Privacy Policy

Last updated September 18, 2026

This document is a working draft and is being reviewed by counsel. It describes how OpenRoster works today.

The short version

  • OpenRoster accounts are for adults only: parents, legal guardians, and coaches, 18 or older.
  • Children never create an account, never sign in, and never send or receive messages.
  • A parent or guardian decides what we keep about their player, and can export or delete it at any time from inside the app.
  • We do not sell personal information. We do not run advertising. We do not use third-party tracking or analytics cookies.

Who we are

OpenRoster is operated by CB5 Ventures LLC ("OpenRoster", "we", "us"). Questions about this policy or your data: support@cb5v.com.

Information we collect

About you, the adult account holder:

  • Name, email address, and a password (stored only as a salted hash; we cannot read it).
  • Whether you use OpenRoster as a parent/guardian, a coach, or both.
  • For coaches: team name, sport, age group, playing class, and home city.
  • Your consent choices and when you made them.
  • Messages you send to another adult through the in-app relay.
  • Basic session records: sign-in time, IP address, and browser or device type, used to keep your account secure.

About a player, entered by their parent or guardian:

  • First name, last name, and date of birth (used to check age eligibility).
  • Sport, positions, playing level, and optional attributes such as throwing or batting hand.
  • Home city, used to estimate travel distance to an event.
  • Availability windows the guardian posts.
  • Optional links to public stat pages the guardian chooses to add.
  • Match history and trust signals, such as completed guest appearances.

We do not collect a child's email, phone number, photo, precise location, or any login. We do not collect information from a child directly. Everything about a player comes from their parent or guardian.

Parental consent

Before any player profile is stored, the parent or guardian is asked two separate yes-or-no questions: whether we may keep a profile for the player, and whether a limited player card may be shown to coaches when there is a possible match. Matching cannot start until both are granted. Each answer is recorded with a timestamp, and either can be withdrawn at any time in Settings. Withdrawing the second pauses new suggestions to coaches.

Who sees what

  • A coach on a paid team plan can browse limited player cards, but only for players a guardian has allowed coaches to see, who are eligible for that coach's open event, and who are either open for those dates or committed over them. A card shows the player's first name, last initial, age group, positions, city and state, approximate distance to the coach's team, whether the player is Available or Committed, counts of completed guest events and coach endorsements, and links to any stat pages the guardian added along with a small dated snapshot of the stats those pages showed. If a player is Committed, a coach sees only the date the commitment ends, never which team. Cards are listed alphabetically; OpenRoster does not rank or score players.
  • Coaches never see a date of birth, full last name, street address, or the guardian's email or phone number. A guardian can turn card visibility off at any time in Settings, and can end a commitment early at any time.
  • The parent or guardian sees everything about their own player.
  • Nothing about a player is public. Player information is never shown on the public website or to signed-out visitors.
  • A match is confirmed only when both the guardian and the coach approve it.
  • Messages go through the in-app relay between the guardian and the coach for a specific match. Messages that appear to share phone numbers or move the conversation off-platform are flagged for safety review.

How we use information

  • To check eligibility and suggest matches between roster needs and available players, using published, explainable rules.
  • To let guardians and coaches approve, decline, and message about a match.
  • To send notifications about your matches and messages.
  • To keep the service safe: preventing abuse, reviewing flagged messages, and keeping an audit record of safety-relevant actions.
  • To send product email, only if you opted in. You can opt out at any time in Settings.

Service providers

We use a small number of companies to run OpenRoster. They process data only on our behalf: Vercel (website hosting), Neon (database hosting), and an email delivery provider for account and notification email. We do not share personal information with anyone else, except where the law requires it or to protect someone's safety.

Payments

Coach subscriptions are paid through Stripe. Stripe collects and holds your card details; we never see or store your card number. We keep your subscription status, renewal date, and Stripe customer reference so we can tell whether your coach access is current. Parents are not charged and no payment information is collected from parents.

Cookies

We use only the cookies required to keep you signed in. We do not use advertising or analytics cookies.

Your choices: access, export, and deletion

  • Export: Settings → Export my data downloads everything we hold about you and your players.
  • Delete a player: a guardian can delete a player's record from the player page. Their profile, availability, matches, and messages about those matches are removed.
  • Delete your account: Settings → Delete account permanently removes your account, your players' records, and your consents. Messages you sent remain in the other adult's thread with your identity removed.
  • We keep a minimal audit record of safety-relevant actions, with your identity removed, after deletion.
  • If you cannot sign in, email support@cb5v.com and we will verify you and act on your request.

Retention

We keep account and player information for as long as the account exists. Expired availability and declined or cancelled matches are kept for match history until the player or account is deleted. Backups are overwritten on a rolling schedule.

Children's privacy

OpenRoster is not directed to children and children cannot hold an account. If we learn that a person under 18 has created an account, we will delete it. A parent or guardian may review, export, or delete their child's information at any time using the tools above, or may refuse further collection by deleting the player record.

Security

Data is encrypted in transit. Passwords are hashed. Access to player data is checked on every request against the signed-in adult's relationship to that player or team. No method of storage is perfectly secure, and we will notify affected account holders of a breach as the law requires.

Changes to this policy

If we make a material change, especially one affecting how player information is used or shared, we will notify account holders and ask for consent again where required before the change takes effect.