TeamCaddy

Privacy

Most of this product's design decisions are privacy decisions, so this page is mostly a description of how it works. Last updated 30 August 2026.

TeamCaddy is run by Team Caddy LLC, a Delaware limited liability company. If you want to reach a person about anything on this page, write to privacy@teamcaddy.app.

The short version

  • We sell software. We do not sell data, and there is no advertising in the product.
  • There are no analytics, no trackers and no third-party scripts on this website or in the app. One cookie exists and it is the one that keeps you signed in.
  • A roster is a list of children. Every visibility setting starts closed and has to be opened deliberately by someone with the authority to open it.
  • Medical information is readable by a named, narrow set of people, and every single read is written to an audit log.

What we collect

From people with an account

Your name, email address, and — only if you give it — a mobile number. A password, stored only as a PBKDF2-SHA256 hash; we never hold the password itself. Your timezone and locale, so times render correctly. Optionally a profile photo.

About players, from the adults who enter it

A player's name and date of birth. The date of birth is required, because age eligibility for a season is calculated from it rather than typed in by an administrator — that calculation is the whole point of it, and it prevents a category of dispute that the alternative causes.

Where a club asks for it: emergency contact details, allergies, medications and medical notes. Uniform and position details. Guardian relationships, including a staff-only note where custody arrangements are not equal.

Generated by using the product

Attendance replies, messages, event and venue details, invoices and payment records, registration answers, waiver signatures, and files people upload. Waiver signatures record the signer's name, their asserted relationship to the player, the time, their IP address and their browser's user-agent string — that combination is what makes a signature evidence rather than a tick-box.

Sessions record an IP address and user-agent so you can see and revoke your own sign-ins. Privileged actions — removing someone from a roster, changing a role, reading a medical field, issuing a refund — are written to an audit log with the actor, the action and the time.

What we do not collect

We do not collect behavioural analytics, we do not build advertising profiles, we do not buy data about you from anyone, and we do not run third-party scripts that would let someone else do any of those things on our pages.

Children's data

This is the part that matters most, so it is stated plainly.

Almost every player in this product is a minor, and almost none of them have an account. Their information is entered by a parent, guardian or club official — an adult with a relationship to that child — and it is that adult, not the child, who agrees to our terms. Where a club is the one entering the data, the club is responsible for having the authority to do so.

Where a player is old enough to have their own login, an account for anyone under 13 is flagged as a minor's account, and consent from a parent or guardian is recorded before it is usable.

We do not serve advertising to anyone, and we do not profile children for any purpose. A public team page shows nothing about a player unless an administrator has explicitly turned the roster on, and even then it shows a first name, a last initial, a shirt number and a position — never a date of birth, never contact details, never a guardian's name. Photographs require a second, separate setting.

If you believe a child's information is in this product and should not be, write to privacy@teamcaddy.app and we will remove it.

Who can see what

Access is decided by one permission table in the software, not by a rule repeated in different places and hoped to be consistent. In practice:

  • Medical fields and emergency contacts are readable by the player's own guardians, the player, and only the most senior team roles — an assistant coach cannot read them, and neither can another parent. Every read is logged.
  • Financial aid applications are readable by a club's owner, an administrator and a treasurer. They are not readable by a coach, by any team role, or by a division director, and nothing about them appears on a roster or a team page.
  • Contact details are never shown on a public page and are not visible to the fan role at all.

Who we share it with

We use a small number of processors, each for one job, and we do not share your information with anyone else:

  • Cloudflare — hosting, the database, file storage, content delivery, and the transactional email we send you, such as an invitation or a password reset. Email runs on the same platform as the rest of the product, which means one fewer company holds your address than would otherwise.
  • Stripe — card and bank payments, where a club collects money. Card details go to Stripe directly; we never hold a card number.
  • Twilio — text messages, only to numbers whose owner has opted in, and only for the categories they chose.

We will disclose information if the law compels us to. If we are ever bought or merged, your information moves with the product, and this policy travels with it until it is replaced by one you are told about.

Where it is kept, and for how long

Data is stored on Cloudflare's network. Because that network is global, information may be processed outside the country you live in; the transfer terms in Cloudflare's data processing agreement cover that.

Most things you can delete are removed from view immediately and retained for 30 days before being erased, so that a mistaken deletion of a roster or a season is recoverable. Financial records are kept for as long as tax and accounting law requires. Audit log entries are kept for 24 months, because their purpose is to answer a question asked long after the event. Closing an account removes personal information except where we are required to keep it.

Your rights

Depending on where you live, you can ask us for a copy of the information we hold about you or the children you are guardian of; ask us to correct it; ask us to delete it; object to a particular use; or ask for it in a portable format. Write to privacy@teamcaddy.app and we will answer within 30 days.

If you are in the UK or the EU and think we have handled your information badly, you can complain to your data protection authority. We would rather you told us first.

Security

Passwords are hashed and never stored. Session tokens are stored only as a hash, so a database leak does not hand anyone a working session. The session cookie is HttpOnly, so a scripting bug cannot read it. Everything is served over TLS. Sensitive fields are omitted from a response entirely when the person asking is not entitled to them, rather than being sent and hidden by the interface.

No system is perfect. If you find a vulnerability, tell us at security@teamcaddy.app and we will work with you.

Cookies

One cookie, named tc_session. It keeps you signed in. It is HttpOnly, Secure, and SameSite=Lax. There is no advertising cookie, no analytics cookie, and no third-party cookie, which is why this site does not interrupt you with a banner asking permission to set them.

Changes

If we change this in a way that matters, we will tell account holders by email before it takes effect, and the date at the top of this page will change.

Start with one team. Add the club later.

A single team is free, forever, with the whole core loop — schedule, roster, RSVP, chat, public page. Nothing is held back to make you upgrade.

No credit card. No ads, ever.