Legal
Privacy Policy
Drabble holds records about young athletes. That makes this document more than a formality, so it is written to be read — plainly, and specifically about what this product actually does.
1. Who we are
Drabble is operated by [[LEGAL ENTITY NAME]] ("Drabble", "we"), [[REGISTERED ADDRESS]]. Questions about this policy, or a request about your data, go to [[PRIVACY CONTACT EMAIL]].
Drabble is sold to organizations — clubs, schools, teams and families. When an organization enters information about an athlete, the organization decides what to collect and who may see it; we process it on their behalf and under their instructions.
2. What we collect
Information organizations enter
| Category | What it is | Why |
|---|---|---|
| Roster records | Athlete and coach names, birth year, positions, jersey numbers, team and season membership | To identify who a statistic belongs to |
| Performance data | Game events, statistics, lineups, rotations, practice and development records | The core purpose of the product |
| Photographs and video | Media uploaded by an operator, optional captions, and the athletes tagged in it | To annotate a game record |
| Contacts and guardians | Names, phone numbers, email and postal addresses, relationship to the athlete, and a reachability note | So a coach can reach a family in an emergency |
| Venues and schedules | Locations, courses and game details | To organize play |
We deliberately collect a birth year rather than a full date of birth, and we hold no medical or health information — no diagnoses, medications, physicians, insurance or hospital preferences. That was considered during design and rejected.
Information about accounts
Drabble accounts are issued through our identity service at id.scaledapps.com, which holds the account holder's email addresses, phone numbers, postal addresses and sign-in credentials. Drabble reads those; it does not store its own copy.
Information collected automatically
- Public page views. When someone views a public
/@handlepage we record the date, the entity viewed, a hashed IP address and the host of the referring site. We do not store raw IP addresses, full referring URLs, or any access code contained in them. - Photograph metadata. Cameras write a capture time and sometimes GPS coordinates into a photograph. We read those to place a photo in the right moment of a game, and we remove them from the stored file so they cannot travel with a downloaded image. Coordinates are kept only in our database, are never displayed, and are never published.
- Operational logs. Standard server logs, and an audit record of who viewed a child's contact details and of any support session conducted on an account's behalf.
What we do not collect
- No advertising or marketing trackers, no analytics products, no cookies for advertising.
- No biometric identifiers. We do not run facial recognition, face grouping or face-geometry extraction on any photograph or video, and we do not tag people automatically.
- No third-party content hosts. Fonts, styles and scripts are served from our own servers, so viewing a Drabble page does not disclose your address to anyone else.
- No precise device location. The only coordinates we ever hold are the ones a camera wrote into a photograph.
3. What is public, and who decides
Nothing is public by default because it exists. Every organization, team, athlete, coach, game and series carries its own visibility setting — visible (anyone with the link), hidden (the page does not exist to anyone without a role), or secured (reachable only with a code the organization issues). An organization sets its own policy and can override it record by record.
Public pages are excluded from search engine indexing. Contact and guardian information is never public, under any setting — it cannot be placed on a public page, included in an automatically generated recap, or exposed through any public surface.
4. Children
Drabble is a tool for the adults who run youth sports. Accounts are intended for adults — coaches, administrators, and parents or guardians — and we do not knowingly collect personal information directly from a child under 13. Information about a young athlete reaches Drabble because their organization or their guardian entered it.
A parent or guardian may ask us to see, correct or delete information about their child by writing to [[PRIVACY CONTACT EMAIL]], or by asking their organization, which can do it directly. We will not condition a child's participation in the product on disclosing more information than is needed.
5. How we use information
To run the product for the organization that entered it: recording statistics, producing reports and recaps, rendering the pages that organization chose to publish, sending the messages it asks us to send, and keeping the service secure and working.
Automatically generated written recaps are produced by a language model that we run on our own hardware. Athlete data is not sent to a third-party model provider and is not used to train anyone's model.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not profile anyone for advertising purposes.
6. Who else touches the data
Only service providers who need it in order for the product to function:
| Provider | What they handle |
|---|---|
| Cloudflare (R2) | Storage of uploaded photographs and video |
| Microsoft (Graph) | Delivery of transactional email — the address a message is sent to, and the message itself |
| Microsoft Azure (Communication Services) | Text-message delivery. Configured but not in use; enabling it would require a separate, express opt-in. |
| Stripe | Payment processing for paid plans. Card details are entered on Stripe's own hosted checkout page and are never sent to, or stored on, our servers — we hold only a customer reference, the plan bought, and whether it is paid. |
No one hosts the application for us. Drabble and its database run on virtual machines on hardware we own and operate ourselves. The three companies above handle specific, named jobs — storing media, sending a message, taking a payment — and none of them holds the database or the records inside it.
We may also disclose information where the law requires it, or to protect someone's safety.
7. How long we keep it
Records are kept while the organization's account is active, because a career of statistics is the point of the product. Deleted media is removed from storage 30 days after deletion. [[RETENTION SCHEDULE — the remaining categories, including contact records and access logs, need a stated period here; see the pending purge work before publishing.]]
An organization can delete its records at any time. On request we will delete an account and its data, subject to anything we are legally required to retain.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete or obtain a copy of your personal information, and to object to certain processing. Athletes and families can exercise these rights through the organization that holds their record, or by contacting us directly at [[PRIVACY CONTACT EMAIL]]. We will not treat you differently for exercising them.
Automated messages we send carry a way to stop receiving them. Emergency contact is deliberately exempt: if an athlete is hurt, everyone on the emergency list is contacted regardless of messaging preferences.
9. Security
Access is controlled by role, scoped to the organization and record. A person's contact details can only be read by someone with administrator authority over that athlete, and every such read is logged. Media for a non-public game is stored privately and served through short-lived signed links.
No system is perfect, and we do not claim otherwise. If a breach affects your information we will notify you as required by law.
10. Changes
If we change this policy materially we will update the date above and notify account holders. Continued use after a change means the new version applies.
11. Contact
[[LEGAL ENTITY NAME]]
[[REGISTERED ADDRESS]]
[[PRIVACY CONTACT EMAIL]]