Privacy Policy
Last Updated: July 20, 2026
How athletical.ly collects, uses, and protects your information.
1.1 Athletically LLC, a Delaware limited liability company registered as a foreign entity in Texas ("athletical.ly," "we," "us," or "our"), operates the athletical.ly sports-management platform.
1.2 This Privacy Policy applies to personal information processed through:
- (a) the athletical.ly website and public league websites;
- (b) the athletical.ly administrative dashboard;
- (c) the Scorekeeper mobile application for iOS and Android;
- (d) the athletical.ly application programming interface;
- (e) registration, payment, messaging, media, artificial-intelligence, analytics, and support functions; and
- (f) related communications and services.
1.3 The Platform serves sports organizations, administrators, employees, referees, scorekeepers, players, team captains, families, fans, prospective customers, and other visitors worldwide.
1.4 "Personal information" means information that identifies, relates to, describes, or can reasonably be linked with an individual. Terms such as "personal data," "processing," "controller," and "processor" have the meanings assigned by applicable privacy law.
2.1 athletical.ly acts as a controller or business when it determines why and how personal information is processed for Account creation, authentication, platform security, billing, analytics, customer support, service administration, marketing communications, and athletical.ly's own legal obligations.
2.2 Sports organizations using the Platform may separately determine why and how they collect and use information concerning their players, employees, officials, volunteers, parents, guardians, registrants, and other participants.
2.3 An Organization may act as an independent controller or business in relation to:
- (a) player and team rosters;
- (b) registration forms and participation records;
- (c) waivers, consents, and releases;
- (d) registration fees and refunds;
- (e) public league and player pages;
- (f) direct messages and mailing lists;
- (g) photographs, videos, blog posts, and news content; and
- (h) decisions concerning membership, eligibility, discipline, or participation.
2.4 athletical.ly may act as a processor or service provider when it stores or otherwise handles personal information solely on an Organization's documented instructions.
2.5 Questions about an Organization's independent decisions, including publication of a Player profile, registration requirements, refunds, waivers, or Organization communications, should ordinarily be directed to that Organization.
3.1 Account and Identity Information
We may collect:
- (a) first name, last name, and display name;
- (b) email address;
- (c) optional avatar or profile photograph;
- (d) optional date of birth;
- (e) Organization memberships, roles, permissions, and administrative status;
- (f) OAuth provider identity and subject identifier; and
- (g) authentication and session information.
athletical.ly uses passwordless authentication. Users may sign in through an email magic link or through Google, Apple, or Facebook. We do not collect or store Account passwords.
When an OAuth provider makes a profile photograph available, athletical.ly may receive and store that image as the user's Account avatar.
3.2 Player, Team, and League Information
Organizations and their Authorized Users may submit:
- (a) Player names and profile photographs;
- (b) hometown, height, weight, age, jersey number, position, and team;
- (c) schedules, rosters, attendance, and participation records;
- (d) scores, plays, penalties, substitutions, and Game events;
- (e) Player and team statistics, rankings, awards, and historical records;
- (f) league, division, season, venue, and official information; and
- (g) registration details and signed Organization documents.
Some Player information and Platform-generated statistics may appear on public league pages accessible without an Account. Publicly displayed information may include a Player's name, photograph, age, jersey number, position, team, Game history, statistics, and awards.
3.3 Registration and Payment Information
athletical.ly uses Stripe for payment processing.
For fees paid directly to athletical.ly, we may receive and retain:
- (a) Stripe customer identifiers;
- (b) invoice numbers and billing records;
- (c) payment amount, currency, status, and date;
- (d) limited payment-method information, such as card brand and last four digits, where supplied by Stripe; and
- (e) refund, dispute, and webhook records.
Full payment-card numbers are entered on Stripe-hosted pages and do not pass through or remain on athletical.ly's servers.
Organizations may save a payment method with Stripe for future billing. athletical.ly may store the associated Stripe customer and payment-method identifiers but not the full card number.
Organizations that enable registration payments may be required to establish a Stripe Connect account. Business representatives and beneficial owners provide identification, banking, business, tax, sanctions-screening, and verification information directly to Stripe. athletical.ly does not collect or store the underlying identity-verification documents or full banking details.
athletical.ly may receive the Organization's Stripe connected-account identifier, onboarding status, transaction status, platform-fee records, and other information supplied through Stripe Connect.
3.4 Communications and Mailing Lists
We may process:
- (a) direct messages and channel messages;
- (b) message participants, timestamps, and delivery information;
- (c) email content sent through the Platform;
- (d) mailing-list subscriber email addresses;
- (e) links between subscribers and Accounts;
- (f) subscription status and consent source;
- (g) subscription and unsubscription timestamps; and
- (h) hard-bounce and spam-complaint information.
Organization administrators may add subscribers to Organization mailing lists and represent that they hold any consent or other lawful authority required for that addition.
athletical.ly's product-update list uses a confirmation process before subscription is completed. Organization-managed lists may use different enrollment methods selected by the Organization.
A suppression record may be retained after Account deletion to prevent further email from being sent to an address that unsubscribed, generated a hard bounce, or submitted a spam complaint.
Direct messages are not routinely available to Organization administrators. athletical.ly personnel may access communications where reasonably necessary to provide support, investigate abuse, comply with law, maintain security, or enforce applicable terms.
Authorized athletical.ly administrators may use operational functions that permit communications to be sent on behalf of the Platform or an Organization.
3.5 Uploaded Content
Users and Organizations may upload:
- (a) avatars and profile photographs;
- (b) Organization logos;
- (c) photographs and videos;
- (d) blog and news content;
- (e) documents and attachments;
- (f) signed waivers and agreements; and
- (g) other media made available through Platform features.
Uploaded files may contain personal information concerning the uploader or another person. The person or Organization submitting the file must hold the authority and permissions required for its collection, use, and publication.
3.6 Voice and Audio Information
Web users may choose to record audio through their browser after granting microphone permission.
The recording is transmitted to athletical.ly's API and sent to OpenAI's Whisper service for transcription. Audio is processed transiently in memory and is discarded after transcription. athletical.ly does not retain the original recording.
The resulting transcript is returned to the user. When the user submits the transcript to the AI assistant or another Platform feature, it may be stored as message content.
3.7 Artificial-Intelligence Information
athletical.ly's AI assistant is powered by Anthropic.
Information submitted to the assistant may include:
- (a) the user's messages and conversation history;
- (b) the user's email address and Organization roles;
- (c) Organization, league, team, season, and Player names;
- (d) information retrieved in response to the user's request;
- (e) a digest of recent administrative activity from the user's own audit records;
- (f) tool calls and tool results; and
- (g) token-count and usage information.
The AI assistant is designed to perform read-only navigation and information-retrieval functions. It does not independently modify Platform records.
Full AI chat history is stored without a fixed automatic deletion period. Long conversations may be summarized by an additional model, and the generated summary may also be retained.
3.8 Information Collected Automatically
We may automatically collect:
- (a) Internet Protocol address;
- (b) browser type and version;
- (c) operating system and app version;
- (d) user-agent string;
- (e) requested page or API path;
- (f) date and time of access;
- (g) referring source;
- (h) response status and performance information;
- (i) approximate location derived from an IP address;
- (j) Account and Organization identifiers;
- (k) session, authentication, and security events; and
- (l) feature-interaction and page-view information.
Sensitive token parameters are redacted from ordinary API request logs before logging.
IP addresses may also be used transiently for rate limiting, fraud detection, security, and abuse prevention.
3.9 Audit Records
Every Platform action that creates, updates, or deletes a record may generate an audit entry containing:
- (a) the acting user;
- (b) action type;
- (c) target record;
- (d) timestamp;
- (e) IP address; and
- (f) user-agent string.
Read-only activity is not ordinarily included in the write-action audit log, except where separately recorded for security, analytics, AI, or operational purposes.
3.10 Mobile Information
The Scorekeeper App may process:
- (a) assigned Games and role information;
- (b) locally cached rosters, Games, and the user's profile;
- (c) offline Game and scorekeeping data;
- (d) authentication tokens stored in the operating system's encrypted storage;
- (e) app and operating-system versions; and
- (f) production crash or error information.
Crash reports may include the error message, stack trace, app version, operating-system information, and user identifier when the user is signed in.
The mobile application does not collect precise location, contacts, biometrics, advertising identifiers, ATT or IDFA identifiers, or third-party mobile analytics data.
We collect personal information:
- (a) directly from users;
- (b) from Organizations and their Authorized Users;
- (c) from parents, guardians, team captains, and registrants;
- (d) from Google, Apple, or Facebook when a user selects OAuth authentication;
- (e) from Stripe concerning billing and payment activity;
- (f) automatically from browsers, devices, servers, cookies, and Platform activity;
- (g) from other users who submit messages, rosters, media, or Game records; and
- (h) from publicly available sources where lawful and relevant.
We may process personal information to:
- (a) create, authenticate, maintain, and secure Accounts;
- (b) provide public league websites and Organization dashboards;
- (c) manage leagues, teams, seasons, rosters, venues, schedules, and Games;
- (d) record and calculate Game events, scores, statistics, standings, awards, and historical records;
- (e) operate registration and Stripe Connect functions;
- (f) prepare invoices, collect platform fees, and resolve billing errors;
- (g) enable direct messages, channels, mailing lists, and notifications;
- (h) store and display User Content;
- (i) provide voice transcription and AI functions;
- (j) generate Game recaps, summaries, and Platform outputs;
- (k) provide customer support and respond to requests;
- (l) schedule marketing demonstrations through Google Calendar;
- (m) measure web traffic and feature use through Google Analytics;
- (n) maintain audit trails, rate limits, backups, and security controls;
- (o) detect fraud, prohibited activity, unauthorized access, and technical incidents;
- (p) investigate complaints and enforce Platform terms;
- (q) comply with subpoenas, court orders, sanctions requirements, tax duties, and other legal obligations;
- (r) establish, exercise, or defend legal claims; and
- (s) develop and maintain Platform functionality.
6.1 Where the General Data Protection Regulation, UK GDPR, or a comparable legal framework applies, athletical.ly relies on one or more of the following legal bases:
- (a) Contract: Processing necessary to provide the Services, authenticate Accounts, manage requested Platform functions, process billing, and perform agreements with users or Organizations.
- (b) Legitimate Interests: Processing necessary for security, fraud prevention, service administration, analytics, customer support, product development, recordkeeping, and protection of legal rights, where those interests are not overridden by the individual's rights.
- (c) Consent: Processing based on consent, including optional analytics cookies, selected marketing communications, microphone access, and certain processing concerning minors.
- (d) Legal Obligation: Processing necessary to comply with tax, accounting, payment, sanctions, regulatory, court, and law-enforcement requirements.
- (e) Protection of Rights: Processing necessary to protect the vital interests, safety, or legal rights of a person where applicable.
6.2 The GDPR establishes rights and transparency obligations concerning the collection and use of personal data. The official text is available through EUR-Lex.
6.3 Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect processing lawfully carried out before withdrawal.
7.1 Organizations and Platform Users
Information may be disclosed to:
- (a) the Organizations a user joins;
- (b) Organization owners, administrators, employees, officials, and scorekeepers;
- (c) teams, Players, parents, and other participants;
- (d) message recipients; and
- (e) visitors to public league pages.
The scope of disclosure depends on Account roles, Organization settings, Platform functionality, and the information published by an Organization.
7.2 Service Providers
We use the following service providers:
- Amazon Web Services: Hosting, databases, file storage, Redis, secrets management, backups, server logs, and related infrastructure in the United States.
- Cloudflare: Content delivery, network performance, traffic routing, and security protection.
- Stripe: Payment acceptance, stored payment methods, invoicing support, refunds, webhooks, Stripe Connect, and Organization identity and sanctions screening.
- Google, Apple, and Facebook: OAuth authentication.
- Google Analytics 4: Web traffic and usage analytics.
- Mailchimp Transactional, also known as Mandrill: Transactional email, mailing-list delivery, and bounce, complaint, and unsubscribe processing.
- Anthropic: AI-assistant processing and conversation summarization.
- OpenAI: Whisper audio transcription.
- Google Calendar: Marketing-site demonstration booking.
- GIPHY: GIF search within messaging.
- Slack: Private operational alerts involving errors, Organization events, and mobile crash reports.
- Expo and EAS: Mobile application building, updating, and distribution infrastructure.
- Expo Push Service, Apple Push Notification Service, and Google Firebase Cloud Messaging: Planned push-notification services when the feature becomes available.
Service providers receive information only as reasonably necessary for their contracted function, subject to applicable contractual and legal obligations.
7.3 Business Transactions
Personal information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction. The recipient will remain subject to applicable privacy obligations concerning the transferred information.
7.4 Legal, Security, and Protective Disclosures
We may disclose information where reasonably necessary to:
- (a) comply with law, legal process, or a binding governmental request;
- (b) investigate fraud, abuse, threats, or security incidents;
- (c) protect athletical.ly, an Organization, a user, or another person;
- (d) enforce contracts or collect amounts owed;
- (e) establish or defend a legal claim; or
- (f) respond to an emergency involving risk of serious harm.
8.1 athletical.ly does not sell personal information.
8.2 athletical.ly does not disclose personal information for cross-context behavioral advertising.
8.3 The Platform contains no third-party advertising networks, advertising identifiers, or behavioral-advertising cookies.
8.4 Google Analytics is used on the web Platform for audience measurement and service analytics, subject to cookie-consent controls where required.
8.5 athletical.ly does not use automated decision-making to make decisions that produce legal or similarly significant effects concerning users. AI functions provide information and content assistance but do not independently determine eligibility, discipline, registration, employment, or access to a sports program.
9.1 The web Platform uses essential authentication cookies, a first-party affiliate-attribution cookie, and Google Analytics cookies.
9.2 Web local storage may hold interface preferences and state, including theme preferences, active chat or channel identifiers, and scoreboard filters. Credentials and profile information are not intentionally stored in web local storage.
9.3 The mobile application stores authentication tokens in encrypted operating-system storage and may cache rosters, Games, and the user's own profile in a local SQLite database. Mobile cached data is cleared on logout, subject to technical recovery and synchronization processes.
9.4 Additional details concerning cookie categories, durations, consent, and browser controls appear in athletical.ly's Cookie Policy.
10.1 athletical.ly is established in the United States, and its principal hosting infrastructure is located in the AWS us-east-1 region in Northern Virginia.
10.2 Information concerning users and Organizations outside the United States is transferred to and processed in the United States.
10.3 Stripe, Mailchimp, Anthropic, OpenAI, and other providers may also process information through infrastructure located in the United States or another country identified in their documentation.
10.4 Where European Economic Area personal data is transferred to a country without an applicable adequacy decision, athletical.ly may rely on the European Commission's Standard Contractual Clauses, supplementary safeguards, or another transfer mechanism permitted by law. The European Commission explains that protections continue to apply when personal data is transferred outside the EEA.
10.5 The European Commission's Standard Contractual Clauses are available at Standard Contractual Clauses.
10.6 UK personal data may be transferred under an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the European Commission's Standard Contractual Clauses, or another lawful safeguard.
11.1 Account information is retained while an Account remains active and as required for legitimate operational, security, contractual, and legal purposes.
11.2 When a user completes self-service Account deletion:
- (a) the user record is soft-deleted and anonymized;
- (b) the display name is changed to "Deleted User";
- (c) name, email address, avatar, and date of birth are removed;
- (d) OAuth identities are deleted;
- (e) active sessions are revoked;
- (f) Organization memberships and roles are removed;
- (g) links to Player cards are severed;
- (h) in-app notifications are deleted; and
- (i) mailing-list subscriptions and pending confirmations linked to the user and email address are deleted.
11.3 Player statistics may remain as de-identified historical records after the Account is deleted.
11.4 An Organization may request deletion through an email-confirmed process. A seven-day grace period applies, during which an Organization owner may cancel the request. After the grace period, Organization data is permanently purged from the active databases, subject to the exceptions below.
11.5 Automated encrypted database backups are retained for seven days.
11.6 Write-action audit logs are retained indefinitely for compliance, billing, security, and forensic purposes. Audit records may survive Organization deletion after the Organization reference and other identifying links are removed or limited.
11.7 Game records and statistics may be retained indefinitely as historical league records.
11.8 Uploaded media remains until deleted by an authorized user or Organization, subject to backups, legal holds, and technical archives.
11.9 AI chat content, tool calls, results, and generated summaries are retained without a fixed automatic deletion period unless deleted in response to an applicable request or a future retention setting.
11.10 Email-suppression records may be retained indefinitely to honor unsubscribe requests, hard bounces, and spam complaints.
11.11 Invoice, payment, tax, transaction, dispute, and legal records are retained for the period required by applicable law and legitimate accounting, fraud-prevention, and claim-management needs.
11.12 Server and security logs are retained according to operational settings and for as long as reasonably necessary to maintain security, diagnose incidents, enforce agreements, and comply with law.
12.1 Depending on the individual's location and applicable law, privacy rights may include:
- (a) receiving information about processing;
- (b) obtaining access to personal information;
- (c) correcting inaccurate or incomplete information;
- (d) requesting deletion;
- (e) restricting certain processing;
- (f) objecting to processing based on legitimate interests;
- (g) withdrawing consent;
- (h) obtaining portable information in an appropriate format;
- (i) opting out of certain sales, sharing, advertising, or profiling activities;
- (j) appealing a refusal where applicable; and
- (k) lodging a complaint with a privacy regulator.
12.2 UK privacy rights include rights to be informed, access, rectification, erasure, restriction, portability, objection, and protections concerning certain automated decisions. Official guidance is available from the Information Commissioner's Office.
12.3 Canadian privacy law may provide rights to learn whether an organization holds personal information, obtain access, and challenge its accuracy and completeness. Official PIPEDA guidance is available from the Office of the Privacy Commissioner of Canada.
12.4 California residents may have rights under the California Consumer Privacy Act where athletical.ly is subject to that law. The CCPA may provide rights to know, delete, correct, limit certain uses, and opt out of sale or sharing, together with protection against discriminatory treatment. Official information is available from the California Department of Justice.
12.5 athletical.ly does not sell personal information or disclose it for cross-context behavioral advertising. A sale or sharing opt-out request will be recorded and handled as required if applicable practices change.
13.1 Users may edit certain profile information through the Platform.
13.2 Users may delete their Account through the web or mobile "Delete Account" function. Facebook users may also initiate deletion through the Facebook data-deletion callback and view the deletion status through the associated public status page.
13.3 Access, correction, export, objection, restriction, and other privacy requests may be sent to info@athletical.ly.
13.4 A request should identify the Account, Organization, relevant email address, requested action, and jurisdiction of residence.
13.5 athletical.ly may request information reasonably necessary to verify identity and authority. A parent, guardian, or legally authorized agent may submit a request where permitted by law, subject to verification.
13.6 athletical.ly ordinarily responds within 30 days, subject to any extension, exception, or shorter period permitted or required by applicable law.
13.7 A request may be denied or limited where disclosure would adversely affect another person, reveal protected information, undermine security, conflict with a legal obligation, interfere with fraud prevention, or fall within another lawful exception.
13.8 athletical.ly will not unlawfully discriminate against a person for exercising a privacy right.
14.1 The Platform supports youth leagues, schools, and sports programs involving children, including children under 13.
14.2 The United States Children's Online Privacy Protection Act and COPPA Rule require covered online services to provide notice and obtain verifiable parental consent before collecting, using, or disclosing personal information online from a child under 13, subject to limited exceptions. Official information is available through the Federal Trade Commission's COPPA Rule page.
14.3 A child under 13 must not independently create or activate an Account, submit personal information, upload content, or use interactive features unless athletical.ly has obtained verifiable parental consent or another legally valid authorization applies.
14.4 Parents and legal guardians may request:
- (a) access to personal information collected from their child;
- (b) correction or deletion of the child's information;
- (c) withdrawal of consent;
- (d) termination of further collection or use; and
- (e) deletion of the child's Account, subject to lawful retention exceptions.
14.5 Organizations must obtain all legally required parental or guardian permissions before submitting or publishing information concerning a minor.
14.6 Player profiles, photographs, ages, rosters, teams, statistics, and awards may be displayed on publicly accessible pages. Organizations must not publish a minor's information without valid legal authority and all required consent.
14.7 athletical.ly may restrict, remove, or anonymize a minor's information where consent cannot be verified or where continued processing would violate applicable law.
14.8 A parent or guardian may contact info@athletical.ly regarding a child's information.
15.1 athletical.ly maintains administrative, technical, and organizational safeguards designed to protect personal information, including:
- (a) TLS encryption for data transmitted over supported connections;
- (b) encryption at rest for Aurora databases;
- (c) AWS Secrets Manager for stored credentials and secrets;
- (d) passwordless authentication;
- (e) short-lived access credentials and rotating session mechanisms;
- (f) role-based access controls;
- (g) Organization-level tenant separation;
- (h) rate limiting;
- (i) signed webhooks and unsubscribe tokens;
- (j) presigned file-upload mechanisms;
- (k) encrypted mobile credential storage;
- (l) write-action audit records; and
- (m) encrypted database backups.
15.2 No system can guarantee absolute security. Users must protect their email accounts, connected authentication providers, devices, and active sessions.
15.3 Suspected unauthorized access should be reported promptly to info@athletical.ly.
15.4 Where a personal-data breach triggers a legal notification duty, athletical.ly will notify affected individuals and competent authorities within the period required by applicable law.
16.1 The Platform may contain links to third-party websites, payment pages, authentication services, GIF results, calendars, and other external services.
16.2 External services operate under their own privacy policies and terms. athletical.ly is not responsible for a third party's independent collection, security, use, or disclosure of information.
16.3 Users should review the privacy documentation of each external service before providing information.
17.1 athletical.ly may update this Privacy Policy to reflect changes in law, Platform functionality, service providers, security practices, or data-processing activities.
17.2 The revised policy will state its updated effective date.
17.3 Material changes may be communicated through the Platform, by email, or through another reasonable notice before taking effect where required by law.
17.4 Additional consent will be obtained where a material change requires consent under applicable law.
18.1 Privacy concerns should first be sent to info@athletical.ly.
18.2 Individuals in the European Economic Area may lodge a complaint with the supervisory authority in their country of residence, employment, or alleged infringement. A directory of European authorities is available through the European Data Protection Board.
18.3 Individuals in the United Kingdom may complain to the Information Commissioner's Office.
18.4 Canadian individuals may contact the Office of the Privacy Commissioner of Canada.
18.5 California residents may submit a privacy complaint to the California Privacy Protection Agency.
Athletically LLC
5000 Plaza on the Lake
Suite 100 #3014
Austin, Texas 78746
United States
Privacy Email: info@athletical.ly
Business Contact: info@athletical.ly
Website: https://athletical.ly