Skip to main content

Privacy Policy

Last updated: September 11, 2026 · Effective: September 11, 2026

This Privacy Policy explains how Scorecrypt, LLC, an Illinois limited liability company ("Scorecrypt," "we," "us," or "our"), collects, uses, shares, and protects personal information in connection with the Scorecrypt websites (including scorecrypt.com and app.scorecrypt.com), our web application, our mobile and tablet applications, and related services (together, the "Services").

Scorecrypt is a wrestling program management platform used by wrestling programs and the people connected to them — program administrators, athletic directors, coaches, team managers, parents and guardians, and athletes (including minors). Because our users include children, children's privacy is central to how we built the Services; Section 5 describes it in detail, and our companion Children's Privacy Notice provides the notice required by the Children's Online Privacy Protection Act ("COPPA").

The Services are intended for use in the United States only.

1. Our roles, and how to read this policy

1.1 When we are the "business" / controller.

For information about our website visitors, account holders, and people who contact us or sign up for our communications, Scorecrypt determines how and why the information is used, and this Privacy Policy governs.

1.2 When we act on a program's behalf (service provider / processor).

When a Program or Organization (a school, district, club, or an individual coach — the "Customer") uses the Services to manage its roster, athletes, events, and communications, the Customer directs what information is entered and how it is used, and Scorecrypt processes that information as the Customer's service provider / processor. If you are an athlete, guardian, or other member of a Program, please direct requests about that information to your Program in the first instance; we will support the Program in responding, and you may also contact us at privacy@scorecrypt.com.

1.3 Schools and districts.

Where a school, district, or other educational institution is the Customer, we act as a service provider and "school official" handling student information for the institution's educational purposes, consistent with the Family Educational Rights and Privacy Act ("FERPA") and applicable state student-privacy laws, and we will enter into a written agreement with the institution where one is required. Parents may exercise rights regarding student data through the institution or by contacting us.

2. Information we collect

2.1 Information you or your Program provide.

  • Account and identity. Name, email address, phone number (optional), password or authentication credentials, and role (for example, administrator, coach, guardian, athlete, team manager).
  • Athlete and roster information entered by a Program about its athletes, which may include name, date of birth or age, guardian name and contact details, school, hometown, grade or graduation year, weight class, weigh-in and weight-management data, eligibility information (including an "injured" yes/no flag), headshots or avatars, and competition statistics, records, and results.
  • Messages and content you submit through the Services, including messages between users (see Section 3.3 on messaging) and files you upload.
  • Billing information. Subscriptions are processed by our payment processor, Stripe. Stripe collects and processes your payment card details; we do not store full payment card numbers. We receive limited billing information such as subscription status and the last four digits of a card.
  • Communications and preferences. Information you provide when you contact support, request information, or sign up for our newsletter or marketing communications.

2.2 Information we collect automatically.

When you use the Services, we and our analytics and infrastructure providers automatically collect certain technical information, such as device and browser type, operating system, app version, IP address, approximate location derived from IP address (not precise geolocation), pages and features used, and diagnostic and error data. We collect this using cookies and similar technologies (see Section 8) and error-monitoring and analytics tools. We do not collect precise device geolocation.

2.3 Information from third parties.

If you sign in using a third-party identity provider (for example, Sign in with Apple), we receive limited profile information from that provider as permitted by your settings. We receive subscription and payment-status information from Stripe. We do not obtain personal information from data brokers or advertising networks.

2.4 Sensitive information.

Some information we process for athletes — such as weigh-in and weight-management data and the eligibility "injured" flag — may be considered sensitive. We use it only to provide the Services (for example, to monitor weight against governing-body guidelines) and handle it consistent with this policy. We do not collect biometric identifiers and do not perform facial recognition.

3. How we use information

3.1 To provide and operate the Services.

To create and manage accounts; build and manage rosters, lineups, events, and scoring; process weigh-ins and weight-management monitoring; and enable the features you use.

3.2 Billing.

To process subscriptions and payments through Stripe and to manage renewals and cancellations.

3.3 Messaging and youth safety.

To deliver messaging features and to support athlete safety. Consistent with our approach to protecting minors, messages involving a minor athlete are copied to the athlete's guardian, are logged and stored in accordance with applicable legal and athlete-safety guidelines, and are subject to automated review and flagging of potentially unsafe content. Automated review is a safety aid and does not detect all inappropriate content. We may review, flag, remove, or restrict content and may disclose information to Program administrators, guardians, or authorities where permitted or required by law.

3.4 Communications.

To send transactional messages (such as account, consent, billing, and safety notices) and, where you have opted in or as otherwise permitted, newsletters and marketing communications — which you can unsubscribe from at any time using the link in the message or by contacting us.

We do not currently use open or click tracking in our email. Transactional messages — sign-in, consent, billing, and safety notices — will never carry it. If we introduce it for newsletters and other marketing messages, those messages will contain a small invisible image that records that the message was opened, and their links will be rewritten through our own tracking host, track.news.scorecrypt.com, so that we can see which links were clicked. We would use this only to measure how our own mailings perform. We would not use it to build a profile of you, and we would not share it with advertisers. Unsubscribing stops it.

3.5 Analytics, product improvement, and security.

To understand how the Services are used, improve and develop features, run product experiments, diagnose and fix errors, and protect the Services and users against fraud, abuse, and security threats.

3.6 De-identified and aggregated data.

We may create de-identified and aggregated data from information in the Services and use it for any lawful purpose, including analytics, research, and training artificial-intelligence and machine-learning models. We do not attempt to re-identify this data. We do not use identifiable information about minors to train artificial-intelligence or machine-learning models except in de-identified form.

3.7 Legal.

To comply with law, enforce our Terms, and protect the rights, safety, and property of Scorecrypt, our users, and the public.

4. Public display of athlete information

Scorecrypt does not currently display athlete information publicly. We will update this policy before any public display of athlete information is introduced.

5. Children's and students' privacy

Protecting children is central to Scorecrypt. This section, together with our companion Children's Privacy Notice, describes how we handle information about minors and provides notice required by COPPA.

5.1 Age tiers and accounts.

  • A person who creates, owns, or pays for an account must be at least 18.
  • A minor athlete ages 13–17 may have a login only after their guardian grants consent as described below.
  • A child age 12 or under does not have a login. Where an under-13 child's information is used in the Services, an adult — a coach or the child's guardian — provides it, and it is handled under this section.

5.2 How consent works.

Our consent flow is the same for all Programs, including schools and clubs:

  1. A coach adds an athlete, including the guardian's email (required) and phone number (optional).
  2. We send the guardian a consent request (via our email provider).
  3. For an athlete 13–17, the guardian is asked to consent to the athlete's account and use of the Services. If the guardian consents, the athlete is invited to create an account; if the guardian declines, no athlete account is created.
  4. For a child 12 or under, no athlete account is created, and the child does not log in.
  5. We log consent decisions.

5.3 Verifiable parental consent method.

We are not yet collecting children's personal information through the Services. We will describe the verifiable parental consent method we use here before we begin.

5.4 Parental requests.

A guardian may contact us about their child's information at privacy@scorecrypt.com.

5.5 Consent lifecycle (age transitions).

When an athlete turns 18, we notify the athlete and guardian that guardian copying of the athlete's messages will end and that direct adult-to-adult communication (for example, between a coach and the now-adult athlete) becomes available.

5.6 Categories of third parties.

We share children's information only with the service providers that help us operate the Services (Section 8), within the child's Program, and as required by law or to protect safety. We do not sell children's information or use it for advertising.

5.7 Children's data retention.

We retain a child's personal information while the child is on a Program's roster. When a child leaves a Program, a twelve-month retention period begins; if the child is not rostered again with that Program within those twelve months, we delete the child's personal information at the end of that period, subject to legal retention obligations. See Section 10.

5.8 Schools and students (FERPA).

Where a school or district is the Customer, we handle student information as the institution's service provider and "school official," using it only to provide the Services and, in de-identified form, to improve them, and we will enter into a written agreement with the institution where one is required. We do not use student information for advertising and do not sell it. Parents may exercise rights regarding student data through the institution or by contacting us.

6. How we share information

We share personal information only as described here:

  • Within your Program. With administrators, coaches, guardians, athletes, and team managers in your Program, according to their roles.
  • Service providers. With vendors that perform services for us, such as cloud hosting and database (Supabase), application hosting (Vercel), payment processing (Stripe), email delivery (Resend), and error monitoring and product analytics providers. These providers may process personal information only on our instructions and for the purposes we specify. A current list of our key sub-processors is available and linked from this policy.
  • Legal, safety, and youth protection. When we believe in good faith it is necessary to comply with law or legal process, enforce our Terms, protect the safety of a minor or any person, or investigate suspected wrongdoing — including disclosures to guardians, Program administrators, or appropriate authorities.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
  • With your direction or consent.

We do not sell personal information, and we do not share personal information for cross-context behavioral or targeted advertising.

7. Analytics and experimentation

We use a first-party product-experimentation tool to run experiments — for example, on our marketing site — and to keep your experience consistent between visits. Our current experimentation provider is identified on our sub-processors list.

We do not currently use an analytics provider. If we adopt one, it will be first-party, we will add it to our sub-processors list, and we will not use it for advertising.

We do not use any of these tools for advertising, and we do not allow third-party advertising trackers in the product.

8. Cookies and similar technologies

We use cookies and similar technologies only where they are needed. Our website sets one first-party cookie, sc_anon_id, which holds a randomly generated identifier used to keep your experience consistent and to run product experiments. It contains no personal information and is not linked to an account. We set it only if you agree: the first time you visit we ask, and until you answer it is not set. You can change or withdraw your answer at any time using the "Cookie settings" control at the bottom of any page, and withdrawing deletes the identifier rather than merely stopping its future use. A second cookie, sc_consent, records your answer so that we can honour it; it is strictly necessary, because without it a refusal would not survive to your next visit.

We set sc_anon_id for scorecrypt.com and its subdomains, so that a visit which begins on our marketing site and continues into our web application at app.scorecrypt.com is counted once rather than twice. It remains a first-party identifier that contains no personal information, and it is not shared with advertisers. We set it only if you agree, and withdrawing your agreement removes it from our marketing site and our web application alike.

We do not use analytics or advertising cookies, and we do not allow third-party advertising trackers. You can block or delete cookies through your browser settings.

If your browser sends a Global Privacy Control signal, we treat it as a refusal: we do not set sc_anon_id, we delete it if it is already present, and we do not ask you the question, because you have already answered it. While the signal is on it overrides an acceptance, so pressing Accept with the signal switched on will not set the cookie. Separately, because we do not sell personal information or use it for targeted advertising, there is nothing further for such a signal to act on.

Our Cookie Policy describes all of this in full.

9. Your privacy choices and rights

We extend the following rights to all Scorecrypt users in the United States, regardless of the state you live in:

  • Access the personal information we hold about you and obtain a copy (portability);
  • Correct inaccurate personal information;
  • Delete your personal information;
  • Opt out of any sale or sharing for targeted advertising (note: we do not sell or share personal information for these purposes, so there is nothing to opt out of);
  • Limit the use of sensitive information to what is necessary to provide the Services; and
  • Not be discriminated against for exercising your rights.

How to exercise your rights. Email privacy@scorecrypt.com. We will verify your request (for example, by confirming control of the account email) and respond within the time required by applicable law. You may use an authorized agent, and we may ask the agent to demonstrate authority. If we decline a request, you may appeal by replying to our response.

Requests about a Program's data. If your information is managed by a Program (for example, your athlete profile), we will refer or coordinate your request with that Program as its service provider.

Parental requests. Guardians may contact us about their children's information as described in Section 5.4.

10. Data retention

We retain personal information for as long as your account or Program is active and as needed to provide the Services. When a Program ends or a person leaves a Program, a twelve-month retention period begins; if the account or roster entry is not reactivated within that period, we delete or de-identify the information at the end of it, except where a longer period is required by law or for legitimate purposes such as resolving disputes, enforcing agreements, or meeting regulatory and legal-hold obligations. We retain de-identified and aggregated data. Backups are deleted on our routine cycles. Retention of children's information is described in Section 5.7.

11. Data security

We maintain a written information security program with reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption of data in transit and at rest, access controls and tenant isolation (row-level security), and monitoring. We periodically assess and update these safeguards. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you and authorities as required by law.

12. Where information is processed

The Services are intended for use in the United States, and we store and process personal information in the United States. We do not offer the Services to, or direct them to, individuals outside the United States.

13. Third-party links and services

The Services may link to or interoperate with third-party sites and services (for example, app stores or an identity provider). Their privacy practices are governed by their own policies, and we are not responsible for them.

14. Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change, we will provide reasonable notice (for example, by email or an in-product or on-site notice) before it takes effect. The "Last updated" date above indicates when this policy was last revised, and your continued use of the Services after an update means you accept the revised policy.

15. Contact us

For privacy questions or to exercise your rights, contact us at:

Scorecrypt, LLC
Attn: Privacy
548 Sparrow Ct., Lindenhurst, IL 60046
privacy@scorecrypt.com

For legal notices, contact legal@scorecrypt.com.