Notice at Collection — the short version
This is the summary the app links to when you sign up. The full policy below governs.
- What we collect:your phone number and/or email address (sign-in identifiers, stored encrypted), display name and username, date of birth, your school and team follows, check-ins and game attendance, posts, reactions and messages, cards, packs and rewards, app usage, device identifiers and push tokens, and — only if you turn them on — precise location (check-ins) and hashed contacts (Find Friends). Details: Section 2.
- Why:to run Fantera (accounts, rewards, leaderboards, moderation, security), to share your fan profile with an athletic program you engage with, to build and sell aggregated de-identified insights, and — as measurement features launch — to measure whether sponsorships worked. Details: Section 4.
- Sold or shared?Yes, as those words are defined in California and Texas law — aggregate insights sold to brands (always groups of 50 or more fans), your fan profile shared with a program you engage with, and hashed measurement matching. Your phone number and email are never part of it. One switch, Partner Sharing, turns all of it off; it is off until you turn it on. Details: Sections 6 and 8. Fans under 18 are never sold or shared.
- How long: contact identifiers until you delete your account; precise coordinates about 30 days; hashed contacts about 90 days after your device stops confirming them; activity history while your account is active. Details: Section 12.1.
- Your choices: Do Not Sell or Share My Personal Information (Section 6), export or delete your account any time (Section 9).
1. Who We Are
This Privacy Policy describes how Fantera, Inc. (“Fantera,” “we,” “us”) collects, uses, discloses, shares, and sells personal information when you use the Fantera mobile app, our website, and related services (the “Service”). Fantera is a fan engagement platform for college athletics. Fans earn Fan Reward Tokens (“FNR”) by attending games, completing challenges, making predictions, and interacting with the community. The Service uses the Ovatra blockchain as an audit layer for certain events, such as consent records and FNR issuance.
This policy is designed to comply with the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”) and the Texas Data Privacy and Security Act (“TDPSA”). We extend the core rights it describes to all users of the Service regardless of where you live, subject to identity verification and applicable law.
2. Information We Collect
2.1 Information you give us
- Account information: your mobile phone number and/or email address (used to sign in with a one-time passcode), a display name, and a username. Contact identifiers are stored in encrypted form and as one-way hashes.
- Date of birth: collected to confirm you meet our minimum age and to set age-appropriate defaults.
- Optional profile details: if you choose to provide them, demographic fields such as birth year, gender, ZIP code, and similar. These are optional and self-reported.
- Content you create: posts, poll votes, predictions, replies, reactions, photos you upload, reports you file, and profile text such as a bio.
- Messages you send:Fantera includes fan-to-fan messaging — crew chat, and (as messaging features are enabled for your account) direct messages and group conversations. We collect and store the messages you send, including any images you attach, so we can deliver them and keep the conversation available to its participants. Messages are visible to the people in the conversation (the other fan, the group’s members, or the crew’s members); group and crew moderators can remove messages in spaces they moderate. To keep messaging safe, automated systems screen message text and images for policy violations (such as threats, harassment, or sexual content), and messages that are reported to us may be reviewed by our team. Unsending a message removes it for everyone, including attached images; editing a message shows an “edited” mark; deleting a conversation hides it for you only. The contents of your messages are never used for advertising, never shared with athletic programs, brands, or data buyers, and never included in the datasets described in Section 4.3.
- Contacts you choose to match (“Find Friends”):if you use Find Friends, the app reads the phone numbers in your device contacts and sends only one-way cryptographic hashes of those numbers to our server. We never receive your contacts’ names, emails, or actual phone numbers. We use the hashes to look for people already on Fantera, and we retain them so we can also let you know when someone from your contacts joins Fantera later and keep your Find Friends results current. If the app on your device stops confirming a hash (for example, you deleted that contact), we delete it after about 90 days. This feature is optional: you can skip it, and you can turn contact matching off at any time in Settings → Privacy & data, which deletes all of your stored contact hashes. Using Find Friends turns it back on.
- A payment card you choose to link (card-linked rewards — when this feature launches): if we offer card-linked rewards and you opt in by linking a payment card, the link is created through our card-linked offer provider (named in Section 5), and Fantera never receives or stores your card number. We receive a token representing the card and, when it is used at a participating merchant, a transaction record: merchant, amount, date and time, and the token. We use these records to credit rewards and for the measurement described in Section 4.4. Linking is optional and limited to fans 18 or older; you can unlink at any time in Settings, which stops future transaction matching.
2.2 Information we collect automatically
- Activity data:check-ins, game attendance, challenge and prediction activity, interactions with content, and other in-app events, along with metadata such as timestamps and the team context of an action, and records of purchases you make in the app (through Apple’s or Google’s billing — we receive the transaction record, never your payment details).
- Sponsored content and offers: if the app shows you content from a sponsor or brand (for example a sponsored challenge, offer, or post), we record that it was shown and how you interacted with it, so we can limit repetition and measure whether it worked (Section 4.4).
- Location:with your permission, we use your device’s location to verify that you are physically at a venue when you check in or post a location-tagged photo. Precise location is used for that verification; we treat it as sensitive information (see Section 7).
- Device and usage information: app session and diagnostic information and an internal device identifier used for security. We do not use advertising identifiers (such as the IDFA) and we do not include any third-party advertising or analytics tracking SDKs in the app.
2.3 What we do NOT collect
We do not collect Social Security numbers, driver’s license or passport numbers, payment card numbers (if you link a card for card-linked rewards, we receive only a token — never the card number), account passwords, genetic or biometric data, the contents of your private communications for advertising, or health information.
We do not put third-party advertising or analytics trackers in the app, we do not use advertising identifiers (such as the IDFA), and we do not buy data about you from data brokers to build a profile of you. If measurement features launch, we may match limited, pseudonymous data — never your mobile phone number — with a brand or its measurement provider to check whether a sponsorship or promotion worked. When we do, it happens under contracts that prohibit re-identification, only aggregate results (groups of at least 50 fans) are reported to the brand, and it is controlled by your Partner Sharing consent. Section 4.4 explains exactly how.
3. Sources of Information
We collect information (a) directly from you when you create an account, provide profile details, or use the Service; (b) automatically as you use the Service; (c) if you use Fantera in connection with an athletic program, from that program and from venue ticketing systems, which may confirm that a linked ticket was scanned at a gate; (d) from the Ovatra blockchain, which records certain events tied to an internal pseudonymous identifier; (e) if card-linked rewards launch, from our card-linked offer provider, which reports qualifying transactions made with a card you linked; and (f) if measurement features launch, from brands, sponsors, and their measurement providers, which may provide hashed identifiers or records of promotions they ran (for example, that an ad campaign ran in a given market) so we can measure outcomes as described in Section 4.4.
4. How We Use Information
4.1 Operate the Service
To create and authenticate your account, credit FNR, track challenge and tier progression, power the feed and predictions, deliver your messages and crew chat, deliver in-app notifications, operate leaderboards, respond to support, and keep the Service secure — including the automated safety screening of fan content and messages described in Section 2.1.
4.2 Share individual fan data with an athletic program you engage with
If you use Fantera in connection with an athletic program — for example, a school whose team you follow on the Service — then, with your Partner Sharing consent (Section 8, on by default and able to be turned off), we may share fan profile and engagement information — such as your name, attendance records, purchase and spending behavior (Sections 2.1 and 2.2), engagement history, tier, and any demographic details you provided — with that program. A program may use this for fan engagement, ticketing outreach, and development and alumni relations.
4.3 Build and sell aggregated, de-identified datasets
Fantera builds and sells datasets derived from fan behavior.These are offered to advertisers, sponsors, and research firms and cover topics such as attendance, spending, cross-sport affinity, and fan demographics. Before any dataset is sold, it is aggregated and de-identified using k-anonymization: every published row represents at least 50 indistinguishable fans, precise fields (such as exact age or ZIP) are replaced with coarse ranges, and no direct identifier — no name, phone number, email, or fan identifier — is ever included. Whether your activity is used to build these datasets is controlled by your Partner Sharing consent. When you opt out, your future activity is excluded from new datasets, but data already included in a dataset that was built or sold cannot be recalled (see Section 8).
4.4 Measure whether sponsorships and promotions worked (attribution) — as these products launch
A brand that sponsors college sports wants proof the sponsorship worked. If Fantera offers measurement products, we will use activity data (such as check-ins and attendance), your interactions with sponsored content in the app, and — if you link a payment card — card-linked transaction records, in the following privacy-protective ways. All of it is controlled by your Partner Sharing consent (Section 8).
- Aggregate lift reporting:counting outcomes across groups of at least 50 fans — the same k-anonymization standard as Section 4.3. Example: “fans who saw this sponsor’s challenge visited the sponsor 12% more often than fans who didn’t.”
- Clean-room-style matching:a brand or its measurement provider supplies hashed (one-way scrambled) identifiers, or we supply ours, and records are matched inside a controlled environment under a contract that prohibits re-identifying anyone and any use other than producing the report. The brand receives only the aggregate result — never a list of matched fans.
- Conversion reporting:confirming, in hashed or aggregated form, that fans exposed to a promotion later took an action (attended, visited, purchased), including through automated reporting interfaces (“conversions APIs”).
Three hard limits apply to all of it: (1) your mobile phone number and your SMS consent are never part of it, in raw or hashed form; (2) any record that leaves Fantera at the individual level is pseudonymous or hashed, goes only to a provider under contract (Section 5), and never includes your name, phone number, or email; (3)anything a brand, sponsor, or merchant sees is aggregate-only, at least 50 fans per row. Precise location coordinates are never used or disclosed here — only the fact of a verified check-in or attendance (Section 12.1), which exists only if you granted the location permission that created it.
4.5 Personalize, improve, prevent fraud, and comply with law
To personalize what you see, test and improve features, detect and prevent fraud and reward abuse, and comply with legal obligations and enforce our terms.
4.6 Communicate with you
To send account messages such as sign-in codes. See Section 10 for our SMS practices.
5. Who We Share Information With
- An athletic program you engage with may receive individual fan profile and engagement data as described in Section 4.2, subject to your Partner Sharing consent.
- Advertisers, sponsors, and research firmsreceive aggregated, de-identified datasets as described in Section 4.3 — never direct identifiers.
- Measurement and clean-room providers (if measurement features launch) process hashed, pseudonymous records under contract, solely to produce the aggregate reports described in Section 4.4. Re-identification and independent use are prohibited by contract. Brands themselves never receive individual-level data from this process.
- Service providers who process data on our behalf, under contract and only for the purposes we specify. These currently include: Twilio (SMS delivery), SendGrid (email delivery), OpenAI and Google’s Perspective API (automated content moderation of posts and images), Anthropic (summarizing public sports news — no fan data is sent), Google Firebase Cloud Messaging and Apple Push Notification service (delivering push notifications), and our encrypted cloud object-storage provider (storing uploaded photos and event records). If we launch the features above, this list will grow to include a card-linked offer provider and measurement or clean-room infrastructure providers. We may engage additional or successor providers in these categories under the same contractual limits; this page always reflects the current list, and a new category of provider handling personal information is a material change under Section 12.5. We also use public sports-data sources such as ESPN as inputs; we do not send them information about you.
- Legal, safety, and successors: we may disclose information where required by law, to protect safety, or in connection with a merger, acquisition, or sale of assets.
We do not sell your personal information to third-party data brokers such as Acxiom or Experian, and we do not enrich your profile with data purchased from them. Fantera is the first-party collector and seller of the data described here.
6. Sale and Sharing of Personal Information (CCPA/CPRA and TDPSA)
Fantera “sells” and “shares” personal information as those terms are defined under the CCPA/CPRA and the TDPSA.Specifically, we sell aggregated, de-identified datasets derived from your activity, we share individual fan profile and engagement information with an athletic program you engage with, and — if measurement features launch — we may disclose hashed, pseudonymous activity records to measurement providers to produce aggregate attribution reports, which we conservatively treat as a “sale” or “share” under these laws. One opt-out covers all of it. You have the right to opt out of this sale and sharing. To opt out:
- In the app: open Settings → Privacy & data and turn off Partner Sharing, or tap Do Not Sell or Share My Dataon the Settings screen. Either is your “Do Not Sell or Share My Personal Information” control.
- By email: write to privacy@fantera.netwith the subject “Do Not Sell or Share.”
- Global Privacy Control: we honor valid GPC signals where technically feasible.
Opting out is forward-looking: we stop future sale and sharing, but information already shared with an athletic program or already included in a dataset that was built or sold cannot be recalled. To go further, use your right to delete (Section 9).
Minors. We collect your date of birth at sign-up, so we know when an account belongs to someone under 18. If you are under 18, we do not sell or share your personal information: Partner Sharing is off for your account and cannot be turned on while you are under 18.
7. Sensitive Information
The main category of sensitive personal information we handle is precise location, used to verify venue check-ins and location-tagged photos. Location sharing is off until you grant permission, and you can turn it off at any time in your device settings, which stops future collection. You have the right to limit our use of sensitive personal information; turning location off is your control for that right. We do not sell or share precise location coordinates, and we never give them to a partner, brand, sponsor, merchant, or measurement provider. Coordinates are used to verify a check-in and are then retired as described in Section 12.1; only the verified event (“checked in at the stadium”) remains.
8. Consent and the Three Tiers
You can review and change your consent any time in Settings → Privacy & data:
- Basic (required):the account and activity data the Service needs to function. If you don’t want to share this, please don’t create an account.
- Partner Sharing (off until you turn it on; asked once at sign-up as a separate choice; off and locked for fans under 18):one toggle that covers everything beyond running the Service: (a) sharing individual fan data with an athletic program you engage with (Section 4.2) — the onlyindividual-level sharing; (b) including your activity in the aggregated, de-identified datasets we sell (Section 4.3); and (c) if measurement features launch, using your activity — and, if you link a card, your card-linked transactions — in the measurement described in Section 4.4, including hashed, pseudonymous matching with a brand’s measurement provider under contracts that prohibit re-identification. Whatever the product: brands, sponsors, merchants, and advertisers only ever receive aggregate results covering at least 50 fans. Turning Partner Sharing off stops (a), (b), and (c) for your future activity and is your “Do Not Sell or Share My Personal Information” opt-out (Section 6).
- Precise Location (off by default, opt-in): precise location, treated as sensitive.
We record your consent choices on the Ovatra blockchain as a tamper-evident history, along with a timestamp and the prior and new state; the version of this policy in effect at each change is recorded in the consent audit log that anchors every change to its blockchain transaction. That record does not contain your name, phone number, or email. Withdrawing consent is forward-looking, as described in Section 6.
9. Your Rights and How to Exercise Them
Subject to verification and applicable law, you have the right to:
- Know and access the categories and specific pieces of personal information we have collected, used, and shared;
- Delete personal information we collected from you (see below and our Account Deletion page);
- Correct inaccurate personal information;
- Opt out of the sale and sharing of your personal information (Section 6);
- Limit the use of sensitive personal information (Section 7);
- Data portability— receive a copy of your information in a portable format; and
- Non-discrimination— you will not be penalized for exercising these rights (see Section 11).
You can delete your account directly in the app under Profile → Data Rights. To make an access, portability, correction, or other request, email privacy@fantera.net from the address on your account, or write to us at the address in Section 13. We respond within the time required by law (generally 45 days, extendable with notice). You may use an authorized agent. There is no charge unless a request is excessive.
10. Your Phone Number, Email Address, and Sign-in Codes
We use your mobile phone number and/or your email address to send one-time sign-in codes and to identify your account. You can sign in with either, and add or change either in Settings → Your profile → Sign-in methods. We do not send marketing text messages or marketing email; the only email Fantera sends you is a sign-in code you asked for.
Fantera, Inc. does not share, sell, or rent your mobile phone number or your SMS consent with any third party.
If you sign in by phone: message frequency varies based on your sign-in activity. You may receive up to 4 messages per month. Message and data rates may apply. You can reply STOP to opt out and HELP for help. Full details are on our SMS Terms page.
11. Non-Discrimination and the Tier Program
Fantera operates a tier program (Bronze, Silver, Gold, Platinum, MVP) based on FNR earning and engagement. Consistent with California Civil Code § 1798.125(b), certain tier progression for fans 18 or older is tied to Partner Sharing: only FNR earned while Partner Sharing is on counts toward progression, reflecting that Partner Sharing enables the value that funds the rewards. This is a financial-incentive program under California law: the benefit (tier progression and what it unlocks) is reasonably related to the value of your data participation. You join it by leaving Partner Sharing on (or turning it on) after reading this policy — at sign-up, adults are asked once, as a separate choice with Partner Sharing off until they turn it on, and never asked again for at least 12 months after declining — and you can withdraw at any time by turning it off. Importantly: fans who opt out still earn FNR at the base rate, are not demoted from a tier already reached, still get the core Service, and are never charged for exercising their rights. Because Partner Sharing is off for fans under 18 (Section 6), the incentive applies only to adult accounts: fans under 18 progress through tiers normally without Partner Sharing.
Seasonal reset.The tier ladder and your FNR balance both reset at the start of each athletic season (August 1, subject to change): every fan returns to Bronze and every FNR balance is zeroed. Your FNR balance does not carry over between seasons. Lifetime totals and history are preserved for your records and for analytics but do not affect the new season’s balance or tier.
12. Retention, Security, Children, and Other Terms
12.1 Retention
We keep personal information for as long as necessary for the purposes in this policy or as required by law. Encrypted contact identifiers (phone, email) are kept until you delete your account. Hashed contact digests from Find Friends are kept while contact matching is on for your account, are deleted about 90 days after your device stops confirming them, and are deleted immediately if you turn contact matching off or delete your account. Precise location coordinates attached to a check-in or photo are kept for a limited period (currently about 30 days) for fraud and moderation review, after which the precise coordinates are removed from the active record, leaving only a general location reference (such as “posted from the stadium”). The event itself survives the coordinates: the record that you checked in, attended a game, or (if you link a card) made a qualifying transaction — what happened, when, and at which venue or merchant, without precise coordinates — is part of your activity history. We retain it while your account is active, because it is the basis of your rewards, tier, season history, and the measurement described in Section 4.4. Messages you send are kept until you unsend them or delete your account. Activity and de-identified analytics records, and audit and moderation logs, are retained on a longer-term basis for analytics, security, legal compliance, and dispute resolution. Aggregated, de-identified datasets and measurement reports are retained indefinitely; datasets and reports already sold or delivered are governed by the buyer’s terms and cannot be recalled. Records on the Ovatra blockchain are tamper-evident by design and cannot be deleted; they do not contain direct identifiers.
12.2 Security
We use administrative, technical, and physical safeguards, including encryption of contact identifiers at rest, TLS in transit, access controls, and audit logging. No system is perfectly secure. If you believe your account was compromised, contact privacy@fantera.net.
12.3 Children’s Privacy
The Service requires you to be at least 13 years old. We collect your date of birth when you create an account and do not permit accounts for anyone under 13. We do not knowingly collect personal information from children under 13; if you believe we have, contact privacy@fantera.netand we will delete it. If you are between 13 and 17, please use the Service only with the involvement of a parent or guardian. We do not sell or share the personal information of fans we know are under 18 — see Section 6.
12.4 U.S. Users, GPC, and Do Not Track
The Service is intended for users in the United States; your information is processed here. We honor Global Privacy Control signals where feasible (Section 6). Because there is no common standard for “Do Not Track” browser signals, we do not currently respond to them.
12.5 Changes to This Policy
We may update this policy. For material changes we will update the date above, post a notice in the app, and provide any notice required by law. Your continued use after the effective date constitutes acceptance to the extent permitted by law.
Previous versions: Effective July 29, 2026.
13. Contact Us
Fantera, Inc.— Attn: Privacy
3100 Carlisle Street, 9107, Dallas, TX 75204
privacy@fantera.net
In-app: Profile → Data Rights