Privacy Policy
Last updated August 4, 2026
Fieldhouse Connection is software that youth sports organizations — parks, leagues, clubs, and teams — use to run registration, dues, schedules, and team communication. This policy explains what we collect, why, and the rules the system enforces on itself.
The short version
- We never sell personal information, and we never sell or share children's data.
- Children under 13 do not get logins, and nothing about a child is collected without a guardian's recorded consent.
- A coach can see the children on their own roster and no one else's. This is enforced by the database, not by screen design.
- Every message a child can read, their guardian can read. There is no private adult-to-child channel in this product.
Who controls the data
The organization you belong to — your park, league, club, or team — decides what to collect and who on their staff may see it. They are the data controller. Fieldhouse Connection is the processor: we store and protect the data and act on the organization's instructions. Requests to correct or delete records normally go to your organization first; you can also contact us directly and we will help.
What we collect
- Adults (guardians, coaches, admins, trainers): name, email, password (stored hashed, never in readable form), and optionally a phone number for text notifications. Organization staff may also have compensation and tax records if their organization pays them through the platform.
- Athletes: first and last name, birthdate, team and jersey number, and — where the organization collects it — a home address, emergency information, and answers to that organization's registration form. Athletes 13 and older may have their own email and phone on file; younger athletes may not, and the database refuses to store them.
- Payments: handled by Stripe. Card numbers never touch our servers. We keep the amount, date, status, and Stripe's reference so your organization's books balance.
- Operational records: RSVPs, attendance, messages in team channels, and schedule history.
Children's privacy (COPPA)
Fieldhouse Connection is designed so that information about a child enters the system only through a parent or legal guardian.
- A profile for a child under 13 cannot be created without a guardian consent record attributed to that guardian's own account. This is a database constraint; there is no path around it, including for administrators importing a roster.
- When an organization uploads a roster spreadsheet, children are staged — not created. Each guardian receives an invitation, and the child's record exists only after that guardian confirms it and gives consent.
- Children under 13 are never issued logins. Athletes 13 and older can be given access only when a guardian turns it on.
- Guardians may review what is stored about their child, correct it, withdraw consent, or request deletion at any time, through their organization or by contacting us.
- We do not use children's data for advertising or profiling, and we never sell it.
Who can see what
Access is enforced at the database level with row-level security, so it applies identically to the website, the mobile app, and any future interface. Guardians see their own children. Coaches see the athletes on the teams they coach. Organization administrators see their own organization and the teams beneath it. Nobody sees another organization's families.
Who we share with
Only the service providers required to operate: Supabase (database and authentication), Vercel (website hosting), Stripe (payments), and Resend (email delivery). We do not sell personal information, and we do not share it with advertisers or data brokers. We may disclose information if legally required, or to protect someone's safety.
Keeping and deleting data
Organizations keep records for as long as they need them to run their programs and meet their own financial and legal obligations. You can delete your account from Settings; when you do, we remove your personal data except records we must retain for financial or legal reasons, such as completed payment history. Deleting a guardian account also removes the child profiles that exist solely under it.
Security
Data is encrypted in transit and at rest. Passwords are hashed. Access rules live in the database rather than in application code, which means a bug in a page cannot expose data the rules forbid. Payment card details are handled entirely by Stripe and never reach our systems.
Contact
Questions, corrections, or deletion requests: privacy@fieldhouseconnection.com. Guardians can also raise anything with their organization's administrator, who can act on their records directly.
If we change this policy in a way that affects how we handle your information, we will notify organizations and update the date above. Terms of Service