Legal
Data Processing Addendum
The data-protection terms between an organization and InSeasonHQ. Part of the Terms of Service — it governs the family and player information we handle on an organization's behalf.
Last updated August 28, 2026 · InSeasonHQ LLC
Roles
For the personal information of players and families, the organization determines the purposes and means of processing, and InSeasonHQ processes it on the organization's documented instructions.
Using the platform's ordinary features — building a registration form, running a season, sending a message to a team — is the organization's instruction. We do not use family or player information for our own purposes, and we never sell it or use it for advertising.
Separately, InSeasonHQ acts on its own behalf for the accounts of an organization's administrators, our billing records, and the security and operation of the service.
Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Providing the InSeasonHQ platform |
| Duration | The term of the subscription, plus the deletion window below |
| Nature and purpose | Registration, rosters, scheduling, communication, volunteering, equipment, and payment facilitation |
| Types of data | Player and guardian contact details, dates of birth, addresses, health information provided for safety, registration answers, signatures, season activity, and payment metadata |
| Categories of people | Players (mostly minors), parents and guardians, coaches, staff, and volunteers |
Our obligations
- Instructions. We process only per the organization's instructions and this agreement, unless the law requires otherwise — in which case we will tell the organization first if we are permitted to.
- Confidentiality. Our personnel with access are bound by confidentiality obligations and get access only where needed to support or operate the service.
- Security. We maintain appropriate technical and organizational measures: encryption in transit, hashed passwords, per-organization data isolation, role-based access, and audit logging of administrative actions.
- Breach notification. We will notify the organization without undue delay after becoming aware of a personal-data breach affecting its data, with the information it needs to meet its own obligations.
- Assistance. We will help the organization respond to requests from parents or others exercising their rights, and provide the information it reasonably needs for a data-protection assessment.
- Children. We handle children's information consistent with our Children's Privacy Notice, and we do not use it for marketing or profiling.
The organization's obligations
- Have a lawful basis for the information it provides, including any parental consent required for a child's data;
- Give its families an accurate privacy notice of its own;
- Configure roles so staff see only what their job requires, and remove access promptly when someone leaves;
- Not enter special categories of information the platform is not designed for — the health fields exist for event safety, not medical records.
Sub-processors
The organization authorizes us to use sub-processors who are bound to equivalent obligations. Today they are:
| Sub-processor | Purpose |
|---|---|
| Stripe | Payment processing and payouts |
| Twilio | Text-message delivery |
| Microsoft Azure | Hosting, database, and file storage (United States) |
| Postmark | Sending transactional and bulk email |
Deletion and return
When a subscription ends, the organization may export its data. After a wind-down period we delete its personal information from active systems, and from backups on our normal backup cycle — except where the law requires us to keep records, such as financial records for tax purposes.
Audits
On reasonable request, we will provide the information needed to demonstrate compliance with this addendum.
Order of precedence
This addendum forms part of the Terms of Service. Where it conflicts with them on the processing of personal information, this addendum controls.