guestsubs.com
Privacy & Cookie Policy
What we collect, why, who can see it, and the choices you have.
← Back to homeEffective Date: October 11, 2026 · Version 2.2
Version 2.2 adds how members' share links are counted (Sections 3.6, 9 and 11).
This version replaces Version 2.0. It names the company behind the Service, adds a section on exactly who we share information with, and states two commitments about minors more plainly: no account is ever created for a Player, even after they turn 18, and Player Data never reaches recruiters or scouts.
1. Who We Are and What This Covers
BKS and Associates LLC, a Virginia limited liability company doing business as GuestPlayers.com ("guestplayers.com," "we," "us," "our"), operates the guestplayers.com website, application, and related services (the "Service"). This Policy explains what information we collect, why, how we use and share it, how long we keep it, and the choices and rights you have. We are the controller (and, where applicable, the business or operator) of the information described here.
guestplayers.com is intended solely for adults. Accounts may be held only by individuals aged 18 or older — parents and legal guardians, coaches, club administrators, and advertisers ("Members"). Youth players ("Players") do not hold accounts and are not users of the Service. Information about Players is entered by adult Members. Section 7 explains how we protect children's information, and it governs in the event of any conflict with another section.
2. Our Data Principles
- Minimization. We collect only what is reasonably necessary to provide the specific service you requested. We do not collect data "just in case."
- No sale of personal data. We do not sell personal data, and we do not sell Player Data — for money or any other consideration — under any circumstances.
- No targeted advertising involving minors' data. We do not use minors' data for targeted advertising — not Player Data, and not the personal data of anyone we know or should know is under 18. Our advertising system has no fields in which age-based targeting could even be expressed (Section 10).
- No sensitive data. We do not request, and do not permit Members to submit, sensitive categories of data about Players (Section 3.9).
- Isolation by construction. A Player's identifying record lives in a separate database with its own storage, reachable only through one audited code path — the safeguarding kernel. The public website, the advertising system, the email system, and the account system have no code route to a child's record at all.
- Purpose limitation. We use data for the purposes stated in this Policy and not for materially different purposes without notice and, where required, consent.
3. Information We Collect
3.1 Account information
When you create an account we collect your email address, a password (stored only as a salted cryptographic hash — never in plain text), your role (guardian, coach, club, or advertiser), and optionally a display name. We record the date you agreed to our Terms, your sign-in times, and failed sign-in attempts (used only to lock an account briefly after repeated failures).
You may optionally add profile details: a photograph of yourself, a headline, a biography, a general location (your town), and a phone number. All of it is optional. An account with no profile works the same way.
3.2 Player information, entered by adults
A guardian (or a coach who certifies guardian authorization — see our Terms) may enter information about a Player: name, date of birth, gender, the guardian-entered town, current team, skill level, player-card issuer, positions, GPA, graduation year, travel radius, honors, tournaments played and targeted, and two yes/no paperwork flags — whether a player card and a medical release are on file. The flags record only that a document exists. We never collect the documents themselves, and we never collect health information (Section 3.9).
Player information is stored in the isolated players database described in Section 2, together with the guardian links and consent state that control who may ever see it.
When a coach creates a Player record, the system issues a single-use claim code — a credential the guardian uses to take ownership of their child's record. Claim codes are stripped from every screen, export, and report except the claim flow itself, and are destroyed on use.
3.3 Player photographs
A guardian may optionally add a photograph of their Player. A photograph is never required to use the Service.
- A photograph is treated as identity. A coach cannot see a Player's photograph unless that Player's guardian has approved that coach's specific request. Photographs are never shown in search or matching, never public, never indexed, and never used for advertising.
- Before a photograph is stored, we strip its embedded camera metadata — EXIF, GPS coordinates, and text fields — on our server. A phone photo can carry the location where it was taken; a child's photograph must not carry a child's whereabouts. The pixels are untouched; only metadata is removed. If an image cannot be safely processed, the upload is refused rather than stored.
- Before upload, a check runs locally in the guardian's browser to catch obvious problems (wrong file type, very small images, photos that look like team shots). Nothing about the photo leaves the device during this check.
- We do not generate face templates, perform facial recognition, or derive biometric identifiers from any photograph. A photograph is not biometric data on this Service.
- A guardian may remove a photograph at any time. It is deleted immediately when the Player is deleted (Section 11).
3.4 Adult and club profiles
Profiles are visible only to signed-in Members, never to the public, and are not indexed by search engines.
- Coaches, clubs, and advertisers have a professional card: display name, headline, biography, location, photograph, email address, and phone number, visible to any signed-in Member. This is how a guardian can check who is asking about their Player before deciding.
- Guardians have a quiet card: display name and role only. A guardian's email address, phone number, and photograph are not shown on any card. A coach reaches a guardian only through the request flow the guardian controls.
- Administrator accounts are operational and have no card and no visible photograph.
You can edit or remove any part of your profile at any time. Deleting your account removes your profile and photograph with it.
3.5 Teams, squads, requests, and match records
We store organization, team, squad, and tournament information entered by Members, including a squad's coach contact details, which are shown to guardians before they decide on a request.
A guest request is born anonymized. The request record holds only status, position, paperwork flags, and an opaque reference — never the Player's name. Turning that reference into a name requires guardian approval (or an audited administrative action), and every such disclosure is permanently recorded (Section 7). Request note threads are labelled by role, not by name; please do not type a child's name into a note. Notes are redacted when a Player's record is purged.
Match statistics reference a Player only by the same opaque identifier.
3.6 Communications, feedback, and the waitlist
- Contact and feedback messages: your name, email address, and message. If you are signed in, the message is attributed to your account from your session — never from anything a sender claims in the message body.
- Our feedback form: the "Send feedback" link opens a form hosted by Google Forms. What you type there is collected and stored by Google, under Google's own terms and privacy policy, and a copy of each response is passed to our inbox so we can read it. The form asks nothing about Players; please don't include a Player's name or details in it. Our own short feedback form, below the link, stays on our systems.
- Waitlist: your email address only. Every marketing email carries a working unsubscribe link, and we honor it.
- Share links: members can share a personal link to Guest Players. When someone opens one, we count that the link was opened — nothing about the person who opened it. If they then join the waitlist or create an account, we record which member's link they came through, and keep that link's code with the waitlist entry. We use this only to understand how people find us. The member who shared the link is not told who used it, and share links never carry anything about a Player.
- Transactional email: when the Service emails you (for example, "a coach has asked about your player"), the message names your own child by first name only, to you. Subject lines never carry child data. Our sending system structurally drops full-name fields from email content, and stored copies of delivered messages are redacted 30 days after sending (Section 11).
3.7 Push notifications
Notifications are off unless you turn them on, and you can turn them off at any time. If you enable them, your browser issues us a subscription: an anonymous delivery address and two encryption keys. We store those values with your account identifier.
The content of a push notification is empty by construction. The payload contains only a request identifier — no name, no team, no event, no message text — because a notification renders on a locked screen that anyone holding the phone can read. Your device fetches the details after you sign in. Payloads are encrypted so the relaying push service (Google, Apple, Mozilla, or Microsoft, depending on your browser) cannot read them. Turning notifications off, or closing your account, deletes the subscription; dead subscriptions are removed automatically.
3.8 Billing information
Payments, where offered, are processed by Stripe or PayPal on their own systems. Card and bank details never touch our servers. We store the billing account name and email, the plan, the subscription status, and the processor's reference identifiers. The processors act under their own terms and privacy policies for the payment itself.
3.9 What we do NOT collect
We do not request, and Members are prohibited from submitting, the following about Players:
- Health, medical, mental-health, injury, or disability information (the medical flag in Section 3.2 records only that paperwork exists)
- Race, ethnicity, national origin, religion, or immigration status
- Sexual orientation or gender-identity details beyond an optional gender field
- Biometric or genetic data
- Government-issued identifiers
- Precise geolocation — and we strip the GPS coordinates a photograph may carry (Section 3.3)
- Financial account or payment card numbers
If such information is submitted despite this prohibition, we will delete it upon discovery. Our attestation screens deliberately have no free-text fields next to items like "medical release," so there is no place to type what we must not hold.
3.10 Collected automatically
We keep our measurement deliberately small:
- Cookieless usage counts. When a page loads, we record the page path, the referring site's host name, the country, and a coarse device class (mobile, tablet, or desktop). No IP address is stored, no cookie is set, no identifier is assigned, and no raw browser fingerprint is kept. These counts cannot identify you.
- Consent choices. When you make a cookie-banner choice, we record the choice and the country — nothing that identifies you.
- Request metrics. Hourly counts of requests, errors, and response times by type of traffic. They contain no personal data.
- Security and audit records. Significant actions — sign-ins, administrative changes, and every access to a child's identity — are logged with the acting account and the IP address of the action. These records protect Members and Players; the safeguarding portion is permanent by design (Section 7).
We use no third-party analytics service. There is no Google Analytics on this Service.
4. How We Use Information
We use the information above to provide and operate the Service (matching, requests, rosters, eligibility tracking); to create, authenticate, and secure accounts; to send the transactional messages the Service depends on; to understand usage through the aggregate counts in Section 3.10; to detect and prevent fraud, abuse, and security incidents; to protect the safety of Members and, above all, Players; and to comply with legal obligations and enforce our Terms.
We do not use Player Data for advertising. We do not sell Player Data. We do not use Player Data to train any AI model, ours or anyone else's.
5. Automated Processing and AI
We think you should know exactly what runs on its own, and what never will.
5.1 What is automated today
All of today's automation is deterministic — rules and schedules, no machine-learning model anywhere in the flow:
- Request expiry. A guest request that goes unanswered closes on its own after 14 days.
- Reminders. Two days before expiry, the guardian and the coach each get a nudge. The coach's copy contains no identity — they already hold only the anonymized request.
- Match notifications. When an open roster need has matching candidates, the coach is told a count and a position — "2 goalkeepers match your open need" — never a name, never a profile. Acting on it goes through the same guardian-gated request flow as everything else.
- Weekly summary. Administrators receive a digest built from counts alone: requests opened, requests rostered, mail-queue health. It never names a child.
- Housekeeping. Expired sessions are deleted, delivered email content is redacted after 30 days, deleted Player records are purged after their 30-day recovery window, and old usage counts are removed on schedule.
5.2 Photo processing
Two automated steps touch a Player's photograph, and both are described in Section 3.3: the metadata strip on our server (removing EXIF, GPS, and text data before storage, with no model and no external call) and the local pre-check that runs entirely in the guardian's browser. Neither sends the photograph anywhere.
5.3 Our commitment on AI
- Today, no AI model — hosted by us or by anyone else — processes any user data on this Service. The platform makes no calls to any AI provider.
- A child's name, photograph, date of birth, or record will never be sent to an external AI model. This is enforced as a build-time rule in our code, not a policy aspiration: the isolated players database has no code path to any model endpoint.
- No automated system on this Service issues a verdict about a child. Our eligibility engine reports individual checks and what is outstanding; it never pronounces a player "eligible," and no automated process approves a disclosure of a child's identity. People decide those things.
- If we ever add AI features, they will operate only on our own operator content or, for adult data, with clear disclosure and opt-in — and this Policy will be updated first.
6. Legal Bases (EEA/UK, if applicable)
Where the GDPR or UK GDPR applies, we rely on: contract (providing the Service you requested); consent (marketing email, waitlist communications, optional notifications — withdrawable at any time); legitimate interests (security, fraud prevention, service improvement, and protecting minors, balanced against your rights); and legal obligation (where we must retain or disclose data by law).
7. Children's and Minors' Privacy
This section governs in the event of any conflict with another section.
7.1 Our structure
- No one under 18 may create or hold an account. We do not knowingly collect personal information directly from children. The Service is not directed to children.
- A Player never "graduates" into an account. Turning 18 does not convert a Player record into an account or give anyone new access to it. An adult who wants their own account signs up separately, in their own name, with their own consent.
- Player Data is submitted by adult Members — the Player's parent or legal guardian, or a coach who has certified guardian authorization (Terms, Section 4).
- A Player's identifying record lives in an isolated database that only one audited part of our software can read. The marketing site, ads, email, and billing systems have no code route to it.
7.2 Anonymized by default, revealed by consent
A coach searching for a guest player sees an anonymized candidate: position, skill level, region (never the town), and playing history — no name, no photograph, no date of birth, no GPA. Search never matches on names. A coach sees a Player's identity only after that Player's guardian approves that coach's specific request, and a guardian can revoke a reveal at any time, which re-anonymizes the request. Every reveal, every revocation, and every administrative view of a child's record is written to a permanent safeguarding record — the proof that each disclosure was authorized.
7.3 Parental and guardian rights
A parent or legal guardian may, at any time: review the Player Data we hold about their child; correct it; delete it; refuse further collection or use; and withdraw any approval previously given to a coach. Deletion is available directly in the product. To exercise any right by request instead, contact us through the contact form with the Player's name and the club or team involved. We will verify that the requester is the Player's parent or legal guardian before acting, and respond within 30 days. There is no charge.
7.4 If a child contacts us directly
If we learn that a person under 13 has provided personal information to us directly, or that a person under 18 has created an account, we will delete the information and terminate the account promptly.
7.5 No sale, no targeted advertising, no third-party disclosure
We do not sell the personal data of any person under 18 and do not process it for targeted advertising, regardless of any consent offered. Player Data is not disclosed to third parties beyond the essential service providers in Section 8, and none of those providers ever receives more than Section 8 describes. We do not disclose Player Data to data brokers, ad networks, or analytics services — we use no third-party analytics at all.
Player Data is never surfaced to college recruiters, scouts, or professional clubs. A club's recruiting campaign on the Service advertises that club's open roster spots to adults; it contains no Player Data and cannot target a Player.
7.6 Information security program
We maintain a written information security program covering how Player Data, including photographs, is collected, used, stored, and destroyed. It names a person responsible for it, addresses the risks particular to children's data, and is reviewed at least once a year. The technical measures are in Section 12.
7.7 Retention of Player Data
Player Data is retained only while the guardian relationship stands, and deletion is real: a 30-day recovery window, then permanent destruction of the record, the photograph, and every free-text field that could carry the child's name (Section 11).
8. How We Share Information
We share personal data only with the following, and only for the purpose shown:
| Recipient | Purpose | Safeguard |
|---|---|---|
| Cloudflare (hosting, databases, and file storage) | Running the Service, storing its data and files, security, and protection against attacks | Data processing agreement; acts only on our instructions |
| Resend (email delivery) | Sending the Service's emails — invitations, password links, request notices | Data processing agreement |
| Stripe and PayPal (payments) | Processing a payment you choose to make (Section 3.8) | They handle card and bank details on their own systems |
| Your browser's push service (Google, Apple, Mozilla, or Microsoft) | Delivering a notification, only if you turn notifications on; the content is empty and encrypted (Section 3.7) | Encrypted payload |
| Google (Google Forms — our feedback form) | Collecting and storing what you choose to submit in the feedback form; a copy of each response comes to our inbox (Section 3.6) | Google's terms and privacy policy; the form asks nothing about Players |
| Microsoft 365 (our business email) | Our own team's correspondence with you — replies to support, privacy, and safety messages; never automated Service email | Data processing agreement; access limited to authorized staff |
| Other Members, as the Service works | For example, a coach's contact details shown to a guardian deciding on a request, or a Player's identity shown to a coach after that Player's guardian approves | Our Terms; the guardian controls every identity reveal (Section 7.2) |
| Professional advisors (legal, accounting) | Advice to us | Duty of confidentiality |
| Law enforcement and authorities | When the law requires it, or when we believe in good faith it is necessary to protect a minor or any person, or to investigate fraud or a breach of our Terms | Limited to what is required |
| A successor | A merger, acquisition, financing, or sale of assets | The successor is bound by this Policy for data collected under it; we will tell you of any material change |
Our service providers are contractually bound to process data only on our instructions, keep it confidential, protect it, and delete or return it when our relationship ends. We do not disclose Player Data to anyone for their own marketing, advertising, or commercial purposes, and we do not disclose it to data brokers.
9. Cookies, Local Storage, and Measurement
The Service sets one cookie: a session cookie (`gp_session`) that keeps you signed in. It is strictly necessary, lasts up to 30 days, and its value is stored on our side only as a cryptographic hash. There are no analytics cookies, no advertising cookies, no social media pixels, and no cross-site tracking of any kind. On our separate demo site, a second strictly necessary cookie (`gp_demo`) keeps an invited visitor signed in.
A few preferences are kept in your browser's local storage — your light or dark theme, your cookie-banner choice, and whether you have dismissed a tip. They stay on your device, are never sent to us, and you can clear them with your browser's site-data controls. If you arrive through a member's share link, the link's code is kept for that browser tab only (session storage, not a cookie) and sent with a waitlist signup; it is gone when you close the tab.
Our usage measurement is the cookieless counting described in Section 3.10. It sets nothing on your device and stores nothing that identifies you.
10. Advertising on the Service
The Service may show clearly labelled sponsored placements sold directly to advertisers. How they work is deliberately constrained:
- Targeting is by city only — the town on the adult viewer's own profile, if they chose to provide one. Our campaign system has no age-group, tournament, or demographic targeting fields. This is structural: the columns do not exist.
- No ad is ever shown on a screen that displays a child's record, or on a screen where an adult is deciding something about a child's safety. Ad placements are drawn from a fixed allowlist of surfaces, and the excluded screens are excluded in code.
- Every placement carries a "Sponsored" label. The label is served with the ad and cannot be removed.
- We count impressions and clicks in aggregate per advertisement — we do not record who saw or clicked anything, and no advertiser receives any information about any Member or Player.
- No third-party ad network, SDK, or tracking pixel is present on the Service.
11. Data Retention and Deletion
We keep personal data only as long as it serves the purpose it was collected for.
- Account information — until you close your account.
- Sessions — expire after 30 days; expired sessions are deleted on an hourly sweep.
- Player Data — until the guardian deletes it. Deletion hides the record immediately from everyone, including administrators; after a 30-day recovery window the record is permanently purged: identity fields destroyed, photograph deleted (the photograph is removed at deletion, not at purge), guardian links removed, request notes redacted, and email records mentioning the Player redacted at once.
- Player photographs — deleted immediately when removed by the guardian or when the Player is deleted.
- Delivered email content — redacted 30 days after sending; a content-free delivery record remains so the same notice is never sent twice.
- Push subscriptions — deleted when you turn notifications off, when your account closes, or when your browser reports them dead.
- Waitlist addresses — until you unsubscribe. We keep the unsubscribed marker so we keep honoring it.
- Share-link records — a member's link and its counts are kept while that member's account exists and deleted with it.
- Contact and feedback messages — retained while relevant to support and safety; you may ask us to delete yours.
- Usage counts and consent events — deleted after 400 days.
- Operational request metrics — aggregate counts with no personal data.
- Security and operational audit logs — retained as long as needed to secure the Service and meet legal obligations.
- Safeguarding disclosure records — permanent. This is deliberate: the record of who was authorized to see a child's identity, and when, is the proof that protects families, and it survives even the deletion of the Player it concerns. It records who looked, not the child's data itself.
- Backups — see Section 12.
Where we are legally required to retain data longer, we isolate and restrict it rather than continue to use it.
12. Security
- Encryption in transit and at rest; passwords stored only as salted, iterated hashes.
- Sign-in rate limiting and automatic lockout after repeated failures.
- One session store, hashed at rest, excluded from every administrative browse, export, and query surface.
- Deny-by-default access control. Administrative capability is granular: an owner can scope an administrator to exactly the areas their job needs, and safeguarding access is a distinct grant, not a default.
- Every access to a child's identity — including by our own administrators and moderators — is individually gated and permanently logged. A moderator opening a child's photograph is a recorded decision, not a page render.
- Backups are a deliberate act, not an automatic export. Ordinary backups exclude the players database and photographs entirely, and blank credential material by default. The complete archive — the only backup that includes child records and photographs — can be taken only by an owner, and taking one is written to the permanent safeguarding record, start and finish.
- A build-time boundary test fails our deployment if any code outside the safeguarding kernel gains a path to the players database or the photo store.
- A written information security program with an accountable owner (Section 7.6), data processing agreements with every service provider, regular review of who has access, and a documented incident-response and breach-notification process.
No system is perfectly secure and we do not promise otherwise. If a breach affects your personal data, we will notify you and any applicable regulator as required by law.
For clarity, stated once and plainly: we do not screen adults. What protects a Player here is the structure above — a coach cannot see, search, or contact a child, and identity is shared only when that child's guardian approves a specific request. Our Terms, Section 5, explains this in full.
13. Your Privacy Rights
Depending on where you live, you may have the right to know or access the personal data we hold about you, correct it, delete it, obtain a portable copy, opt out of sale or sharing for targeted advertising (we do neither), obtain a list of third-party disclosures, appeal a denial, and not be discriminated against for exercising any of these rights.
To exercise a right, use the in-product controls or the contact form. We verify identity before acting and respond within the timeframe applicable law requires (generally 45 days, extendable once where permitted). You may use an authorized agent where the law allows. If we deny a request, you may appeal by replying with the subject line "Privacy Appeal"; we respond within 45 days and will tell you how to reach your state Attorney General if you remain dissatisfied.
Virginia residents: we are based in Virginia and honor the VCDPA. We do not process any known child's data for targeted advertising, sale, or profiling in any case. Maryland residents: we commit to Maryland's stricter under-18 minimization and no-sale protections for all users regardless of residence. EEA/UK residents: you may also lodge a complaint with your supervisory authority and object to or restrict processing.
14. International Users
The Service is operated from the United States on infrastructure that may store or route data in multiple regions. If you use the Service from outside the United States, your data will be transferred to and processed in the United States.
15. Changes to This Policy
We will post any revised version with a new date and version number. For material changes — including any change to how Player Data is used or shared — we will give advance notice and, where children's data is involved, obtain any consent the law requires before the change takes effect. We will not apply material changes retroactively to previously collected data without an appropriate legal basis.
16. Contact Us
For privacy inquiries, rights requests, or a safety concern involving a minor, reach us through the contact form on this site. In an emergency, contact 911 or local law enforcement.
BKS and Associates LLC, doing business as GuestPlayers.com · Virginia, United States