Team Assist ("we," "us," or "our") operates the Team Assist web application and mobile application (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
1. Information We Collect
1.1 Account Information
When you create an account we collect your name, email address, and password (hashed, never stored in plain text). If you sign in with Google, we receive your Google account name, email, and profile photo — we never receive or store your Google password.
1.2 Organization & Team Data
Coaches, administrators, and club staff create organizations, teams, events, and roster records through the Service. This may include:
- Organization and team names
- Player names, jersey numbers, birthdates, and gender
- Event schedules, locations, attendance, lineups, and game statistics
- RSVP responses and volunteer signups
- Polls, announcements, and chat messages
1.3 Guardian & Minor Information
Players are often minors. A player's roster record (name, birthdate, jersey number) is created and managed by one or more guardian users, not by the minor themselves. A player may optionally link to their own user account once they are of age. We do not knowingly allow children under 13 to create accounts or provide personal information directly to us. If you believe a child under 13 has provided us with personal information, please contact us so we can remove it.
1.4 Payment Information
Subscription billing and one-time purchases (viewer passes, storage packs, stream packs) are processed by Stripe or through Apple App Store and Google Play in-app purchases. We do not store credit card numbers, bank account numbers, or other payment credentials on our servers. Stripe retains payment data under its own privacy policy. For organizations collecting dues through Stripe Connect, payment processing is handled entirely by Stripe on the connected organization's account.
1.5 Media
Users may upload photos and videos to the Service. Uploaded media is stored on Amazon Web Services (AWS) S3. Live game streams are delivered through Cloudflare Stream; stream recordings are retained for 30 to 90 days depending on your plan tier and then automatically deleted.
1.6 Device & Usage Data
We collect:
- Device tokens — Firebase Cloud Messaging (FCM) registration tokens for push notifications, associated with your account and device platform (iOS/Android).
- Login records — timestamps, IP addresses, and user-agent strings each time you sign in, to detect unauthorized access.
- Server logs — standard web-server request logs that include IP addresses, request paths, and response codes. These are used for debugging and security monitoring and are rotated regularly.
We do not track your location in the background. Location data in events (venue addresses) is entered explicitly by team staff using Google Places and is not derived from your device's GPS.
1.7 Cookies
The web application uses session cookies for authentication and CSRF protection. These are strictly necessary cookies — we do not use advertising or analytics tracking cookies. The mobile application uses token-based authentication and does not set cookies.
2. How We Use Your Information
We use the information collected to:
- Operate and maintain the Service — team management, scheduling, chat, attendance, statistics, media sharing, and live streaming
- Process payments and manage subscriptions
- Send push notifications and emails you have opted into (event reminders, team messages, game alerts)
- Detect and prevent fraud, abuse, and unauthorized access
- Enforce our Terms of Service
- Respond to support requests
We do not sell your personal information. We do not serve advertising. We do not use your data to build advertising profiles.
3. How We Share Your Information
3.1 Within Your Teams & Organizations
Information you provide (your name, profile photo, messages, RSVPs, and any content you post) is visible to other members of the teams and organizations you belong to, as determined by your role and the team's settings. Player roster information is visible to coaches, staff, and guardians within that team.
3.2 Viewer Pass Holders
When a team enables live streaming and a viewer purchases a viewer pass, they can watch the live stream and any replay within the pass window. Viewers see only the video feed — they do not gain access to rosters, chat, stats, or any other team data.
3.3 Service Providers
We share data with third-party service providers solely to operate the Service:
- Stripe — payment processing and subscription management
- Amazon Web Services (AWS) — cloud hosting and media storage (S3)
- Cloudflare — live-stream delivery, video recording, and content-delivery network
- Google — sign-in (OAuth), Places API (venue search), Firebase Cloud Messaging (push notifications)
- Apple / Google — in-app purchase verification and push notification delivery
These providers process data on our behalf under their own privacy policies and are not permitted to use it for unrelated purposes.
3.4 Legal Requirements
We may disclose information if required to do so by law, court order, or governmental authority, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
4. Data Retention
- Account data — retained while your account is active. When you delete your account, your personal data is removed. Content you posted in team chats and shared albums may be retained in anonymized form within those teams.
- Player records — retained while the player is part of a team roster. Soft-deleted players are recoverable by team staff; permanently deleted upon team or organization deletion.
- Media — photos and videos are retained until explicitly deleted by team staff or until the team/organization is deleted. Stream recordings are automatically pruned after the plan's retention period (30 days for Coach, 90 days for Club).
- Server logs — rotated and deleted within 90 days.
- Payment records — Stripe retains transaction records under its own data-retention policies and applicable financial regulations.
5. Your Rights & Choices
- Access & correction — you can view and update your profile information at any time through the app's settings.
- Account deletion — you can delete your account from the settings page. This cancels all active subscriptions and removes your personal data.
- Push notifications — you can disable push notifications through your device's system settings or mute individual teams within the app.
- Data export — to request an export of your data, contact us at the address below.
If you are located in the European Economic Area (EEA) or a jurisdiction with similar data-protection laws, you may also have the right to request erasure, restrict processing, or object to processing. Contact us to exercise these rights.
6. Security
We protect your data using:
- HTTPS encryption for all data in transit
- Encrypted storage for sensitive credentials (stream keys, tokens)
- Hashed passwords (bcrypt)
- Two-factor authentication and passkey support
- Scoped API tokens (Sanctum) with minimal necessary permissions
- Signed, time-limited URLs for live-stream playback
No system is perfectly secure. If you discover a security vulnerability, please report it to us promptly.
7. Children's Privacy
The Service is designed for use by coaches, parents, and club administrators — adults managing youth sports teams. We do not knowingly collect personal information directly from children under 13. Player records for minors are created and managed by their guardian(s). If we learn that we have collected personal information from a child under 13 without parental consent, we will delete that information promptly.
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the Service or by email. Your continued use of the Service after the effective date of the revised policy constitutes acceptance of the changes.
9. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: