1.Information We Collect
We collect the following categories of information when you use the MyRoster website and mobile apps:
- Account information, including your name, email address, phone number, profile photo, and password. Passwords are stored only in hashed form.
- Family and player profiles, including a child's name, date of birth, and optional gender and photo. These profiles are created and managed by the child's parent or guardian. Children are not issued login credentials, and no email address is stored for them.
- Organization data, including teams, rosters, registrations, programs, schedules, and the organizations you belong to.
- Payment information, including invoices, amounts, due dates, and payment status, together with a payment token and the card brand, last four digits, and expiry month and year supplied to us by our payment processor. MyRoster never receives or stores full card numbers or security codes.
- Communications, including messages, announcements, and images you send through the app, along with your notification preferences.
- Technical data, including device type and platform, app version, push notification token, IP address, sign-in times, and a log of changes made from your account.
2.How We Use Information
We use information to operate the service, which includes running registrations, rosters, schedules, messaging, and billing. We also use it to communicate with you about your account and your organization, to protect the platform against abuse, to improve the product, and to meet our legal and financial record-keeping obligations.
3.Information Sharing
MyRoster does not sell personal information and does not share it for advertising. Information is shared only in the following situations:
- With the organization you registered with. Its directors, administrators, and the coaches of the teams you or your child are assigned to can see registration, roster, schedule, and payment status information for their own organization only.
- With service providers acting on our behalf, including our payment processor (Stripe), our hosting provider, and our email and push notification delivery providers. Each may use the information only to perform that service for us.
- With legal authorities where we are required to do so by law, or where it is necessary to investigate fraud or protect the safety of users.
- With your consent, or at your direction.
4.How We Protect Your Data
We treat account credentials, payment information, children's profile information, and private messages as sensitive data. The following technical and organizational safeguards are applied to it:
- Encryption in transit. The mobile apps and the website communicate with our servers over HTTPS using TLS. The production API sends a Strict-Transport-Security header valid for one year and covering all subdomains, so browsers will not fall back to an unencrypted connection, and both mobile apps are built to reject connections that are not encrypted.
- Password protection. Passwords are hashed with bcrypt before they are stored, and are never stored, displayed, or transmitted in readable form. No member of MyRoster staff can read your password. A forgotten password is reset through a single-use link or code sent to your registered email address.
- Payment data handling. Card details are captured directly by Stripe, our PCI-DSS compliant payment processor, and are never transmitted to or stored on MyRoster servers. We retain only Stripe's token for the card together with its brand, last four digits, and expiry date, which cannot be used to charge the card outside our platform.
- Session security. Sign-in tokens are short-lived and refresh automatically. Refresh tokens are stored only as irreversible hashes, are replaced each time they are used, and any attempt to reuse a previous token revokes that session immediately. You can sign out of a single device or of all devices at any time. Sessions left inactive for 90 days expire on their own, and every session is revoked when an account is deleted or when its password is reset by an administrator.
- Access controls. Access is restricted by role and by organization, so staff of one organization cannot see another organization's data. A child's information is available only to that child's verified guardians and to the staff of the organization the child is registered with, and every request for a child's record is checked against the guardianship record before any information is returned.
- Protection against unauthorized access attempts. Repeated failed sign-in attempts temporarily lock the account and network address they came from, and our sign-in and password-reset forms are protected against automated abuse.
- Auditability. Changes made from an account are recorded in an internal activity log together with the acting user and a timestamp, and payment events are recorded in a separate audit trail, so unauthorized activity can be traced.
- Data minimization. We do not collect precise location, contacts, health, or biometric data. Children's records hold no email address, no phone number, and no sign-in credentials.
5.Data Retention
We keep personal information only for as long as it is needed for the purpose it was collected for:
- Account, profile, roster, and message data is kept while your account is active, and is removed when you delete your account.
- Payment and invoice records are kept for 7 years after the transaction in order to meet tax and financial record-keeping requirements. Card details are held by Stripe and are never stored by MyRoster.
- Records of failed sign-in attempts, used for lockout protection, are kept for 24 hours.
- Deletion is completed within 30 days of the request, and the data is purged from backups within a further 90 days.
6.Children
MyRoster is used by youth sports organizations, and a child's profile is created and managed by a parent or guardian rather than by the child. Children are not issued accounts and cannot sign in. A child's information is visible only to their guardians and to the staff of the organization the child is registered with. A guardian may review, correct, or delete their child's profile at any time from the app or by writing to us. Organizations using MyRoster are responsible for obtaining the parental permissions required in their jurisdiction.
7.Your Rights
Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal information, including information held about a child for whom you are the guardian. Write to us at info@myroster.co and we will respond within 30 days.
8.Account Deletion
You can delete your MyRoster account and all associated data at any time, from inside the app or by emailing us. See Delete Your MyRoster Account for the steps, what we delete, what we retain, and for how long.
9.Cookies
The MyRoster website uses cookies and similar technologies to keep you signed in, to remember your preferences, and to measure how the site is used. The mobile apps do not use advertising identifiers.
10.Policy Updates
We may update this Privacy Policy from time to time. Material changes will be reflected in the effective date shown above, and continued use of the service after a change signifies acceptance.
11.Contact Us
Questions about this policy, or about how your information is handled, can be sent to info@myroster.co. If you believe you have found a security vulnerability in MyRoster, please report it to the same address.
Privacy Policy
Effective Date: September 11, 2026