Security & Privacy

Trust you can check,
not trust you’re asked for.

What we hold about your child, who can open it, and what a thief would walk away with. Including the parts we can’t protect.

The claim we make

“Encrypted, never sold, and you can see who looked.”

Here is what that covers. And where it stops.

What we hold

Some of it has to stay readable. The rest is locked.

WhatFor exampleHow we keep it
ScheduleTeams, seasons, games, who is comingReadable. The app runs on it
NamesNames, jersey numbers, who coaches which teamReadable. Every list needs them
ContactEmail, phone, date of birthEncrypted
MedicalAllergies, action plans, emergency contacts, signed agreementsEncrypted, and every look is written down. Staff prove who they are first
The thing worth stealing isn’t any one field. It’s the picture: which adult is connected to which child, on which team, at which phone number. We can’t lock that away, because a team list has to work. So we do the things you can do about a picture. We never sell it and never hand it to advertisers. Neither this site nor the app carries a tracker. Another family can never look up your number: they see names and staff contacts, and that is all. And every look at what is behind the lock is written down with a name against it.

Encryption

Steal a copy of our database and your child’s medical notes come out as gibberish.

The app scrambles contact, medical and emergency details before they are ever saved. What it does not cover is the company we rent the server from, which could reach what the app reaches. That is true of nearly every app you use, and you should hear it from us rather than assume otherwise.

  • Two things stay readable, and we’d rather tell you now. Names and rosters, because every list needs them. And the address you sign in with, because a sign-in link has to go somewhere. The email on your member record is encrypted. The one your account signs in with is not.

What this covers

What locking the details protects you from, and what it doesn’t.

The difference comes down to one thing: whether someone has the running app, or only a copy of the database.

What it stops
  • A stolen copy of the database. Contact, medical and emergency details come out as gibberish. A stolen database password, or a copy carried out the door, gives up the same nothing. What a thief does get is names, rosters, and the address each person signs in with.
  • Someone prying rows out through the website. Same gibberish.
  • A coach wandering where they shouldn’t. A head coach can open medical details for their own team. An assistant coach or team manager can’t, unless an admin grants it for a named reason that runs out on its own. Either way, you see it.
  • Phishing. There’s no password to steal. You sign in with your own device, and it only works on our site.
  • A stolen invite or sign-in link. Each one works once, then expires.
What it does not stop
  • Someone taking over the server itself. This is the honest one. The app has to hold the key while it’s running, so anyone who gets that far reads what the app reads. We run on ordinary hosting. Saying otherwise would be a lie.
  • The company we rent the server from. They run the machine the app runs on, so the same thing applies to them. What we can tell you is that we never hand them your family’s details for any purpose of their own, and nothing about your family is sold or shared with anyone.
  • An admin who goes looking. An admin is supposed to reach this data. Making them prove who they are, and writing down every look, makes it slower and easy to trace. It doesn’t make it impossible.
  • Everything around the data. Team sizes, timings, and which adult is linked to which child stay readable. Lock those and nothing works.
  • A forgotten password. There isn’t one. You sign in with your own device, so there is nothing for us to reset and nothing for anyone to guess. Lose every device you have signed in with and a club admin re-invites you.
  • A phone that’s already been taken over. Whoever controls a parent’s phone is in that parent’s account. We can cut off that one device.

Three conveniences each trade a little privacy, and you can turn all three down. A calendar feed is a secret link, so anyone you forward it to sees that child’s schedule. A one-tap answer link works without signing in, which is the point of it. And message search keeps an index of who said what, so it can find anything at all.

Rules nobody can switch off

Your club can be stricter than the law. It can never be looser.

Four sets of rules, settled the same way every time.

4 · you

What you prefer

Your own choices, inside what the layers above allow.

is bounded by ↓
3 · club

Your club’s rules

Can be stricter than everything below. Can’t be looser.

is bounded by ↓
2 · league

Your league’s rules

Cover games played under that league: clocks, rosters, who has to be certified.

is bounded by ↓
1 · law · the floor

Rowan’s Law · PIPEDA · Rule of Two · a guardian’s right to see

Built in. Nobody turns these off. Not your club, not us.

Your club can decide the app goes quiet from 9pm to 7am. It cannot decide that 1am is fine. The law keeps midnight to 6am quiet, and the app refuses to save a rule that breaks it. A suspected concussion or a safeguarding alert still gets through. Those can’t wait for morning.

Stricter sticks. Looser gets pulled back.

How governance works →

No ads, nothing sold

The club’s subscription pays for this, so there’s nothing to gain by selling anything, and no ad trackers in the app to do it with. One outside company does see something: the service that sends the emails. It gets the address and the message. A reminder says your child’s first name, the team, and when and where to be. A removal notice names your child and says a concussion is suspected, because Rowan’s Law says you have to be told at once. It never gets what’s behind the notice: no medical history, no emergency contacts, no list of families.

Built around Canada’s privacy law

PIPEDA applies, and a child’s information counts as sensitive from the start. We go further than Ontario Basketball (OBA)’s own thin privacy policy: medical details kept apart, access only for people who need it, nothing collected we don’t need. Your club writes down how long it keeps records. But nothing deletes them when that time is up. Someone at the club has to remove them by hand.

Which country the data sits in: the United States

Arizona. Our host has no Canadian option, so the choice was between an American location, a European one, and changing hosts. Names, rosters and the address you sign in with are stored readable, so a company in the United States can see which adult is connected to which child. It runs the server our app runs on, which means it could reach the encrypted details too. The app shows the location on screen, filled in the day a club is created.

Who looked

You can read the list of everyone who opened your child’s record.

Written down before it’s opened

The entry goes in the list before anything is unlocked. If it won’t write, nobody gets in. Opening your own child’s emergency contacts doesn’t ask you to prove yourself again, but it’s written down the same as anyone’s.

You read it yourself, admins included

It shows who they are and exactly what they opened. It doesn’t show where they were sitting. A coach’s home connection is the coach’s business.

No override button

To give someone medical access, an admin names the person, names the team, and types why. It runs out by itself within three days. You see the reason they typed, word for word.

Take back medical consent and the record goes

Not a flag saying ignore this. The record itself is deleted. Photo consent works differently: taking it back opens a takedown request for a person to action. An agreement you already signed is kept, because it recorded something that already happened.