Legal · Privacy
Privacy Policy
OlliPlay is built for youth sports, so protecting children and families is not a footnote — it is the design brief. We are ad-free by default, we do not sell your data, and the standards that govern children's and student data shape how the platform works. This policy explains what we collect, why, and the choices you have.
01
Our privacy commitment & ad-free guarantee
OlliPlay does not sell, rent, or trade your personal information or athlete data to advertisers or data brokers. Our revenue comes from software subscriptions and service fees, never from monetizing your data. The platform is ad-free by design: there are no third-party advertising trackers, no behavioral profiling of children, and no "surveillance" business model hiding behind a free tier.
We collect only what a sports organization genuinely needs to run its programs, and we hold that data on behalf of the organization that invited you.
02
Information we collect
- Account & profile data: names, email addresses, phone numbers, and roles (parent, athlete, coach, volunteer, staff) provided by you or your organization.
- Athlete data: names, birthdates, jersey and roster details, and emergency or medical information provided by a parent, guardian, or club to operate a program.
- Registration & financial data: the programs you sign up for and payment records. Card numbers are handled entirely by our payment processor — OlliPlay never stores raw card data (see Security).
- Communications data: messages, consents, and delivery records for email, SMS, WhatsApp, and voice features you use through the platform.
- Technical data: log data, device and browser information, and essential cookies needed to keep you signed in securely and to prevent fraud.
03
How we use information
We use personal information to provide and operate the Service on behalf of your organization — processing registrations and payments, managing rosters and schedules, sending the communications you have consented to, tracking compliance and safety requirements, and providing support.
- To run programs: registration, team and roster management, scheduling, and events.
- To handle payments: collecting fees, issuing receipts and refunds, and reconciling finances.
- To communicate: sending only the categories of messages a recipient has consented to, and honoring opt-outs and quiet hours.
- To keep programs safe & compliant: tracking waivers, consents, and SafeSport or background-check status.
- To secure and improve the Service: preventing fraud and abuse, diagnosing problems, and maintaining reliability.
We do not use children's data for advertising or profiling, and we do not make high-stakes decisions about people through automated processing without human review.
04
Children's privacy — COPPA, FERPA & the Parent-Direct shield
- Parent-Direct by design: OlliPlay does not allow children under 13 to create their own accounts. Data about minors is entered and controlled by a parent, guardian, or authorized program administrator.
- Consent gates: where required, parental consent is collected before a minor's information is processed, and enhanced data-handling rules apply automatically to records flagged as belonging to a minor.
- No unmonitored contact: the platform is designed to prevent private, one-on-one digital contact between adults and minor athletes, supporting both COPPA and SafeSport obligations.
- Student records (FERPA): when OlliPlay serves a school or a program under a school's administrative umbrella, student data is handled under a FERPA-compliant data-use agreement and is never used outside the contracted purpose.
Parents may review, correct, or request deletion of their child's data at any time through the platform or by contacting our privacy team. See our Compliance page for the full picture.
05
Service providers & data processing
- Roles: your organization (the "Club") is the data controller; OlliPlay acts as the data processor, handling data on the organization's behalf and instructions.
- Sub-processors: we rely on a small set of vetted providers — Stripe (payments), QuickBooks and Gusto (accounting and contractor payments), and Twilio / WhatsApp (messaging). Each is bound by contractual data-protection obligations and uses your data only to provide their service to OlliPlay.
- Data Processing Agreements: DPAs are available for organizations that require them, establishing our role as processor and the terms under which personal data is handled.
- Breach notification: OlliPlay will notify an affected organization of any confirmed data breach without undue delay, and within 72 hours where required.
06
Your privacy rights & choices
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to receive a portable copy, and to object to or restrict certain processing. We honor these rights regardless of location wherever we reasonably can.
- California (CCPA/CPRA): the rights to know, delete, correct, and to opt out of the "sale" or "sharing" of personal information. OlliPlay does not sell personal data.
- EU/EEA & UK (GDPR): the rights of access, rectification, erasure, portability, restriction, and objection, plus the right to lodge a complaint with a supervisory authority.
- Global Privacy Control: our platform automatically honors GPC signals from your browser to disable non-essential tracking.
To exercise a right, use the controls in your account or contact legal (at) olliplay.com. Requests that concern data held on behalf of an organization may be routed to that organization as the controller, and we will help fulfill them within the timeframes the law requires.
08
How we protect your data
Security is architecture at OlliPlay, not an add-on. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), access to production systems is gated by role-based permissions with no shared credentials, and administrative actions are recorded to a tamper-evident audit trail. Each organization's data is isolated in a multi-tenant architecture.
Payments are processed exclusively through Stripe, which holds PCI-DSS Level 1 certification. Card data is tokenized by Stripe at the point of entry and never passes through or is stored on OlliPlay's servers. For the full breakdown of our SOC 2, PCI-DSS, and youth-safety posture, see the Compliance page.
09
Data retention
We retain personal data for as long as your organization maintains an active account and as needed to provide the Service, comply with legal and financial-record obligations, resolve disputes, and enforce our agreements. Per-tier retention settings determine how long historical records remain queryable inside an active subscription.
Upon termination, OlliPlay will maintain your organization's data for ninety (90) days as a courtesy to allow for final exports. After this grace period, OlliPlay is not obligated to retain the data and it may be permanently deleted, except where longer retention is required by law.
10
International transfers, changes & contact
OlliPlay is operated from the United States, and personal data may be processed there and in the regions our sub-processors operate. Where required, we rely on appropriate safeguards such as standard contractual clauses for cross-border transfers. Organizations with specific data-residency requirements should contact us to discuss available options.
We may update this policy as the product and the law evolve. Material changes will be reflected by updating the effective date above and, where appropriate, by notifying account administrators. Questions or requests? Contact legal (at) olliplay.com or support (at) olliplay.com LinkedIn.
This policy is provided for transparency and may be supplemented by the agreement between OlliPlay and your organization.