Legal

Privacy Policy

Last updated June 10, 2026

01Introduction

ROOTS Volleyball Academy (“ROOTS,” “we,” “us”) runs a club volleyball program in the Kansas City, Missouri area and operates this website and a companion iOS application. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to athletes (players), parents, prospective families, and visitors to our public site.

By using our services, you agree to this policy. If you don’t agree, please don’t use them — and reach out via the contact page if you have questions before deciding.

02Information we collect

We collect information in three ways:

Information you give us

  • Account information: name, email address, and a hashed password when you create an account.
  • Athlete (player) information: name, date of birth, position, jersey number, graduating class, height, photo (optional), and parent/guardian email.
  • Performance data: physical measurements (vertical jump, attack vertical, approach touch, block touch, height, weight), academic information for college-track athletes (GPA, test scores, graduation year, intended major), and coach-entered notes.
  • Recruitment inquiries: contact info, athlete details, and any message you submit through the /recruitment form.
  • Messages and content:in the companion iOS app, the direct messages, team and group chat messages, chat attachments, reactions, announcements, practice plans, and recruitment inquiries you create. Each message stores its text along with the sender’s name and email. This content is not private from ROOTS — see the Messaging, monitoring & moderation section.
  • Onboarding documents: typed e-signatures (your legal name plus the date and time you signed), agreement acknowledgements, form answers, and uploaded files such as insurance cards, physicals, certifications, and headshots. Coaches paid by ROOTS may also be asked for tax and bank information (for example a W-9 and bank account details) — see Data security.
  • Schedule and attendance: the attendance status and notes staff record for practices, games, and tournaments, which also feed House Cup standings.
  • Payment information: we do not store credit card numbers. Card data is collected and stored by Stripe; we receive transaction metadata (amount, plan, status, billing name and email, and Stripe identifiers). ROOTS also supports a cash or check option, recorded manually by an administrator with the same transaction metadata.
  • Device information (iOS app): when you turn on push notifications, we store the Apple Push Notification service (APNs) device token tied to your account, your app version, last-seen time, and your notification preferences, so we can deliver alerts.

Information we collect automatically

  • Authentication cookies used to keep you signed in (set by Supabase, our auth provider).
  • Basic server logs: IP address, browser, device type, pages visited, and timestamps — used for debugging and security. We do not use third-party advertising or analytics trackers.

Information from third parties

  • Stripe sends us payment confirmations, refund records, and dispute notices for invoices.

03How we use it

  • To run the club: roster athletes, schedule practices and tournaments, track development.
  • To keep our community safer and run the club: directors and administrators can read messages and review content, every message in the app is automatically checked against a keyword list, and members can report messages. See the Messaging, monitoring & moderation section.
  • To process payments, record cash or check payments, and send invoices/receipts.
  • To deliver notifications you have set up — message and announcement pushes, schedule changes, billing reminders, recruitment responses.
  • To respond to recruitment inquiries from prospective families.
  • To improve the website and iOS app.
  • To meet legal obligations (tax records, dispute responses, parental consent for minors).

We do not sell your personal information. We do not run third-party advertising on our services and we do not let advertising networks track you across the web through our site.

04Who we share it with

We share your information only with service providers necessary to operate the club, and only the minimum each one needs:

  • Stripe — payment processing. Stripe receives card data, billing details, and transaction history; see stripe.com/privacy.
  • Supabase — database + authentication hosting. Supabase stores everything we collect on your behalf, encrypted at rest; supabase.com/privacy.
  • Resend — transactional and announcement email delivery (receipts, recruitment confirmations, password resets, and announcement emails, which can include announcement content); resend.com/legal/privacy-policy.
  • Apple— delivers push notifications to the iOS app through the Apple Push Notification service (APNs). Message and announcement notifications sent through APNs include the sender’s name and a preview of the content, which may appear on a device lock screen; apple.com/legal/privacy.
  • Vercel — website hosting and DNS; vercel.com/legal/privacy-policy.
  • Tournament organizers and college recruiters — at parent direction, when we share an athlete’s athletic + academic profile for recruiting purposes.
  • Legal authorities— if compelled by valid legal process, or to investigate fraud or protect someone’s safety.

We don’t share information for marketing purposes outside of ROOTS itself.

05Children's privacy

ROOTS rosters athletes as young as 12 years old (12U house), so many of our members are minors, including children under 13, and much of the information we collect is about children. We follow the U.S. Children’s Online Privacy Protection Act (COPPA).

How that works in practice:

  • Accounts for athletes under 13 must be created and held by a parent or legal guardian, not by the child. The app uses the date of birth entered at signup to enforce that no one under 13 creates their own account.
  • We collect a child’s name, date of birth, photo, contact information, player and development data, attendance, and the messages and content the child sends in the app. We use this to run the club and keep the community safer, and we may share it with the service providers listed above, with college coaches for recruiting only at a parent’s direction, and with authorities when required by law.
  • Children under 13 can use messaging, and it is monitored.Under-13 players are automatically enrolled in their team’s chats and can send messages. Those messages can be read by club directors and administrators without notice and are automatically checked against a keyword list, exactly as described in the Messaging, monitoring & moderation section. When a parent or guardian completes onboarding and accepts our Terms of Service, that consent specifically includes this monitoring. Please be sure you are comfortable with your child using messaging on these terms before consenting.
  • Parents and guardians can review, correct, or request deletion of their child’s information at any time — email support@rootsvolleyball.com. We verify that you are the parent or guardian before acting. See Data retention and Your rights for what deletion does and does not remove.

06Messaging, monitoring & moderation

ROOTS is a youth sports organization, and the app includes messaging — direct messages, team and group chats, announcements, reactions, and attachments. To help keep our community safer and to run the club, messages and other content you send in the app are not private from ROOTS, and they are not end-to-end encrypted. Please read this section carefully before using messaging, and do not treat any conversation in the app as private or confidential from the club. This applies to messages sent by minors as well as adults.

Directors and administrators can read your messages. Because many of our members are children, club directors and administrators can read any message in any conversation in the app — including private direct (one-to-one) messages, messages in team and group chats, and messages sent by minors — at any time, even conversations they are not a part of. They can do this without notifying the people in the chat and without any visible sign that the chat was viewed or searched. We do this to investigate safety concerns, enforce our rules, and operate the club. Coaches and other members cannot read conversations they are not part of; this broad access is limited to directors and administrators.

Every message is automatically checked against a keyword list. At the moment a message is sent, it is automatically compared against a list of keywords that ROOTS maintains (for example, terms related to bullying, harassment, threats, or inappropriate content). When a message matches, a copy of that message — including its full text and the sender's name and email — is flagged and saved for a director to review. This is an automated keyword check. It is not artificial intelligence, it is not shared with any outside AI service, it is not a person reading every message in real time, and it does not understand the meaning of what is written. It only matches the specific words on the list, it will not catch everything, and if the check ever fails the message is still sent. A flag does not mean ROOTS has reviewed or acted on a message. Automated checking is a best-effort safety tool, not a guarantee that harmful or inappropriate messages will be detected, prevented, or removed.

Reporting and moderation. Members can report a message to ROOTS staff using the report option in the app or by emailing support@rootsvolleyball.com; reporting saves a copy of the reported message, the sender's identity, your stated reason, and the fact that you reported it. If another member is bothering you, report the message or email support@rootsvolleyball.com and a director can mute that member so they can no longer send messages. Directors and administrators can remove a message, mute a member, and archive a conversation, and these actions are recorded in a moderation log. Removing a message does not erase it from ROOTS' systems: before a removed message disappears for members, ROOTS saves a copy of its text and the sender's identity as a moderation record (evidence), and any file attached to a removed message may remain in our storage. Flagged and reported messages are likewise retained as moderation records.

Automatically created team chats. The club automatically creates team and role-based group chats and enrolls players (including minors), parents, and coaches into them based on the roster and their role, without a separate sign-up step. To help protect minors, who you can directly message is limited by role: players can only directly message other players (by default on the same team, and across teams only if the club enables that setting), and players cannot directly message adults. Within these chats, members can see who is on a team and the connection between a parent or guardian and their player.

Storage, delivery, and retention. Messages, chat attachments, and reactions are stored on our backend (Supabase) in readable form, not end-to-end encrypted, and are currently retained until removed by staff or the account is deleted; members cannot edit or delete their own sent messages. Chat attachments may include photos or files involving minors and are stored in a private storage bucket. When you send a message, the recipients' devices receive a push notification through Apple's APNs showing the sender's name (and in some cases email) and a preview of the message text (up to about 200 characters), which may appear on a lock screen; announcements may also be delivered by email through our provider (Resend). We use the message content only for safety, moderation, and running the club; we do not use it for advertising, we do not build advertising profiles from it, and we do not send chat content to any artificial-intelligence service.

07Cookies and tracking

We use a small number of cookies, all functional. None of them are for advertising or cross-site tracking.

  • Authentication cookiesset by Supabase when you sign in, so you don’t have to re-enter your password on every page.
  • Preferences — light/dark mode and similar UI state, stored in your browser.

You can clear or block these cookies in your browser settings; the site will still load but you won’t be able to stay signed in.

08Data security

We take reasonable measures to protect your information: HTTPS in transit, encrypted-at-rest database storage, role-based access controls on internal data, hashed passwords, and payment card data handled exclusively by Stripe (a PCI DSS Level 1 service provider).

Two important limits to be clear about. First, role-based access controls do not restrict club directors and administrators, who can read any message in the app — see Messaging, monitoring & moderation. Messages are stored in readable form, not end-to-end encrypted, and are not private from ROOTS.

Second, regarding tax and bank information we may collect from coaches paid by ROOTS (such as a W-9 or bank account details): we do not currently claim this information is encrypted, tokenized, or held by a specialized secure payment provider, because today it is not. Access is restricted to the submitter and ROOTS administrators, who can view it when reviewing onboarding. We are working to move this information to secure handling, and we recommend you do not submit tax or bank information until that change is in place — email support@rootsvolleyball.com with questions first.

No system is perfectly secure. If we become aware of a data breach affecting your information, we will notify affected families promptly and follow Missouri’s breach-notification requirements.

09Data retention

We keep your information for as long as you have an active relationship with ROOTS, plus a retention period after:

  • Active athletes/families: for the duration of enrollment.
  • Alumni: career data (measurements, college outcomes) retained indefinitely so we can support recruiting references and alumni outreach, unless you request deletion.
  • Recruitment inquiries that didn’t convert: retained 24 months, then deleted.
  • Financial records: retained 7 years for tax purposes.
  • Messages and moderation records: messages, chat attachments, reactions, and moderation records — including saved copies of reported, flagged, or removed messages kept as safety evidence — are currently retained until they are manually removed by staff or the account is deleted. There is no automatic purge today, and members cannot delete their own messages. We are working to put in place a defined, limited retention period for moderation records of children’s content.

10Your rights

You can request the following at any time:

  • A copy of the personal information we hold about you.
  • Corrections to incorrect information.
  • Deletion of your information (subject to legal-retention requirements like financial records, and to the limits described just below).
  • An export of your data in a portable format.
  • That we stop sending you non-essential communications.

What “Delete My Account” removes: the in-app account-deletion tool removes your login, your profile and device tokens, your uploaded profile and community video/photo files, your onboarding submissions and the files you uploaded during onboarding, and the chat attachments you sent. It also anonymizesyour name and email on messages you previously sent (they are replaced with “Removed member”). It does notremove everything we may hold — it keeps moderation records (saved copies of flagged, reported, or removed messages kept as safety evidence), financial records we must retain for tax purposes, and a player’s roster, attendance, and career/academic records, which are tied to the team roster rather than to your login. The text of messages you sent stays in conversations, but with your identity removed. To request fuller deletion of a record (including a child’s roster, attendance, or academic record), email the address below and we will remove what we can, subject to our legal-retention obligations.

Email support@rootsvolleyball.com and we’ll respond within 30 days. For minors, the parent or guardian on file must make the request, and we will verify them before acting.

11Changes to this policy

We update this policy when our practices change. Material changes will be communicated via email to active account holders at least 14 days before they take effect. Minor edits (typos, clarifications) may be made silently — check the “last updated” date at the top of this page.

12Contact us

Questions about this policy or how we handle your information:

See also our Terms of Service.