Private-first by design. Role-scoped by default.
This policy explains the practical data posture for Player Planner during launch and real-user onboarding. It is written plainly for program leaders, parents, guardians, coaches, and support operators.
Effective September 16, 2026
What Player Planner is
Player Planner is a private-first operating system for youth programs. It helps churches, academies, teams, coaches, parents, guardians, and players coordinate schedules, practice work, goals, homework confirmations, messaging, and safe support.
Information we handle
- Account and invite details such as name, email address, role, organization, team assignment, and invite acceptance status.
- Program data such as teams, calendar items, facility names, exact venue addresses, third-party location-provider place identifiers, location details, practice plans, homework confirmations, assessments, goals, and coach handoff notes.
- Family and player workflow data such as parent/guardian confirmations, player check-ins, help requests, and role-appropriate progress summaries.
- Messaging data such as team/direct messages, attachments, reactions, read status, and message audit records.
- Restricted eligibility images, such as birth certificates, league forms, or identification, only when a current guardian provides versioned authorization for tournament or league participation.
- Operational data such as authentication events, webhook sync status, support access requests, audit logs, and security diagnostics.
- Email-notification choices and minimized delivery records, including a one-way recipient-address hash, delivery status, and bounded provider message identifier.
Role boundaries
- Program admins manage local setup, teams, memberships, invites, and locally approved support access.
- Coaches see their assigned team context, coaching workflows, and coach-visible notes needed to support players.
- Parents and guardians see family-safe player summaries, confirmations, goals, messages, and next steps intended for them.
- Players see direct, encouraging workflows written for them, not internal labels or private adult notes.
- HQ/support views default to aggregate organization health. Deeper support access must be scoped, time-limited, locally approved, and audited.
How we use data
- To operate the app, protect accounts, authenticate users, route people to the correct dashboard, and enforce role boundaries.
- To help organizations run seasons, practices, homework workflows, assessments, family communication, and launch onboarding.
- To provide support, investigate delivery or access issues, maintain audit trails, and improve reliability.
- To comply with legal, safety, security, and abuse-prevention obligations.
Address and venue processing
When an authorized program admin or coach searches for a facility or away location, partial search text is sent through Player Planner’s protected server route to Geoapify for address suggestions and verification. Geoapify may receive the query, request headers, IP address, and timestamp and states that successful-request data is normally retained for no longer than 24 hours. Player Planner stores the selected exact address and Geoapify place identifier with the organization’s calendar data. Exact locations on published events are visible to the assigned team’s families and players. Organizations should use program venues rather than private residential addresses unless that use is appropriate, disclosed, and authorized.
Restricted player eligibility documents
A currently linked guardian must authorize collection before any player, guardian, or program administrator can upload an eligibility image. Only JPG or PNG images are accepted; Player Planner removes metadata, converts the image to a canonical JPEG, and encrypts it before database storage. Family accounts see metadata only for their own uploads. Binary retrieval is limited to program administrators and requires recent step-up verification. Guardians can revoke future player access or request earlier deletion through the document area or support. Active document rows are scheduled for deletion after 11 months; encrypted database backups may remain until the infrastructure provider's backup retention cycle expires and are not served as active documents.
Transactional email notifications
Player Planner may email currently authorized message-thread recipients about new messages, excluding the sender. Message alerts contain the sender display name and a short preview; they do not include thread titles, attachment details, player identity, or sign-in tokens. A team's currently assigned head or assistant coaches and active authenticated parents who are currently linked as guardians of a player on that team may also receive alerts for newly published games and game-time changes. Game alerts contain the team name and relevant date/time, not player names, and never use roster contact addresses or invitation history as delivery authority. Parents and assigned coaches can separately control message, new-game, and game-time-change alerts; program administrators and players can control message alerts only. HQ accounts do not receive these notification controls. Preference changes also apply to notifications already waiting to send, and delivery eligibility—including the current guardian or coach relationship and active imported-game source mapping—is checked again immediately before sending. Minimized event payloads and replay snapshots are purged after 30 days once delivery is terminal; account, membership, team, source-message, and source-event deletion cascades remove dependent delivery records.
Service providers
Player Planner uses trusted infrastructure providers for hosting, authentication, database persistence, DNS/domain services, email/auth delivery, observability, and Geoapify address search and verification. These providers process data only as needed to provide the app and keep it secure.
Youth and family data
Player Planner is designed for supervised youth-program use. Organizations are responsible for inviting appropriate adults and players, obtaining any required permissions, and keeping their roster data accurate. We intentionally limit player-visible and HQ-visible data to role-appropriate views.
Retention, deletion, and corrections
Organizations or authorized users can request corrections, export help, account removal, or organization data deletion through support. Some audit, security, or legal records may be retained for a limited period when needed to protect the service and document authorized access.
Security posture
- Production traffic is served over HTTPS.
- Authentication is handled by Clerk-hosted sign-in and server-side session verification.
- Sensitive role sessions use httpOnly cookies where applicable.
- Webhook events are verified before identity sync.
- Production secrets are kept in hosting-provider environment variables, not client-side source code.
Need help?
During launch, contact Player Planner support at support@playerplanner.app.