Draft — not in force
This text has not been reviewed by a lawyer and is published so the sign-up experience can be tested. It does not bind anyone, and it will be replaced before LeagueBinder is offered to leagues outside our own. Version 2026-08-08.draft.2.
Still to be settled: date, legal entity name, mailing address, privacy email, subprocessor url.
Privacy Policy
LeagueBinder Privacy Policy
DRAFT — NOT REVIEWED BY COUNSEL. NOT FOR PUBLICATION.
Version: 0.1 (draft) Effective Date: [DATE]
The most important thing to understand first
LeagueBinder handles two different kinds of information, and our responsibilities are different for each.
Information we control. Account and billing information about the organizations that buy LeagueBinder and the board members who use it. This policy governs that information.
Information we process for our customers. The documents, records, and rosters a league's board stores in LeagueBinder — which may include information about players, parents, coaches, and volunteers, including children. We do not decide what that information is, why it is collected, or how long it is kept. The league does. We handle it only on the league's instructions, under our Data Processing Addendum.
If you are a parent, player, coach, or volunteer and you want to know what a league holds about you, or you want it corrected or deleted, contact the league directly. We cannot act on those requests ourselves — we will refer you to the league, and we will help the league respond.
The Service is offered only to organizations in the United States.
1. Who we are
[LEGAL ENTITY NAME], a Massachusetts limited liability company, doing business as LeagueBinder. Contact: [PRIVACY EMAIL] / [MAILING ADDRESS].
2. Information we control
2.1 What we collect
Account information. Organization name, address, and type; the name, email address, role, and password credentials of each authorized user.
Billing information. Billing contact, billing address, and transaction records. We do not collect or store payment card numbers — payments are processed by our payment provider, which receives that information directly.
Usage and technical information. Log data including IP address, browser and device type, pages accessed, actions taken, and timestamps. Authentication events and administrative actions are recorded in an audit log.
Support communications. Messages you send us and our responses.
Marketing information. If you contact us or sign up for updates, your name, email, and organization.
2.2 Why we use it
- To provide, secure, maintain, and support the Service
- To authenticate users and prevent unauthorized access
- To bill and collect fees
- To detect, investigate, and respond to security incidents and misuse
- To communicate about the Service, including outages, changes, and renewals
- To improve the Service, including through aggregated and de-identified analysis
- To comply with law and enforce our agreements
2.3 What we do not do
- We do not sell personal information.
- We do not share personal information for cross-context behavioral advertising.
- We do not use customer content to train machine learning models.
- We do not serve third-party advertising in the Service.
3. Information we process for leagues
Leagues use LeagueBinder to store board records, which may include meeting minutes, policies, budgets, correspondence, contact lists, rosters, and volunteer screening status.
Our role is limited. We store it, secure it, make it available to the people the league authorizes, and delete it when the league tells us to or when our agreement ends. We do not use it for our own purposes. We do not sell it. We do not use it to train models. Our handling is governed by the Data Processing Addendum at [URL].
Children's information — exactly what we hold. Leagues store a limited set of information about players who are minors. That set is: first name, last name, and year of birth. Nothing else.
We do not store a child's full date of birth — only the four-digit year, which is what youth sports age groups are based on. We do not collect or store children's email addresses, phone numbers, home addresses, photographs, health or allergy information, emergency contacts, or location data. There is no way for a child to create an account, log in, or communicate through the Service.
We also require, by contract, that the league has the legal right to collect the information it stores and has given any notices and obtained any consents required by law, including from parents and guardians. Leagues are contractually prohibited from uploading Social Security numbers, government identification numbers, financial account numbers, health information subject to HIPAA, or background check reports.
4. Sharing
We share information only as follows:
Service providers (subprocessors). Vendors who host, secure, and operate the Service on our behalf — hosting and database, object storage, transactional email, payment processing, and error monitoring. Each is bound by contract to protect the information and use it only to provide services to us. Our current list is published at [SUBPROCESSOR URL].
Legal requirements. When required by law, subpoena, or legal process, or to protect rights, safety, or property. Where we are legally permitted, we will notify the affected customer before disclosing information stored on their behalf.
Business transfer. In connection with a merger, acquisition, or sale of assets, subject to this policy or a successor policy providing comparable protection. Customers will be notified.
We do not otherwise disclose personal information to third parties.
5. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including: encryption in transit and at rest; separation of each league's data enforced at the database layer; multi-factor authentication; role-based access controls; append-only audit logging; least-privilege access for personnel; and regularly tested backups.
We maintain a written information security program. A current description of our security measures is available in Annex II of our Data Processing Addendum.
No system is perfectly secure. We do not guarantee that information will never be accessed without authorization.
6. Retention
Information we control. Account information is retained while the account is active and for a reasonable period afterward for legal, tax, and audit purposes. Log and audit data is retained for [X] months. Billing records are retained as long as required by law.
Information we process for leagues. Retained according to the league's instructions and our agreement with them. On termination, leagues may export their data for 30 days, after which it is deleted. Free trials work differently: if a league does not subscribe at the end of its 60-day trial, the account is suspended and its data is held for a further 90 days so the league can come back and pick up where it left off. During that period the league can sign in to an export-only view to download its data at any time. At the end of the 90 days we permanently delete everything it uploaded.
Copies in encrypted backups are removed on the normal backup rotation cycle, within [Y] days.
7. Your choices and rights
Board members and account users. You may access and update your account information in the Service, or contact us at [PRIVACY EMAIL]. You may opt out of marketing email at any time; you cannot opt out of transactional messages about your account.
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information we control about you, and to be free from discrimination for exercising those rights. To make a request, contact [PRIVACY EMAIL]. We will verify your identity before responding and will respond within the time required by applicable law.
Requests about league records. If your request concerns information a league stores in LeagueBinder — for example, a player's or parent's information — please contact the league. We will forward the request and assist the league in responding, but the league decides.
Do Not Track and Global Privacy Control. We do not sell personal information or share it for cross-context behavioral advertising, so these signals do not change our practices.
8. Cookies
We use cookies and similar technologies only for essential purposes: keeping you signed in, maintaining session security, and remembering preferences. We do not use advertising or cross-site tracking cookies. [DRAFTING NOTE: if any analytics tool is added, this section and the subprocessor list must be updated, and a cookie banner may become necessary.]
9. Children
The Service is designed for use by adult board members and volunteers. It is not directed to children, and we do not knowingly collect personal information directly from children.
Leagues may store information about children in their own records. That information is handled as described in §3. If you believe a child's information has been provided to us other than through a league's account, contact [PRIVACY EMAIL] and we will investigate.
[DRAFTING NOTE — SEE COVER MEMO §3(B): counsel must confirm the COPPA analysis underlying this section. It is an assumption, not a conclusion.]
10. United States only
The Service is offered only to organizations in the United States and information is stored in the United States. We do not offer the Service to individuals or organizations in the European Economic Area, the United Kingdom, or Switzerland.
11. Changes
We may update this policy. Each version carries a version number and effective date, and prior versions are retained and available on request. Material changes will be communicated by email to account administrators or by notice in the Service before taking effect.
12. Contact
[LEGAL ENTITY NAME] [MAILING ADDRESS] [PRIVACY EMAIL]