← Back to OlliPlay

Compliance

Built to protect the people you serve.

Youth sports run on trust. OlliPlay is engineered around the standards that protect children, families, schools, and payments — not as add-ons, but as architecture. Here is what each standard means, how it is met, and exactly how OlliPlay meets it.

01 · Data Security

SOC 2

SOC 2 (System and Organization Controls 2) is an auditing framework from the American Institute of CPAs (AICPA) that evaluates how technology companies manage customer data. It is organized around five Trust Service Criteria: security, availability, processing integrity, confidentiality, and privacy. Rather than a prescriptive checklist, SOC 2 is principles-based — companies define their own controls and then prove to an independent auditor that those controls actually work. A Type I report verifies controls are designed correctly at a point in time; the more rigorous Type II report verifies they operated effectively over six to twelve months.

How it is accomplished

SOC 2 compliance is achieved through technical controls, operational policies, and continuous monitoring. Technically, that means encryption of data at rest and in transit, role-based access control with least-privilege enforcement, multi-factor authentication, automated vulnerability scanning, and comprehensive audit logging of all system events. Operationally, it requires documented incident response procedures, employee security training, vendor risk assessments, and change management — with cloud infrastructure validated across compute, storage, networking, and identity layers, often through platforms such as AWS Security Hub, Vanta, or Drata that automate evidence collection.

How OlliPlay complies

OlliPlay is built on a SOC 2 compliant architecture from the ground up, so the trust service criteria shape infrastructure decisions rather than being retrofitted. Access to production systems is gated by role-based permissions with no shared credentials, all data is encrypted in transit (TLS 1.2+) and at rest (AES-256), and every administrative action is written to a tamper-evident audit trail. OlliPlay runs regular internal reviews against the criteria and engages independent auditors to validate compliance. Customers who need a copy of the SOC 2 report for vendor due diligence can request it under NDA through their account representative.

02 · Children's Privacy

COPPA

The Children's Online Privacy Protection Act (COPPA) is a U.S. federal law enacted in 1998 and enforced by the Federal Trade Commission that restricts online collection of personal information from children under 13. It applies to any service directed at children, or any operator with actual knowledge it is collecting data from a child under 13. Operators must give clear notice of their data practices, obtain verifiable parental consent before collecting a child's information, let parents review and delete that data, and never condition participation on disclosing more than is reasonably necessary. Violations carry civil penalties of up to $51,744 each — and "per violation" can mean per child, per day.

How it is accomplished

Compliance requires identifying where child data enters the system and placing parental consent gates before that point: age-screening at registration, a documented parental consent workflow (email-based, form-based, or ID-verified depending on risk), and data minimization that limits what is collected from minors to only what is operationally necessary. Organizations also maintain a privacy policy that specifically addresses children's data, provide a mechanism for parents to access or delete a child's records, and train staff on COPPA obligations. For youth sports, this extends to roster management, photo uploads, and any communication feature that could expose a minor's information.

How OlliPlay complies

OlliPlay treats minor status as a first-class data attribute. When a participant under 13 is registered — by a parent, coach, or administrator — the platform flags that record and applies enhanced data-handling rules automatically. Parental consent workflows are built into the registration flow for youth programs, with configurable consent-collection methods available to tenant administrators. OlliPlay never uses children's data for advertising or profiling, only for the sports-management functions it is deployed to serve. Parents can request access to or deletion of their child's data through the platform or OlliPlay's privacy team, handled within the timeframes the law requires.

03 · Student Records

FERPA

The Family Educational Rights and Privacy Act (FERPA) is a U.S. federal law from 1974 that protects the privacy of student education records. It applies to any educational institution receiving federal funding — nearly all public schools and most private K–12 schools and universities. FERPA gives parents the right to inspect their child's records, request corrections, and control disclosure to third parties; at 18, those rights transfer to the student. Critically for software vendors, schools may only disclose student records to vendors with a legitimate educational interest who agree to act as a "school official" under a formal data-use agreement — making FERPA a vendor contracting obligation as much as a school policy.

How it is accomplished

For platforms serving schools, FERPA compliance is established through contractual and technical controls. The contractual layer is a data-use agreement between the vendor and the school establishing that the vendor acts as a school official, uses student data only for the contracted purpose, and does not re-disclose records without authorization. The technical layer involves access controls that restrict which staff can view student records, audit logs of record access, and data retention and deletion policies aligned with the school's own FERPA obligations.

How OlliPlay complies

When OlliPlay is deployed by a K–12 school or a program under a school's administrative umbrella, it enters a FERPA-compliant data-use agreement that formalizes the school-official relationship and restricts how student data may be used. Inside the platform, tenant administrators can configure FERPA controls — restricting roster visibility to authorized staff, limiting data exports, and enforcing retention schedules. OlliPlay does not share or sell student records and does not use data from school-affiliated programs for anything outside the contracted scope of service.

04 · EU Privacy

GDPR

The General Data Protection Regulation (GDPR) is the European Union's comprehensive data privacy law, in force since May 2018 and widely regarded as the most stringent in the world. It applies to any organization — wherever based — that processes personal data of individuals in the EU or European Economic Area. GDPR establishes broad individual rights: access, correction, erasure ("right to be forgotten"), data portability, and objection to certain processing. It mandates a lawful basis for every processing activity, requires breach notification within 72 hours of discovery, and imposes penalties of up to €20 million or 4% of global annual revenue — whichever is higher.

How it is accomplished

GDPR compliance requires a structured data-governance program covering the full lifecycle of personal data. It begins with a data inventory — what is collected, where it is stored, who has access, how long it is kept, and the legal basis for processing. From there: consent management for non-essential processing, data-subject-request procedures, Data Protection Impact Assessments for high-risk activities, a Data Protection Officer where required, and GDPR-compliant Data Processing Agreements binding any third-party processors. Cross-border transfers outside the EU must be covered by standard contractual clauses or an adequacy decision.

How OlliPlay complies

OlliPlay's privacy architecture is designed to support GDPR compliance for any tenant serving EU participants or operating under EU jurisdiction. Tenant administrators can honor data-subject requests — access, correction, deletion, and portability — from the admin panel, and OlliPlay's privacy team handles requests that escalate beyond tenant level. Data Processing Agreements are available for organizations that require them, establishing OlliPlay's role as a data processor. OlliPlay maintains records of processing activities, applies data minimization throughout the product, and encrypts personal data in transit and at rest. Organizations with data-residency requirements can contact OlliPlay to discuss options.

05 · California Privacy

CCPA

The California Consumer Privacy Act (CCPA), effective January 2020 and strengthened by the California Privacy Rights Act (CPRA) in 2023, is the most comprehensive state-level consumer privacy law in the United States. It applies to for-profit businesses that collect personal data from California residents and meet at least one threshold: over $25 million in annual revenue, buying or selling data of 100,000+ consumers or households a year, or deriving 50%+ of revenue from selling personal data. It gives residents the right to know what is collected and why, to delete it, to opt out of its sale or sharing, to correct inaccuracies, and to non-discrimination for exercising these rights. CPRA added the right to limit use of sensitive personal information and created the California Privacy Protection Agency as a dedicated enforcer.

How it is accomplished

CCPA compliance centers on transparency, consumer-request handling, and data governance. Organizations publish a clear privacy policy disclosing the categories of data collected, the purposes, and the categories of third parties it is shared with. A "Do Not Sell or Share My Personal Information" mechanism must be accessible from the homepage. Consumer requests — to know, delete, correct, or opt out — must be acknowledged within 10 business days and fulfilled within 45. Internally this requires a data inventory, defined retention schedules, and staff training, plus service-provider contracts that include CCPA-compliant terms restricting how data may be used.

How OlliPlay complies

As a company headquartered in California, OlliPlay takes CCPA obligations seriously and applies its principles broadly rather than only to California residents. OlliPlay's privacy policy discloses the categories of data collected and the purposes for which they are used, and OlliPlay does not sell personal data to third parties. California residents — parents, coaches, and participants — may submit requests to know, delete, or correct their personal data through OlliPlay's privacy-request process, handled within statutory timeframes. Service-provider agreements include CCPA-compliant data-use restrictions, ensuring vendors and subprocessors handle customer data only for the contracted purpose.

06 · Payment Security

PCI-DSS

The Payment Card Industry Data Security Standard (PCI-DSS) is a set of security requirements maintained by the PCI Security Standards Council — a consortium of the major card networks including Visa, Mastercard, American Express, Discover, and JCB. It applies to any organization that processes, stores, or transmits cardholder data, spanning network security, access control, encryption, vulnerability management, monitoring, and information security policy. It is organized into twelve core requirements, validated annually through a self-assessment questionnaire or an on-site audit by a Qualified Security Assessor. Non-compliance can bring fines, higher transaction fees, and ultimately the loss of the ability to accept card payments.

How it is accomplished

The most effective PCI-DSS strategy for a SaaS platform is scope reduction — architecting the system so cardholder data never enters the platform's own environment. This is done by using a PCI-DSS Level 1 certified payment processor (the highest tier, validated annually by an independent assessor) that tokenizes card data at the point of entry, before it reaches the platform's servers. With this design the platform's PCI scope shrinks dramatically: it never stores, processes, or transmits raw card numbers, and only needs to demonstrate compliance for the narrow controls governing its interaction with the processor's API and tokenization outputs.

How OlliPlay complies

OlliPlay processes all payments exclusively through Stripe, which holds PCI-DSS Level 1 certification — the most rigorous level of validation in the standard. Card data entered by users is captured directly by Stripe's infrastructure using client-side tokenization, so raw cardholder data never passes through or is stored on OlliPlay's servers. OlliPlay interacts only with Stripe's payment tokens and API responses, keeping its own PCI scope to a minimum. Administrators retain full access to transaction history, refund management, and financial reporting inside OlliPlay — all without exposing underlying card data. PCI documentation for vendor due diligence can be requested through an account representative.

07 · Athlete Safety

SafeSport

The U.S. Center for SafeSport is an independent nonprofit established by Congress under the Protecting Young Victims from Sexual Abuse and Safe Sport Authorization Act of 2017, with a mission to prevent and respond to abuse — sexual, physical, and emotional, as well as bullying and harassment — in sport. Compliance is mandatory for national governing bodies affiliated with the U.S. Olympic and Paralympic Committee, and increasingly expected of youth leagues, Christian athletic associations, and community programs as a baseline standard of care. Unlike the data regulations above, SafeSport is not about information security — it is about creating and maintaining safe physical and organizational environments for youth athletes, with particular emphasis on adult-to-minor interactions, reporting obligations, and response protocols.

How it is accomplished

SafeSport compliance rests on four pillars: education and training, policy adoption, reporting infrastructure, and response procedures. Every adult with regular access to youth athletes — coaches, referees, administrators, volunteers — must complete SafeSport-certified training covering abuse recognition, prevention, and mandatory reporting. Organizations adopt a Minor Athlete Abuse Prevention Policy (MAAPP) governing one-on-one interactions, electronic communication between adults and minors, locker-room monitoring, and travel. A clear, accessible reporting channel must exist for athletes, parents, and staff — and organizations must follow defined response protocols, including mandatory reporting to law enforcement where required.

How OlliPlay complies

OlliPlay supports SafeSport compliance at the platform level through features and policies that reduce risk and surface concerns early. Role-based access controls limit adult access to minor participant data to authorized, credentialed personnel only. Communication features are designed for transparent, documented interactions between coaches and athletes — reducing the conditions under which grooming or inappropriate contact can go undetected. Compliance indicators in the admin dashboard let program administrators track staff and volunteer SafeSport certification status, flag expired credentials, and keep audit-ready records of who has access to youth participants. OlliPlay does not adjudicate SafeSport violations — that authority rests with the U.S. Center for SafeSport and law enforcement — but it gives administrators the visibility and documentation to run safe, compliant programs.

Documentation

Need our compliance materials?

SOC 2 reports, Data Processing Agreements, FERPA data-use agreements, and PCI attestation materials are available for vendor due diligence. Reach out and we'll get the right documents to your team.

This page describes OlliPlay's compliance posture and program design. It is informational, not a legal representation or warranty; specific contractual commitments are governed by your agreement with OlliPlay. Standards, thresholds, and penalties cited reflect the referenced laws and frameworks and may change over time.