Data Processing Addendum (lite)
How LeagueBucket handles a league's member data on that league's behalf.
{{PLACEHOLDER}} marks a fact that has not been decided or does not exist yet. Do not treat this page as legally binding until it has been reviewed by an attorney and republished with a real effective date.1. Purpose and how this applies
When a league's commissioner enters information about that league's Members -- rosters, contact details, results -- into LeagueBucket, the league is directing how that information is used and LeagueBucket is acting on the league's instructions. This addendum describes that relationship. It's incorporated into the Terms of Service by reference and applies automatically to every league; it isn't a separate contract you need to sign.
This is a "lite" version written for leagues of the size LeagueBucket serves at launch -- local recreational leagues, not large organizations with their own compliance requirements. A league that needs a fuller, separately-negotiated data processing agreement should contact support@leaguebucket.com.
2. Roles
For its own Members' personal data, the league (through its commissioner) is the controller (or business, under CCPA terminology) -- it decides what member information gets collected and why. LeagueBucket is the processor (or service provider) -- we process that information only to provide the Service, and only on the league's instructions as expressed through how the league configures and uses the Service.
3. Subject matter, duration, and purpose
Subject matter: the personal data of a league's Members that the league enters into or generates through the Service. Duration: for as long as the league's account is active, plus the retention period described in the Privacy Policy. Purpose: providing the scheduling, standings, roster, communication, and (where applicable) payment features of the Service to that league.
4. Categories of data and data subjects
Categories of data subjects: players, parents/guardians of players (once the Service supports youth leagues -- not yet), coaches, officials, and other league Members.
Categories of data: names, contact information (email, phone), team/roster assignments, game participation and results, messages sent through the Service, and payment-related metadata for dues or registration fees (never full card numbers, which Stripe handles directly).
5. Our obligations as processor
LeagueBucket will:
- Process Member data only on the league's instructions (as configured through the Service) and for the purposes in section 3, except where required to do otherwise by law.
- Keep Member data confidential, and limit access to it -- both by our own systems (Postgres row-level security scoped per league, per LEAGUEBUCKET_LAUNCH_PLAN.md §6/§7) and by our staff.
- Use only the subprocessors listed in the Privacy Policy, and tell leagues if that list materially changes.
- Assist a league in responding to a data subject request (access, correction, deletion) from one of its own Members, since the league -- not LeagueBucket -- typically controls what was entered about that Member.
- Notify the affected league without undue delay if we become aware of a security incident affecting that league's Member data.
- Delete or return a league's Member data at the end of the relationship, consistent with the Privacy Policy's retention section, except where we're required by law to keep it longer.
6. The league's obligations
A league's commissioner is responsible for having a lawful basis and, where required, valid consent to enter each Member's information into the Service, for the accuracy of that information, and for complying with the adult-only requirement in the Terms of Service.
7. International transfers
LeagueBucket processes data in the United States. {{PLACEHOLDER: if a league's Members are located outside the US (in particular the EEA/UK), a transfer mechanism (e.g. Standard Contractual Clauses) may be required and isn't included in this draft -- see the Privacy Policy's "International visitors" section, flagged the same way, for the underlying open question.}}
8. Contact
Questions about this addendum can be sent to privacy@leaguebucket.com.