← Back to BFFLbwayfan.com →

Privacy Policy

Last Updated: April 7, 2026

1. Introduction

This Privacy Policy describes how BWAY FAN LLC (the "Company," "we," "us," or "our") collects, uses, discloses, retains, and protects information when you access or use the Broadway Fandom Fantasy League (BFFL) website, progressive web app, and iOS mobile application, including bfflbway.com and related app experiences we make available (collectively, the "Service").

The Service is hosted on Vercel and uses third-party service providers to operate core functions, including Supabase (database, storage, and backend services), Airtable (operational workflows, reporting, and/or parallel administrative records during a transition period, where applicable), Clerk (authentication), Apple Inc. ("Apple") (Sign in with Apple and App Store distribution, if applicable), Meta Platforms, Inc. ("Meta") (Facebook Login and Meta Business Tools such as the Meta Pixel, Conversions API, or mobile attribution and measurement tools, if enabled), Google (Google sign-in, Google Analytics, Google Ads tags, Firebase or other mobile analytics or measurement tools, and related advertising or measurement services, if enabled), Vercel (hosting and analytics), Wix (website hosting, site content, support/contact pages, or registration/contact forms on bwayfan.com, where applicable), SendGrid (transactional email delivery), Broadway Index LLC (affiliate analytics, reporting, and partner-services support, where applicable), and any payment processor or app marketplace operator we use if we later offer paid features, paid season access, subscriptions, or other digital purchases.

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. Where required by applicable law, you consent to the collection, use, and disclosure of information as described herein.

2. Information We Collect

2.1. Information You Provide Directly

When you create an account and use the Service, we may collect information you provide to us, including without limitation:

  • Account information: verified email address, password, and display username.
  • Ballot predictions: nominee selections (up to five per category) and winner predictions (one per category with confidence levels, where applicable).
  • Fan Circle participation: circles you create or join, invite codes you generate or redeem, and related standings.
  • Quest and achievement data: completion records, earned badges, pins, and unlock progression.
  • Token transactions: Spotlights balances, earning actions, and spending history.
  • Support and contact information: if you submit a support request, contact form, early-access registration, or similar inquiry through bwayfan.com or another Company-operated form, we may collect your name, email address, subject matter, message content, and related correspondence.
  • Purchases and transaction information (if introduced later): if we later offer paid season access, subscriptions, or other digital purchases, we and our payment providers (including Apple, where purchases are made through the App Store) may collect transaction metadata such as purchase status, subscription status, receipt or order identifiers, and limited billing or account information needed to process, validate, support, and record the transaction. We do not receive your full payment card number from Apple for App Store transactions.

2.2. Information Collected Automatically

When you access the Service, we and our service providers may automatically collect certain information, including without limitation:

  • Analytics data: page views, feature usage patterns, session duration, and interaction events through Google Analytics 4 and Vercel Analytics.
  • Advertising and attribution data: we use Meta Business Tools such as the Meta Pixel and the Meta Conversions API, and we may also use the Google tag and Google Ads conversion tracking (and, if enabled, remarketing or audience features) to measure the effectiveness of marketing, attribute sign-ups, and understand ad performance. These tools may collect or receive information about page visits, referral URLs, ad interactions, registrations, browser data, and similar event information. Before transmission to Meta through the Conversions API, email addresses are hashed using SHA-256. We also capture UTM parameters (source, medium, campaign, term, content) on first visit to attribute how you found the Service.
  • Device and browser information: browser type, device type, operating system, screen resolution, and IP address (collected by third-party analytics providers).
  • Mobile application data: if you use our iOS app, we and our service providers may collect app version, device model, operating system version, language, time zone, IP address, app session events, and crash, diagnostic, or performance data needed to operate, secure, debug, and improve the app.
  • Mobile permissions and device settings: if you enable optional mobile features such as notifications, we may collect the device token or similar technical identifier required to deliver those communications. Where required by law or platform rules, we will request permission before accessing protected device features or using non-essential mobile tracking or measurement technologies.
  • Session data: session identifiers stored via sessionStorage to maintain UTM attribution through authentication redirects. These are not persistent cookies and are cleared when you close your browser tab.
  • Cookies and Similar Technologies: We and our service providers may use cookies, pixels, SDKs, local storage, browser or device identifiers, server-side event transmissions, and similar technologies to collect or receive information about how users access and interact with the Service. These technologies support core functionality, analytics, attribution, conversion measurement, campaign performance analysis, and, where enabled, audience-building or remarketing features. For example, we use Google Analytics 4, Vercel Analytics, and Meta Business Tools such as the Meta Pixel and Meta Conversions API. Some of these technologies operate in the browser, while others operate through server-side or app-based event transmission. Depending on your location, we may request your consent before using non-essential analytics, attribution, advertising, or similar technologies. You can manage certain preferences through your browser settings, device settings, and any consent tools we make available.

2.3. Information from Third-Party Services

We use Clerk for authentication and identity management. Depending on availability, you may create an account and sign in using (i) email and password, (ii) Google, (iii) Facebook ("Facebook Login"), and/or (iv) Apple ("Sign in with Apple"). Availability of authentication methods may vary by platform, operating system, app version, and over time.

If you choose Facebook Login, Meta will provide (through Clerk) your Facebook-associated email address and your public profile name (i.e., the name associated with your Facebook account). We do not request and do not receive additional Facebook profile information, such as your friends list, posts, photos, or other account data.

If you choose Sign in with Apple, Apple may provide (through Clerk) your name, your Apple Account-associated email address, and/or an Apple private relay email address if you choose Apple's "Hide My Email" option. We do not request and do not receive additional Apple account information beyond what is needed to authenticate you and create or maintain your account.

Third-Party Login Policies. When you use Google, Facebook Login, or Sign in with Apple, your interaction with those providers is also subject to the provider's own terms and privacy policy, in addition to this Privacy Policy. We do not control those providers' practices, and they may collect information directly from you in connection with authentication.

Token Handling and Access Scope. The Company does not store Facebook or Apple access tokens and does not use social login methods to access third-party account data beyond the initial sign-in, account verification, and related account-maintenance functions supported by Clerk. Any authentication tokens, if used, are handled by Clerk solely for purposes of enabling sign-in.

Apple Private Relay and Re-identification. If you choose to anonymize your email address through Sign in with Apple, we will not attempt to link that anonymized Apple login data with information that directly identifies you and that was obtained outside Sign in with Apple without your consent.

3. How We Use Your Information

We may use information we collect for the following business and commercial purposes, including without limitation to:

  • Operate and administer the Service: create and manage accounts; process predictions; calculate scores; maintain leaderboards and Fan Circle standings.
  • Compute scoring and results, including nominee scoring, winner scoring based on confidence levels, engagement bonuses, and tie-breakers.
  • Communicate with you: send transactional emails, security notices, reminders, service notices, and, if enabled by you and supported by the Service, push notifications.
  • Respond to support, contact, and registration inquiries submitted through bwayfan.com or other Company-operated channels.
  • Analyze, maintain, and improve the Service: understand usage, diagnose issues, improve features and performance, and enhance user experience.
  • Measure marketing effectiveness, attribution, and campaign performance, and support advertising or remarketing activities where enabled and permitted by law.
  • Process, validate, support, and record transactions, season passes, subscriptions, or other digital purchases if we later offer them.
  • Generate aggregated and/or de-identified insights about prediction trends and platform usage.

4. How We Share Your Information

4.1. Publicly Visible Information

Certain information is visible to other users by design, subject to your settings and actions:

  • Your display username appears on leaderboards and Fan Circle rosters.
  • If you share your public ballot link (/ballot/[USERNAME]), your predictions become viewable by anyone with the link.
  • Your scores, rankings, and earned achievements may be visible within Fan Circles you join.

4.2. Service Providers

We may share information with vendors, consultants, and other service providers that perform services on our behalf ("Service Providers"), including without limitation Supabase (database, storage, and backend services), Airtable (operational workflows, reporting, and/or parallel administrative records during a transition period, where applicable), Clerk (authentication and social login), Vercel (hosting and analytics), Wix (website hosting, site content, support/contact pages, or registration/contact forms on bwayfan.com, where applicable), Apple (Sign in with Apple authentication data, when you choose that option), Meta (Facebook Login and Meta Business Tools for advertising, attribution, and measurement), Google (Google sign-in, Google Analytics, Google Ads conversion tracking, and related measurement or advertising services, if enabled), SendGrid (transactional email delivery), and Broadway Index LLC (affiliate analytics, reporting, and partner-services support, where applicable). Service Providers are authorized to use information only as necessary to provide services to us.

We may create and disclose aggregated and/or de-identified analytics, trend summaries, benchmark data, consensus reporting, and similar business intelligence derived from Service activity to affiliated entities, including Broadway Index LLC, and to approved business partners. These outputs are intended not to identify individual users. Except as otherwise described in this Privacy Policy, we do not disclose your directly identifying account information, login credentials, email address, or private ballot activity tied to you as a named individual to external partners without your consent or another lawful basis.

4.4. Restrictions on Sign in with Apple Data

We use data obtained through Sign in with Apple solely for authentication, account access, account administration, fraud prevention, security, and related Service operations. We do not share or sell data obtained through Sign in with Apple to advertising platforms, data brokers, or information resellers. If you choose Apple's anonymized email option, we do not attempt to re-identify that data with information obtained outside Sign in with Apple without your consent.

4.5. Legal Requirements; Protection of Rights

We may disclose information if required to do so by law or in the good-faith belief that such disclosure is reasonably necessary to (a) comply with legal process; (b) enforce these policies or our Terms of Service; (c) respond to claims that any content violates rights of third parties; or (d) protect the rights, property, or safety of the Company, our users, or the public.

4.6. Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, dissolution, or sale or transfer of some or all of our assets, information may be transferred as part of that transaction, subject to applicable law.

If you use our iOS app, you should also review the information we provide in the App Store privacy label and inside the app at the time of download and use. Those disclosures summarize categories of data collected through the app and should be read together with this Privacy Policy.

5. Data Retention

We retain personal information for as long as reasonably necessary to provide the Service, fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods may vary depending on the category of information and the applicable context.

Examples (non-exhaustive):

  • Account information: retained until you delete your account or request deletion, subject to Section 5 and applicable law, and may include social-login profile information or relay email information when provided through a supported authentication method.
  • Ballot predictions and scores: retained for the duration of an awards cycle and may be archived thereafter for historical leaderboard purposes.
  • Analytics data: retained according to the retention settings of each provider (e.g., GA4).
  • UTM attribution data: retained for campaign performance analysis for up to 24 months.
  • Token transaction history: retained for the awards cycle plus 24 months for audit and integrity purposes.
  • Support and contact records: retained for as long as reasonably necessary to respond to your inquiry, maintain service records, and comply with legal or operational obligations.
  • Purchase and subscription records (if introduced later): retained for as long as reasonably necessary for transaction fulfillment, customer support, accounting, tax, fraud prevention, chargeback management, and compliance with platform or payment-provider requirements.

6. Data Security

We implement commercially reasonable technical and organizational measures designed to safeguard information, including authentication and password protections through Clerk, encryption in transit (SSL/TLS), and access controls for sensitive operations.

However, no method of transmission over the Internet or method of electronic storage is completely secure. Accordingly, while we strive to protect your information, we cannot and do not guarantee absolute security.

If we determine that a security incident or data breach has compromised personal information, we will provide any notices required by applicable law.

7. Your Rights and Choices

7.1. Account Management and Deletion

You may update your display username and certain preferences through your account settings. You may request deletion of your account and associated data by contacting privacy@bwayfan.com and, where available, by using self-service deletion controls in your account settings on the Service. Please review our Data Deletion Policy for details regarding the scope and timing of deletions.

7.2. Analytics, Attribution, and Advertising Choices

You may opt out of Google Analytics via the Google Analytics Opt-Out Browser Add-on, manage Google ad personalization through Google Ads Settings, and manage Meta advertising preferences through your Facebook or Instagram ad settings. You may also control cookies through your browser settings and, where offered, our consent tools; however, disabling certain cookies may limit functionality.

7.3. U.S. State Privacy Rights

Depending on your state of residence, you may have rights to access, delete, correct, or opt out of certain processing. To submit a request, contact privacy@bwayfan.com and we will respond as required by applicable law.

7.4. California Notice (CPRA)

If applicable, California residents may have rights to know the categories and specific pieces of personal information we collect, use, disclose, and retain; to request deletion or correction; to request portability; to opt out of the sale or sharing of personal information; and to be free from discrimination for exercising those rights.

We do not sell personal information for money. However, certain analytics, attribution, and marketing-related technologies we use or may enable, including Meta Business Tools, Google tags, Google Ads conversion tracking, remarketing technologies if enabled, or similar tools, may be considered "sharing" or cross-context behavioral advertising under California law. You may submit a request to know, delete, correct, or opt out by emailing privacy@bwayfan.com with the subject line "California Privacy Request."

We do not use or disclose sensitive personal information for purposes that would require us to offer a separate right to limit under California law, except as otherwise permitted by law.

7.5. International Privacy Rights (EEA/UK/Switzerland)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, and the Service is offered to you, you may have rights under applicable data protection law, including the rights to access, correct, delete, restrict, object to certain processing, request portability, and withdraw consent where processing is based on consent.

Our legal bases for processing may include performance of a contract (for account creation, predictions, and Service delivery), legitimate interests (for security, fraud prevention, product improvement, and internal analytics), compliance with legal obligations, and your consent where required. If and when applicable law requires prior consent for non-essential analytics or advertising technologies, we will seek that consent before using those technologies for affected users.

We are based in the United States. If personal information is transferred internationally, we will use applicable safeguards where required by law.

You may contact privacy@bwayfan.com to exercise applicable rights or to obtain more information. You may also have the right to lodge a complaint with your local supervisory authority.

8. Children's Privacy

The Service is not directed to children under thirteen (13) (or sixteen (16) in the EU/EEA). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child without required consent, we will take steps to delete such information promptly.

9. Third-Party Links

The Service may contain links to third-party websites or services (including social media). We do not control and are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party site or service you visit.

10. Changes to This Policy

We may update this Privacy Policy from time to time in our discretion by posting an updated version with a revised "Last Updated" date. If changes are material, we may provide additional notice (such as by email or in-Service notice), as required by applicable law.

11. Contact Us

Questions or requests:

Email: privacy@bwayfan.com
Website: bwayfan.com

Mailing address: 94 Wanaque Ave. #149, Pompton Lakes, NJ, 07442

Terms of ServicePrivacy PolicyData DeletionOfficial Rules
Back to BFFLSupportbwayfan.com
© 2026 BWAY FAN LLC