Privacy policy
Last updated: August 5, 2026
The short version
We collect only what a soccer league needs to run a season, we never sell or share your data, and you can get it back or have it deleted by asking. Most of our users are volunteers and parents — this policy is written for them, not for lawyers.
What we collect
Account details (your name and email, and a password we store only as a one-way hash). Player details entered by a parent, guardian, or league administrator: name, birth date, division, team, and any medical notes the league chooses to collect for player safety. Payment records — handled by Stripe; we see the amount and status, never your card number. Signed waivers, stored with a timestamp and IP address so the signature holds up. Messages and announcements sent through the platform, plus a delivery log of the emails we send. On this website, our waitlist form stores your email and which page you signed up from.
Who's responsible for your data
Two organizations touch a player's information, with clear roles. Your league is the controller — it decides what to collect and is responsible for having the right to collect it from its members. LeagueMgmt is the processor — we provide the software and handle data only on the league's instructions, never for our own purposes and never sold or shared for advertising. When you register a child, you're entrusting that information to your league; we're the tool they use to run the season. Either your league or we can correct or remove data when you ask.
Children's information
Most players are minors, so we hold their information to a higher bar. Children never create accounts — a parent or guardian (or the league) enters and controls a player's information, gives consent on the child's behalf, and can correct or remove it at any time. We collect the minimum a league needs to place a child on a team safely, and we never use children's information for marketing, profiling, or anything beyond running the league. (In British Columbia the age of majority is 19, so a parent or guardian consents for players under 19.)
How we ask for consent
When you register a player you actively agree to this policy and sign your league's waiver — we don't bury consent in fine print or pre-ticked boxes. Anything sensitive a league chooses to collect, like a medical note for player safety, is entered by you, on purpose, because it helps keep your child safe on the field. You can withdraw consent at any time by removing the information or closing the account.
Where your data lives
This website is delivered by Cloudflare's global network. Some services we rely on process data in the United States — Stripe (payments) and Resend (email) both do — so some information crosses the border, under contracts that require them to protect it to a standard comparable to Canada's. When the LeagueMgmt application launches for your league, application data will be hosted with our infrastructure provider and the specific regions will be listed here before any league data is stored. We follow PIPEDA and BC's Personal Information Protection Act (PIPA), and wherever data crosses a border we say so plainly — like we just did.
Who we share it with
Our subprocessors, used only to run the service: Stripe (payments), Resend (email delivery), Cloudflare (website and application delivery), and our application hosting provider. Your league's administrators and your player's coach see the roster information they need to run the season. That's the whole list — no advertising networks, no data brokers, no exceptions.
How we protect it
Your data is encrypted in transit (HTTPS everywhere) and at rest. Access is scoped — a league only ever sees its own data, and within a league people see only what their role needs: a coach sees their team, and medical notes are limited to administrators and the player's coach. Passwords are stored only as a one-way hash, so even we can't read them, and we never store card numbers — Stripe handles those.
If there's ever a data breach
If a breach ever put your information at real risk of harm, we won't sit on it. We'll notify the affected league and the people involved, report to the Office of the Privacy Commissioner as PIPEDA and BC PIPA require, and keep a record of the breach as the law expects. It's the outcome we work hardest to prevent — but you deserve to know the plan.
Cookies & analytics
This website uses Cloudflare Web Analytics, which is cookieless and doesn't track you across sites — which is why you don't see a cookie banner here. The application uses only the cookies and local storage needed to keep you signed in.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it — email us and it happens, no forms or phone trees. Leagues can export their full data (players, contacts, registrations, payment records) as CSV at any time, self-serve. If you close an account, we delete the associated data after a 30-day grace period, except records we're legally required to keep (like payment records for tax purposes).
Changes to this policy
If we make a material change, league administrators get an email 30 days before it takes effect, and the date below always reflects the current version.
Contact
Questions about privacy or your data: creative@thinkxdesign.com. You'll get an answer from a human.