Privacy Policy

Last updated 11 August 2026

Draft, pending legal review.This was written against what the software actually does, and we believe it is accurate — but it has not yet been reviewed by a lawyer. If you are considering Club Compass for a club, ask us where that review stands before you enter anyone's data.

Who we are

Club Compass is software for running a youth soccer club. A club signs up, and the club's admins and coaches enter information about their teams, players, matches and events.

The club is the data controller; we are the processor.The club decides what goes in and who may see it. We store it and run the software. If you are a parent and you want your child's information changed or removed, ask your club first — they can do it immediately, and they are the ones who put it there.

What we store

Accounts (anyone who signs in):

  • Name, email address, and a hashed password. We never store a password in readable form.
  • Which clubs and teams you belong to, and your role in each.

Players — usually children — as entered by the club:

  • First and last name; optionally date of birth, shirt number, position, height, and status.
  • Optionally a photo URL, if the club adds one.
  • Optionally a guardian's name, email address and phone number, so the club can reach a parent.

Activity the club records:

  • Matches, events, attendance and RSVPs.
  • Coach evaluations of players — ratings and written notes.
  • Answers to forms the club creates (for example a medical or consent form).

We do not collect payment details, we do not run advertising, and we do not sell or share anything with data brokers.

Children

Most players in Club Compass are minors, and we treat their information accordingly.

  • Children do not have accounts.There is no signup path for a player. A child's information is entered by their club's staff, and a parent responds to RSVPs through a private link that needs no account and no password.
  • The club is responsible for the consentto hold a child's information, under whatever rules apply where the club operates — in the United States that includes COPPA, and in the EU/UK the GDPR rules on children's data.
  • A parent or guardian may ask their club, or us, to see or delete what is held about their child. We will act on a request from a club immediately, and on a direct request from a parent after checking with the club that you are who you say you are.

Who else processes it

We keep this list short on purpose, and it is the whole list. Each of these is a company that necessarily touches data in order for the product to run:

  • Vercel — hosts the application and serves every page. Sees requests and server logs.
  • Neon — hosts the Postgres database where everything above is stored, in the United States (AWS us-east-1).
  • Sentry — collects error reports and performance data so we can fix crashes. This includes a sampled session replay: a reconstruction of what happened on screen when something broke. Replays are recorded with all text and all inputs masked, so names and contact details are not captured in them.
  • Cloudflare — runs the domain and forwards email sent to our contact address.

The optional in-product AI assistant sends only the question you type, plus the records it is asked about, to whichever AI provider you supply a key for. It is off unless you add a key, and the key is kept in your own browser, never on our servers.

How long we keep it

As long as the club keeps it. Delete a player and their evaluations, attendance, form answers and match appearances go with them; delete a team and its players go; delete a club and everything under it goes. Deletion is immediate and is not recoverable by us.

Backups held by our database provider may retain a copy for a short window after deletion, after which it is gone.

Where it is stored

In the United States. If your club is in the EU, the UK, or Latin America, information about your players is transferred to and stored in the US. Tell us before you sign up if that is a problem for your club — we would rather say so now than surprise you.

Security

Traffic is encrypted in transit. Passwords are hashed. Access is scoped to the club you belong to: a coach or admin at one club cannot read another club's players, and the software is written so that asking for another club's record returns “not found” rather than confirming it exists.

We are a two-person team and we do not pretend to hold a security certification. If you find a vulnerability, our disclosure process is in SECURITY.md in our source repository, and the contact address below reaches us.

Your choices

  • See, correct or delete anything about you or your child — ask your club, or us.
  • Close your account — ask us and we will remove it.
  • Object to how your club uses the product — that conversation belongs with your club, since they decide what to record.

Changes

If we change this policy in a way that affects what we collect or who processes it, we will say so on this page and date it. The date at the top is when this version took effect.

Contact