Privacy Policy
Effective September 10, 2026 · Last updated September 10, 2026
See also our Terms of Service.
This policy explains how JTL Made LLC, doing business as ClubKeepr ("we," "us," "our"), collects, uses, shares, and protects personal information when you use ClubKeepr (which we call "the Service"). Please read it together with our Terms of Service.
ClubKeepr is offered only in the United States and is intended for people in the United States. We do not target or offer the Service to people outside the United States.
We wear two different hats. ClubKeepr is software we provide to sports clubs.
- For the information a club enters, or that families put into a club's space (player records, registrations, documents, and so on), the club is in charge of that information. We are just handling it for the club, following the club's instructions. (In legal terms the club is the "controller" and we are the "service provider" or "processor.")
- For the information we collect to run our own business (login details for the people who use the Service, billing details for clubs, and security and activity logs), we are in charge. By activity logs we mean the record the Service keeps of who did what and when: who changed a roster, who recorded or refunded a payment, who signed in, who changed a setting. Clubs rely on that record to answer questions about their own money and their own decisions.
If you are a parent, guardian, coach, or staff member and you have a question about how a particular club uses your information, please ask that club directly. We will help the club as its service provider.
A note for clubs: if your club needs a short written data processing agreement (a "DPA") that spells out how we handle personal information on the club's behalf, email us at privacy@clubkeepr.com and we will provide one.
1. What information we collect
1.1 Account and profile details. When someone creates or is invited to an account (club administrators, treasurers, coaches, team managers, and parents or guardians), we collect a name, an email address, a phone number (if given), the roles the person has in a club, and login information. We do not use passwords. Instead, we sign you in with a one-time code sent to your email, plus a second security step for higher-level roles.
1.2 Player (child) information. Parents, guardians, and authorized club staff enter information about young athletes. This can include the player's name, date of birth, jersey and uniform details, team assignments, guardian and emergency contacts, and answers to the club's waivers, consent forms, and registration questions. We ask for date of birth because clubs use it to check age eligibility, and we do not store Social Security numbers or any card or bank numbers for players. This is information about children, entered by adults, not by the children. See Section 6 for how we handle children's information.
1.3 Payment information. When a family pays a registration fee or makes a donation, or when a club pays for its subscription, the card and bank details are collected and handled by Stripe, not by us. We do not store full card numbers or bank-account numbers. We do keep non-sensitive payment details, such as amounts, dates, status, a Stripe reference number, and (for donations and registrations) the payer's name and email and which registration it was for, so clubs can balance their books and handle receipts and refunds.
1.4 Documents and files. Clubs and families can upload files. These are bug-report screenshots, expense receipts, and images attached to survey or feedback responses, which we keep in our file storage (see Section 8).
1.5 Tax and organization details (for clubs). For clubs that use the tax-reporting features, we store organization-level details the club gives us, such as its legal name, its EIN (a business tax ID), any "doing business as" names, its mission statement, and the name, title, and address of its main officer. This is the organization's information, not a personal profile of an individual.
1.6 Messages. We store the club-business and account-related emails sent through the Service and basic delivery details (for example, that a notification was sent), plus what we need to respect each person's notification preferences.
1.7 Technical and security data. We collect basic technical and security information needed to run the Service, such as logs of important actions, sign-in events, error reports, and performance measurements (for example, how long a page took to load, or how long a database query took). We do not feed your data into any AI system. Error reports and performance measurements go to a tool called Sentry, which strips out personal information before it is sent and runs only when the app is in production.
1.8 Cookies and browser storage. We use a small number of cookies. Every one of them is first-party, which means ClubKeepr sets it and no other website can read it. The cookies that sign you in are locked down further, so that even scripts running on our own pages cannot read them. The cookies do four jobs. Signing you in and keeping you signed in: your session, the email address you typed while a one-time code is outstanding, a device you asked us to remember for your second factor, and a short-lived value that makes signing in with a passkey work. Keeping you where you left off: which club you were last looking at, if you belong to more than one. Remembering a display choice you made: light or dark appearance, and a page toggle or two. Support: a record that a ClubKeepr administrator is temporarily acting as a user to help with a problem, which we also write to the audit log. Your browser separately keeps a small note when you dismiss certain in-app banners, so they stay dismissed. We do not use tracking cookies, advertising tools, or any cookie that follows you to another website. Because each of these is either needed to run the Service or is remembering something you chose, we do not show a cookie consent banner. You can clear or block cookies in your browser at any time, though signing in will not work without the session cookie.
1.9 Usage measurement. We measure which pages of the Service are used, including pages you see after you sign in, so we can tell what to improve. This runs through Vercel Web Analytics (see Section 8), which sets no cookies and uses no cross-site identifier. Vercel counts a visitor using a temporary value calculated from the web request itself, and discards that value within 24 hours, so return visits on a later day are not linked to earlier ones. Each page view records the page address, the page you arrived from, your browser, device type, operating system, and an approximate location (country, region, and city).
Before a page view is sent, we rewrite the web address to strip out anything that could identify a person or a record. A page such as /your-club/rosters/players/a1b2c3 is recorded only as /[club]/rosters/players/[id]. Club names, player names, record IDs, and one-time links (invitations, offers, surveys) never leave your browser, and any search terms attached to the address are dropped. The result tells us that a roster page was viewed. It does not tell us which club, which player, or which family.
1.10 Availability responses. A club can ask whether a player or a staff member is able to attend a particular game, practice, or other event. This is off unless the club turns it on. When it is on, we store the answer (going, maybe, or not going), who the answer is about, which event it is for, an optional short note, when it was given, and whether the person gave it themselves or a coach or manager recorded it for them. A parent or guardian answers for their own player; coaches and managers answer for themselves. Answers are visible to that team's coaches and managers, to the club's administrators, and to the other families on the same team, so everyone can see who is coming. A note is visible only to the team's coaches and managers and the club's administrators, never to other families. Answers for one team are not visible to other teams in the club. A club can also email you a request to answer, and we send a reminder about two days before the event if you have not. Those emails contain a private link that lets you answer without signing in. The link only ever answers for you and the players you are already connected to, and it shows you your own answers plus how many people in total are going, never a list of other people's names. Treat it like any other private link and do not forward it. You can turn these emails off under Notifications in your profile.
What we do not collect: Social Security numbers or personal tax IDs, full card or bank-account numbers, exact location, biometric data (like fingerprints or face scans), or advertising IDs. We also do not track you across other websites, and we do not show you ads.
2. How we use information
We use information to:
- run, secure, and maintain the Service and each Club Workspace;
- sign people in and protect accounts (one-time codes, the second security step, limits on repeated attempts, and lockouts);
- process payments through Stripe and let clubs balance their finances, send receipts, and give refunds;
- send account-related and club-business messages (like registration confirmations, payment receipts, waiver requests, and club announcements), based on each person's notification settings;
- let clubs ask who is able to attend an event, and show those answers to that team's coaches and managers so they know who to expect;
- provide support, fix problems, and look into abuse or safety and security issues (including the account-access controls in Section 5);
- create the financial and tax-report outputs clubs ask for; and
- follow the law and enforce our Terms.
We do not sell personal information, and we do not use it for advertising or to build advertising profiles across websites.
3. Why we are allowed to use your information
We use personal information to provide the Service you or your club signed up for, to keep it secure and prevent abuse, to meet our legal and record-keeping duties, and, where we ask for it, with your consent (including a guardian's consent to handle a player's information). For information we handle on a club's behalf, the club is responsible for the reason it is collected.
4. When and with whom we share information
We only share personal information in these situations:
- With the club and its staff. Information inside a Club Workspace is available to that club's authorized administrators and staff, based on their roles. Clubs are walled off from one another. This wall is built into the database itself, not just the app, so one club genuinely cannot reach another club's data.
- With the companies that help us run the Service (we call them "sub-processors"), listed in Section 8. They may only use the information to provide their service to us.
- With Stripe, to process payments (see Sections 1.3 and 8, and the Terms of Service).
- For legal reasons, to follow the law, respond to lawful requests, enforce our Terms, or protect the rights, safety, and security of people (including children), the public, or ClubKeepr.
- If our business changes hands, for example in a merger, sale, financing, or reorganization, information may transfer as part of that deal, still protected by this policy or one that replaces it. (This matches the "business changes hands" part of our Terms of Service.)
- With a calendar app, if you choose to sync a schedule. If you subscribe to a ClubKeepr schedule from your phone or computer, the calendar app you pick (for example Apple Calendar, Google Calendar, or Outlook) checks back with us on its own and receives that schedule, including player names, event times, and locations. You start this, you choose the app, and you can stop it at any time by resetting the link in ClubKeepr. Those companies are not our sub-processors here: they are acting for you, under their own privacy policies.
5. Support access to your account
Our staff cannot get into your account unless you let them in. If you want our help with a problem, you turn on "support access" yourself, and only then can an authorized staff member view your account and, where needed, take actions in it to help you.
- You grant this access from your account settings (Settings → Support access), or by ticking a box when you file a bug report. You choose how long it lasts: 24 hours, 3 days, or 7 days.
- Without your active, unexpired approval, our staff cannot enter your account. You can turn the access back off at any time, and it also switches off by itself when the time window ends.
- When you have granted access, it is still tightly controlled: only certain roles can use it, the staff member must confirm their identity with a second security step and record a reason, it is time-limited, it is logged when it starts and ends, and while it is happening you see a clear banner in the app.
The only narrow exceptions are things the law can require of any company (for example, responding to a valid legal order) or steps we must take to protect safety and security. See Section 8 of the Terms of Service for the full details.
6. Children's information
Protecting children's information is central to what we do, because ClubKeepr is used to run youth sports. Children do not create or hold ClubKeepr accounts. A player's information is entered by the player's parent or legal guardian and by authorized club staff.
- We collect a player's information (like name, date of birth, and whatever a club needs for registration, eligibility, and safety) to provide the Service to the club and the family, for example to register the player, check age eligibility, collect required waivers, and allow team messaging.
- We do not ask a child to share more than is reasonably needed to take part, we do not make a child's participation depend on giving us unnecessary information, and we do not use children's information for advertising, and we do not sell it.
- A parent or guardian can review a player's information, ask us to correct it, or ask us to delete it, either through the club or by contacting us at privacy@clubkeepr.com. We will help the club, which is in charge of the record. Deleting some records may end the player's ability to take part, and some records must be kept for legal reasons (for example, financial records tied to a payment).
A player's information is entered by the adults a club has authorized (the club's staff and the family's parent or guardian). The club decides who those authorized adults are; ClubKeepr does not separately verify that a given adult is a specific child's parent.
7. How long we keep information
We keep personal information only as long as we need it to run the Service and to meet our legal, tax, accounting, and security duties.
7.1 While your account is active. We keep Club Data and account information for the life of the account, so the club can run its programs.
7.2 After a subscription ends. When a subscription is canceled or ends, the Club Workspace goes into a 60-day holding period. During that time, the account can be turned back on with its data intact, and the club can export its data, including its signed documents. After the 60 days, we delete the club's operational personal information, including player records (names, dates of birth), guardian and emergency contacts, signed documents, messages, and uploaded files, except as described in 7.3.
7.3 What we keep longer. We keep the limited financial and transaction records we need for our own tax, accounting, audit, and legal purposes and for our payment provider, for up to 7 years after an account ends. Where we can, we keep these in anonymized form, meaning we strip out the details that identify a specific person and keep only what we genuinely need, such as amounts and dates. We keep no more than we need, and we protect it as described in Section 9.
7.4 Activity logs age out on their own. Activity logs are not kept forever. A log entry about club operations (a roster change, a settings change, a sign-in) is deleted automatically after 15 months. A log entry about money (a payment, a refund, an expense, a donation, a tax record) is kept for 7 years, to match the financial records it explains, and is then deleted automatically as well. This happens on a schedule, without anyone having to ask.
7.5 Records that cannot be changed. While we hold them, some records are locked against editing: activity logs, signature records, and certain payment details. Nobody, including us and including a club administrator, can rewrite them. That is what makes them worth anything to a club that has to show its books were not altered after the fact. Locked against editing is not the same as kept forever: the periods above still apply, and when a record reaches the end of its period it is deleted.
7.6 Short-lived data. Some operational and security data is kept only briefly and then routinely deleted. For example, bug-report screenshots and diagnostic images are deleted on a rolling basis, and one-time codes, sign-in records, and rate-limit data expire on their own.
| Type of information | While your account is active | After your account ends |
|---|---|---|
| Player, guardian, signed document, message, and availability records; uploads | Kept for the life of the account | Deleted after the 60-day holding period (you can export first) |
| Financial and transaction records | Kept for the life of the account | Kept up to 7 years (anonymized where practical) |
| Activity logs about club operations | Deleted automatically after 15 months | Deleted automatically after 15 months |
| Activity logs about money, and certain payment details | Kept 7 years, locked against editing | Kept 7 years, locked against editing |
| Bug screenshots and diagnostic images | Deleted on a rolling short-term basis | Deleted with the account |
8. The companies that help us run ClubKeepr (sub-processors)
We use the outside companies below to run the Service. Each one is only allowed to use information to provide its service to us. This list reflects what is actually connected and sending data today. Each company's own privacy policy is linked so you can read how it handles information.
| Company | What it does for us | What personal information it receives | Their privacy policy |
|---|---|---|---|
| Stripe, Inc. | Processes payments, handles subscription billing, and pays clubs | Payer name and email; donation and registration amounts; card and bank details go straight to Stripe; a reference code for the registration; club and account details. No child information is sent to Stripe. | https://stripe.com/privacy |
| Resend | Sends account-related and club-business email | Recipient name and email; the content of the email, which for some club messages includes a player's first name (for example, "Registration confirmed for [player]") | https://resend.com/legal/privacy-policy |
| Supabase | Hosts our main database | All Service data as stored, including account, player, registration, document details, and financial records | https://supabase.com/privacy |
| Cloudflare R2 | Stores uploaded files | Uploaded files: bug-report screenshots, expense receipts, and images attached to survey or feedback responses | https://www.cloudflare.com/privacypolicy/ |
| Inngest | Runs background tasks (like sending bulk club announcements) | Task details that may include recipient email addresses and player first names (for sending announcements) | https://www.inngest.com/privacy |
| Sentry | Monitors errors and measures performance, so we can diagnose problems and make the Service faster | Technical error and performance information (such as page and database timings); personal information is stripped out before it is sent; only turned on in production | https://sentry.io/privacy/ |
| Vercel | Hosts and delivers the app, and measures page usage (Vercel Web Analytics) | Standard request and log information needed to serve the app. For usage measurement: the page address with identifying parts removed (see Section 1.9), the page you arrived from, browser, device type, operating system, and approximate location. No cookies and no cross-site identifier | https://vercel.com/legal/privacy-policy |
A note on fonts: the typefaces in the app originally come from Google Fonts, but we download them once when we build the app and serve them from our own servers. Your browser never connects to Google, so no information about you is shared just by using the app's fonts.
We can provide an up-to-date list of these companies on request, and we will update this policy when we add or change a company that handles personal information.
9. How we protect information
We protect information with technical and organizational safeguards, including:
- Keeping clubs separate, so one club's data is walled off from another's at the database level.
- Encryption while data travels across the internet, and encryption of especially sensitive secrets while stored (for example, the second-security-step secrets are stored encrypted).
- Modern sign-in, using one-time email codes instead of reusable passwords, a required second security step for higher-level roles, limits on repeated attempts, and lockouts after repeated failures.
- Giving people only the access they need, with role-based access inside each club, tightly limited and recorded support access, and key records that cannot be changed.
One deliberate exception: calendar links. If you turn on calendar sync, the link we give you works without signing in, because that is the only way calendar apps are able to read a schedule. Anyone who has that link can see that schedule. We say so at the point where you copy it, the link is long and randomly generated so it cannot be guessed, and you can cancel it at any time with Reset link, which stops every device that already subscribed.
We work hard to protect your information using these safeguards and by keeping our security up to date. Like any online service, we cannot guarantee that it is impossible for information to ever be accessed improperly, but we treat protecting your information as a core responsibility.
If a data breach ever affects your personal information, we will notify you (and, where required, the appropriate authorities) as required by law, within the timeframes the law sets.
10. Your rights and choices
Depending on where you live and your relationship with us, you may have the right to see, correct, delete, or export personal information, or to object to or limit certain uses. Here is how to use those rights:
- Information inside a club's workspace (player, registration, and club records): contact the club, which is in charge of that information. We will help the club respond, as its service provider.
- Your own account information, where we are in charge: contact us at privacy@clubkeepr.com.
- Message preferences: you can change your notification settings in the Service. A few critical messages (like security, payment, and account-status notices) cannot be turned off while you use the Service.
To make a request about your own account information, email us at privacy@clubkeepr.com. We handle these requests by hand (there is not a self-service "download my data" button yet), and we will respond within the time the law allows, generally within 45 days, after first making sure the request is really coming from you (so we do not hand your information to someone pretending to be you). We may keep some information where we have a legal duty or a genuine need to (for example, the financial and activity records described in Section 7, which are locked against editing until their retention period ends).
11. State privacy rules
ClubKeepr is offered only in the United States. Some U.S. states give their residents specific privacy rights, such as the right to see, correct, delete, or get a copy of their personal information, and the right not to have it sold (we do not sell personal information). You can use these rights the same way described in Section 10.
11.1 For California residents. If you live in California, the California Consumer Privacy Act (as updated by the CPRA) gives you specific rights. Here is how it applies to ClubKeepr:
- What we collect, and why. The categories of personal information we collect are described in Section 1: identifiers (like name, email, and phone number), account and login information, commercial information (like payment amounts, dates, and status, but not full card or bank numbers), internet and network activity (like security logs, sign-in events, and error reports), and, for players, the information a parent or guardian enters (like a name, date of birth, and emergency contacts). We collect these for the purposes described in Section 2, and we get them from you, from your club, and from your use of the Service.
- We do not sell or "share" your personal information. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising (the CCPA's special meaning of "share"). We have not done so in the past 12 months. Because we do not sell or share, there is nothing to opt out of, but you can still tell us you object at privacy@clubkeepr.com.
- Sensitive information. We do not use sensitive personal information to figure out characteristics about you, and (as Section 1 explains) we do not collect Social Security numbers, precise location, or biometric data at all.
- Your rights. You have the right to know and access the personal information we hold about you, to have it corrected, to have it deleted, and not to be treated differently for using these rights. A few records must be kept for legal reasons (see Sections 7 and 10).
- How to use them. For information inside a club's workspace, contact the club; for your own account information, email privacy@clubkeepr.com (see Section 10). You may use an authorized agent to make a request for you, and we will confirm the request is genuine before acting on it.
11.2 For Washington residents (My Health My Data Act). Washington's My Health My Data Act gives Washington consumers rights over "consumer health data." ClubKeepr does not have a built-in field for health or medical information, and we do not collect, use, or sell consumer health data as a first-party matter. If a club chooses to ask a health-related question through its own custom form, the answer is the club's information, collected under the club's own authority and its own policy, and the club is responsible for it; we handle it only as the club's service provider. We never sell consumer health data and never use it for advertising. If you are a Washington resident, you can withdraw your consent and ask to have such information deleted by contacting the club, or us at privacy@clubkeepr.com.
12. Changes to this policy
We may update this policy. If a change is important, we will let you know (for example, by emailing affected account holders or showing a notice in the app) before it takes effect, and we will update the "Last updated" date at the top.
13. How to contact us
JTL Made LLC, doing business as ClubKeepr. Privacy contact: privacy@clubkeepr.com.