Your information

Privacy Policy

This policy explains what Softball-League handles, why we handle it, who can see it, and the choices available to you.

Effective and last updated:

1. Scope and who is responsible

This policy applies to the Softball-League website, public league sites, team and administration portals, and the Softball League Broadcast apps for iOS and Android (together, the Service). The Service is operated by SJSR Labs, which can be reached using the details at the end of this policy.

A participating league controls many of the records it enters, including rosters, schedules, eligibility information, statistics, documents, and media. League administrators decide which authorized people may use those records and which league information is public. SJSR Labs hosts and processes that information to provide the Service. A league's own privacy notice may supplement this one.

2. Information we collect

CategoryExamplesWhy it is used
Account and contact informationDisplay name, username, email address, password hash, account links, roles, passkey public credentials, and invitation status.Authentication, account recovery, access control, invitations, and service communications.
League, roster, and participation informationLeague and team memberships, roster name, position, batting side, eligibility, league-configured gender classification, availability, and lineups.Team administration, scheduling, scorekeeping, lineup rules, eligibility, and statistics.
Messages and other user contentPrivate team messages, reactions, read state, notification choices, support requests, and information entered into free-form fields.Team communication, notifications, support, safety, and moderation.
Game and statistics informationSchedules, attendance responses, lineups, plays, scores, pitch counts, player statistics, spray locations, awards, and game status.Operating games, publishing results, historical records, and league reporting.
League documents and waiversPublic rulebooks and private waiver PDFs uploaded by a league administrator, which may include information supplied on a signed form.Publishing league rules and maintaining the league's waiver records.
Photos, video, and audioLogos or images selected for an overlay, live camera and microphone content, server-side game recordings, replay chapters, and highlight clips.Broadcasting games, displaying league branding, replay, highlights, and media administration.
Connected YouTube channel informationChannel ID, title, handle, granted OAuth scopes, encrypted refresh token, connection health, audience and visibility defaults, and administrator connection activity.Identifying the exact league-owned channel, maintaining authorized server-side access, running an administrator-requested private readiness test, archiving league broadcasts, and providing live or replay viewing.
Device, session, and security informationRevocable session and device identifiers, push-notification tokens, access scope, session activity, IP address, security or delivery events, and sanitized broadcast connection diagnostics such as app/OS version, device model, network type, connection stage, and error code.Keeping accounts signed in, delivering notifications, preventing abuse, protecting the Service, and diagnosing delivery or broadcast failures.
Website usage and inquiriesPage interactions collected by our optional first-party analytics deployment and information submitted through league, player-pool, alert, or sales forms.Providing requested features, responding to inquiries, measuring reliability, and improving the Service.

We receive information directly from you, from league administrators and scorekeepers, from other authorized team members, and automatically when the Service must establish a secure session or deliver a requested feature. Passwords are not stored in readable form. Apple or Android biometric data used to approve a passkey or unlock secure device storage is handled by the operating system and is not available to us.

3. How we use information

  • Provide accounts, league administration, document storage, schedules, rosters, scorekeeping, statistics, chat, notifications, streaming, recordings, replays, and highlights.
  • Authenticate users, enforce league and team permissions, and protect accounts and infrastructure.
  • Process invitations, profile corrections, player-pool requests, support requests, and other actions you initiate.
  • Maintain historical league records and public results where the league has configured them to be public.
  • Monitor reliability, investigate abuse or security events, back up the Service, and comply with legal obligations.
  • When a league administrator enables YouTube media features, identify the authorized channel, create and manage a separate YouTube broadcast for an eligible game, relay the live game video, verify the resulting archive, upload administrator-selected or policy-selected vertical highlight videos, and provide live, replay, or highlight viewing. After a public or unlisted highlight upload is verified, the league may choose to remove the Service's local highlight copy.

We do not sell personal information. We do not use personal information for third-party advertising, and the native apps do not include advertising or cross-company tracking SDKs.

4. Who can see information

  • Public visitors: A league may publish schedules, team and roster information, player names and profiles, statistics, scores, awards, broadcasts, recordings, and highlights. Public availability depends on league configuration.
  • Team members: Authorized active members can see their team's private chat, submitted lineups, availability, roster, and team reports. Team chat is not a public surface.
  • League staff: Authorized coaches, scorekeepers, league administrators, and the platform operator can access information needed for their assigned responsibilities. Private waiver PDFs, chat reports, reported-message snapshots, reporter details, and moderation history are limited to league administrators and the platform superuser.
  • People you contact: When you submit a league inquiry, player-pool request, invitation, or message, the intended league staff or team recipients receive the information needed to respond.

5. Service providers and disclosures

We disclose information only as needed for the purposes described above, including to:

  • Hosting, database, realtime messaging, media-streaming, storage, and off-site backup infrastructure used to operate and recover the Service.
  • Email delivery providers for invitations, password recovery, alerts, recaps, and other requested communications.
  • Apple Push Notification service and Firebase Cloud Messaging when a user opts into mobile notifications. A notification may contain the team name, message author, and message preview so the requested alert can be displayed.
  • Our optional self-hosted analytics deployment for aggregate website usage and reliability information.
  • Google and YouTube when a league administrator chooses to connect a league-owned channel. Google handles account selection and consent; we use the resulting authorization only for the connected-channel workflow described in this policy. An embedded YouTube player sends the viewer's playback request and this site's origin referrer to YouTube; opening the external YouTube link also sends a playback request. Use of YouTube is also subject to the YouTube Terms of Service and Google Privacy Policy.
  • Professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect users, investigate abuse, or preserve the security and integrity of the Service.
  • A successor in a merger, financing, reorganization, or sale, subject to this policy or notice of materially different practices.

If you choose a third-party maps option, iOS or Android opens that provider with the field address you selected. The provider's privacy policy then applies.

6. Mobile permissions and local storage

  • Camera and microphone: Requested when an authorized user prepares the broadcast studio. Capture is transmitted only after the user starts a broadcast. The server may retain that game as a recording and may create replay or highlight media.
  • Photos: The system picker lets an authorized user choose an optional overlay logo. The selected image is stored in the app's local storage and may appear in the outgoing broadcast; the original is not separately uploaded to a photo library or media gallery.
  • Notifications: Requested only when a user chooses team-chat alerts. The preference and platform push token are stored so alerts can be delivered and can be disabled later.
  • Passkeys and device security: The operating system may use Face ID, Touch ID, a device credential, or Android biometrics. We receive the passkey result, not biometric measurements.
  • Broadcast diagnostics: When an authorized user starts a broadcast, the app may send a bounded connection timeline containing the game/session correlation, platform, app and operating-system versions, device model, network type, selected video profile, retry stage, timing, and a sanitized error. Publishing URLs, credentials, media, account contact details, advertising or hardware identifiers, and unrestricted device logs are not collected.

The apps store non-sensitive preferences locally. If Remember this deviceis enabled, iOS Keychain or Android encrypted storage holds only the expiring, server-revocable mobile session credential, not the account password.

7. Retention

We keep information only for as long as reasonably needed for the uses described in this policy:

  • Mobile sessions expire and can be revoked by signing out, removing the saved device session, or changing relevant account security details.
  • Private team-chat messages are deleted when the team conversation expires after playoffs are completed or, for a season without playoffs, when that season becomes inactive.
  • Chat reports retain the reported message snapshot, reason, reporter, moderation decision, and audit timestamps while the underlying message and team account exist. Reports are deleted with the reported message or reporting account.
  • Deleting a team portal account immediately removes messages authored by that account, reactions, read state, RSVPs, saved sessions, device registrations, and account-authored free-form lineup notes.
  • Game results and statistics may remain as historical league records unless corrected or removed by an authorized administrator.
  • Private waiver PDFs remain until an authorized league administrator removes them. Public rulebooks remain until they are replaced or removed.
  • Local recordings and highlight files remain until an authorized administrator deletes them, an applicable operational retention rule removes them, or an enabled league setting retires a local highlight after its YouTube replacement is verified. YouTube game archives and highlight videos remain under the connected channel's retention and deletion controls; disconnecting the channel does not delete existing YouTube videos.
  • A pending YouTube channel confirmation can be used for 15 minutes. Connected-channel authorization data remains until an administrator disconnects the channel, Google revokes the grant, or operational cleanup removes an abandoned connection attempt.
  • Sanitized native broadcast connection diagnostics are scheduled for deletion after 30 days during diagnostic maintenance so authorized operators have a limited window to investigate device-specific failures.
  • Security, audit, job, delivery, and backup records are retained on limited operational schedules and may remain in a protected backup until that backup ages out.

We may retain information longer when required by law, needed to resolve a dispute, protect the Service, enforce an agreement, or preserve a legitimate historical league record. When deletion is appropriate, we delete or de-identify the information from active systems and allow protected backups to expire normally.

8. Your choices and privacy requests

Depending on your location, you may have rights to access, correct, obtain a copy of, restrict, object to the use of, or delete personal information associated with you. You can also withdraw optional notification permission in device settings, stop a broadcast at any time, sign out, or remove the saved mobile session.

Players and coaches can permanently delete their team portal identity from the account deletion page after signing in and verifying their current credentials. This deletes the account and its authored chat content immediately; it does not require an email or support request. League-managed roster identities, staff assignments, league documents, game results, statistics, broadcasts, and historical media are separate league records and remain after account deletion. Administrator accounts are organization-managed and can be permanently deleted by the site superuser.

Account and roster details can be corrected through available account tools or an authorized league administrator. To request access, export, correction, or deletion of a league-managed record, email [email protected] or use the information on our Support page. We may need to verify your identity and coordinate with the league responsible for the record. We will explain if a legal or integrity obligation prevents deletion of a specific item.

A league administrator can disconnect YouTube from the league's Media administration area. Disconnecting removes the stored credentials and asks Google to revoke the grant; existing videos on YouTube are not deleted. You can also review or revoke the Service directly in Google's security settings. Because Google revocation applies to the account's grant for this application, leagues should use a separate Google identity for each league-owned channel.

9. Security

We use measures designed to protect information, including encrypted transport, hashed passwords and session tokens, role-based access, revocable sessions, restricted administration surfaces, network isolation, security logging, and protected backups. YouTube refresh tokens are encrypted at rest with a dedicated key, bound to the league and channel identity, and never returned to a browser or broadcaster. No system can guarantee absolute security, so please report suspected account or privacy problems promptly.

10. Children's privacy

The Service is designed for leagues and their authorized participants and is not directed to children under 13. A league must have appropriate authority and any required parental consent before providing information about a minor. If you believe information about a child was provided without appropriate permission, contact us so we can investigate and remove it where required.

11. Changes to this policy

We may update this policy when the Service, our providers, or legal requirements change. The current version will remain at this URL with a revised effective date. We will provide additional notice when a change materially affects how we use personal information.

12. Contact

SJSR Labs / Softball-League
Email: [email protected]
Web: www.softball-league.com/support