guestsubs.com

guestsubs.com

Privacy & Cookie Policy

What we collect, why, who can see it, and the choices you have.

← Back to home

Effective Date: October 11, 2026 · Version 2.2

Version 2.2 adds how members' share links are counted (Sections 3.6, 9 and 11).

This version replaces Version 2.0. It names the company behind the Service, adds a section on exactly who we share information with, and states two commitments about minors more plainly: no account is ever created for a Player, even after they turn 18, and Player Data never reaches recruiters or scouts.

1. Who We Are and What This Covers

BKS and Associates LLC, a Virginia limited liability company doing business as GuestPlayers.com ("guestplayers.com," "we," "us," "our"), operates the guestplayers.com website, application, and related services (the "Service"). This Policy explains what information we collect, why, how we use and share it, how long we keep it, and the choices and rights you have. We are the controller (and, where applicable, the business or operator) of the information described here.

guestplayers.com is intended solely for adults. Accounts may be held only by individuals aged 18 or older — parents and legal guardians, coaches, club administrators, and advertisers ("Members"). Youth players ("Players") do not hold accounts and are not users of the Service. Information about Players is entered by adult Members. Section 7 explains how we protect children's information, and it governs in the event of any conflict with another section.

2. Our Data Principles

3. Information We Collect

3.1 Account information

When you create an account we collect your email address, a password (stored only as a salted cryptographic hash — never in plain text), your role (guardian, coach, club, or advertiser), and optionally a display name. We record the date you agreed to our Terms, your sign-in times, and failed sign-in attempts (used only to lock an account briefly after repeated failures).

You may optionally add profile details: a photograph of yourself, a headline, a biography, a general location (your town), and a phone number. All of it is optional. An account with no profile works the same way.

3.2 Player information, entered by adults

A guardian (or a coach who certifies guardian authorization — see our Terms) may enter information about a Player: name, date of birth, gender, the guardian-entered town, current team, skill level, player-card issuer, positions, GPA, graduation year, travel radius, honors, tournaments played and targeted, and two yes/no paperwork flags — whether a player card and a medical release are on file. The flags record only that a document exists. We never collect the documents themselves, and we never collect health information (Section 3.9).

Player information is stored in the isolated players database described in Section 2, together with the guardian links and consent state that control who may ever see it.

When a coach creates a Player record, the system issues a single-use claim code — a credential the guardian uses to take ownership of their child's record. Claim codes are stripped from every screen, export, and report except the claim flow itself, and are destroyed on use.

3.3 Player photographs

A guardian may optionally add a photograph of their Player. A photograph is never required to use the Service.

3.4 Adult and club profiles

Profiles are visible only to signed-in Members, never to the public, and are not indexed by search engines.

You can edit or remove any part of your profile at any time. Deleting your account removes your profile and photograph with it.

3.5 Teams, squads, requests, and match records

We store organization, team, squad, and tournament information entered by Members, including a squad's coach contact details, which are shown to guardians before they decide on a request.

A guest request is born anonymized. The request record holds only status, position, paperwork flags, and an opaque reference — never the Player's name. Turning that reference into a name requires guardian approval (or an audited administrative action), and every such disclosure is permanently recorded (Section 7). Request note threads are labelled by role, not by name; please do not type a child's name into a note. Notes are redacted when a Player's record is purged.

Match statistics reference a Player only by the same opaque identifier.

3.6 Communications, feedback, and the waitlist

3.7 Push notifications

Notifications are off unless you turn them on, and you can turn them off at any time. If you enable them, your browser issues us a subscription: an anonymous delivery address and two encryption keys. We store those values with your account identifier.

The content of a push notification is empty by construction. The payload contains only a request identifier — no name, no team, no event, no message text — because a notification renders on a locked screen that anyone holding the phone can read. Your device fetches the details after you sign in. Payloads are encrypted so the relaying push service (Google, Apple, Mozilla, or Microsoft, depending on your browser) cannot read them. Turning notifications off, or closing your account, deletes the subscription; dead subscriptions are removed automatically.

3.8 Billing information

Payments, where offered, are processed by Stripe or PayPal on their own systems. Card and bank details never touch our servers. We store the billing account name and email, the plan, the subscription status, and the processor's reference identifiers. The processors act under their own terms and privacy policies for the payment itself.

3.9 What we do NOT collect

We do not request, and Members are prohibited from submitting, the following about Players:

If such information is submitted despite this prohibition, we will delete it upon discovery. Our attestation screens deliberately have no free-text fields next to items like "medical release," so there is no place to type what we must not hold.

3.10 Collected automatically

We keep our measurement deliberately small:

We use no third-party analytics service. There is no Google Analytics on this Service.

4. How We Use Information

We use the information above to provide and operate the Service (matching, requests, rosters, eligibility tracking); to create, authenticate, and secure accounts; to send the transactional messages the Service depends on; to understand usage through the aggregate counts in Section 3.10; to detect and prevent fraud, abuse, and security incidents; to protect the safety of Members and, above all, Players; and to comply with legal obligations and enforce our Terms.

We do not use Player Data for advertising. We do not sell Player Data. We do not use Player Data to train any AI model, ours or anyone else's.

5. Automated Processing and AI

We think you should know exactly what runs on its own, and what never will.

5.1 What is automated today

All of today's automation is deterministic — rules and schedules, no machine-learning model anywhere in the flow:

5.2 Photo processing

Two automated steps touch a Player's photograph, and both are described in Section 3.3: the metadata strip on our server (removing EXIF, GPS, and text data before storage, with no model and no external call) and the local pre-check that runs entirely in the guardian's browser. Neither sends the photograph anywhere.

5.3 Our commitment on AI

6. Legal Bases (EEA/UK, if applicable)

Where the GDPR or UK GDPR applies, we rely on: contract (providing the Service you requested); consent (marketing email, waitlist communications, optional notifications — withdrawable at any time); legitimate interests (security, fraud prevention, service improvement, and protecting minors, balanced against your rights); and legal obligation (where we must retain or disclose data by law).

7. Children's and Minors' Privacy

This section governs in the event of any conflict with another section.

7.1 Our structure

7.2 Anonymized by default, revealed by consent

A coach searching for a guest player sees an anonymized candidate: position, skill level, region (never the town), and playing history — no name, no photograph, no date of birth, no GPA. Search never matches on names. A coach sees a Player's identity only after that Player's guardian approves that coach's specific request, and a guardian can revoke a reveal at any time, which re-anonymizes the request. Every reveal, every revocation, and every administrative view of a child's record is written to a permanent safeguarding record — the proof that each disclosure was authorized.

7.3 Parental and guardian rights

A parent or legal guardian may, at any time: review the Player Data we hold about their child; correct it; delete it; refuse further collection or use; and withdraw any approval previously given to a coach. Deletion is available directly in the product. To exercise any right by request instead, contact us through the contact form with the Player's name and the club or team involved. We will verify that the requester is the Player's parent or legal guardian before acting, and respond within 30 days. There is no charge.

7.4 If a child contacts us directly

If we learn that a person under 13 has provided personal information to us directly, or that a person under 18 has created an account, we will delete the information and terminate the account promptly.

7.5 No sale, no targeted advertising, no third-party disclosure

We do not sell the personal data of any person under 18 and do not process it for targeted advertising, regardless of any consent offered. Player Data is not disclosed to third parties beyond the essential service providers in Section 8, and none of those providers ever receives more than Section 8 describes. We do not disclose Player Data to data brokers, ad networks, or analytics services — we use no third-party analytics at all.

Player Data is never surfaced to college recruiters, scouts, or professional clubs. A club's recruiting campaign on the Service advertises that club's open roster spots to adults; it contains no Player Data and cannot target a Player.

7.6 Information security program

We maintain a written information security program covering how Player Data, including photographs, is collected, used, stored, and destroyed. It names a person responsible for it, addresses the risks particular to children's data, and is reviewed at least once a year. The technical measures are in Section 12.

7.7 Retention of Player Data

Player Data is retained only while the guardian relationship stands, and deletion is real: a 30-day recovery window, then permanent destruction of the record, the photograph, and every free-text field that could carry the child's name (Section 11).

8. How We Share Information

We share personal data only with the following, and only for the purpose shown:

| Recipient | Purpose | Safeguard |
|---|---|---|
| Cloudflare (hosting, databases, and file storage) | Running the Service, storing its data and files, security, and protection against attacks | Data processing agreement; acts only on our instructions |
| Resend (email delivery) | Sending the Service's emails — invitations, password links, request notices | Data processing agreement |
| Stripe and PayPal (payments) | Processing a payment you choose to make (Section 3.8) | They handle card and bank details on their own systems |
| Your browser's push service (Google, Apple, Mozilla, or Microsoft) | Delivering a notification, only if you turn notifications on; the content is empty and encrypted (Section 3.7) | Encrypted payload |
| Google (Google Forms — our feedback form) | Collecting and storing what you choose to submit in the feedback form; a copy of each response comes to our inbox (Section 3.6) | Google's terms and privacy policy; the form asks nothing about Players |
| Microsoft 365 (our business email) | Our own team's correspondence with you — replies to support, privacy, and safety messages; never automated Service email | Data processing agreement; access limited to authorized staff |
| Other Members, as the Service works | For example, a coach's contact details shown to a guardian deciding on a request, or a Player's identity shown to a coach after that Player's guardian approves | Our Terms; the guardian controls every identity reveal (Section 7.2) |
| Professional advisors (legal, accounting) | Advice to us | Duty of confidentiality |
| Law enforcement and authorities | When the law requires it, or when we believe in good faith it is necessary to protect a minor or any person, or to investigate fraud or a breach of our Terms | Limited to what is required |
| A successor | A merger, acquisition, financing, or sale of assets | The successor is bound by this Policy for data collected under it; we will tell you of any material change |

Our service providers are contractually bound to process data only on our instructions, keep it confidential, protect it, and delete or return it when our relationship ends. We do not disclose Player Data to anyone for their own marketing, advertising, or commercial purposes, and we do not disclose it to data brokers.

9. Cookies, Local Storage, and Measurement

The Service sets one cookie: a session cookie (`gp_session`) that keeps you signed in. It is strictly necessary, lasts up to 30 days, and its value is stored on our side only as a cryptographic hash. There are no analytics cookies, no advertising cookies, no social media pixels, and no cross-site tracking of any kind. On our separate demo site, a second strictly necessary cookie (`gp_demo`) keeps an invited visitor signed in.

A few preferences are kept in your browser's local storage — your light or dark theme, your cookie-banner choice, and whether you have dismissed a tip. They stay on your device, are never sent to us, and you can clear them with your browser's site-data controls. If you arrive through a member's share link, the link's code is kept for that browser tab only (session storage, not a cookie) and sent with a waitlist signup; it is gone when you close the tab.

Our usage measurement is the cookieless counting described in Section 3.10. It sets nothing on your device and stores nothing that identifies you.

We honor the Global Privacy Control. Because we do not sell data or share it for targeted advertising, there is nothing for the signal to switch off — but we record the preference and respect what it stands for.

10. Advertising on the Service

The Service may show clearly labelled sponsored placements sold directly to advertisers. How they work is deliberately constrained:

11. Data Retention and Deletion

We keep personal data only as long as it serves the purpose it was collected for.

Where we are legally required to retain data longer, we isolate and restrict it rather than continue to use it.

12. Security

No system is perfectly secure and we do not promise otherwise. If a breach affects your personal data, we will notify you and any applicable regulator as required by law.

For clarity, stated once and plainly: we do not screen adults. What protects a Player here is the structure above — a coach cannot see, search, or contact a child, and identity is shared only when that child's guardian approves a specific request. Our Terms, Section 5, explains this in full.

13. Your Privacy Rights

Depending on where you live, you may have the right to know or access the personal data we hold about you, correct it, delete it, obtain a portable copy, opt out of sale or sharing for targeted advertising (we do neither), obtain a list of third-party disclosures, appeal a denial, and not be discriminated against for exercising any of these rights.

To exercise a right, use the in-product controls or the contact form. We verify identity before acting and respond within the timeframe applicable law requires (generally 45 days, extendable once where permitted). You may use an authorized agent where the law allows. If we deny a request, you may appeal by replying with the subject line "Privacy Appeal"; we respond within 45 days and will tell you how to reach your state Attorney General if you remain dissatisfied.

Virginia residents: we are based in Virginia and honor the VCDPA. We do not process any known child's data for targeted advertising, sale, or profiling in any case. Maryland residents: we commit to Maryland's stricter under-18 minimization and no-sale protections for all users regardless of residence. EEA/UK residents: you may also lodge a complaint with your supervisory authority and object to or restrict processing.

14. International Users

The Service is operated from the United States on infrastructure that may store or route data in multiple regions. If you use the Service from outside the United States, your data will be transferred to and processed in the United States.

15. Changes to This Policy

We will post any revised version with a new date and version number. For material changes — including any change to how Player Data is used or shared — we will give advance notice and, where children's data is involved, obtain any consent the law requires before the change takes effect. We will not apply material changes retroactively to previously collected data without an appropriate legal basis.

16. Contact Us

For privacy inquiries, rights requests, or a safety concern involving a minor, reach us through the contact form on this site. In an emergency, contact 911 or local law enforcement.

BKS and Associates LLC, doing business as GuestPlayers.com · Virginia, United States