Privacy policy
Placeholder
What the product collects today
- Account: email, name, role, and date of birth. Passwords are handled by the authentication provider and yelloball never sees one.
- Athlete profile: positions, class year, ZIP code, travel organization and team, and any optional field she fills in — height, weight, bats and throws, measured fastpitch metrics, pitch arsenal, GPA, test scores, intended major, bio, photo, and highlight video links.
- Contact, if a family chooses to give it: an email and phone for the athlete, for a parent or guardian, for both, or for neither.
- Activity: camps saved, followed, marked interested, and registration links clicked.
What is never shown to a coach
The email address used to sign in, date of birth, street address, ZIP code, precise location, and test scores. These are not merely hidden by a setting — they are not part of what a coach can retrieve at all.
There is no public athlete profile. A profile is visible only to the athlete and a confirmed linked parent until she sends a connection request to a specific college coach and that coach approves it. Following a coach exposes nothing. Either side can end an approved connection at any time, and her contact details close with it. Accounts are not available under the age of 13. A program cannot see who saved its camp as individuals — only counts.
Athlete photos never sit on the open internet. They are kept in a private store and handed out as links that expire after an hour, issued one viewer at a time — so a photo's address cannot be shared, saved, or found.
See Trust & safety for the full list of what is visible and to whom.
Analytics
None is being collected today. The product can send interaction events to PostHog, but no key is configured, so nothing leaves the browser.
If it is switched on, what would be sent is the shape of what people do — a camp viewed, a search run, a registration link clicked — tied to an account id and a role, and nothing else. No name, email, school, or location. Automatic capture is off and text on the page is masked, so the fields an athlete fills in are never recorded. That is pseudonymous rather than anonymous: the account id is not a name, but it is the same id every time.
Who else touches the data
The services yelloball runs on, and what each one holds:
- Supabase — the database, sign-in, and file storage. Everything above lives here.
- Vercel — hosting. It serves the pages and keeps ordinary web request logs.
- Mapbox — the map on camp search. It is sent the area of the map being looked at.
- Resend — email. Not configured today, so no email is being sent.
- PostHog — analytics. Not configured today, as above.
Still to be written, by counsel
- Legal basis for processing, and parental consent for users under 13.
- Retention periods and the deletion procedure.
- Data subject rights and how to exercise them.
- Breach notification commitments.
- Where the services above hold data, and the terms yelloball is on with each.