Fieldhouse Connection

Privacy Policy

Last updated August 13, 2026

Fieldhouse Connection is software that youth organizations — parks, leagues, clubs, studios, schools, and teams — use to run registration, dues, schedules, and group communication. This policy explains what we collect, why, and the rules the system enforces on itself.

The short version

  • We never sell personal information. We never sell children's data, and we never hand it to advertisers or data brokers.
  • Children under 13 do not get logins, and a child's profile is only ever created by their own guardian.
  • Staff can see the children in their own groups and no one else's. This is enforced by the database, not by screen design.
  • Every message a child can read, their guardian can read. There is no private adult-to-child channel in this product.
  • The optional AI features do send text to an outside AI provider, and that text can include a child's first name. We list exactly what, and when, further down.

Who controls the data

The organization you belong to — your park, league, club, studio, school, or team — decides what to collect and who on their staff may see it. They are the data controller. Fieldhouse Connection is the processor: we store and protect the data and act on the organization's instructions. Requests to correct or delete records normally go to your organization first; you can also contact us directly and we will help.

What we collect

  • Adults (guardians, coaches, admins, trainers, staff): name, email, password (stored hashed, never in readable form), and optionally a phone number for text notifications. Organization staff may also have compensation and tax records if their organization pays them through the platform.
  • Participants (children and youth members): first and last name, birthdate, group assignment and optional identifier (for example a jersey number), and — where the organization collects it — a home address, emergency information, and answers to that organization's registration form. Participants 13 and older may have their own email and phone on file; younger participants may not, and the database refuses to store them.
  • Payments: handled by Stripe. Card numbers never touch our servers. We keep the amount, date, status, and Stripe's reference so your organization's books balance.
  • Operational records: RSVPs, attendance, messages in group channels, and schedule history.

Children's privacy (COPPA)

Fieldhouse Connection is designed so that information about a child enters the system only through a parent or legal guardian.

  • A profile for a child under 13 cannot be created without a guardian consent record attributed to that guardian's own account. This is a database constraint; there is no path around it, including for administrators importing a membership spreadsheet.
  • When an organization uploads a membership spreadsheet, those details are held in a staging area — visible only to that organization's own staff and to the guardian the organization named — and no child profile exists yet. The profile is created only when that guardian confirms it and gives consent from their own verified account. Staff cannot change who the named guardian is; correcting a row means deleting it and re-uploading, which leaves a record.
  • Children under 13 are never issued logins. Participants 13 and older can be given access only when a guardian turns it on.
  • Guardians may review what is stored about their child, correct it, withdraw consent, or request deletion at any time, through their organization or by contacting us.
  • We do not use children's data for advertising or profiling, and we never sell it.
  • If your organization turns on the optional AI features, a child's first name and their training or check-in entries can be sent to an outside AI provider so a coach gets a draft to review. What is sent is listed below. Ask your organization whether they use these features; they can leave them off.

Who can see what

Access is enforced at the database level with row-level security, so it applies identically to the website, the mobile app, and any future interface. Guardians see their own children. Staff see the participants in the groups they lead. Organization administrators see their own organization and the groups beneath it. Nobody sees another organization's families.

Who we share with

The service providers required to operate, and nobody else. We do not sell personal information, and we do not share it with advertisers or data brokers. We may disclose information if legally required, or to protect someone's safety.

  • Supabase — database and sign-in. Holds everything described above.
  • Vercel — website hosting.
  • Stripe — payments. Receives the payer's email and the amount; card and bank details go straight to Stripe and never reach us.
  • Resend — email delivery. Receives recipient addresses and message contents.
  • Twilio — text messages, where an organization uses them. Receives phone numbers and message contents.
  • Expo — push notifications to the mobile app. Receives device tokens and notification text.
  • OpenAI and Anthropic — the optional AI features. This is the only place where text about a child leaves our systems, so it gets a section of its own rather than a line: AI features, and exactly what they send.

AI features, and exactly what they send

Parts of Fieldhouse can ask an outside AI provider to write a first draft, or to work out what a typed question means. These features are optional: with no AI provider configured they are off, the assistant falls back to a rule-based parser that runs on our own servers, and nothing leaves. Because this is the one place where text about a child can leave our systems, we describe it in full instead of in a sentence.

Which provider

Drafting runs on either OpenAI or Anthropic — one at a time, whichever the deployment is configured to use. The assistant runs on OpenAI only. Your organization's administrator can ask us which one is live for you.

Drafting

None of this happens on its own; a staff member presses a button. What we send:

  • A progress note about one child — that child's first name, their training log entries from the last 30 days including any notes staff typed on them, their check-in entries (sleep, energy, mood, soreness, and any injury flag), and any trainer session notes.
  • A weekly readiness digest for one team — the first names and recent check-in entries of the children on that team's roster, and nobody else's.
  • An announcement draft — your organization's name and the bullet points the staff member typed.
  • A dues-reminder rewrite — your organization's name, the invoice title, the amount, how far past due it is, and that invoice's payment link.

Last names, birthdates, addresses, and contact details are not sent as fields: the queries behind these features do not read those columns. What we cannot promise is the free text. A session note, a training log note, announcement bullets, and an invoice title are all written by a person at your organization, and an invoice title routinely contains a child's name. We do not inspect or rewrite what somebody typed, so whatever is in that note is what gets sent. Staff should write notes with that in mind, and an organization that would rather not take that risk can leave these features off.

The assistant

When you type a question to the assistant, a rule-based parser on our own servers reads it first. For ordinary phrasings it understands you and nothing leaves. When it cannot, the sentence you typed is sent to OpenAI word for word, together with the list of things the assistant knows how to do — and the model's only job is to say which one of them you meant.

Your sentence is not filtered before it goes, and that is a real limitation rather than a theoretical one: if a coach types “is Marcus eligible for 12U,” a child's first name goes to OpenAI. What is never sent is the data itself. The model is not given a roster, an invoice, a health record, or any other record, and it is not asked to answer your question. Every name, number, and date in the answer you get back is looked up afterwards by our own code, under the same access rules as every other screen.

What holds in every case

  • AI output is a draft. A person reads it and decides whether to send it. Nothing an AI writes reaches a family on its own.
  • The AI is never given the ability to act. It cannot send a message, change a record, or move money.
  • Neither provider trains their models on what we send. That is the standing default of the commercial API terms these features run under.
  • Both providers do hold what we send for a limited period so they can check for misuse of their own service, and then delete it. We have not negotiated a zero-retention arrangement with either of them, so we are not going to tell you nothing is stored.
  • Every drafting request is written to your organization's audit log — who asked, and what for. Assistant questions are not recorded there.
  • The people using these features are adults: staff and guardians. A participant 13 or older whose guardian has given them a login can also use the assistant, and if they do, what they type is handled exactly as described above. Children under 13 have no login at all.

Keeping and deleting data

Organizations keep records for as long as they need them to run their programs and meet their own financial and legal obligations. You can delete your account from Settings. When you do, we anonymize it: your name and email are removed, and any child you solely guard has their name, address, and contact details cleared as well. We deliberately do not erase the underlying registration and payment rows, because an organization has its own financial and legal duty to keep a record that a program period was paid for — but what remains no longer identifies you or your child. If you want a record erased entirely rather than anonymized, write to us and we will do what the law allows.

Security

Data is encrypted in transit and at rest. Passwords are hashed. Access rules live in the database rather than in application code, which means a bug in a page cannot expose data the rules forbid. Payment card details are handled entirely by Stripe and never reach our systems.

Contact

Questions, corrections, or deletion requests: privacy@fieldhouseconnection.com. Guardians can also raise anything with their organization's administrator, who can act on their records directly.

If we change this policy in a way that affects how we handle your information, we will notify organizations and update the date above. Terms of Service

Privacy Policy — Fieldhouse Connection