OneClub OS Privacy Notice

Version 2026-09-10 · Effective September 10, 2026

What changed

  • Staff and player users aged 13 to 17 accept their own account terms without parent onboarding for basic access. The parent-operated player flow remains for children under 13. Adult-only responsibilities and separate optional permissions remain protected.

Effective September 10, 2026. This version does not amend a signed club agreement or change a historical acceptance. Restricted features remain unavailable until the required controls and permissions are verified.

Go Maximus Enterprises LLC operates OneClub OS and provides club-management software to sports organizations ("clubs"). Your club decides what information to enter into the platform and how it is used inside the club; OneClub OS processes that information to provide the platform. In the language of U.S. state privacy laws, your club generally directs its club data and we process it to provide the service. We separately determine purposes for our account security, service administration and consent records; these descriptions do not remove either party’s legal duties.

This notice explains what we collect, where it comes from, how it is used and protected, who we share it with, how long we keep it, and the rights available to you. Two companion notices cover specific categories in more detail: the Consumer Health Data Privacy Policy for wellness, injury, and treatment information, and the Children’s Privacy Notice for players under 18.

Questions or requests: legal@oneclubos.com. Legal notices: legal@oneclubos.com.

We reuse current valid permissions for their covered purposes. Existing signed adult-player or guardian permission can be assessed against the actual current collection, sharing, recipients and processors, with evidence of the original notice and the current notice provided. The original document, signature date and versions are preserved; the current assessment and its reasons are recorded separately. An approved assessment supports only its identified scope and period, and does not establish legal sufficiency merely because a form was completed. Missing, expired, withdrawn or materially changed coverage remains restricted until resolved.

1. What we collect and where it comes from

We collect and retain age information, its source and review history to decide whether account access is permitted. Staff age confirmations distinguish ages 13 to 17 from adults without requiring a birthdate. A staff role alone does not establish age. Staff aged 13 to 17 can accept for basic access without a parent flow; adult-only responsibilities, including guardian verification, independent privacy review and staff health workspaces, still require adulthood. Player birthdate routing and staff account confirmation are separate. Player account setup uses the player’s birthdate already recorded by the club. If it is missing, the person setting up the player profile is asked for the player’s birthdate before age-based player routing can be completed. The birthdate remains separate from the parent’s own identity and age. We retain the supplied information, its source and time; supplying it is not independent age or guardian verification. Existing authoritative age information and contradictions cannot be bypassed by a new entry. The server evaluates eligibility from the recorded player birthdate and current restrictions; staff do not complete this player setup. You may request correction of your own inaccurate birthdate. Routine corrections may pass an automated review without a club administrator when the change does not override conflicting authoritative evidence or make a current or future access restriction less protective. We preserve the original information, its source and the correction decision. An accepted routine correction updates your own recorded birthdate and any player record already securely linked to your account, with a correction receipt. It cannot move an eligibility date earlier, extend a permission, override conflicting club age information or establish guardian authority. Conflicts and changes that would increase access need appropriate additional review or verification. Account setup also asks for your name, email, identity-provider credentials and the access code your club gave you where applicable. Clubs and authorized users supply the other information below. Do not create a direct account for a child under 13; use the parent’s own account and a separate child profile.

CategoryExamplesSource
Account and identityName, email, optional phone; recorded or supplied player birthdate for player setup, or the applicable staff age statement; role, club and team membership. Sign-in events are held by our identity providerYou; your club; our identity provider
Player profileName, preferred name, date of birth, jersey number, positions, preferred foot, height, weight, nationality, photograph, status, trial details, and where the club records them, contract, compensation, and valuation detailsYour club’s staff; imports the club runs
Contacts and guardiansPlayer email and phone, parent or guardian name, relationship, email, and phoneYour club’s staff; you, from your own account settings
Wellness and availabilitySelf-reported readiness, sleep, soreness, mood, and body-map indicators; availability statusPlayers; club staff
Injury and availabilityAvailability, restrictions and return-to-play status and dates; separate confidential clinical notes restricted to authorized athletic trainers.Players; athletic trainers and authorized staff
Performance and loadAuthorized, necessary performance and load metrics from approved imports; source and participant provenance; evaluations and development records. Unnecessary raw fields, identifiers and coordinates must be excluded.Club imports; coaches; players
Video and mediaMatch and training footage, clips, markers, and tags that may show players, including minorsClub uploads and connected video sources
CommunicationsMessages, group chat, posts, reactions, notification preferences, push subscription tokens, and the read-only audit view of club messaging that directors and designated staff can openYou; your club
Coaches CornerContent interactions, quiz results, and coaching development recordsCoaches; club administrators
TechnicalIP address, browser and device information, timestamps, request identifiers, and error diagnostics in server logs; page analytics scrubbed of record identifiersAutomatically, when you use the platform
Legal recordsYour acceptance of our Terms and notices: version, a fingerprint of the text you saw, time, IP address, browser, and the age statement you selectedYou, at the consent step

Our account and player forms do not request payment card data, Social Security or other government identifiers, precise device location, or biometric identifiers. Clubs must remove unnecessary sensitive information and location coordinates from uploaded files and free text. Video is stored as ordinary media and is not processed for facial recognition or other biometric identification.

2. How we use information

  • To provide club membership, schedules, development, coaching and other selected functions within authorized roles, teams and purposes.
  • To maintain age, guardian, permission and source-rights evidence, and protect account and participant safety.
  • To send generic reminders or service notifications. Health values, diagnoses and clinical notes do not belong in email, push, general messaging or notification previews. Authorized detail is accessed in its restricted workspace.
  • To provide support, investigate security incidents and fulfill lawful rights requests.

We do not sell personal information, use it for targeted advertising or train or fine-tune models on it. Staff help and optional coaching-content drafting are restricted to approved non-personal coaching content. Player data, health, private messages, video and GPS must not be sent to AI providers. Staff free-text AI is unavailable when the approved content policy or provider controls are missing. A staff role or a prompt warning alone does not establish that input is safe.

No current acceptance authorizes player-data AI, independent-player AI, historical-data reuse, model training or cross-club datasets. Those features remain deferred.

Planned independent-player and AI features

We plan a player experience for people without an affiliated club. It may use information a player chooses to enter to produce personal summaries, comparisons and AI-assisted sporting insights. This experience, player-data AI and model training are not enabled by this policy update. Before launch, we will explain the actual inputs, purposes, recipients, retention and choices for the selected feature.

For a direct player service, OneClub OS would be responsible for its own processing decisions and for handling rights requests directly, rather than routing them to a club you do not have. Independent-player information would not automatically become visible to a club. Moving or sharing information with a club would require an authorized, specific action.

Generating an answer for you, building comparison statistics and training or improving a model are different uses. Accepting these notices does not authorize future training on your information or reuse of historical club records. Health-related inferences receive health-data protections. Any new use that requires consent will have a separate, specific choice before it starts, with parental permission where required. Contact legal@oneclubos.com with questions.

3. Who we share information with

Club information is restricted by current club, team, role and purpose authority. Player-only accounts cannot enter staff health workspaces. Clinical notes are restricted to authorized athletic trainers, including when an administrator has general roster access. The providers below support the named functions; a listing does not mean every optional service is activated. External media hosts apply their own privacy terms when their player is loaded. External clip delivery remains disabled pending separate review.

ProviderPurpose
Supabase (on Amazon Web Services)Database and private file storage
VercelApplication hosting and privacy-scrubbed web analytics
Auth0 (Okta)Sign-in and password management
CloudflareVideo streaming and clip processing when enabled
ResendTransactional email
SentryError monitoring and diagnostics, with cookies, authorization headers, user identity, and record identifiers in request paths removed before an event is sent
Google, Apple, and MozillaBrowser push services deliver notifications to your device; the notification body sent through them carries no report values. Google also provides the optional Drive metadata sync a club administrator connects
YouTube, Vimeo, and XWhen your club links Coaches Corner content hosted on one of these services, your browser loads the player or preview from that service, which applies its own cookies and privacy policy
OpenAI and AnthropicStaff help and optional coaching-content drafting, summaries and quiz generation; inputs, configured provider and retention depend on the enabled feature. No customer-data training is authorized by us

We may also disclose information to comply with a subpoena, court order, or legal process; to protect the rights, safety, or property of users, minors, or the public; or in connection with a merger, acquisition, or sale of assets, in which case this notice will continue to apply.

OpenAI API content is not used for training by default. Standard abuse-monitoring logs may be retained for up to 30 days; endpoint, model, stored features and legal exceptions can differ. Disabling response storage is not proof of zero data retention. Anthropic ordinarily deletes API inputs and outputs within 30 days, with contractual, feature, enforcement and legal exceptions; flagged content may be kept up to two years, classification scores up to seven years, and feedback up to five years. Some covered models require 30-day safety retention unless an exception is expressly authorized. Only the reviewed account and feature configuration determines an enabled feature’s actual handling. See OpenAI data controls and Anthropic retention.

4. Google user data

A club administrator may optionally connect a Google Drive folder to the Coaches Corner asset library. When connected, OneClub OS accesses only file metadata (file name, type, size, link, modified time, and the owner’s display name) through the read-only scope drive.metadata.readonly; we do not read, download, or store file contents. Metadata is stored scoped to the connecting club and refreshed when an administrator syncs, when the Coaches Corner portal opens, and by a daily scheduled refresh that keeps the connection current. OAuth refresh tokens are encrypted at rest with a key held outside the database.

OneClub OS’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only for the connected feature and necessary service processing, never for advertising or model training. Do not select private Drive content for an external AI workflow unless that transfer is permitted and disclosed. A club can disconnect its Drive folder at any time inside Coaches Corner (which deletes the stored tokens) or revoke access from its Google account permissions.

5. How we protect information

  • Server authorization and database row-level policies restrict access to club data. Team, purpose and age restrictions also apply; administrative status is not blanket health or guardian authority.
  • Providers protect data in transit and at rest. Private storage and expiring links limit access; previously downloaded copies cannot be recalled by changing an account setting.
  • Health records and access evidence require restricted review. Notifications use generic content, and detailed health information is viewed only after current authorization.
  • Support access and administrative changes require their own authorization and audit trail. No system guarantees absolute security.

If we learn of a breach of security involving personal information, we will notify the club and affected people as required by applicable law, without unreasonable delay. This draft does not claim an unverified certification or service level.

6. How long we keep information

InformationPolicy and activation condition
Club records and restricted historical health recordsA documented purpose, accountable reviewer and bounded deletion schedule are required. New clinical notes and player status history are retained for 24 calendar months after the player’s departure from the club, subject to an earlier valid erasure requirement or shorter source permission and any specific lawful hold. Existing records stay restricted pending review and are not automatically deleted. An open account or annual review alone does not justify indefinite storage.
Own match filmApproved target: eight calendar months after the game. Deletion requires a verified authorized export and delivery receipt. This draft is not proof that a scheduled provider deletion has completed.
Opponent/scouting filmSource use remains disabled. The approved policy, if separately authorized in future, is 48 hours after the game; expiry of a scouting copy must not delete an authorized own-film original.
ClipsApproved target: 12 calendar months from clip creation. Provide seven days’ advance export notice. Source rights and participant permissions apply independently.
Export packagesPrivate authorized delivery only. Deletion of hosted footage waits for verified export and delivery receipts. Archive availability ends 30 days after confirmed deletion from the streaming provider; a scheduled date does not start that clock. A delivery failure does not authorize ordinary retention deletion. A lawful deletion or revoked right must be assessed separately and cannot be blocked indefinitely by an export promise.
Training video and footage without a recorded match dateNo automatic match deadline is assumed. New use requires an approved bounded retention schedule. Existing items stay restricted pending a specific review and lawful deletion or authorized disposition.
New wellness, health measurements, GPS and sanitized import recordsApproved policy: new wellness, health measurements (height and weight), and GPS records are retained for 24 calendar months from collection. Sanitized import files are retained for 90 days after successful import. A shorter source permission or a valid erasure requirement takes priority. Failed or incomplete imports require restricted review; the successful-import clock must not be fabricated. Existing records stay restricted pending review and are not automatically deleted under this new schedule.
Acceptance and guardian evidenceRetained while needed to evidence the agreement or a specific permission, dispute or legal duty under a documented bounded schedule. Append-only history is not blanket permission for perpetual retention.
AccountsDeactivation ends access; it does not prove identity-provider erasure, file deletion or removal from club records. A verified erasure request tracks those separately and explains any lawful scoped hold.
Staff AI conversationsApplication conversation history has a maximum of 30 days in active storage, with clear-history controls. Provider logs and other retained records are separate and follow the verified provider configuration described above.
Backups and operational logsActual provider windows and request-specific deletion deadlines must be verified before real-data activation. Restored data must be screened against prior deletions and withdrawals before use. Applicable legal deadlines control; this is not an unspecified backup exception.

7. Your U.S. state privacy rights

Depending on where you live, state law may give you rights over personal information, including to know what is held about you, to access it, to correct it, to delete it, to receive a portable copy, to opt out of its sale, of sharing for targeted advertising, and of profiling that produces legal or similarly significant effects, and not to be discriminated against for exercising those rights. We honor these rights for every user in every state, whether or not a particular statute applies to us, and regardless of the applicability thresholds in those statutes.

Contact legal@oneclubos.com or your club. You may request access, correction, withdrawal or deletion without accepting a new notice or opening a new account. We verify identity and authority using proportionate evidence, route club-controlled requests and perform our own duties. We respond within 45 days; where law permits, one additional 45-day extension requires notice and reasons during the initial period. Appeals receive a written response within 45 days; a denial explains how to contact the applicable attorney general. Requests, downstream recipient notices, provider completion and any narrowly justified hold are tracked separately.

We do not sell personal information and do not share it for targeted advertising, so there is nothing to opt out of; we treat browser Global Privacy Control signals as an opt-out request in any case. We do not use personal information for profiling that produces legal or similarly significant effects.

State-specific notes:

  • California. This notice serves as our notice at collection. The categories in Section 1 map to the CCPA categories of identifiers, personal records, protected classifications (age and, where a club records it, nationality), commercial information, internet activity, geolocation (none precise), audio and visual information, professional information, and sensitive personal information (health, and precise data about children). We do not sell or share personal information and have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16. California residents may also request a list of third parties to whom we disclosed personal information for their direct marketing purposes; we make no such disclosures.
  • Washington, Nevada, and Connecticut. Wellness, injury, and treatment information is consumer health data under the Washington My Health My Data Act, Nevada SB 370, and Connecticut law. The Consumer Health Data Privacy Policy explains the consents we obtain, how to withdraw them, and how to request deletion.
  • Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. The rights above apply, including the right to appeal a denial. Health information and personal information of a known child are sensitive data; we process sensitive data only with the consent your club obtains and records, as described in the companion notices.
  • Maryland. We do not sell, and do not process for targeted advertising, the personal data of anyone we know to be under 18, and we collect only the data reasonably necessary for the platform.
  • Texas. Where we know a user is a minor, we support parents and guardians through the club in supervising the minor’s use, as described in the Children’s Privacy Notice.
  • Illinois and Texas biometrics. We do not collect biometric identifiers or biometric information.
  • New York and Massachusetts. Additional security requirements may apply to covered information. Contact us about the safeguards described in this notice; additional requirements depend on the circumstances.
  • Nevada. We do not sell covered information as defined in NRS 603A.

8. Children

For children under 13, the parent or legal guardian operates their own account with a separate child profile. The parent overview uses the player dashboard’s presentation with parent-specific wording. It currently shows authorized teams, upcoming team events and completed shared development plans; it does not yet provide every player-portal feature. The child must not use the parent’s credentials. A parent confirmation records the statement but does not establish identity, parental authority or required permission.

Direct accounts for children under 13 are not available, including when a guardian permission record exists. Adult guardians use a separate channel under their own identity; entry confirmation does not establish a child-specific relationship or permission. Players aged 13 to 17 may accept for basic personal account access, subject to current club membership, age information and applicable restrictions. Optional health, media, messaging and external-delivery permissions remain separate, and player-data AI remains unavailable. Known minor staff remain subject to existing staff eligibility and safeguarding restrictions. A player’s acceptance or age correction cannot override a verified parent’s withdrawal, an account restriction, an unresolved age or safeguarding hold, or inactive club membership. Verified guardians retain their available supervision, privacy-request and withdrawal rights. A missing optional permission restricts the affected purpose; it does not by itself require a new signature for an already permitted purpose. Additional restrictions apply where required by law or an applicable club safeguarding policy. See the Children’s Privacy Notice.

The planned handover will be available only after its account and permission controls have been implemented and verified. When the server establishes that the player has reached 13 and meets the current account requirements, a popup will offer the verified parent a handover to the player’s own email and account. The player must verify their own email and accept the current terms before the new player access is activated. The parent’s identity and personal account, the player’s history and original evidence remain intact. Handover grants no optional permissions. Valid guardian-controlled permissions remain subject to their original scope, expiry and withdrawal. A pending, expired or canceled handover does not change existing account control.

9. Cookies, analytics, and do-not-track

We use strictly necessary cookies for sign-in sessions, security, and your preferences. We use aggregate page analytics from our hosting provider; before a page view is reported, record identifiers are removed from the path and the query string is dropped, to reduce the risk of linking analytics to a player. We do not use third-party advertising cookies. Content your club links from YouTube, Vimeo, or X loads from those services with their own cookies. Because we do not track you across other sites, we treat do-not-track and Global Privacy Control signals as honored by default.

10. Where information is processed

We operate from the United States. Our providers may store or process information in the United States and other countries as needed to deliver their services. Locations depend on the service, configured hosting region and global delivery or support infrastructure. Contact us for information about the services used by your club and applicable transfer safeguards.

11. Changes to this notice

We will update this notice as the platform evolves. Material changes are announced to club administrators and, because acceptance is recorded per version, every user is shown the new version with a summary of changes at their next sign-in. Use of the platform is also governed by our Terms of Service.