Privacy policy
Last updated: May 27, 2026
Plain-English summary up front. The formal policy is the source of truth — but if you only read one section, read this one: we collect what we need to run your club, we never sell data, we encrypt everything in transit and at rest, and we honor every COPPA + GDPR right available to you.
What we collect
From families: guardian name, email, phone; per-athlete name, date of birth, sizes, medical info you choose to provide. From org admins: name, email, role at the org. From everyone: standard server logs (IP, user agent, request path).
Why we collect it
To run the platform you signed up for: registrations, communications, store orders, finance, scheduling. Nothing else. No third-party ad targeting. No selling lists.
Minor data + COPPA
Athletes under 13 are in scope on day one. Parental/guardian consent is required before any athlete data is collected. Minor data is retained only as long as the family stays active with the org plus a 90-day grace period — then deleted unless the family opts to keep it portable across orgs.
Your rights
Access, correction, deletion, and data portability are available on request through your family portal or by emailing privacy@seasonstand.com. We respond within 30 days.
Subprocessors
SeasonStand relies on Stripe (payments), Clerk (authentication), Cloudflare (hosting + CDN), Neon (database), Resend (email), Twilio (SMS), and Sentry (error tracking). Each is GDPR-compliant and bound by data-processing agreements.
Cookies
Strictly necessary cookies for authentication + session state. No advertising cookies. No third-party analytics that share data — we use PostHog with strict data-residency settings.
Changes
Material changes get a 30-day notice via email to every org admin + a banner in the family portal. The "last updated" date at the top changes with every revision.
Questions about how we handle your data, or a request to exercise any of the rights above? Email privacy@seasonstand.com and we'll respond within 30 days.