DugoutHQ Privacy Policy

Last updated: August 25, 2026

Plain-English summary. DugoutHQ is software that baseball clubs and teams use to manage rosters, schedules, and dues. This policy explains what information we collect, why we collect it, who we share it with, and the choices and rights you have. We do not sell your personal information. We do use limited advertising measurement so we can tell which of our own ads brought a coach to DugoutHQ — this applies only to adults who sign up, never to youth athletes, and you can opt out at any time (see Section 7.6). Because our product involves youth athletes, we treat information about children with particular care — please read Section 8 (Children's Privacy) closely. DugoutHQ also includes team messaging and photo-sharing; see Section 17 (Messaging), Section 18 (Photos and Other Attachments), and Section 21 (Automated Content Screening) for what we collect, who can see it, and how we may use automated tools to help keep it safe. DugoutHQ also lets a team opt in to Team Discovery so coaches and admins at other Organizations can find it for scrimmages and practice games (Section 22), supports direct, cross-Organization coach-to-coach messaging for arranging those games (Section 23), and lets an Organization publish a subscribable calendar link so families can add its schedule to their own calendar app (Section 24).


1. Introduction and Scope

This Privacy Policy ("Policy") describes how DugoutHQ ("DugoutHQ," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the DugoutHQ website, applications, and related services (collectively, the "Service").

DugoutHQ is a multi-tenant software-as-a-service platform that enables baseball clubs, leagues, and teams (each, an "Organization") to manage their teams, seasons, rosters, schedules, budgets, and member dues. We provide the Service to and on behalf of Organizations and their authorized users.

This Policy applies to:

Our two roles. For information we collect about our own account holders and website visitors, and for our own operational purposes, we generally act as a controller (or "business"). For most information that an Organization enters into the Service about its Players, guardians, and members — including roster and financial data — the Organization is the controller and DugoutHQ acts as a processor ("service provider") that handles the information on the Organization's behalf and under its instructions. Where DugoutHQ acts as a processor, the Organization's own privacy notice and its agreement with the affected individuals govern the collection of that information, and this Policy describes our practices as a processor. See Section 15.


2. Information We Collect

We collect the following categories of information.

2.1 Account and Identity Data

When you create an account or are invited to one, we collect your name, email address, and a hashed (cryptographically protected) password. Authentication is handled through the "better-auth" library; we store a salted hash of your password and never store your password in plaintext. We also collect your role within an Organization (e.g., coach, treasurer, admin, parent/guardian) and your Organization affiliation(s).

2.2 Player (Minor Athlete) Data

Organizations and their authorized users enter information about youth athletes to build and manage rosters. This may include a Player's first and last name, jersey number, playing positions, roster status, and team/season assignments. This information is entered by adults (coaches, organization administrators, or a Player's parent/guardian) — it is not collected directly from children through the Service. We do not knowingly request or collect a Player's contact information, precise location, photographs (except team logos and documents uploaded by adults), persistent identifiers used to track the child, or any information beyond what is needed to manage a roster.

Team messaging (Section 17) lets adults share photos with other adults in the same conversation — for example, an action shot from a game — and a shared photo may incidentally show a Player. That is content one adult chose to share with other adults, governed by Sections 17–18, not a structured "Player photo" field we collect or maintain as roster data.

2.3 Guardian and Family Contact Data

For parents, guardians, and other designated family contacts, we collect names, email addresses, and phone numbers, along with the relationship/association linking a guardian to a Player or team, and any "family access" login credentials described in Section 2.1.

2.4 Financial and Payment Data

To support dues collection and team budgeting, we process financial data such as dues amounts, budget line items, invoices, and payment status (all monetary amounts are stored as integer cents). Payments are processed by Stripe and Stripe Connect. When you make or receive a payment, your card or bank details are transmitted to and handled by Stripe, not by DugoutHQ. DugoutHQ does not collect or store full payment card numbers. We may store limited, non-sensitive payment metadata returned by Stripe (for example, a payment/transaction identifier, the last four digits of a card, card brand, payment amount, any service fee applied, status, and timestamps) in order to reconcile dues and display payment history.

2.5 Donation Data

When you donate through an Organization’s public fundraising page, we collect your name (optional), email address, donation amount, and any message you write, along with whether you chose to give anonymously. Card details go directly to Stripe and never to DugoutHQ, and the payment is a direct charge on the Organization’s own Stripe account — DugoutHQ does not hold, take custody of, or control donated funds. Unless you choose to give anonymously, your name, message, and the amount you gave are published on a publicly accessible web page; your email address is never published. Donations made through the Service are personal gifts to the Organization and are not tax-deductible charitable contributions.

2.6 Content You Upload

Users may upload documents, receipts, and team logos, which are stored in S3-compatible object storage. You are responsible for the content you upload (see the Terms of Service).

2.7 Schedule and Event Data

We collect schedule and event information such as games, practices, and other events, including dates, times, locations, and related notes.

2.8 Log, Device, and Usage Data

When you use the Service we automatically collect certain technical information, including IP addresses, session metadata, browser/user-agent information, timestamps, and pages or features accessed. We also maintain audit logs of significant actions (particularly financial actions) and platform administrator logs used to operate, secure, and troubleshoot the Service.

2.9 Cookies and Similar Technologies

We use strictly necessary cookies and similar technologies to keep you signed in and to operate the Service. We also store, in a first-party cookie, the advertising click identifiers present in the web address you arrive on (for example utm_* campaign parameters and a Meta fbclid click id), so we can tell which of our ads brought you to us. See Sections 6 and 7.6.

2.10 Communications

If you contact us for support or otherwise correspond with us, we collect the information you provide in those communications.

2.11 Messaging and Photo Data

When you use the Service's messaging features (team channels, groups, direct messages, and the org-wide staff channel), we collect the message content you send (text and, where you attach one, a photo), who sent it and when, and which conversation it belongs to. If a message is reported, we also keep a record of the report. See Section 17 (Messaging) and Section 18 (Photos and Other Attachments) for how this is stored, who can see it, and how long we keep it.

2.12 Push Notification Data

If you turn on push notifications, we collect a device token (for the mobile app) or a browser push subscription (for the web app) and link it to your account, along with your per-category notification preferences and any conversation you've muted. See Section 19 (Push Notifications).

2.13 Availability (RSVP) Data

When a guardian or staff member responds to a scheduled event on behalf of a Player, we collect that In/Out/Maybe status and any optional note. See Section 20 (Availability/RSVP Data).

2.14 Team Discovery Data

If a team's staff opts in to Team Discovery (off by default), we collect and publish, to other Organizations, a limited projection of that team: its name, age group, current season label, its coaches' first name and last initial (never a coach's full name, email, or phone number), and a base location — a town/area the team chooses, geocoded to coarse, rounded coordinates, never an exact address. See Section 22 (Team Discovery).

2.15 Cross-Organization Messaging Data

If a coach or administrator uses the cross-Organization messaging feature to exchange direct messages with a coach or administrator of a different Organization, we collect the text of those messages (this surface does not support photos or file attachments), who sent each message and when, any block one participant places on the other, any report a participant files, and any message a participant flags for review. See Section 23 (Cross-Organization Coach-to-Coach Messaging).

2.16 Calendar/Schedule Feed Access Data

If an Organization publishes a season's schedule as a subscribable calendar link, the link contains a long, random token that is the sole credential needed to retrieve that season's event titles, dates/times, and locations. Retrieving the feed does not require signing in, and we do not log who subscribes beyond the ordinary technical/usage logs described in Section 2.8. See Section 24 (Calendar Subscriptions and Schedule Export).

Plain-English summary. We collect account info (name, email, hashed password), limited roster info about Players (entered by adults, not by kids), guardian contact info, dues/budget info (with Stripe handling the actual card data), files you upload, schedules, and technical logs.


3. How We Collect Information

We collect information: (a) directly from you when you register, sign in, or use the Service; (b) from your Organization and its authorized users, who enter Player, guardian, roster, schedule, and financial information; (c) automatically through your use of the Service (logs, cookies, session data); and (d) from our service providers, such as Stripe (payment status and metadata) and our email provider (delivery status).

We do not collect personal information directly from children through the Service.


4. How We Use Information

We use personal information for the following purposes:

  1. Providing the Service — creating and managing accounts, Organizations, teams, seasons, rosters, schedules, budgets, and dues.
  2. Authentication and security — verifying identity, maintaining sessions, preventing fraud and abuse, and protecting the integrity of the Service.
  3. Payments — facilitating dues and payment workflows through Stripe, reconciling transactions, and displaying payment history and status.
  4. Communications — sending transactional and administrative messages (e.g., account notices, invitations, receipts, schedule updates, and service announcements) through our email provider.
  5. Donations — processing gifts made through an Organization’s public fundraising page, sending the donor a receipt, publishing the donor’s name and message on that page unless they gave anonymously, and reporting totals to the Organization. We do not add donors to any marketing list and do not use a donor’s email address for anything other than their receipt and any necessary follow-up about that gift.
  6. Support — responding to inquiries and troubleshooting.
  7. Operations, analytics, and improvement — monitoring performance, diagnosing problems, and improving features and reliability, using aggregated or de-identified data where practicable.
  8. Marketing measurement for our own Service — determining which of our advertisements and campaigns led a coach or administrator to sign up, and measuring whether those signups went on to use the product. This is limited to adult account holders and is described in Section 7.6.
  9. Legal, safety, and compliance — complying with law, enforcing our Terms, maintaining audit logs, and protecting the rights, property, and safety of DugoutHQ, our users, and the public.
  10. Messaging, moderation, and safety — operating team channels, groups, direct messages, and the org staff channel; delivering push notifications; handling reports of messages or photos; and, as described in Section 21, using automated tools (which may include AI/ML models) alongside human review to screen for safety and policy violations.
  11. Team discovery and cross-Organization coordination — operating the opt-in Team Discovery directory and cross-Organization coach-to-coach messaging described in Sections 22–23, and generating a subscribable calendar feed when an Organization chooses to publish one, as described in Section 24. These features are limited to adult, staff-role users and never expose Player, guardian, roster, or financial data.

We do not sell personal information. We do not use information about Players (minors) for advertising or marketing measurement of any kind. Our advertising measurement is limited to adult account holders and is described in Section 7.6, including how to opt out.


5. Legal Bases for Processing (EEA/UK)

Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:

Where DugoutHQ processes Player and member data on behalf of an Organization, the Organization is responsible for establishing the legal basis (including any required parental consent) for that processing. See Sections 8 and 15.


6. Cookies, Sessions, and Similar Technologies

We use cookies and similar technologies primarily to keep you authenticated and to operate core Service functions:

We do not operate our own cross-site tracking, and we do not show third-party advertisements inside the Service. However, because we disclose limited identifiers to Meta so it can measure and optimize our own advertising, that disclosure may constitute "sharing" for cross-context behavioral advertising under California law. You may opt out — see Sections 7.6 and 13.2. Most browsers let you manage cookies through their settings; disabling strictly necessary cookies may prevent you from using the Service.

Google Fonts. Our website may load fonts from Google Fonts. When your browser requests a font, your IP address is necessarily disclosed to Google to deliver it. See Section 7 regarding subprocessors.


7. How We Share Information; Subprocessors

We do not sell personal information. We disclose limited identifiers about adult account holders to our advertising platform so it can measure and optimize our own advertising, which may constitute "sharing" under California law — see Section 7.6, including how to opt out. We never do this with information about Players (minors). We disclose personal information only as described below.

7.1 Within and For Your Organization

Information entered into an Organization's workspace is accessible to that Organization's authorized users according to their roles and permissions (for example, coaches, treasurers, and administrators). Family access users receive read-only access to information relevant to their Player(s) and team(s). Messages and photos you send through the Service's messaging features are visible only within the conversation you sent them in — see Section 17.2 for exactly who that includes for each kind of conversation.

7.2 Service Providers (Subprocessors)

We use the following categories of third-party subprocessors to operate the Service. Each is bound by contractual confidentiality and data-protection obligations and may process personal information only to provide services to us.

Subprocessor Purpose Data involved
Stripe (incl. Stripe Connect) Payment processing for dues and budgets Payment/card data (collected directly by Stripe), payer/payee identifiers, transaction metadata
Resend Transactional and administrative email delivery Recipient name, email address, message content, delivery metadata
Railway Application hosting and infrastructure All Service data processed/stored on our infrastructure
our S3-compatible object storage provider Object storage for uploaded documents, receipts, and logos Uploaded files and associated metadata
Google Fonts Web font delivery IP address and browser request data (at font load time)
Meta Platforms (Conversions API) Measuring which of our advertisements produced a signup, and optimizing delivery of our own ads For adult account holders only, at the moment they create a team or invite a family: a hashed (SHA-256) email address, IP address, browser user agent, and Meta advertising click identifiers. No Player data, no guardian data, no donor data, and no roster, schedule, or financial data.

We may update this list as our infrastructure evolves; material changes will be reflected in an updated version of this Policy. Organizations that require advance notice of subprocessor changes should contact us at [email protected].

7.3 Publication on Public Fundraising Pages

If you donate through an Organization’s fundraising page, your name and any message you write are published on that page, which is accessible to anyone on the internet and may be indexed by search engines — unless you choose to give anonymously, in which case your name is replaced with “Anonymous.” The amount you gave is shown next to your name (or next to “Anonymous”). Your email address is never published. An Organization may hide a published message; ask the Organization, or contact us, to have one removed.

7.4 Legal, Safety, and Corporate Transactions

We may disclose information: (a) to comply with law, legal process, or lawful government requests; (b) to enforce our agreements and protect the rights, property, and safety of DugoutHQ, our users, and others; and (c) in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, in which case personal information may be transferred as a business asset (subject to this Policy or a successor policy with equivalent protections).

7.5 With Your Direction or Consent

We share information as you or your Organization otherwise direct or consent.

7.6 Advertising Measurement (Meta Conversions API)

We advertise DugoutHQ to coaches and club administrators. To understand which advertisements actually work — and to avoid spending on ones that do not — we send a limited, server-side signal to Meta Platforms when an adult account holder completes a meaningful step.

When this happens. Only when an adult account holder (a) creates a team, or (b) invites a family to a team they manage.

What we send. The event name and time, the page address, and identifiers used to match the event to an advertisement: a SHA-256 hash of the account holder's email address (never the address itself), the IP address, the browser user agent, and Meta advertising click identifiers.

What we never send. Information about Players (minors). Information about guardians or family access users. Donor information. Rosters, schedules, documents, budgets, dues, or payment data. Names. Raw email addresses.

Why. To measure the effectiveness of our own marketing and to let Meta optimize delivery of our advertisements. Meta acts as our service provider for measurement and also uses this data for its own ad delivery optimization. Under California law this disclosure may be treated as "sharing" for cross-context behavioral advertising.

Your choice. You can opt out yourself at any time — sign in and go to Your account → Privacy, and turn off advertising measurement. You can also email [email protected] from your account address and we will do it for you. Either way we record the opt-out against your account, and from that point no conversion for your account is sent to any advertising platform — this is enforced automatically, not manually. Opting out takes effect immediately and has no effect on your use of the Service. Browser-level controls (blocking third-party cookies, "Limit Ad Tracking"/ATT on iOS, or a tracking-blocking extension) also reduce or prevent this measurement.

EEA/UK note. DugoutHQ is offered to U.S. youth baseball organizations and our advertising is directed at the United States. Where this processing would require consent under EEA/UK law, we do not intend to carry it out, and you may object at any time using the contact above.

7.7 Team Discovery and Cross-Organization Messaging

If your team's staff opts in to Team Discovery, the limited team projection described in Section 22 is shared with verified coaches and administrators of other Organizations so they can find your team for scrimmages and practice games. Separately, if a coach or administrator on your team exchanges messages with a coach or administrator of another Organization, that Organization's staff member(s) can see the messaging information described in Section 23. Neither feature shares roster, player, guardian, dues, or contact information with another Organization — see those sections for the full detail, including how to opt out or stop a conversation.


8. Children's Privacy (COPPA and State Children's-Privacy Laws)

Plain-English summary. DugoutHQ is built for adults to manage youth teams. Kids do not create accounts or enter data. The limited roster information about a Player is entered by that Player's coach, club administrator, or parent/guardian. We ask Organizations and guardians to make sure they have the right to provide any information about a child, and we give guardians tools to review and delete that information.

The Service is not directed to children and is not intended for use by children. Accounts may only be created and used by adults (18+). Children do not register for, log into, or provide information directly to the Service.

Nevertheless, because the Service is used to manage youth athletes, information about children (Players) — such as name, jersey number, positions, and roster status — is entered into the Service by adults (coaches, Organization administrators, or a Player's parent/guardian). We handle this information as a processor on behalf of the Organization.

If you believe a child's information has been provided to us without proper authority, contact us at [email protected] and we will investigate and, where appropriate, delete the information.


9. Data Retention

We retain personal information for as long as needed to provide the Service and for the legitimate and lawful purposes described in this Policy, and thereafter as required to comply with legal, tax, accounting, audit, and dispute-resolution obligations. Illustrative retention periods:

Organizations control the retention of the data they enter and may delete it within the Service. When an account or Organization is deleted, we will delete or de-identify associated personal information within a commercially reasonable period, subject to the exceptions above.


10. Security

We implement administrative, technical, and organizational measures designed to protect personal information, including: encryption of data in transit (TLS); storage of passwords only as salted hashes; access controls and role-based permissions scoped to each Organization (multi-tenant isolation); audit logging of sensitive actions; and use of reputable infrastructure and payment providers. Payment card data is handled by Stripe under its PCI-DSS-compliant environment and is not stored by DugoutHQ.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials and for activity under your account.


11. Data Breach Notification

We maintain procedures to detect, investigate, and respond to security incidents. In the event of a personal-data breach affecting your information, we will notify affected users, Organizations, and/or regulators as and when required by applicable law, and we will assist Organizations (where we act as processor) in meeting their own notification obligations. Notifications will describe, to the extent known and permitted, the nature of the incident and the steps we are taking.


12. International Data Transfers

DugoutHQ is operated from the United States, and our subprocessors may process information in the United States and other countries. If you access the Service from outside the United States, you understand that your information may be transferred to, stored in, and processed in the United States and other jurisdictions that may have data-protection laws different from those in your country.

Where we transfer personal information originating in the EEA, UK, or Switzerland to a country not deemed to provide adequate protection, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA where applicable). To request more information about these safeguards, contact us at [email protected].


13. Your Privacy Rights

Depending on where you live and the role we play with respect to your information, you may have some or all of the following rights. Where DugoutHQ acts as a processor for an Organization, we will route your request to, or fulfill it in coordination with, the relevant Organization.

13.1 Rights Available to Many Users

Donors without an account exercise these rights the same way — email us from the address you used to donate. We can remove your name and message from a public fundraising page on request; we generally cannot delete the underlying record of the gift itself, because the Organization needs it for its accounting and for handling any refund or chargeback.

To exercise these rights, contact us at [email protected]. We will verify your identity before acting and will respond within the timeframes required by applicable law. You may authorize an agent to submit a request on your behalf. We will not discriminate against you for exercising your rights.

13.2 California Residents (CCPA/CPRA)

Plain-English summary. California residents have specific rights to know, delete, correct, and opt out. We do not sell your personal information. We do disclose limited identifiers about adult account holders to Meta to measure our own advertising, which may count as "sharing" — you can opt out by emailing us. We do not use or disclose sensitive personal information beyond permitted business purposes.

If you are a California resident, you have the right to:

The categories of personal information we collect map to the CCPA categories: identifiers; customer records (Cal. Civ. Code § 1798.80); commercial/financial information; internet or network activity information; and, in limited cases, information about minors. We collect these for the business purposes in Section 4 and disclose them to the service providers in Section 7. We have not sold personal information in the preceding twelve (12) months. In that period we have disclosed identifiers and internet activity information about adult account holders to Meta for advertising measurement as described in Section 7.6, which may constitute "sharing"; we have not shared information about minors. To submit a request, contact [email protected].

13.3 EEA, UK, and Swiss Residents (GDPR/UK GDPR)

Plain-English summary. If you are in the EEA, UK, or Switzerland, you have rights to access, correct, delete, restrict, object to, and port your data, and to complain to a regulator.

In addition to the rights above, you have the right to restrict or object to processing, the right to data portability, and the right to lodge a complaint with a supervisory authority in your country of residence, work, or the place of the alleged infringement. Where we rely on legitimate interests, you may object based on your particular situation. Our legal bases are described in Section 5. We do not sell personal data. See Section 7.6 regarding advertising measurement and your right to object to it.

13.4 Other U.S. State Rights

Residents of other U.S. states with comprehensive privacy laws (e.g., Virginia, Colorado, Connecticut, Texas, and others) may have analogous rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling. We do not sell personal information and do not engage in profiling that produces legal or similarly significant effects. We do conduct advertising measurement for our own ads as described in Section 7.6, which may fall within "targeted advertising" under some of these laws — opt out in Your account → Privacy, or email [email protected]. Contact the same address to exercise any other applicable right.


14. Guardians vs. Players — How We Treat Each

To be clear about the two categories of family data:


15. Our Role as a Processor / Service Provider

For personal information that an Organization enters into the Service (including Player, guardian, roster, schedule, and financial data), the Organization is the controller/business and DugoutHQ acts as a processor/service provider. In that role:

If you are an Organization, a Data Processing Addendum (DPA) is available on request at [email protected].


16. Third-Party Links and Services

The Service integrates with or links to third-party services (for example, Stripe). Those services are governed by their own privacy policies, and we are not responsible for their practices. An Organization may also link from its fundraising pages to a governing charitable organization for corporate or tax-deductible giving; following that link takes you off the Service, and DugoutHQ does not verify, endorse, or vouch for that organization or control how it handles your information. We encourage you to review Stripe's privacy policy for details on how it handles payment information.


17. Messaging Between Members

Plain-English summary. DugoutHQ lets coaches, admins, and parents/guardians message each other inside the app — team channels, small groups, direct messages, and an org-wide staff channel. Who can see a message depends on the kind of conversation it's in. Anyone who can see a message can report it, and the people responsible for that conversation review reports. You can block another member to stop unwanted direct messages. Deleting a message hides it right away, but we keep a minimal record for safety, and messages you sent stay visible to the other people in that conversation even if you later delete your account.

17.1 What a Message Includes

A message's text and, where you attach one, a photo (see Section 18). Every message we store also carries who sent it (the display name and role shown at the time you sent it), when, and which conversation it belongs to.

17.2 Kinds of Conversations and Who Can See Them

For message content an Organization's members send each other, we act as a processor on the Organization's behalf, the same as for roster data — see Section 20. We don't read message content except as described in Section 21 (automated/human safety screening), to investigate a report, or where required by law.

17.3 Reporting and Moderation

Anyone who can see a message can report it. A report is reviewed by the people responsible for that conversation: a team's staff moderators for a team channel or group, the Organization's admins for a direct message (a DM has no built-in moderator, so a report always goes to org admins instead of the other participant), and the Organization's staff for the staff channel. A moderator may remove a message; repeated or serious violations can lead to suspension or removal of an account — see the Terms of Service.

17.4 Deleting a Message

The author of a message, or a moderator of that conversation, can delete it. A deleted message's text and any photo are hidden from everyone right away, but we keep a minimal "tombstone" record — that a message existed, who sent it, and when — mainly for safety/moderation history and so the conversation doesn't show a confusing gap. Deleting a message doesn't remove it from a report already filed against it.

17.5 Blocking

You can block another member. Blocking stops that person from starting or continuing a direct message with you. It doesn't delete a direct message you already had with them, and it doesn't remove either of you from a team channel, group, or the org staff channel you're both in — blocking stops unwanted one-to-one contact, it isn't a way to hide from an Organization's staff/roster structure. A block applies to that person specifically, across every Organization you happen to share with them (blocking isn't limited to one Organization).

17.6 Retention

We keep message content for as long as the conversation exists, and a deleted message's minimal tombstone record for a limited period for safety and moderation purposes, consistent with Section 9. If you delete your account (Section 13.1), messages you sent remain visible to the other people in that conversation, with your display name attached exactly as it was when you sent them — a message is part of the conversation history of the people you sent it to, not solely your own record, so it isn't deleted or anonymized when your account is.


18. Photos and Other Attachments

18.1 What Happens When You Share a Photo

When you attach a photo to a message, we process it before storing it. In almost every case, we automatically remove EXIF metadata — including GPS/location data —, correct its orientation, resize it so it's no larger than needed, and re-encode it to a standard format. In the rare case a file can't be automatically processed, we store it as uploaded rather than block your message; if you don't want to share your device's location or other embedded metadata, remove it yourself before uploading, especially on an older device or app version.

18.2 Where Photos Are Stored and Who Can Access Them

Photos are stored in private, access-controlled storage — never at a public web address. The same visibility rule as the message itself applies (Section 17.2): only people who can see the conversation can retrieve the photo, and only through a short-lived, time-limited link generated when an authorized viewer requests it. The link expires quickly (currently a few minutes) and can't be reused or guessed.

18.3 Automated Screening

Uploaded photos may be automatically screened for safety, consistent with Section 21.


19. Push Notifications

19.1 What We Collect

If you turn on push notifications, we (or the app) register a device token — an Expo push token for the mobile app, or a browser push subscription (an endpoint and encryption keys) for the web app — and link it to your account.

19.2 What We Send

What a notification contains depends on its category: a lineup posted, a schedule change, a dues reminder, an announcement, or a new message. A message notification may include a short preview of the message text (currently roughly the first 100 characters) — enough to identify that you have a new message, not the whole conversation. Notifications are delivered through Apple's and Google's standard push infrastructure (via Expo's push relay, for the mobile app) or your browser's push service (for the web app); those providers see a notification's content only as needed to deliver it and don't receive it for their own advertising or profiling purposes.

19.3 Your Controls

You can turn push notifications off entirely on your device. Inside the app, you can also turn off individual categories (lineups, schedule, dues, announcements, and messages) and mute an individual conversation, independent of your other settings. A small number of safety alerts — specifically, notifying a team's or Organization's moderators/admins that a message was reported — aren't covered by these controls, because they protect other users rather than deliver ordinary chat volume.

19.4 Deletion

Device tokens and push subscriptions are removed when you sign out on that device, and deleted entirely when you delete your account (Section 13.1).


20. Availability (RSVP) Data

When a team posts a scheduled event (a game or practice), a Player's parent/guardian may respond on that Player's behalf — In, Out, or Maybe — and add a short optional note (for example, "leaving early for a conflict"). Staff with roster-management permission may also set or override any player's status. We use this to show the team's overall headcount and, to staff, each player's individual status and note. A family sees only their own player's response plus the team's aggregate counts; staff with the right permission see every player's individual response. Availability data is tied to the event and retained on the same basis as other schedule/roster data (Section 9).


21. Automated Content Screening

Plain-English summary. We may use automated tools — including AI/machine-learning models, which may be operated by a third-party service provider under contract with us — to help find messages or photos that violate our policies or the law (for example, child sexual abuse material, harassment, or spam), in addition to (not instead of) member reporting and human moderator review. This is a safety measure, not advertising or profiling: we don't use it to build a profile of you or to target ads at you, and we won't use your messages or photos to train a general-purpose AI model without asking you first, separately from this Policy.

21.1 What This Covers

DugoutHQ may use automated tools — which may include artificial-intelligence or machine-learning models, potentially operated by a third-party processor under contract with us — to screen message content and photos for indicators of policy violations or illegal content, including but not limited to child sexual abuse material (CSAM), harassment or bullying, and spam or abuse. This screening supplements, and doesn't replace, the member reporting and human moderator review described in Section 17.3.

21.2 Human Review

Content flagged by an automated tool, like content flagged by a member, is reviewed by a person — a team/Organization moderator or, where the flag concerns a legal violation such as suspected CSAM, DugoutHQ staff and, where legally required, the National Center for Missing & Exploited Children (NCMEC) or another appropriate authority.

21.3 Not Advertising or Profiling

We don't use this screening, or anything it detects, for advertising, marketing, or to build a behavioral profile of you. It's unrelated to the advertising measurement described in Section 7.6, which is a separate, adult-only, opt-out-able signal about account creation — not message or photo content.

21.4 No AI Training Without Separate Consent

We don't use your messages, photos, or other User Content to train a general-purpose AI/ML model without your separate, explicit consent. If that ever changes, we'll ask first — it won't happen merely because this Policy is later updated to describe screening in more detail, or because a screening tool covered by this Section is turned on or expanded.

21.5 Availability of This Feature

We're describing this capability so you know it may be used. Whether, and which, automated screening tools are actually active can change without a new version of this Policy, provided the change stays within the scope described here (safety screening, human review, no advertising use, no AI training without consent). If we materially expand beyond that scope, we'll update this Policy as described in Section 25.


22. Team Discovery

Plain-English summary. A team's coaches/admins can choose to make the team "discoverable" so coaches and admins at other clubs can find it to set up a scrimmage or practice — it's off unless a team's staff turns it on. What's shared is deliberately thin: team name, age group, current season, the coaches' first name and last initial, and a rounded, approximate location — never full names, emails, phone numbers, or anything about your roster, players, guardians, or dues. Only staff (coaches/admins), never parents or players, can search the directory or appear as a searcher. Turning discovery off removes your team from it immediately.

22.1 What Team Discovery Is

Team Discovery is an opt-in directory that lets a team's coaches and administrators make basic, non-identifying information about the team visible to coaches and administrators of other Organizations, so they can find nearby teams looking for scrimmages, practice games, or similar coordination. It is off by default for every team; a team's staff must affirmatively turn it on.

22.2 What a Discoverable Team's Profile Contains

If a team opts in, we generate a limited profile that other Organizations can find in search. It contains only:

22.3 What Team Discovery Never Includes

Team Discovery's profile is built from a small, purpose-limited data set that cannot carry — and never displays — any Player, roster, guardian, dues/financial, or contact (email/phone) information, exact addresses, schedules, or messages. It exists so another club's coach can decide whether to reach out, not so they can see anything about your organization's members.

22.4 Who Can See It

Only verified coaches and administrators of other Organizations can search the directory or view a team's discovery profile. Searching (and appearing as a searcher) is limited to staff roles — head coach, coach, and administrator. Parents, guardians, and Players cannot search Team Discovery and are never shown as part of it, whether or not their team has opted in.

22.5 Your Choices

Turning Team Discovery on or off is a decision made by a team's own coaches/administrators, in the team's settings. Opting out removes the team from the directory immediately — other Organizations can no longer find or view it. There is no separate individual opt-out for a coach shown in a team's profile short of the team opting out or that coach leaving the team's staff (at which point their name no longer appears, consistent with how the profile is kept in sync with current team/coach data).

22.6 Retention

A discoverable team's profile reflects the team's current name, age group, season, coaching staff, and base location; it is recalculated whenever those change and is deleted entirely if the team opts out. We do not keep a history of past discovery profiles once they are superseded or removed.


23. Cross-Organization Coach-to-Coach Messaging

Plain-English summary. Coaches and admins at two different clubs can send each other text-only direct messages in the app — for example, to arrange a scrimmage — separate from your own Organization's team messaging. Each of you sees the other only as a first name and last initial, never an email or phone number. You can block someone to stop the conversation, report them (your report goes to your own club's admins), or flag a specific message; flagged messages are reviewed by DugoutHQ platform staff, since a cross-club conversation doesn't belong to either club alone. This feature is for adult coaches and admins only — parents and players don't have access to it.

23.1 What This Feature Is

Separately from the team/group/direct/staff-channel messaging described in Section 17 (which stays within one Organization), the Service offers a cross-Organization messaging surface that lets a coach or administrator at one Organization exchange direct messages with a coach or administrator at a different Organization — typically to coordinate a scrimmage, practice game, or similar arrangement. Messages on this surface are text only; it does not support photo or file attachments.

23.2 What We Collect and Who Can See It

We collect the text of each message, who sent it and when, and which cross-Organization conversation it belongs to — the same categories described in Section 2.15. A cross-Organization conversation is visible only to its two participants. Each participant is shown to the other as a first name and last initial only — we do not expose either participant's full name, email address, or phone number through this feature. This feature is staff-only: it is available to coaches and administrators and is not accessible to parents, guardians, or Players (Section 23.6).

23.3 Blocking, Reporting, and Flagging

23.4 Moderation by DugoutHQ Platform Staff

Because a cross-Organization conversation belongs to neither participant's Organization alone, flagged messages are reviewed by DugoutHQ platform staff — a neutral party to the conversation — rather than by either Organization's own moderators. Platform staff may remove a flagged message; every such moderation action is logged in our platform administrator records (Section 2.8), the same way other administrator actions are.

23.5 Retention and Muting

A cross-Organization message persists until it is deleted; either participant can mute a conversation to stop notifications from it without leaving or deleting it, the same as muting within your own Organization (Section 19.3). Retention otherwise follows Section 9.

23.6 Not Available to Parents or Players

This feature exists for adult, staff-to-staff coordination between clubs. Parents, guardians, and Players do not have access to cross-Organization messaging and cannot send, receive, or be shown in a cross-Organization conversation.


24. Calendar Subscriptions and Schedule Export

Plain-English summary. A team's staff can publish a season's schedule as a link you (or your phone's or computer's calendar app) can subscribe to, so it updates automatically as the schedule changes. The link itself — not a login — is what lets someone view that season's game/practice titles, dates/times, locations, and any event notes a coach added (like field numbers or uniform colors), so treat it like a shared secret and only share it with your own team's community. It never exposes your roster, contact information, dues, or messages. Staff can generate a brand-new link at any time, which immediately turns off the old one.

24.1 What This Feature Is

An Organization's staff may publish a season's schedule as a subscribable calendar feed in the standard iCalendar (ICS) format, reachable at a webcal:// or https:// link. Adding that link to a phone's or computer's calendar app lets it periodically re-fetch the feed, so the app's copy of the schedule updates automatically as games, practices, and other events are added, changed, or removed.

24.2 What the Link Exposes

The feed contains only schedule/event data: event titles, dates and times, locations, and coach-written event notes (e.g. field numbers or uniform colors) for the season it was generated for. It does not include rosters, Player or guardian information, contact details, dues or other financial data, or any message content.

24.3 The Link Is an Unauthenticated Bearer Credential

Unlike most of the Service, retrieving the feed does not require signing in. The link contains a long, randomly generated token, and that token — not your identity — is what the feed checks: anyone who has the link can view that season's schedule information for as long as the link stays valid, whether or not they are otherwise a member of the Organization. Because of this, we describe the link as a "bearer" link, and we ask Organizations and families to treat it the way you would any shared password or invitation: share it only with people you want to be able to see that season's schedule (typically your own team's community), and be aware that anyone you share it with — or anyone they in turn share it with — can view the feed until it is regenerated.

24.4 Regenerating (Revoking) the Link

A team's staff can regenerate a season's calendar link at any time from that season's schedule page. Regenerating immediately creates a new token and invalidates the old link — anyone still using the previous link will no longer be able to retrieve the feed. Regenerate the link if you believe it has been shared more widely than you intended.

24.5 Your Choices

Publishing a calendar link is a choice a team's staff makes; a season's schedule is not exposed this way unless staff generates and shares the link. If you no longer want a previously shared link to work, ask your team's staff to regenerate it (Section 24.4). Because the feed requires no account, we cannot identify or remove access for a specific person who received the link from someone else — regenerating the link is the only way to cut off access.


25. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice (such as by email or an in-Service notice). Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy, to the extent permitted by law.


26. Contact Us

If you have questions, requests, or complaints regarding this Policy or your personal information, contact:

DugoutHQ Attn: Privacy — Privacy Team (available on request) Email: [email protected]

If you are in the EEA or UK, you also have the right to contact your local data-protection authority.


This Policy is governed by and construed in accordance with the laws of the State of Maryland, without regard to conflict-of-laws principles, except where a data-protection law of another jurisdiction mandates otherwise.