for product demonstration and app-store review are exempt from the 30-day purge so their sample conversations stay readable; messages in those pools (including anything typed there by a reviewer) may be retained beyond 30 days.
- Exception — reported content: when a message — or a display name, team name, or pool name — is reported for moderation, a copy (snapshot) of the reported content is kept in our moderation records so we can review the report and enforce our rules; these snapshots are retained beyond the 30-day window, are kept even if the reported name is later changed, and survive the deletion of the reported account. We keep these snapshots on the basis of our legitimate interest in moderating the service and keeping its members safe, and only for as long as necessary to review and act on the report and enforce our rules; a snapshot that is no longer needed for that purpose is deleted.
- Everything else (account, pool history, rosters, standings) is kept for as long as your account exists, because a pool's history is the product.
- Expired push tokens are pruned automatically; the push token for a device is deleted when you sign out on that device.
7. Deleting your account
You can delete your account yourself, in the app, on both platforms:
- Web: Settings → danger zone → Delete account.
- Mobile: More → Settings → Delete account.
What deletion actually does (we describe this precisely because your teams don't simply vanish):
- Your profile, display name, avatar link, notification settings, chat messages, direct messages (including the other person's copy of your DM conversations), notifications, and login sessions are permanently deleted, with one exception: moderation snapshots of content that was reported, described below. Your login itself is destroyed.
- Your teams remain in their pools as unnamed, unclaimed placeholder teams. The team's game history (rosters, draft picks, trades, standings) stays, because it belongs to the pool's shared record — but the team name you gave it is removed at deletion (the team shows as an unnamed team until someone names it again), it is no longer connected to you, and nothing left in it identifies you. A pool's commissioner can later hand the team to a new person.
- A small number of audit records are kept in anonymized form (for example, "this trade was reviewed" without who reviewed it), for the integrity of pool history.
- If any of your content was reported for moderation — a message, or a display name, team name, or pool name — the snapshot of that reported content in our moderation records is kept after your account is deleted, so the report can still be reviewed and acted on. Such a snapshot can therefore preserve a display name, team name, or pool name you used at the time of the report, even after your profile is otherwise deleted. These snapshots are kept on the legal basis and for the limited duration described in §6 (moderation and member safety, only as long as necessary).
- Analytics (if you had opted in): any usage events still queued on your device are discarded — never sent — at deletion, and the deleted account's identifier is detached from your device. Usage events already collected by our analytics provider are identified only by your account's random internal ID (never your email or name; see §3) and are not automatically erased by account deletion; to have them deleted, write to support@riserpool.com and we will delete them.
- If you are the host (commissioner) of any pool, you must first delete each pool you host (from that pool's Commissioner page); the app will block account deletion and tell you so. There is currently no way to transfer a pool to another host.
- Uploaded avatar image files are deleted from storage by the deletion routine.
Deletion is immediate and cannot be undone.
8. Your rights
You can ask us, at support@riserpool.com, to:
- Access the personal information we hold about you;
- Correct it if it is inaccurate or incomplete;
- Delete it (or use in-app deletion, described above);
- Withdraw consent to optional processing (for example, turn off email or push notifications — you can also do this directly in your settings);
- Receive a copy of the computerized personal information you gave us, in a structured, commonly used technological format (right to portability).
We will respond within 30 days.
If you are unsatisfied with our response, you may file a complaint with the Commission d'accès à l'information du Québec (CAI).
9. Cookies and local storage
- Website: we use only the cookies required to keep you logged in (authentication session cookies from Supabase), your language choice, and, once you have used the "Help improve Riser" switch in Settings, two small cookies that remember that choice and the moment you made it (they hold only "granted" or "declined" and a timestamp; the timestamp lets the site apply your latest choice consistently if you change it in several open tabs). No advertising or analytics cookies: the analytics library runs without cookies, and only if you turned analytics on; it keeps a random identifier and its own settings in your browser's local storage, and that identifier is reset when you turn analytics off. Your browser also stores a few interface preferences (like a hidden-column toggle) locally; these never leave your device.
- Mobile app: the app stores your login session, language choice, selected pool, and a few interface preferences on your device.
10. Security
Data in transit is encrypted (HTTPS). Access to data in the database is restricted by per-user authorization rules enforced by the database itself (row-level security). No system is perfectly secure; if a breach affecting your personal information were to occur, we would notify you and the CAI as required by law.
11. Children
Riser is not directed at children.
12. Changes to this policy
If we change this policy, we will post the new version at this address with a new "last updated" date, and for significant changes we will notify you in the app or by email.
13. Contact
Questions, requests, complaints: support@riserpool.com — addressed to the person in charge of the protection of personal information (William Paquin-Brien).