Skip to content

Policy review copy · August 30, 2026

Privacy at TryoutFlow

This draft explains how the planned TryoutFlow service would handle information for organizations, staff, guardians, and minor athletes.

Scope and roles

TryoutFlow is intended to process tryout information for the subscribing sports organization. The organization determines why athlete and guardian information is collected and who on its staff may use it. TryoutFlow acts as service provider or processor for that organization, while handling account, billing, security, and service-operation information for its own stated purposes.

Information we expect to process

  • Organization, membership, role, and account details.
  • Guardian contact information and athlete registration details selected by the organization.
  • Check-in status, assigned number, evaluator assignments, scores, completion state, notes, flags, rankings, decisions, and rosters.
  • Message delivery, subscription, audit, security, and privacy-safe operational events.

Organizations should collect only information needed to run the tryout. Emergency or eligibility fields should be optional and organization-controlled.

How information is used

Information is intended to publish and administer tryouts, accept registrations, check athletes in, support independent evaluation, calculate transparent aggregates, build rosters, communicate with participants, provide confirmed exports, secure accounts, bill organizations, and maintain an audit trail. Private evaluation content must not be used in third-party advertising or general product analytics.

Children and minor athletes

Most athlete records may concern minors. Registration is designed to be completed by a guardian or authorized adult; athletes do not need their own account. Organizations are responsible for authority to collect and use minor-athlete information, notices to families, and any consent required in their jurisdiction. The required age, consent, parental-access, and child-privacy language remains an unresolved legal-review item.

Access, sharing, and disclosure

Role and assignment boundaries are intended to limit access: for example, check-in staff should not see rankings, and evaluators should not see peer scores during live evaluation by default. Information may be disclosed when instructed by the subscribing organization, required by law, needed to protect the service, or provided to approved subprocessors under appropriate terms.

Service providers and subprocessors

Planned processor categories include cloud hosting, database/authentication and private storage, subscription billing, transactional email, error monitoring, and privacy-safe product analytics. Current technical vendors include Vercel, Supabase, Stripe, and Resend, but the final subprocessor list, locations, transfer terms, and change-notice process must be verified before production launch.

Cross-border processing and residency

Service providers may process information outside the organization’s province or country, where it may be subject to local law. Canadian-only data residency is not promised. Exact hosting regions, international transfer safeguards, customer-jurisdiction requirements, and any Canadian public-sector restrictions remain unresolved and require written approval.

Retention, deletion, and correction

Organizations need tools and procedures to export, correct, and delete information, subject to lawful recordkeeping and audit needs. Exact retention periods for registrations, scores, notes, rosters, messages, audit logs, backups, and support records have not been approved. Production onboarding must not begin until a retention schedule, deletion workflow, backup-expiry rule, and post-termination handling process are adopted.

Security and incidents

Planned safeguards include tenant isolation, row-level database policies, role-based authorization, private storage, encrypted transport, protected credentials, verified webhook signatures, audit events, and privacy-safe logs. No system is risk-free. A security contact, incident-response procedure, notification assessment, support-access policy, and breach timeline must be approved before launch.

Individual and guardian requests

Requests to access, correct, export, or delete information should normally be directed to the sports organization that collected it. TryoutFlow would assist the organization as required by contract and law. Identity verification, authorized-agent handling, appeal rights, response timelines, and direct-request routing remain subject to legal review.

Changes to this notice

An approved notice would identify its effective date and material changes. Organizations would receive notice through an approved channel when required. This draft has no effective date because it is not yet operative.

Contact and unresolved owner

Privacy contact: to be confirmed before launch. The approved version must provide a monitored email or postal address, the accountable privacy role, and escalation details. Do not send athlete or guardian information to an unconfirmed contact.