DR
Draft Research.com
ReDraft Room Prospect Probabilities CarProd Tables Trade Calculator The Intel
DraftResearch Pro
ReDraft Room Prospect Probabilities CarProd Tables Trade Calculator The Intel DraftResearch Pro
Legal

Privacy Policy

Effective: May 20, 2026 · Last updated: May 20, 2026
Plain English: We collect the minimum we need to run accounts, billing, and analytics. We don't sell your data. You can request deletion at [email protected] and we'll act on it within 30 days.
Contents
  1. Who we are
  2. Data we collect
  3. Data we do not collect
  4. Recognition of NHL scouting staff & front office personnel
  5. How we use it
  6. Legal basis (GDPR)
  7. Third-party services
  8. Cookies, analytics & consent
  9. Data retention
  10. International transfers
  11. Your rights
  12. Brazil residents (LGPD)
  13. California residents (CCPA)
  14. Security
  15. Children
  16. Do Not Track
  17. Changes to this policy
  18. Contact

1. Who we are

DraftResearch.com ("we," "our," "us") is a hockey research platform operated by S.P.A. Sports Performance Analysis, based in British Columbia, Canada. References to "the Service" mean the website at draftresearch.com and any subdomains, tools, and APIs we run. The data controller for personal information processed through the Service is S.P.A. Sports Performance Analysis.

2. Data we collect

We collect two categories of data:

Data you give us. Email address (when you create an account or subscribe), payment information (handled directly by Stripe — we never see or store your card number), and anything you submit via contact forms or email.

Data collected automatically. IP address, approximate location derived from IP (country/region only), browser and device type, pages visited, referring URL, time on page, and interactions like clicks, scrolls, and form submissions. We use this to understand how the Service is used and to debug issues.

3. Data we do not collect

  • Card numbers, CVCs, or banking credentials — Stripe handles all payment data directly.
  • Sensitive personal data (race, religion, sexual orientation, health, biometric, government-issued IDs).
  • Precise geolocation (we never request GPS-level location).
  • Children's data (the Service is not directed at users under 13).

4. Recognition of NHL scouting staff & front office personnel

DraftResearch.com publishes professional recognition content about NHL scouting staff and front office personnel. All such content is limited to factual career achievements, draft class milestones, and positive professional recognition. DraftResearch.com does not publish performance evaluations, criticism, or negative assessments of any individual. Staff members wishing to update, correct, or request removal of their information may contact us at [email protected]. Requests are reviewed and responded to within 30 days.

5. How we use it

  • Operate your account and process subscription billing.
  • Provide, maintain, and improve the Service.
  • Send account and billing notifications (you can't opt out of these while you have an active account or subscription).
  • Send product updates and marketing emails only if you've opted in — you can unsubscribe at any time.
  • Investigate fraud, abuse, or violations of our Terms of Service.
  • Comply with legal obligations.

6. Legal basis (GDPR)

If you're in the EU/EEA or UK, our lawful bases for processing your personal data are:

  • Contract — processing necessary to create your account, deliver the Service, and bill your subscription.
  • Legitimate interests — analytics, fraud prevention, and Service improvement, balanced against your privacy rights.
  • Consent — non-essential cookies (analytics, session replay) and marketing emails. You can withdraw consent at any time.
  • Legal obligation — retaining billing records for tax purposes.

7. Third-party services (sub-processors)

We rely on a small number of trusted sub-processors. Each handles a defined slice of data under a data-processing agreement that requires GDPR-compliant safeguards.

Sub-processorFunctionData handledLocationPrivacy policy
Stripe, Inc.Payment processingEmail, payment method tokens, billing address, transaction historyUnited Statesstripe.com/privacy
Google LLCGoogle Analytics 4 — aggregate site usageIP (truncated), pageviews, events, device typeUnited Statespolicies.google.com/privacy
PostHog Inc.Product analytics + session replay (form inputs masked)Pseudonymous IDs, pageviews, clicks, masked session recordingsUnited Statesposthog.com/privacy
Cloudflare, Inc.Hosting, CDN, DDoS protection, email forwardingIP address, request logs (rotated), email-forwarding metadataUnited States / global edgecloudflare.com/privacypolicy

We do not sell, rent, or trade personal information to any third party. If we add or change a sub-processor, we'll update this list and (if the change is material) notify account holders by email at least 14 days in advance.

8. Cookies, analytics & consent

We use the following categories of cookies and similar technologies. Essential cookies are always on; analytics cookies only load after you click "Accept all" on our cookie banner (or remain on, if you've already accepted). You can change your choice at any time via the "Cookie preferences" link in the footer.

Cookie / storageCategorySet byPurposeDuration
dr-consentEssentialDraftResearch.comRecords your cookie-banner choice so we don't ask again.Persistent (localStorage)
Auth sessionEssentialDraftResearch.comKeeps you signed in. HttpOnly + Secure.30 days
_ga, _ga_*AnalyticsGoogle Analytics 4Distinguishes unique visitors for aggregate site usage.2 years
ph_*AnalyticsPostHogPseudonymous visitor + session identifiers for product analytics.1 year
Stripe checkout cookiesEssential (only on checkout)StripeFraud detection + payment session during checkout. See Stripe's cookie policy.Up to 1 year

We do not use advertising or remarketing cookies. If you're in a jurisdiction with opt-in consent rules (EU/UK/EEA/CH/Brazil/LGPD), analytics cookies stay off until you explicitly accept. Elsewhere they load by default unless you opt out via the cookie banner or browser settings.

9. Data retention

We keep account and subscription records for as long as your account is active, plus up to 7 years afterward as required by Canadian tax and accounting laws. Analytics data is retained on rolling windows (GA4: up to 14 months; PostHog: 12 months by default). When you request deletion, we remove your account record and personal data within 30 days, except for billing records we are legally required to retain.

10. International transfers

S.P.A. Sports Performance Analysis is based in British Columbia, Canada, and our processors (Stripe, Google, PostHog, Cloudflare) are based in the United States. If you're in the EU/EEA, UK, or another jurisdiction with data-transfer rules, your data may be transferred to and processed in Canada and the US. These transfers rely on Standard Contractual Clauses (SCCs) and our processors' own approved transfer mechanisms.

11. Your rights

You can:

  • Access — ask what data we hold about you.
  • Correct — ask us to fix inaccurate data.
  • Delete — ask us to remove your account and personal data (we may keep billing records as required by law).
  • Object — opt out of marketing emails and certain analytics processing.
  • Restrict — ask us to limit how we use your data while a complaint or correction is pending.
  • Portability — receive a copy of your data in a structured, machine-readable format.
  • Withdraw consent — revoke previously given consent for non-essential cookies or marketing emails.
  • Lodge a complaint — if you believe we've mishandled your data, you have the right to complain to your local data-protection supervisory authority. In Canada, that's the Office of the Privacy Commissioner of Canada. In the EU, your national DPA. In the UK, the Information Commissioner's Office.

How to submit a request:

  1. Email [email protected] from the address tied to your account, with the subject line "Privacy Request — [Access / Correct / Delete / Object / Portability / Withdraw consent]".
  2. Tell us what you're asking for and (if it isn't obvious from your email) which account it relates to.
  3. We acknowledge within 5 business days and complete the request within 30 days. If a request is complex we may extend by another 60 days and will tell you why.
  4. If we need to verify your identity (for access, correction, deletion, or portability requests) we'll ask you to confirm a recent transaction or login detail. We won't ask for government ID for routine requests.
  5. Requests are free. We may charge a reasonable fee only if requests are manifestly unfounded or excessive (rare).

12. Brazil residents (LGPD)

If you're in Brazil, the Lei Geral de Proteção de Dados (LGPD) gives you the same core rights listed in §10 (access, correction, deletion, portability, withdrawal of consent, and the right to lodge a complaint with the ANPD — the Brazilian National Data Protection Authority). To exercise these rights, follow the request process described above. Our legal bases under LGPD mirror our GDPR bases.

13. California residents (CCPA / CPRA)

If you're a California resident, the California Consumer Privacy Act gives you additional rights:

  • Right to know — the categories and specific pieces of personal information we collect, sources, business purpose, and any third parties we share with.
  • Right to delete — have us delete personal information we hold, subject to legal-retention exceptions.
  • Right to correct — have us correct inaccurate personal information.
  • Right to opt out of sale/sharing — we do not sell or share personal information as those terms are defined under CCPA/CPRA.
  • Right to non-discrimination — we will not deny service, charge different prices, or provide a different level of quality because you exercised your CCPA rights.

To exercise these rights, email [email protected]. An authorized agent may submit a request on your behalf with written authorization.

14. Security

We use industry-standard practices: HTTPS in transit, encryption at rest, scoped API keys, principle-of-least-privilege access controls, and routine dependency updates. No system is 100% secure; if a breach affects you we'll notify you and the appropriate authorities within the timeframes required by law (typically within 72 hours for the GDPR, without unreasonable delay for PIPEDA).

15. Children

The Service is not directed to anyone under 13 (or 16 in the EU). We don't knowingly collect data from children. If you believe we have, email [email protected] and we'll delete it promptly.

16. Do Not Track

Some browsers transmit a "Do Not Track" (DNT) signal. There is no industry standard for how to respond, so we currently do not act on DNT signals separately from the cookie-consent banner. If you'd like to opt out of analytics, use the banner or the "Cookie preferences" link in the footer.

17. Changes to this policy

We may update this policy from time to time. Material changes will be announced via email to account holders or a banner on the site at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent revision.

18. Contact

Privacy questions or requests:

Sports Performance Analysis

S.P.A. Sports Performance Analysis
British Columbia, Canada
Email: [email protected]

DR
DraftResearch.com
Hockey intelligence on the record.
A Sports Performance Analysis Company

Research Tools

  • ReDraft Room
  • Prospect Probabilities
  • CarProd Tables
  • Trade Calculator
  • The Intel

Company

  • About
  • Consulting & Services

Legal

  • Data Disclaimer
  • Subscription Agreement
  • Privacy Policy
  • Terms of Service
  • Cookie preferences
Data DisclaimerSubscription AgreementPrivacy PolicyTerms of ServiceCookie preferences
Sports Performance Analysis