Legal

Privacy Policy

What we collect, what stays in your own browser, and the rights you have over your personal data.

Last updated: 20 September 2026

1. Who we are

This privacy policy explains how FC AutoBuyer, the website at fcautobuyer.com and the FC AutoBuyer Chrome extension, handles personal data. The data controller is FC AutoBuyer, a sole trader based in the United Kingdom ("we", "us").

If you have any questions about this policy or your data, email [email protected].

2. The short version

  • The extension stores its settings, logs and run history locally in your browser. It does not send them to us.
  • The extension does not ask for or collect your EA password. You sign in to the Web App with EA as normal.
  • Webhook messages go directly from your browser to Discord or the endpoint you add, not through us.
  • Stripe handles payments. We receive purchase details such as your email address and payment status, not your full card number.
  • At the time of writing, our website uses no analytics or advertising cookies.

3. Data in the extension

What is stored, and where

The extension uses Chrome's storage feature (chrome.storage.local) to save the following on your own computer, inside your Chrome profile:

  • your settings, such as filters, saved filters, prices, limits, delays, alerts and hotkeys;
  • the live log and activity history;
  • run history, such as per-run speed, searches, errors and results;
  • the current run state, so a run can be shown correctly and stopped.

The floating panel on the Web App also remembers its position and whether it is collapsed, using your browser's local storage for that page. The dashboard remembers which screen you last opened in the same way.

Apart from the licence check described below, this data is not sent to us, and we cannot see it. It stays on your device until you clear it. You can clear activity and run history from the dashboard, or remove all extension data by uninstalling the extension from Chrome.

The licence check

This is the one thing the extension does send to us. When you activate a key, and roughly every 30 minutes while the extension runs, it contacts our licence server and sends:

  • your licence key;
  • an account identifier. If you are signed into Chrome this is a one-way hash of your Google account ID or email address, worked out on your device. We cannot turn it back into your email address, but if you contact us for support and tell us your email we can check whether it matches. If you are not signed into Chrome, a random installation ID is used instead.

The server keeps, for each key: the key ID, the account identifier it is tied to, when it was first activated, and whether it has been revoked and why. That is what stops a key being shared or a time-limited key being reset by reinstalling. It does not receive your settings, logs, run history, EA account details or anything from the Web App. The licence server runs on Cloudflare (see section 9).

Your EA account and the Web App

The extension works inside the EA SPORTS FC Ultimate Team Web App while you are signed in. It does not ask for, read or store your EA email address or password, and it has no login form of its own. Information the Web App shows, such as your coin balance and transfer market search results, is used inside your browser to run the extension and is not sent to us. Requests to EA are made through the Web App as part of your normal session with EA, and EA handles that data under its own privacy policy.

Chrome permissions

The extension asks Chrome for these permissions:

  • Storage: to save your settings, logs and run history locally, as described above.
  • Notifications: to show desktop notifications, for example when a card is bought or a run stops.
  • Identity (identity and identity.email): to read the ID and email address of the Google account signed into Chrome, so your key can be tied to your account and follow you to a new computer. They are hashed on your device before anything is sent; the address itself never leaves your browser.
  • Access to our licence server (fcab-licence.raspy-butterfly-8bc0.workers.dev): for the licence check above.
  • Access to ea.com: so it can run inside the Ultimate Team Web App.
  • Access to Discord webhook addresses: so it can send alerts to Discord webhooks you add.
  • Optional access to other websites: requested only if you add a custom webhook, so the extension can send alerts to that address. Chrome asks you before granting it.

4. Webhooks and notifications

If you add a Discord webhook or a custom webhook URL, the URL is stored locally in your browser with your other settings. When an alert is triggered (for example a card bought, the bot stopping, a captcha, or a run summary), the extension sends the message directly from your browser to Discord or to your own endpoint. It does not pass through our servers and we do not receive a copy.

Messages can include details of the event, such as the card bought, price paid or run results. Once sent, that data is handled by Discord under its own privacy policy, or by whoever runs the endpoint you chose. Only add webhooks you control or trust. Treat a webhook URL like a password: anyone who has it can post to that channel.

Desktop notifications and sounds are produced by Chrome and your operating system on your device.

5. Payments through Stripe

Payments are taken by Stripe on Stripe's own secure checkout page. Stripe collects your card or wallet details (such as Apple Pay or Google Pay) directly. You can read about how Stripe protects payment data on its security page, and how it handles personal data in the Stripe privacy policy.

From Stripe we receive purchase details such as:

  • your email address and the name you enter at checkout;
  • what you bought, the amount, currency, date and payment status;
  • limited payment information shown to us in Stripe's dashboard, such as card type, the last four digits, expiry date and billing country. We read these in Stripe when we need to check a payment; we do not copy them into our own records.

We do not receive or store your full card number or security code. We use purchase details to send your licence key and purchase email, manage your EA FC 27 licence and any returning-customer discount, provide support, handle refunds, and keep financial records.

6. Contacting us

The contact form on our website does not send your message to our servers. When you submit it, it opens your own email app with a pre-filled message to [email protected], and nothing is sent until you press send in that app. When you email us, or contact us on Discord, we receive your email address or Discord username and whatever you include in your message, and use it to reply and help you.

If you share a run report or log with us for support, it will contain the details shown in that report. Please remove anything you would rather not share.

7. Our website, fonts and cookies

Google Fonts

Our website loads the Barlow and Barlow Condensed typefaces from Google Fonts. When a page loads, your browser requests the font files from Google's servers (fonts.googleapis.com and fonts.gstatic.com). This request includes your IP address and standard browser information, which Google receives under its own privacy policy. We do not receive this data from Google.

Cookies and analytics

At the time of writing, our website does not use analytics, tracking or advertising cookies, and we do not run analytics or advertising scripts. If we add any of these in future, we will update this policy and ask for your consent where the law requires it.

Hosting

Our website is hosted on Cloudflare Pages. Like any website host, Cloudflare may keep standard server logs, such as IP addresses, pages requested and the time of the request, to operate and secure the site. Those logs are held by Cloudflare under its own retention periods and privacy policy; we do not keep our own copy of them and we do not use them to identify visitors.

Links to other sites

Our website links to other sites, such as EA, Stripe and Discord. Their privacy policies apply when you visit them.

Under UK data protection law (UK GDPR and the Data Protection Act 2018), we rely on:

  • Contract: to process your purchase, provide your licence key, check it when the extension runs, and handle billing queries.
  • Legal obligation: to keep financial and tax records.
  • Legitimate interests: to answer support requests, prevent fraud and licence misuse, and keep our website secure.
  • Consent: where we ask for it. We do not currently send marketing or newsletter emails, and there is no signup for them on our website. If that changes we will ask for your consent first, and you will be able to withdraw it at any time.

9. Who we share data with

We do not sell your personal data. We share it only with service providers who help us run FC AutoBuyer, and only as needed:

  • Cloudflare: runs our licence server and stores the licence records described in section 3;
  • Stripe: payment processing;
  • our email provider: the service that hosts our [email protected] mailbox, used to send your key and reply to support;
  • Cloudflare Pages: hosting fcautobuyer.com;
  • professional advisers, or authorities where the law requires it.

Some of these providers are based outside the UK, or may process data outside it. Where they do, the transfer relies on appropriate safeguards: UK adequacy regulations where they apply, or the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, as set out in each provider's own data processing terms.

10. How long we keep data

  • Purchase and licence records: for as long as your licence is active, and then for [6 years, confirm] to meet accounting and tax requirements.
  • Support emails and messages: for [24 months, confirm] after the conversation ends.
  • Licence server records (key ID, hashed account identifier, activation time, revocation status): while the key is valid, and for 12 months after it expires or is revoked so that a revoked key stays revoked.
  • All other extension data: we never hold it. It stays in your browser until you clear it or uninstall the extension.

11. Your rights under UK GDPR

You have the right to:

  • ask for a copy of the personal data we hold about you (access);
  • ask us to correct data that is wrong or incomplete (rectification);
  • ask us to delete your data (erasure), where we do not need to keep it for legal reasons;
  • ask us to limit how we use your data (restriction);
  • object to our use of your data where we rely on legitimate interests;
  • receive data you gave us in a portable format (portability);
  • withdraw consent at any time, where we rely on consent.

To use any of these rights, email [email protected]. We will reply within one month. We may need to confirm your identity first, for example by asking you to write from the email address you used to buy.

Remember that we cannot access or delete data stored by the extension in your browser; you can remove that yourself by clearing history in the dashboard or uninstalling the extension.

If you are unhappy with how we handle your data, please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator, at ico.org.uk.

12. Children

FC AutoBuyer is not intended for children. We do not knowingly collect personal data from anyone under [18, confirm minimum age]. If you believe a child has bought from us, contact us and we will delete their data.

13. Changes to this policy

We may update this policy, for example if the extension or website changes how it uses data. We will change the "Last updated" date above and, for significant changes, tell customers by email.

14. Contact

Data controller: FC AutoBuyer, a sole trader based in the United Kingdom. Email [email protected]. A postal address for correspondence is available on request.

Email: [email protected]

See also our terms and refund policy.