Privacy

What we know about your family, and why

SoccerTrainerHQ is booking software for independent youth soccer trainers. To book a session we need to know who is playing, who to call if something happens on the field, and how to send a receipt. This page lists every field we store, names the database column it lives in, and says who can see it.

Last updated
Version
2026-08-04
  • No card numbers

    Card details are entered on Stripe’s own page and never reach our servers. We store Stripe’s reference numbers, nothing more.

  • No tracking

    No advertising pixels, no third-party scripts, no session recording, no cross-site tracking. We count events, not people: our own server tallies things like “a booking was started”, with nothing attached that identifies you. We do not sell or share personal information.

  • Your trainer sees their roster

    The trainer you book with can see your name, contact details and the medical notes you write, for their own sessions only.


Who this covers

This policy applies to soccertrainerhq.com, every trainer site we host on a subdomain of it (for example marcos.soccertrainerhq.com), and any custom domain a trainer has pointed at us. It covers three groups of people:

  • Parents and guardians who book training for a young athlete, with or without an account.
  • Athletes, who are usually minors. They do not have accounts and do not use this platform. Everything we hold about an athlete was typed in by their parent or guardian.
  • Trainers — independent coaches who use SoccerTrainerHQ to run their own booking, and who have their own account.

“We” is SoccerTrainerHQ LLC, a California limited liability company, and the data controller for everything described here. Privacy questions and any request about your data go to privacy@soccertrainerhq.com, which reaches a person rather than a queue.

What we collect when you book

Booking does not require an account. You pick a time on your trainer’s site, fill in one form, and pay. This is everything that form writes, field by field.

You type it — the bookings table

parent_nameYour name
It goes on the trainer’s roster for the session and on your receipt.
parent_emailYour email address
Where the confirmation, the reminder and any change-of-plan notice are sent. It is also the address that can later be used to sign in and see your bookings.
parent_phoneYour phone number (optional)
So the trainer can reach you about that session. Optional, and left blank if you leave it blank.
athlete_nameThe player’s name
The trainer needs to know who is turning up. It appears on the roster they take onto the field.
athlete_birth_yearThe player’s birth year — the year only
US youth soccer groups by birth year, not age. It powers the “this session is for 2013–2015” fit warning. We deliberately do not ask for a date of birth: the year answers the question and is the less sensitive thing to hold.
emergency_contact_nameEmergency contact name
Who the trainer calls if something happens at training and you are not reachable.
emergency_contact_phoneEmergency contact phone
Same reason. Visible to the trainer running that session.
medical_notesAnything the trainer needs to know — free text
Asthma, an inhaler in the bag, a healing ankle, an allergy. This is health information about a child and it is treated as the most sensitive field on the platform. Write only what a coach needs on a field; it is not a medical record and we are not a healthcare provider.
photo_releaseYes or no to photos
A separate opt-in. It defaults to no and it is never bundled into the waiver. See “Photos and video” below.
marketing_opt_inYes or no to non-essential email
Defaults to no. Booking confirmations and reminders are not marketing and are sent either way.
sms_consent · sms_consent_atYes or no to text messages, and when you said so
Recorded at checkout. We do not currently send any text messages — see “Email and text messages”.

The system writes it — also on the bookings table

waiver_signed_name · waiver_accepted_at · waiver_version · waiver_ipThe waiver record
The name you typed, the moment you agreed, which wording you agreed to, and the IP address the agreement came from. This is evidence of consent, so it is kept even after a booking is cancelled. See “The waiver record”.
display_cents · net_cents · platform_fee_centsWhat you paid, what the trainer keeps, what we keep
The price is fixed at the moment of booking so a later price change cannot alter what you were charged, and so refunds are computed from the real numbers.
stripe_checkout_session_id · stripe_payment_intent_idStripe’s reference numbers for the payment
These are pointers into Stripe, not payment details. They are how a refund is issued and how a receipt is matched to a booking. No card number, expiry or CVC is ever stored by us.
source · referrer_hostRoughly where you came from
Whether you arrived from the trainer’s Instagram, a shared link, or typed the address in. The website domain only — never a browsing history, and never a third-party tracker.
status · hold_expires_at · free_cancel_until · cancelled_atThe state of the booking
Whether the seat is held, paid, or cancelled, and by when you can still cancel for a full refund.
confirmation_sent_at · reminder_sent_atWhen we emailed you
So the same confirmation is never sent twice and a missing one can be re-sent.

Camp registrations are the same shape and are stored the same way, on camp_registrations: parent contact details, athlete name and birth year, emergency contact, medical notes, and the waiver record.

If you create an account

You never need an account to book. An account is offered after a booking is paid for, and its only purpose is that the second booking is two taps instead of a form. Signing in is a one-time link sent to the email address that already paid — we do not ask for or store a password.

If you save a player, that becomes a row on athletes, owned by you:

name · birth_yearThe player’s name and birth year
So you do not retype them. Year only, for the same reason as above.
medical_notes · emergency_contact_name · emergency_contact_phoneCarried forward from a booking
Editable by you at any time. Changing them here changes what is pre-filled next time; it does not rewrite a booking that already happened.
photo_releasePhoto permission for this player
Still separate, still defaults to no.
waiver_version · waiver_accepted_atWhich waiver wording you signed for this player, and when
Signing once per player, rather than once per booking, is the entire point of the record. You are asked again only when the wording actually changes. Neither field can be written from a browser — they are set by the server, with the server’s clock.

Deleting a saved player does not delete a booking

You can delete a saved player from your account at any time, and it is gone. The bookings that player already had are not deleted: each one carries its own copy of the name, birth year and waiver record from the moment it was paid for. Those records are the trainer’s roster, the receipt, and the evidence of what was agreed — see “How long we keep things”.

Apparel pre-orders

Some trainers run pre-order windows for kit, collected at training. If you order, we store your name, email and phone on apparel_orders, along with the player’s name, the amounts, and Stripe’s reference numbers — plus policy_version, policy_accepted_at, policy_ip and policy_user_agent, which record that the non-refundable pre-order terms were shown to you and accepted before payment.

If you personalise an item, the name and number you asked to have put on it are stored on the order line as custom_name and custom_number. That is usually a child’s name, printed on a garment, so it is treated as athlete information like the rest.

There is no shipping address, because there is no shipping — kit is handed over at training.

Information about trainers

A trainer’s public page carries what they chose to put on it: name, photo, bio, Instagram handle, session prices and times. Their account also holds an email address and phone number, a Stripe account identifier for payouts, and any documents they have given us about background checks, SafeSport certification or insurance — background_check_status, background_check_expires_at, safesport_cert_url, insurance_expires_at.

What those trust fields do and do not mean

Those columns record what a trainer told us and what they sent us. We do not run background checks and we do not independently verify any of it. If a trainer’s page says “background check on file”, that means a document was provided and a status was recorded by hand — not that SoccerTrainerHQ has vetted that person. This is stated the same way in the terms of service, and it is the most important sentence on either page.

What we do not collect

It is easier to trust a list of fields when you can also see what is absent. As of 4 August 2026, we do not collect:

  • Card numbers, expiry dates or security codes. Those are typed on Stripe’s own checkout page and never touch our servers.
  • Dates of birth. Only the athlete’s birth year, because that is what youth soccer age groups are actually built on.
  • Home addresses. There is no address field anywhere in the booking flow, and no shipping.
  • Government identifiers — no social security numbers, no driver’s licences, no passport details. Trainers taking payouts provide identity information directly to Stripe; it does not come to us.
  • Precise location. We never ask the browser for your location. The only addresses on the platform are the training fields the trainer typed in.
  • Photographs you upload. There is no photo upload for parents or athletes anywhere on the platform.
  • Anything from an advertising network, data broker or social login. There are none connected.

Children and athlete information

Almost every athlete on this platform is a minor, and we hold their name, birth year and — if you write them — notes about their health. That deserves a direct answer rather than a paragraph of hedging.

The platform is not directed at children

SoccerTrainerHQ is built for the adult who books and pays. There is no athlete login, no athlete profile a child can create, no messaging, no social feed, no content aimed at children, and no advertising anywhere on the platform. Accounts may only be held by adults aged 18 or over. We do not knowingly collect personal information directly from a child under 13.

The parent supplies the athlete’s information

Everything we hold about an athlete was entered by their parent or guardian, in the course of that adult booking a service for their own child. When you book, you are confirming that you are the athlete’s parent or legal guardian, or that you have their permission to make the booking and to provide this information.

What we do with it, and what we never do

  • Athlete information is used to run the session that was booked: the roster, the age-group fit warning, and the emergency contact if something happens on the field.
  • It is never used for advertising or profiling, never sold, never shared with a data broker, and never disclosed to anyone outside the trainer you booked with and the infrastructure providers named below.
  • We ask for the minimum that makes the feature work — the birth year rather than a date of birth is the clearest example of that choice being made deliberately.

What we are not claiming

We are describing how the product is built, not certifying ourselves against COPPA or any other statute. If you believe a child under 13 has provided information to us directly, email privacy@soccertrainerhq.com and we will delete it. Our approach to children’s data is one of the items explicitly queued for attorney review before launch.

Who is responsible: us and your trainer

This matters more here than on most platforms, because the person you are booking with does not work for us.

  • Trainers are independent contractors. They set their own prices, times and locations, run their own sessions, and are paid out to their own bank accounts. They are not our employees or agents.
  • The trainer you book with can see their own roster. That means your name, email, phone, the athlete’s name and birth year, your emergency contact and the medical notes you wrote — for their own sessions, and no one else’s. That is not a leak; it is the point. A coach who cannot see that a player carries an inhaler cannot keep that player safe.
  • No trainer can see another trainer’s bookings. This is enforced in the database itself rather than in application code, by row-level security policies scoped to the owning trainer.

Legally, we and your trainer each decide how the information is used — we for running the platform, they for delivering the coaching. Each of us is responsible for our own handling of it. What your trainer does with your details outside SoccerTrainerHQ — a group chat, a team spreadsheet, their own phone — is between you and them, and we cannot control it.

Being straight about a gap

There is no signed data-protection agreement between us and each trainer today. Trainer obligations are stated in the terms of service they accept. Whether that is sufficient, and whether a separate agreement is required, is an open question flagged for our attorney.

Payments and card details

Payments run through Stripe. When you pay, you are on a checkout page hosted by Stripe on Stripe’s own domain. Your card details go to Stripe, not to us. We never see, receive or store a card number, and there is nowhere in our database for one to go.

What comes back to us is Stripe’s reference for the payment, the amount, and whether it succeeded. That is enough to send a receipt, show your booking, and issue a refund.

Today the charge is created on SoccerTrainerHQ’s Stripe account and the trainer’s share is transferred to theirs, which is why SOCCERTRAINERHQ — not the trainer’s name — is what appears on your card statement. If that changes so that the trainer becomes the merchant of record, this page will be updated before it does.

Stripe handles your payment information under its own privacy policy, as an independent controller of it: stripe.com/privacy.

Who else touches your data

Four companies. That is the whole list, and each one is here because the product cannot run without it.

StripePayments, refunds and trainer payouts
Receives your name, email and the amount. Receives your card details directly from your browser. We do not.
SupabaseThe database and sign-in links
Everything described on this page is stored in a Postgres database operated by Supabase, and the one-time sign-in emails are issued through it.
ResendTransactional email
Sends your booking confirmation, your reminder, and any notice that a trainer changed the time or the field. Receives your email address and the contents of those messages.
VercelHosting
Serves the site. Request logs, which include IP addresses, pass through Vercel’s infrastructure as part of that.

We may also disclose information if the law requires it — a subpoena, a court order, a lawful request from an authority — or where it is necessary to investigate fraud, to protect someone’s safety, or to establish or defend a legal claim. If the business is ever sold or merged, records would transfer with it, and this policy would continue to apply to them until it is replaced by one you are told about.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is no advertising on this platform.

Cookies and local storage

There is no cookie banner on this site, for the simple reason that there is nothing to consent to. We run no advertising pixels, no session recording, no A/B testing tools and no third-party scripts of any kind. Even the typefaces are served from our own domain rather than fetched from Google, so loading a page does not tell anyone else that you did.

We do count, and we would rather say so plainly. Our own server keeps a tally of things that happen — a directory search, a booking started, a payment completed — because otherwise we cannot tell whether the product works. That tally is described in full below. It uses no cookie, sets nothing on your device, contacts no third party, and carries nothing that identifies you.

These are the cookies that exist:

sb-…-auth-tokenYour sign-in session
Set by Supabase only once you sign in, and only so you stay signed in. Strictly necessary. If you never create an account, this cookie never exists.
sthq_srcWhere you arrived from
A first-party cookie read when a booking is created, so a trainer can tell whether a booking came from their Instagram, a shared link, or our directory. It is set only when you arrive on a link carrying a ?src= tag, holds one of five fixed words rather than an identity, is written once and never overwritten, and lasts 30 days.

During checkout you are on Stripe’s domain, where Stripe sets its own cookies for fraud prevention under its own policy. We have no access to them.

What we count, and why it is not tracking

When something happens that tells us whether the product is working — somebody searched the directory, a search found nobody, a booking was started, a payment went through, a trainer published a month — our server writes one row to a table called funnel_events. It is written by us, on our own machine, after the fact. Nothing runs in your browser to make it happen.

The complete row — funnel_events

eventWhich of about fifteen fixed words happened
For example “booking_started” or “directory_zero_results”. The list is fixed in the database itself, so a new kind of measurement cannot be added quietly.
occurred_atWhen it happened
A timestamp. We report these by week.
coach_idWhich trainer it concerned, if any
A trainer is a business we have a contract with, not a member of the public, and they can see their own numbers. Blank for anything that happened before a trainer was involved, such as a directory search.
sourceRoughly where the visit came from
One of a handful of fixed words — “directory”, “instagram”, “direct” — or a trainer’s own campaign tag. Capped at 40 characters so it cannot become a hidden identifier.

There is no column for you

That table has no name, no email, no IP address, no user agent, no device or session identifier, no booking or player reference, and no cookie — not blanked out, not hashed, simply not present. Two bookings by the same family are indistinguishable from two bookings by two families, deliberately. That is the difference between counting events and tracking people, and it is why there is nothing here to show you, correct or delete on request: no row is about you. Requests from automated traffic — search-engine crawlers, and the browser quietly pre-loading a page you have not clicked — are excluded before they are counted, and the user agent used to make that judgement is discarded rather than stored.

Because none of this is tracking, there is no separate cookie policy page and no consent tool to configure — the two cookies above are the complete inventory. If that ever changes, this section changes with it and it will not be a quiet edit.

Messages: in-app, email and text

You can message your trainer inside the product. If you do, we ask your name once — it is stored as parent_profiles.display_name, and it is what the trainer sees on the conversation. The messages themselves live in conversation_messages, visible only to you and that trainer. A trainer can also open a session group for a session your athlete has a confirmed booking on; messages there (group_thread_messages) are visible to the trainer and to every family with a confirmed booking on that same session — the screen says so where you type. Each new message triggers one email notification to the other side.

Messages are deleted automatically after 30 days. A conversation here is for arranging this month’s sessions, not a permanent transcript, and nothing in the product can edit or delete a message earlier — not us, not the trainer. If you need a record of something agreed in a message, keep the email notification.

Transactional email always sends. A booking confirmation, a reminder before the session, and a notice if the trainer moves the time or the field are part of the service you paid for, not marketing, and there is no opt-out for them short of cancelling the booking.

Marketing email is off unless you turn it on. marketing_opt_in defaults to false and is only true if you ticked the box.

We do not send text messages. The checkout records whether you agreed to receive them — sms_consent and sms_consent_at — but no messaging provider is connected and no SMS has ever been sent from this platform. Saying so plainly seems better than implying a service that does not exist.

Photos and video

photo_release is a separate question with its own checkbox, it defaults to no, and it is deliberately never bundled into the liability waiver. Agreeing to the waiver does not agree to photographs.

If you do opt in, you are giving the trainer permission to use images of your athlete from their sessions in their own promotion. The permission runs to your trainer. To withdraw it, tell your trainer and email privacy@soccertrainerhq.com so the flag is turned off; note that a photo already published somewhere else is not something we can reach.

Reviews you write

After a paid session has happened, you can rate it and write a few sentences. A review is public: it appears on the trainer's site and on their marketplace card, immediately, with no approval step, and anyone can read it.

ratingYour 1–5 star score
Shown publicly, and averaged into the stars on the trainer’s card.
bodyThe words you wrote, if any
Shown publicly, exactly as written. Do not include your child’s full name or anything you would not put on a noticeboard.
parent_display_nameYour first name and last initial — “Sarah M.”
Derived from the name on the booking at the moment you post. Your full name is never published, and neither is your email.
booking_idWhich booking the review belongs to
Every review is tied to one paid, completed session — that is what makes the stars mean something. This link is stored but never publicly readable, so a review cannot be traced back to your family’s booking by anyone reading the site.
coach_replyThe trainer’s one public reply, if they write one
A trainer may respond once, publicly, under your review. They cannot edit your words, and they cannot remove the review.

A review taken down for abuse is hidden, not deleted — the record survives (with the reason) but stops being shown. Reviews are never taken down for being unflattering; a trainer cannot pay or ask to have honest criticism removed. If you want your own review removed or corrected, email privacy@soccertrainerhq.com from the address you booked with — your own words are yours, and we hide them on your request.

The waiver record

When you accept the liability waiver at checkout, four things are written down: the name you typed (waiver_signed_name), the moment you accepted (waiver_accepted_at), the IP address it came from (waiver_ip), and — the important one — which version of the wording you agreed to (waiver_version).

The version string exists so that “what did this family actually agree to?” has exactly one answer years later. The waiver text is published on this site with its version number, and when the wording changes the version changes rather than the old text being edited. A record that points at wording nobody can produce is not a record.

Because it is evidence, the waiver record is kept even when the booking it belongs to is cancelled or refunded, and it is not deleted on request while a claim connected to that session could still be brought.

How long we keep things

Honestly: almost nothing is deleted automatically. As of August 2026 exactly one retention rule runs on a schedule — messages, below — and for everything else, no such job has been written. Saying “we keep data for 24 months” would be describing software that does not exist. Here is what is actually true, and what governs it.

  • Messages between you and a trainer are deleted after 30 days — the one scheduled deletion that exists. A daily job removes every in-app message (1:1 and session-group alike) older than 30 days, and it is deliberately the only thing in the system able to delete one.
  • Bookings, camp registrations and apparel orders are kept indefinitely for now. They are financial records. They are needed for tax filings, for responding to a card dispute or chargeback, and for resolving an argument about what was booked and what was refunded. A cancellation does not erase them — a refunded booking is a transaction that has to remain accounted for.
  • Waiver records are kept longer than the booking would otherwise need. A claim relating to an injury to a minor can be brought long after the session, so the evidence of what was agreed has to outlive the session by a wide margin.
  • Medical notes ride along with the booking they were written on. This is the field we would most like to age out automatically, and a retention rule for it is on the list.
  • A saved player is deleted when you delete it. That is the one deletion the product performs itself, and it is immediate.
  • The event counters are kept indefinitely, and there is nothing in them to delete. The funnel_events rows described under “Cookies and local storage” identify nobody, so ageing them out would protect no one — it would only destroy the record of whether this business works. If a row ever carried anything about a person, it would need a retention rule, and it would need this sentence rewritten.
  • Trainer records are kept while the account is open and afterwards to the extent the bookings taken through it require.

This is on the list, not finished

Defined retention periods — and a job that enforces them — are outstanding work, flagged in LEGAL-REVIEW.md for our attorney to set the numbers before launch. We would rather publish that sentence than a period we are not actually keeping to.

How it is protected

What is genuinely in place:

  • Bookings are never written or read from a browser. Every write goes through server code holding a privileged key; the public key a browser carries has no permission to read a bookings row at all.
  • Access rules live in the database, not in the app.Row-level security policies mean a trainer’s query for someone else’s roster returns nothing — even if application code asked for it.
  • Money columns cannot be edited from a browser by anyone, including the trainer whose row it is.
  • No passwords. Signing in is a one-time link to an email address, so there is no password of yours for us to store or leak.
  • No card data anywhere in our systems, by design.
  • Everything is served over HTTPS.

What is not in place: we have no SOC 2 report, no penetration test, no bug bounty, and no formal incident response plan written down. We are a small early-stage business and pretending otherwise would be the first untrue sentence on this page. If a breach affecting your information occurs, we will notify you and the authorities as required by California law.

Your choices, and what is built today

Things you can do yourself, right now:

  • See your bookings — sign in at soccertrainerhq.com/parents with the email address that paid.
  • Cancel a booking within the cancellation window, and get your money back in full — or, with a deposit trainer, get the exact amount shown when you booked. The rules are in the terms.
  • Edit or delete a saved player, including their medical notes, from your account.
  • Leave the marketing box unticked, which is the default.

Things that are not built, and how they are handled instead:

  • There is no self-serve data export. Email us and we will put together what we hold about you.
  • There is no self-serve account deletion. Email us and we will do it, subject to the records we are required to keep.
  • There is no way to correct a booking after payment. Email us or your trainer.

Every request goes to privacy@soccertrainerhq.com. We will confirm receipt within 10 days and respond within 45 days, extendable once by a further 45 days if a request is complicated, which is the California standard and the one we apply to everybody.

California privacy rights

The business is based in California, and most of the families using it are too. Under the California Consumer Privacy Act as amended by the CPRA, you have the right to know what is collected and why, to get a copy of it, to correct it, to delete it, to opt out of its sale or sharing, to limit the use of sensitive personal information, and not to be treated worse for exercising any of that.

The categories, in the statute’s language

IdentifiersName, email address, phone number, IP address
Collected from you at booking, and from your browser in server logs. Used to run and confirm the booking. Disclosed to your trainer, and to the providers named above.
Customer recordsName and contact details tied to a paid transaction
Same sources, same purpose. Retained as a financial record.
Commercial informationSessions and kit you have bought
Generated by using the service. Used for receipts, rosters, refunds and accounting.
Publicly available reviewsA rating, optional text, and your first name with last initial, if you post a review
Provided by you, published at your direction on the trainer’s public site. Hidden on your request — see the reviews section above.
Internet activityThe referring website and standard server log data
Limited to the site you came from and ordinary request logs. No browsing history, no cross-site tracking. The event counters described under “Cookies and local storage” are listed here for completeness only — they are not linked to you or to any identifier, so they are not personal information about anyone.
Sensitive personal informationHealth information in medical_notes, about a minor
Collected from you, used only to deliver the session safely and disclosed only to the trainer running it. Not used to infer characteristics about anyone, and never used for advertising.

Sale, sharing, and sensitive information

  • We have not sold personal information in the preceding twelve months, and we do not sell it now.
  • We have not shared personal information for cross-context behavioural advertising in the preceding twelve months, and we do not now. There is no advertising technology on this platform, which is why there is no “Do Not Sell or Share My Personal Information” link — there is nothing for it to switch off.
  • We do not use or disclose sensitive personal information for any purpose beyond performing the service you asked for, so the right to limit its use does not currently restrict anything we do.
  • We do not knowingly sell or share the personal information of consumers under 16.
  • We offer no financial incentives in exchange for personal information.

How to exercise a right

Email privacy@soccertrainerhq.com from the address you booked with, or tell us which address the booking used. We verify a request by confirming control of that email address, and for a deletion request we may ask for one additional detail that matches the booking. An authorised agent may act for you with written permission that we can check with you directly. Making a request costs nothing and changes nothing about the service you receive.

Requests about an athlete are made by their parent or guardian — the adult who holds the booking — which is the same person the account belongs to.

If you are outside California

The service is aimed at families in the United States and the data is stored in the United States. Several other states now give residents similar rights, and rather than run a different process for each one, we handle every request we receive the same way — the one described above.

We are not currently set up for the European Union or the United Kingdom, and this policy does not attempt to describe GDPR compliance. If you are booking from outside the US, understand that your information will be stored and handled in the US.

Changes to this policy

When this page changes, the date and version at the top change with it. If a change materially affects what we collect or who sees it, we will say so by email to the address on your most recent booking rather than quietly editing the page. The waiver is versioned separately and works the same way — see the waiver.

Contact

Anything at all about this page, about what we hold, or about a request to see, correct or delete it: privacy@soccertrainerhq.com.

For a question about a specific session — what to bring, where the field is, whether it is cancelled for rain — your trainer is the faster answer, and their details are on the confirmation email.

The registered business name and mailing address will be printed here before launch.

Privacy policy · SoccerTrainerHQ