Privacy Policy
The short version
- Nobody under 18 has an account. Children appear in TEAMON3 only as roster entries created and controlled by an adult guardian.
- We do not sell or share your personal information, and there are no third-party advertising, analytics, or fingerprinting SDKs anywhere in our apps. We cannot show you ads; the product has no mechanism for it.
- We do not train AI models on your data, and neither do the AI providers we use — that is a contractual condition of using them.
- Guardians can see the team channels their player is in. This is deliberate, it is how we keep children safe, and it is not optional.
- You can export or delete your data from inside the app at any time.
This summary is for orientation. The sections below are the actual policy, and where they differ from this box, they govern.
TEAMON3 is a youth sports team management service: rosters, schedules, team chat, tasks, fee collection, and — as they become available — live scorekeeping, streaming, and an assistant called Trinity. Youth sports means we hold information about children, and that fact shapes the whole design of this product rather than being handled at the end. This policy explains what we collect, why, who we give it to, how long we keep it, and what you can do about it.
Some features described here have not launched yet. Where that is true, the text says so with a Not yet live marker. We describe them now so that this policy does not have to change on the day they arrive, and so you can see the whole picture before deciding to use the service.
- 1. Who we are
- 2. Accounts are for adults only
- 3. Children's information
- 4. What guardians can see
- 5. What we collect
- 6. How we use it
- 7. What we never do
- 8. Text messages (SMS)
- 9. Push notifications
- 10. Trinity, our AI assistant
- 11. Payments
- 12. Location and venues
- 13. Photos, video, and streams
- 14. Who we share information with
- 15. Legal and safety disclosures
- 16. Where your information is stored
- 17. How long we keep it
- 18. How we protect it
- 19. Your choices and rights
- 20. US state privacy rights
- 21. Changes to this policy
- 22. How to reach us
1. Who we are
TEAMON3 LLC ("TEAMON3", "we", "us") is an Illinois limited liability company. We are the controller of the personal information described in this policy — meaning we decide what is collected and why — except where this policy says a team or organization directs us instead.
You can reach us about anything in this policy at support@teamon3.com. That address is read every day, and it reaches us independently of any team, coach, or club — including when your concern is about one of them.
2. Accounts are for adults only
You must be 18 or older to create a TEAMON3 account. There is no account type for minors at any age, and no way to convert a child's roster entry into one.
When you sign up we ask for your date of birth before collecting anything else. That check happens on your device. The date itself is never sent to us and we never store it. What we record is that the question was asked, when, and which version of the age gate you answered — not the answer. If the date entered is under 18, sign-up stops and we hand off to information for a parent or guardian instead.
If we learn that someone under 18 has obtained an account, we close it and delete the information associated with it.
3. Children's information
Children are in TEAMON3 because their teams are. A child exists in the service as a roster entry — not a user — created by an adult who states that they are that child's parent or legal guardian. The child cannot sign in, cannot message anyone, and cannot be messaged.
Parental consent
Before we collect anything about a child beyond a first name and a jersey number, we obtain verifiable parental consent from a guardian, and we record when it was given and by what method. This is the standard the Children's Online Privacy Protection Act ("COPPA") sets, and we apply it to every player under 18, not only those under 13.
What we collect about a child
Deliberately little. For a player under 18, the complete list is:
- display name and jersey number;
- date of birth, used to determine age-group eligibility and when guardian access ends;
- the link to their guardian or guardians;
- attendance and athletic performance statistics recorded by their team; and
- photos, video, or stream footage their team uploads, where a guardian has not opted the child out. Streaming not yet live
We do not collect a child's email address, phone number, precise location, contacts, or device identifiers, because a child has no device session with us to collect them from.
Guardian rights
As the parent or guardian of a player, you can at any time:
- review everything we hold about your child, through the in-app data export;
- correct it;
- delete it, by removing the roster entry or by asking us — and refuse any further collection, which means removing the child from the team;
- withhold consent for your child's likeness to be used in recordings or clips, per player, which suppresses clip generation featuring them. Not yet live
When a team or account is deleted, minors' data is purged first, ahead of everything else in the queue.
At 18, the relationship ends by design. Guardian access to a player's information stops when the player reaches the age of majority, and both parties are notified before it happens. At that point the young adult may create their own ordinary account — a new account, not an inheritance of the old roster entry.
4. What guardians can see
A guardian has read access to every team chat channel their player participates in. We are stating this prominently because it is the single most important thing to understand about privacy on this platform, and because everyone in those channels should know it.
This is not a setting, it cannot be switched off, and it is not something a coach or an administrator can override. It exists so that no adult can have an unobserved channel to a child. If you are a coach, an assistant, or another parent writing in a team channel, assume that the guardians of every player represented there can read what you write.
Guardian access is calculated at the moment of each request from the guardian-player link — it is not a copied-in membership that could drift out of date when a link is removed. When a guardian link ends, the access ends with it.
5. What we collect
| Category | What it is | Why we have it |
|---|---|---|
| Account | Name, email address, phone number, password (stored only as a hash), profile photo, language and time zone | To create and secure your account and show you to your teammates |
| Age assertion | That you confirmed you are 18 or older, when, and which version of the gate you saw. Never the date itself | To show we asked, which is what our whole no-minors model rests on |
| Team and roster | Teams you belong to, your role, jersey numbers, players you are a guardian of, availability and RSVPs | To run the team |
| Content you create | Messages, photos, videos, files, event details, tasks, notes, reports you file | To deliver it to the people you sent it to |
| Schedule and venues | Events, opponents, and the addresses and coordinates of the places you play | To show the schedule, directions, and travel distance |
| Payments | Amounts owed and paid, who paid, payment status and receipts. Not card numbers — those go directly to Stripe and never touch our servers | To collect team fees and keep the team's books straight |
| Statistics | Game and season statistics recorded by scorekeepers Not yet live | To produce the stats the team is there for |
| Assistant conversations | What you ask Trinity and what it answers, including the data it looked up to answer Not yet live | To hold a conversation that remembers its own context |
| Device and technical | Device model, OS version, app version, push notification token, IP address, session and security logs | To deliver notifications, keep sessions secure, and diagnose faults |
| Usage | First-party events about which features are used and when | To understand what to build next. This is our own pipeline, not a third party's |
| Support and moderation | Messages you send us, reports you file, and the record of what we did about them | To answer you and to act on safety reports |
Most of this comes from you directly. Some comes from other people — a coach adds you to a roster, another guardian records that a fee was paid, a teammate posts a photo you are in. Some is generated automatically by your device when the app runs.
6. How we use it
- To provide the service: show the schedule, deliver messages, collect fees, keep rosters current.
- To send you notifications you have asked for, subject to your preferences and quiet hours.
- To keep the service safe: investigate reports, enforce our Terms, and act on abuse.
- To secure accounts: detect suspicious sign-ins, rate-limit attacks, and verify that a real device is making a request.
- To take payment for team fees and for TEAMON3 subscriptions.
- To support you when you contact us.
- To fix faults and improve the product, using first-party usage events and error reports.
- To meet legal obligations, including our duty to report child sexual abuse material to the National Center for Missing & Exploited Children when we become aware of it.
7. What we never do
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have, and the business does not have a revenue line that would depend on it.
- We do not run advertising, and we have no third-party advertising, analytics, or fingerprinting SDKs in our apps. This is enforced by our build, not by policy: the messaging library we use is installed without its analytics and advertising components, with automatic collection switched off at the manifest level so that a dependency cannot quietly turn it on.
- We do not train AI models on your content, and we do not permit our AI providers to. Both operate under terms that forbid training on our inputs and, in the case of the search provider, retaining them at all.
- We do not use your data to build profiles of children for any purpose beyond running their team.
8. Text messages (SMS)
We use text messages for a small, specific set of purposes: verifying a phone number when you sign up, sending team invitations, and — if you turn them on — alerts for urgent things like a cancelled game or an overdue payment.
- We do not sell, rent, or share mobile phone numbers or SMS consent with anyone for marketing purposes. Phone numbers are shared only with the messaging provider that delivers the message on our behalf, and never with data brokers, advertisers, or other third parties.
- Message frequency varies and depends on your team's activity and the alerts you have enabled. Verification messages are sent only when you request one.
- Message and data rates may apply.
- To stop, reply STOP to any message; we will confirm and send no further texts to that number. Reply HELP for help, or email support@teamon3.com. You can also turn SMS off per category in the app under Settings.
- Opting out of text messages does not close your account or stop in-app and push notifications.
9. Push notifications
Push notifications are delivered through Apple and Google, which means the notification's visible text passes through their systems on the way to your device. Because of that, we deliberately keep sensitive content out of notification payloads — the notification tells you something happened and the app fetches the detail once you open it. You control categories, quiet hours, and whether previews are shown on a locked screen in Settings, and you can turn notifications off entirely in your device settings.
10. Trinity, our AI assistant Not yet live
Trinity is a conversational assistant that can answer questions about your team and propose changes to it. Three things about it matter for privacy:
- It sees exactly what you can see, and nothing more. Trinity runs against the same permission checks as the rest of the app. A parent asking about another family's child gets a refusal, not an answer.
- It cannot change anything without you. Every action it proposes has to be confirmed by you before it happens.
- Your conversations are not training data. The model provider operates under commercial terms that exclude training on our inputs. Conversations are kept for 18 months, you can delete any of them at any time, and deleting your account or your team sweeps them.
To search your team's chat history, messages are converted into a mathematical representation by a search provider engaged under zero-retention, no-training terms. Deleted or moderated content is removed from that index in the same transaction, so it cannot resurface through the assistant.
11. Payments
Team fees are processed by Stripe. Card numbers, bank details, and the identity documents a treasurer submits go directly to Stripe — they do not pass through or rest on our servers, and we could not produce your card number if asked. We keep the amount, the status, the date, and who paid, so the team's books balance.
Stripe is an independent controller of the payment information it collects, and its own privacy policy governs that. Subscriptions bought inside the mobile apps are processed by Apple or Google, which likewise send us confirmation of a purchase, not a payment instrument.
12. Location and venues
We store the addresses and coordinates of the venues your team plays at, so that directions and travel distances work. Those are places, not people.
We do not track your device's location. The app does not run background location collection, and there is no continuous location feature in the product. Venue search and geocoding are performed by AWS Location Service on our behalf.
13. Photos, video, and streams
When you upload a photo or a video, it goes first into a private holding area that no other user can read. Before it becomes visible to anyone, we strip embedded metadata, including GPS coordinates, so that a photo of a child at practice does not publish the location it was taken at. Only then is it promoted and shown.
Media is stored privately and served through short-lived links rather than public URLs. Team recordings and streams, when they arrive, default to team members and fans only, with public sharing off and per-player likeness opt-out available to guardians. Streaming not yet live
14. Who we share information with
We share personal information with service providers who process it on our behalf, under contract, for the purposes below and no others. We do not authorize any of them to use it for their own purposes.
| Provider | What for | What they see |
|---|---|---|
| Amazon Web Services | Hosting, storage, databases, email delivery, venue search | Everything, as the underlying infrastructure |
| Stripe | Payment processing and treasurer identity verification | Payment details, payer name and email, and — for treasurers — identity documents |
| Twilio | Text messages | Phone number and message text |
| Google (Firebase Cloud Messaging) | Push notification delivery to both platforms | Push token and notification payload |
| Apple (APNs) | Push notification delivery on iOS | Push token and notification payload |
| Anthropic | The Trinity assistant Not yet live | Your conversation and the team data needed to answer it. No training on inputs |
| Voyage AI | Chat search indexing Not yet live | Message text, under zero-retention and no-training terms |
| Sentry | Crash and error reporting | Technical diagnostics with personal information scrubbed |
We also share information the obvious way: with the people you are on a team with. Your name, photo, role, and what you post are visible to your team according to its settings and to the guardian access described in section 4.
If TEAMON3 is ever acquired or merged, personal information may transfer as part of that transaction. You would be told before it happened, and any acquirer would be bound by this policy until you were given notice of a new one.
15. Legal and safety disclosures
We will disclose personal information outside the list above when we believe in good faith that it is necessary to:
- comply with a law, subpoena, court order, or other valid legal process;
- report child sexual abuse material, which we are legally obliged to do whenever we become aware of it;
- respond to an emergency involving a risk of death or serious physical injury;
- enforce our Terms of Service, or investigate suspected fraud or abuse; or
- establish or defend legal claims.
Content that staff remove is retained in a restricted audit store rather than destroyed, because deletion is often the first act of someone causing harm, and an investigation after the fact needs the record.
16. Where your information is stored
All of it is stored and processed in the United States, in Amazon Web
Services' us-east-1 region. TEAMON3 is currently offered only in the United
States. If you use the service from elsewhere, you are sending your information to the
United States, where privacy law differs from your own country's.
17. How long we keep it
| Data | Retention |
|---|---|
| Messages | For the life of the team, then archived by age |
| Media and recordings | Set by the team; 12 months by default, then cold archive |
| Assistant conversations | 18 months, and deletable by you at any time |
| Deleted account | 30-day recovery window, then permanently deleted |
| Deleted team | 90-day recovery window, then permanently deleted — minors' data purged first |
| Payment records | As long as tax and accounting law requires |
| Security and audit logs | 7 years |
| Removed content held for moderation | As long as our legal obligations require; access-restricted throughout |
18. How we protect it
- Encrypted in transit (TLS 1.3 minimum) and at rest (AES-256).
- Additional encryption on the fields that most warrant it, including addresses and phone numbers.
- Passwords stored using Argon2id hashing, never in a recoverable form.
- Optional two-factor authentication, required for owners and administrators of teams that collect payments.
- A permission check on every request, plus database-level isolation between teams as a second line of defence.
- Staff access to user data is role-restricted and audited — every read, not only every change — with recorded justification required to view an account as its user.
- Personal information stripped from logs, automated dependency and code scanning, and an annual third-party penetration test.
- An incident response plan with a 72-hour breach notification path.
No service can promise perfect security, and we do not. If a breach affects you, we will tell you.
19. Your choices and rights
Wherever you live, you can:
- See your data — Settings ▸ Privacy ▸ Export requests a full copy, including media.
- Correct it — edit your profile, or ask us.
- Delete it — Settings ▸ Account ▸ Delete account. There is a 30-day window to change your mind, after which it is gone. Some records survive deletion where law requires it, such as payment history and safety-report audit trails.
- Control notifications — per category, per team, with quiet hours.
- See and end sessions — review every signed-in device and revoke any of them.
- Delete assistant conversations individually.
- Stop text messages — reply STOP, or turn them off per category.
Guardians exercise all of these on behalf of their linked players, as described in section 3. To make a request outside the app, email support@teamon3.com. We will verify that the request is really yours before acting on it, usually by confirming control of the account email, and we respond within 45 days.
We will never charge you a different price or give you a worse service for exercising a privacy right.
20. US state privacy rights
If you live in California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, you have the rights listed in section 19 — access, correction, deletion, portability — and the right not to be discriminated against for using them. Section 5 is the required disclosure of the categories we collect, section 6 of the purposes, section 14 of the categories of recipient, and section 17 of how long we keep each.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as California's law defines those terms — so there is nothing for you to opt out of, and we do not need to offer a "Do Not Sell or Share My Personal Information" link. We do not process personal information for targeted advertising or for profiling that produces legal or similarly significant effects.
We collect two categories California treats as sensitive personal information: account credentials, and precise geolocation only in the sense of venue addresses your team enters. We use them solely to provide the service, which is a use California exempts from the right to limit — we do not use or disclose sensitive personal information for any other purpose.
You may use an authorized agent to make a request; we will ask for proof of their authority. If we deny a request you may appeal by replying to our decision, and we will respond within 45 days with our reasoning.
21. Changes to this policy
When we change this policy we publish the new version here with a new version number and effective date. If the change is material — a new category of data, a new purpose, a new recipient — we will tell you in the app or by email before it takes effect, and where the law requires it, ask for your consent. Each version is kept and we record which version each user accepted, so that what you agreed to is always answerable.
22. How to reach us
TEAMON3 LLC
Wayne City, Illinois, United States
support@teamon3.com
For a privacy request, please put "Privacy request" in the subject line. For a concern about a child's safety, put "Safety concern" — that reaches a person the same day, and it reaches us independently of any team or club.