Privacy

ExpectedFootball is a free stats site. This page lists what this browser keeps, what an email signup stores, and what a visit records.

You can read match and club stats with no account. The pages load no advertising tags.

On this browser

Follow lists and a few interface choices stay on the device, so the site can remember them here. Clear site data for expectedfootball.com to remove them.

xf:following
Clubs and leagues you follow, in local storage, so this browser can show them. Unfollow on the club page.
xf:league-filters
Which leagues the matches board is showing.
xf:follow-email-prompt
Clubs you set aside after the email prompt, so that club stays quiet on this browser.
xf:a2hs-dismissed
Set when you dismiss the add-to-home-screen tip.
xf:a2hs-follow-session
Session storage for the rest of that tab. After you follow a club, the home-screen tip waits until the next visit.

Kickoff times use this device's time zone for the page. That zone is not saved.

Adding the site to a home screen registers a service worker so the install can complete. The worker does not cache pages and does not send notifications.

Email alerts

Alerts are optional, at /follow. The consent line is: "Email me when my clubs' reports are ready. Unsubscribe in one click." An address is stored only after that box is ticked. A follow on a club page does not tick it.

The list holds your email, one to three clubs, the time you consented, whether match alerts are on, and a private token for your links. A send record notes which match report went out. The point of the list is one message when that club's report is ready.

After a follow, a prompt can ask if you want email for that club. "Email me" and "Not now" both record the club and the choice, with no email address, and keep that club quiet on this browser. "Email me" opens the signup form. The consent box on that form still starts unchecked.

Messages go out through Resend. Delivery and open counts are read there. Each message has Manage and Unsubscribe, and a one-click unsubscribe header a mail app can use. Manage changes the clubs and the alert switch. Unsubscribe turns match alerts off for that address. Opening the same unsubscribe link again leaves them off.

The manage and unsubscribe addresses contain the private token. Treat the link as the key to that list. The site has no form to remove an address by typing it. Use the link in a message you received.

When alerts are closed, /follow says they are not open.

Visits

A first-party log records some page loads so we can see which shared links land, and whether a known visitor comes back. Bots and prefetches are skipped.

A tagged arrival is a link marked share, email, home screen, or community. On a first share or community arrival, when the country is outside the EU, the EEA, the UK, and Switzerland, the response can set xf_vid. Email arrivals and home-screen arrivals do not create that cookie. When the country is in that set, or the country is missing, the tagged arrival is stored with no visitor id and no cookie.

Once xf_vid is present, a later visit outside that set can add one other page that UTC day, and the first view of a match that day. xf_day remembers the date and those match ids until midnight UTC.

Fields on a row are the path, a match id when the link has one, the campaign tags, a region bucket, whether a cookie was set, and the visitor id when one was issued. The bucket is EU/UK, other, or unknown. The EU/UK label also covers the EEA and Switzerland. The country code is folded into that bucket before the row is saved. Email addresses and IP addresses are not fields on the row. The write uses a public insert key that cannot read the row back.

Public pages also load Vercel Web Analytics, which records page views. Vercel says the script does not use a cookie, and that it separates visits with a hash that resets each day. Our code sends no custom events. We read visit totals, page paths, and referrer hosts from that service. The path you open is part of the page view, so a manage or unsubscribe address can appear there. Certification of that script stays with Vercel.

Cookies

xf_vid
A random visitor id. HttpOnly, Secure, SameSite Lax, on the whole site, for 13 months (13 times 30 days). Set on a first share or community arrival when the country is outside the EU, the EEA, the UK, and Switzerland.
xf_day
The UTC date and the match ids already logged that day. HttpOnly, Secure, SameSite Lax. It lasts until midnight UTC. Written with a return line, which needs xf_vid and the same country rule.
xf_internal
Staff sign-in. Limited to /internal, so a public page does not receive it. HttpOnly, Secure, SameSite Lax, for 30 days.

How to stop

Unfollow a club on its page. Clear site data for expectedfootball.com to drop the local lists and the visit cookies.

For email, use Manage or Unsubscribe in a message you received.

Contact

Contact: thomas.gissing@gmail.com. Changes to the email list go through the manage or unsubscribe link in an alert.