ESP Champ logoESP Champ
Home Log in Create account

Home / Privacy Policy

Privacy Policy

Last Updated: June 7, 2026

ESP Champ ("ESP Champ," the "Service") is a product operated by Vision Tech LLC ("Company," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you create an account, play, or otherwise use the Service at espchamp.com. By creating an account or using the Service, you consent to the practices described here.

Contents 1. Information We Collect 2. How We Use Your Information 3. How We Share Your Information 4. Cookies & Tracking Technologies 5. Email Communications (CAN-SPAM) 6. SMS Messaging & Two-Factor Authentication (TCPA) 7. Account Security & Verification 8. Sensitive Information 9. Your Privacy Rights & Choices 10. Data Security 11. Data Retention & Deletion 12. Children's Privacy 13. Do Not Track 14. International Users 15. Changes to This Policy 16. Contact Us

1. Information We Collect

1.1 Information You Provide Directly

  • Account information. When you register, we collect a username, an email address, and a password. We never store your password in readable form — it is irreversibly hashed (bcrypt) the moment you set it.
  • Optional profile information. If you choose to complete your profile, you may provide your full name, mailing address, country, phone number, date of birth, and ethnicity. These fields are entirely optional, you control them, and you can delete them at any time (see Section 11). Some of this is treated as sensitive information (see Section 8).
  • Communications. Records of messages, support requests, and feedback you send us, which we retain to assist you and improve the Service.

1.2 Information Collected Automatically

  • Device & browser information: browser type and version, operating system, device type, and language settings.
  • Usage data: pages and screens you view, features you use, and session activity.
  • Network information: your IP address, which we use for security, abuse prevention, rate-limiting, and account-lockout protection.
  • Cookies: a small number of strictly necessary cookies that keep you logged in and protect your session. See Section 4.

1.3 Gameplay Information

The Service records the games you play — your card guesses, the hidden targets, your hits, scores, and (for shared events) your participation. We use this to run the game, calculate your statistics and trends, and, for events you join, to compile result leaderboards. Gameplay records are kept as an append-only history so your results remain accurate and tamper-resistant.

1.4 Information from Third Parties

We do not buy contact lists or acquire personal data from data brokers. We may receive limited technical information from the infrastructure and email providers that help us operate the Service (see Section 3).

2. How We Use Your Information

  • To create and maintain your account and authenticate you when you log in.
  • To operate the game — run your sessions and events, score them, and show your statistics and trends.
  • To verify your email address and, if you enable it, to provide two-factor authentication (see Sections 6 and 7).
  • To send you transactional messages (verification, password resets, security notices, and event/result notifications related to your activity).
  • To send optional product or promotional messages where you have opted in, with a clear opt-out in every message.
  • To protect the Service — detecting and preventing fraud, abuse, automated access, and security incidents (including via rate-limiting and account lockout).
  • To comply with legal obligations and enforce our Terms of Service.

We do not use your information for automated decision-making that produces legal or similarly significant effects about you.

3. How We Share Your Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose information only in these limited circumstances:

  • Service providers / subprocessors. We use a small set of vendors strictly to operate the Service — including our web hosting/infrastructure provider, our transactional email delivery provider (Postmark), and, if and when we enable text messaging or two-factor authentication, an SMS provider (Twilio). They receive only the data needed to perform their function and are required to protect it and use it solely on our behalf.
  • Other players (limited). If you take part in a shared event, your username and your event score may appear on that event's results leaderboard to other participants and the event's administrator. Your email and profile details are never shown.
  • Legal requirements. We may disclose information where required by law, legal process, or governmental request, or to protect the rights, property, or safety of Vision Tech LLC, our users, or the public.
  • Business transfers. If Vision Tech LLC is involved in a merger, acquisition, or sale of assets, your information may transfer to the successor, subject to this Policy.
  • With your consent. We may share information for other purposes with your explicit consent.

4. Cookies & Tracking Technologies

ESP Champ is intentionally light on tracking. We use only the cookies needed to run the Service securely:

TypePurposeDuration
Session cookie (essential)Keeps you securely logged in. It is set with the Secure, HttpOnly, and SameSite protections and is restricted to espchamp.com.Session / until logout or expiry
CSRF token (essential)Protects your account against cross-site request forgery when you take actions.Session

We do not currently use third-party advertising or analytics cookies. If we ever add analytics, we will update this Policy and, where required, request your consent first. You can control cookies through your browser settings, but disabling the essential cookies above will prevent you from logging in.

5. Email Communications (CAN-SPAM Compliance)

We send two kinds of email:

  • Transactional emails — address verification, password resets, security alerts, and notifications about your games or events. These are necessary to provide the Service and are not promotional.
  • Optional promotional emails — only if you opt in. We comply with the CAN-SPAM Act (15 U.S.C. § 7701 et seq.): every commercial message identifies the sender, includes our valid physical postal address (11201 N Tatum Blvd STE 300, Phoenix, AZ 85028), provides a clear unsubscribe mechanism, and honors opt-out requests within 10 business days. Opting out of promotional email does not stop transactional messages tied to your account.

To unsubscribe from promotional email, use the link in any such message or contact us at support@espchamp.com.

6. SMS Messaging & Two-Factor Authentication (TCPA)

Text messaging is optional and is never required to use ESP Champ. If you choose to add a phone number for two-factor authentication (2FA) or opt in to other text messages, the following applies:

  • Express opt-in. We obtain your affirmative consent before sending any text messages, as required by the Telephone Consumer Protection Act (TCPA), 47 U.S.C. § 227. Consent to marketing texts is never a condition of using the Service.
  • Security (2FA) texts. If you enable 2FA, we send one-time verification codes to the phone number you provide, solely to confirm it's you. These are account-security messages, not marketing.
  • Opt-out. Reply STOP to unsubscribe from any text program at any time, or HELP for assistance. Standard message and data rates may apply.
  • No third-party sharing. We do not share your phone number with third parties for their own marketing. Your number is shared only with our SMS provider (Twilio) to deliver your messages.

Two-factor authentication and SMS notifications are features we are rolling out; this Policy already governs them so your consent and choices are clear from the start.

7. Account Security & Verification

  • Email verification. After you register, we send a verification link to confirm your email address belongs to you. Verifying helps secure your account and enables password recovery.
  • Two-factor authentication. Where available, you may add a second factor (an SMS one-time code) for stronger protection. See Section 6.
  • Passwords. Passwords are stored only as salted bcrypt hashes — we cannot see or recover your password, only help you reset it.
  • Abuse protection. We apply rate-limiting and temporary account lockout after repeated failed logins, using your IP address and account activity.

8. Sensitive Information

If you voluntarily provide date of birth or ethnicity in your optional profile, we treat these as sensitive personal information. They are encrypted at the application layer (AES-256-GCM) before storage, are never required, are never used for advertising or profiling, and can be erased by you at any time (Section 11). We use sensitive information only to the extent necessary to provide features you request.

9. Your Privacy Rights & Choices

You can access and update your account and profile information at any time while signed in. You can also delete your data yourself: the profile area includes a "Delete my data" control that erases your profile information and anonymizes your account. Depending on where you live, you may also have the rights below.

9.1 California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.), California residents may:

  • Know the categories and specific pieces of personal information we have collected, the sources, our purposes, and the categories of third parties with whom we share it.
  • Delete personal information we have collected, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Opt out of sale/sharing. We do not sell or share personal information for cross-context behavioral advertising; if that ever changes we will provide a prominent opt-out.
  • Limit use of sensitive personal information to what is necessary to provide the Service.
  • Non-discrimination. We will not deny service or charge you differently for exercising these rights.

Categories collected (preceding 12 months): identifiers (username, email, IP address, optional phone); customer records (optional name, mailing address, country); sensitive information (optional date of birth, ethnicity); internet/network activity (usage and gameplay data); and inferences limited to your game statistics. To exercise a right, email support@espchamp.com or call 480-599-0940. We verify your identity before acting and respond within 45 days (extendable once as permitted by law). You may use an authorized agent.

9.2 Nevada Residents

Nevada residents may request that we not sell their personal information. We do not sell personal information; you may still submit a request to be recorded by contacting support@espchamp.com.

9.3 Virginia, Colorado, Connecticut, Utah & Other States

Residents of states with comprehensive privacy laws — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA) — may have rights to access, delete, correct, and opt out of targeted advertising or sale of personal information. To exercise any applicable right, contact us using Section 16.

10. Data Security

We protect your information with layered safeguards, including: HTTPS/TLS encryption in transit and HSTS; bcrypt password hashing; application-layer encryption of sensitive profile fields; a strict Content-Security-Policy and other hardened HTTP headers; least-privilege database access; an append-only design for gameplay records; and rate-limiting and lockout against brute-force attacks. No method of transmission or storage is perfectly secure, so we also encourage you to use a strong, unique password. If a breach affects your personal information, we will notify affected users and authorities as required by law.

11. Data Retention & Deletion

  • Account & profile data is retained while your account is active. You may erase your profile information and anonymize your account at any time using the "Delete my data" control; this scrubs your profile, replaces identifying account fields with anonymized values, disables the password, and ends your active sessions.
  • Gameplay records are kept as an anonymized, append-only history to preserve the integrity of statistics and event results; they are dissociated from your identity when you anonymize your account.
  • Security logs (such as IP-based throttling records) are retained for a limited period — typically up to 90 days — for abuse prevention, then deleted or anonymized.
  • We retain information longer only where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.

12. Children's Privacy

ESP Champ is intended for adults 18 years of age or older and is not directed to children. We do not knowingly collect personal information from anyone under 18 (and never from a child under 13). If you believe a minor has provided us information, contact support@espchamp.com and we will delete it promptly.

13. Do Not Track

Because there is no accepted standard for responding to browser "Do Not Track" signals, the Service does not respond to them. We limit tracking to the essential cookies described in Section 4 regardless.

14. International Users

The Service is operated from the United States. If you access it from elsewhere, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer, and we apply the protections in this Policy wherever data is processed.

15. Changes to This Policy

We may update this Policy to reflect changes in our practices, technology, or legal requirements. We will update the "Last Updated" date above and, for material changes, take reasonable steps to notify you. Your continued use of the Service after changes are posted constitutes acceptance. This Policy is governed by the laws of the State of Arizona, without regard to conflict-of-law principles.

16. Contact Us

For questions about this Policy or to exercise your privacy rights, contact us:

Vision Tech LLC — ESP Champ
11201 N Tatum Blvd STE 300
Phoenix, AZ 85028
Phone: 480-599-0940
Email: support@espchamp.com
© 2026 Vision Tech LLC. ESP Champ is a product of Vision Tech LLC. Privacy · Terms · Home