Privacy Policy

Effective 2026-09-17. Applies to zionball.com and the Zionball app.

Draft This page's wording is a draft awaiting the owner's review. The facts it states about what is stored, for how long, and how to delete it are generated from the site's own configuration and are current.

Zionballhelps softball families find college camps and understand which programs are likely to be recruiting a player's position and class year. Most of the people who use it are high-school players and their parents. This policy says what we hold, why, who can see it, how long we keep it, and how to delete it. A table-by-table technical appendix is at the end for anyone who wants to check the details against the code.

The short version

Who we are

Zionballlists college softball camps and models each program's recruiting need from its own public roster history. It is run by its owner, who you can reach through the contact form. There is no staff with access to your data beyond the owner.

Information we collect

What you give us

Collected automatically

From payment providers

When you subscribe, Stripe (on the website) or Apple (in the app) sends us a customer id, a subscription id, your plan and its renewal date. We never see or store a card number.

What we do not collect

Precise location. Your contacts. Advertising identifiers. Anything from data brokers. We do not run third-party analytics or advertising code, and we do not use your information to train any model.

Public college-roster information

To estimate each program's recruiting need we copy the rosters NCAA programs publish on their own athletics websites: player names, positions, class year, height, hometown, high school, and roster changes season to season. We use this only to model a program's recruiting pattern — we do not build profiles of those athletes or combine this data with anything a Zionball user gives us. A college athlete who would like their entry removed from our copy can ask through the contact form.

Who can see it

Nothing about a player is public by default, and there is no public directory of players. Camp reviews are private to the person who wrote them; the structured ratings on a review may be pooled into an anonymous camp-level figure, never the free-text note.

Companies that process data for us

We use a small number of service providers to run Zionball. Each may use your information only to provide its service to us, under its own terms and privacy policy.

We will disclose information if required by legal process, to enforce our Terms of Service, to investigate fraud or abuse, or to protect someone's safety — telling you first where the law allows it. If Zionball is ever sold or merged, your information transfers with it under this same policy, and we will email account holders first. We do not sell personal information and we do not share it for advertising.

How long we keep it

The rule is simple: we keep information while it is doing the job you gave it to us for, and delete it when it is not. Everything you enter is deleted the moment you delete your account, except the fixed windows below — the same numbers our cleanup job reads, so this page and the job cannot disagree.

Two things fall outside your account's cascade. Sign-in security logs (above) are kept by our authentication system and are not yet on a fixed deletion schedule, though a specific entry is removed if you ask. And routine encrypted database backups exist briefly for disaster recovery, are rotated on our provider's regular schedule, and are never used to reconstruct a deleted account.

Full table, by database location

Your account

What identifies you to the site and lets you sign in.

WhereWhat it holdsWhyKeptOn deletion
auth.usersemail address, a hashed password, sign-in timestampssigning in; confirmation and password-reset mailfor as long as the account existsdeleted with your account
auth.identitiesfor a Google or Facebook sign-in: your id at that provider, and the name, email address and profile-picture link it sentsigning in with Google or Facebookfor as long as the account existsdeleted with your account
usernamesthe username you chosesigning in with a username; the name shown in the headerfor as long as the account existsdeleted with your account
account_roleswhether the account is a player, a parent/guardian or a coachwhich pages and invitations apply to youfor as long as the account existsdeleted with your account

Sign-in security

Written by our authentication system itself, not by this app, when you sign in.

WhereWhat it holdsWhyKeptOn deletion
auth.sessionsthe IP address and browser/device description of each device you are signed in onrecognising a stolen session or an unusual sign-inuntil you sign out or the session expiresdeleted with your account
auth.audit_log_entriesthe account's email address, its IP address, and the type of sign-in event (sign-in, password reset, and similar)investigating a break-in attempt or a compromised accountkept by our authentication system; it is not yet on a fixed automatic deletion schedule, but a specific entry is removed if you askremoved on request

Player profile, stats and academics

Entered by the player or their guardian. Most players here are under 18; see the section on minors.

WhereWhat it holdsWhyKeptOn deletion
player_profilesname, birthdate, positions, graduation year, high school, GPA, and the Athlete Resume fields (hometown, phone, team, coach contact, social handles, achievements, photo and logo paths)the recruiting need shown for your position and class year; the resume; the onboarding wizardfor as long as the account existsdeleted with your account
player_measurablesmeasured athletic figures (pop time, throw velocity, sprint times, exit velocity) with datesyour profile and resumefor as long as the account existsdeleted with your account
player_reported_statsseason stat lines you enteredthe fit-match comparison against each program's recruitsfor as long as the account existsdeleted with your account
core_coursescore courses, grades and test scoresthe academic eligibility summaryfor as long as the account existsdeleted with your account
resume_generationswhen you generated a resume (a count, not the file)the free tier's monthly resume limitfor as long as the account existsdeleted with your account
storage:resume-assetsthe athlete photo and team logo you uploadedthe Athlete Resumefor as long as the account existsdeleted with your account

Schools, camps and your recruiting board

What you follow, save, track and report.

WhereWhat it holdsWhyKeptOn deletion
school_subscriptionsthe schools you followcamp alerts for those schoolsfor as long as the account existsdeleted with your account
saved_campscamps you saved, marked going or attended, and their board stageMy Camps and the recruiting boardfor as long as the account existsdeleted with your account
camp_reviewsreviews you wrote after a camp: structured ratings (coach interaction, whether it ran as an evaluation, whether you heard back) and an optional private noteyour own recruiting board; the structured ratings (never the note) may be pooled into an anonymous camp-level figure shown to other familiesfor as long as the account existsdeleted with your account
event_reportscamps you reported as incorrectalerting us when several people report the same listingfor as long as the account existsdeleted with your account
school_alert_logwhich camp alerts we sent younever sending the same alert twicefor as long as the account existsdeleted with your account
crm_touch_logwhich lifecycle reminders we sent you and whenthe frequency cap on reminder mailfor as long as the account existsdeleted with your account
board_add_tokenssingle-use links from alert emailsadding a camp to your board from an email with one clickuntil used, or 30 daysdeleted with your account

Plan and billing

Card details are never held here; Stripe (and, in the app, Apple) hold them.

WhereWhat it holdsWhyKeptOn deletion
billing_accountsyour plan, Stripe customer and subscription ids, renewal date, the calendar-feed tokenwhich tier you are on; the calendar feedfor as long as the account existsdeleted with your account
plan_historyeach change of plan and whencohort retention reportingfor as long as the account existsdeleted with your account
downgrade_comms_sentthat we sent you a one-time notice about a plan changesending it oncefor as long as the account existsdeleted with your account
coach_promo_redemptionsthat a coach's discount code was used at checkoutattribution for coach discount codeskept for reporting, without the personkept without any reference to you

Alerts, email and messages

Who we email, what they asked for, and what you wrote to us.

WhereWhat it holdsWhyKeptOn deletion
alert_recipientsemail addresses you added to receive your alerts, and whether they confirmedsending camp alerts to both parents or a coachfor as long as the account existsdeleted with your account
email_preferenceswhich reminder streams you have turned off, and your unsubscribe tokenhonouring one-click unsubscribe per streamfor as long as the account existsdeleted with your account
signup_comms_sentthat we sent you a one-time follow-up after you signed upsending it oncefor as long as the account existsdeleted with your account
push_subscriptionseach phone or computer you turned notifications on for: the push service's address for it, its encryption keys, a platform label (iPhone, Android, computer), its time zone, and when it last opened the appcamp alerts on your lock screen, delivered in your device's daytime180 days after the app last opened, or sooner if the push service reports the device gonedeleted with your account
push_outboxeach camp alert that was emailed to you and is queued for your devices: the school, the camp, a title and a one-line summarydelivering the same alert as a notification30 days once delivered or expireddeleted with your account
push_deliveriesthat a notification was sent to one of your devices, and whether the push service accepted it — no contentnever sending the same alert to the same device twice; counting opens90 daysdeleted with your account
subscribersan email address, a state and a graduation year for the daily digest (no account needed)the email digest of new campsuntil you unsubscriberemoved on request
contact_messagesa name, an email, an optional phone and your message from the public contact formreplying to you180 daysexpires on its own
feedback_submissionsfeedback you sent while signed inreplying to you and improving the productfor as long as the account existsdeleted with your account

Guardians and coaches

Relationships you agreed to. A coach sees a player's data only after both sides said yes.

WhereWhat it holdsWhyKeptOn deletion
guardian_linkswhich parent/guardian account is linked to which player account, and its statusa guardian managing a minor's accountfor as long as the account existsdeleted with your account
teamsa coach's team names and organisationthe club hubfor as long as the account existsdeleted with your account
team_linkswhich player accepted which team's invitation, and who initiated itthe consent that lets a coach see a player's recruiting progressfor as long as the account existsdeleted with your account
coach_invitesa hash of the invited coach's email (never the address), the note, and the statusa family inviting its coach30 daysdeleted with your account
coach_preferencesa coach's default teamthe club hubfor as long as the account existsdeleted with your account
coach_promo_codesa coach's discount codesdiscounts for the coach's familiesfor as long as the account existsdeleted with your account
coach_verified_statsstat lines a coach uploaded about a player, the file row they came from, and any disputecoach-verified stats in the fit-match; the dispute trailfor as long as the account existsdeleted with your account
team_stats_pending_rowsrows from a coach's upload not yet matched to a playermatching an upload to the rosterfor as long as the account existsdeleted with your account
team_level_evidencetournament results a coach attested for a team seasonthe travel-team level indexfor as long as the account existsdeleted with your account
player_team_season_linkswhich team season a player's stats belong tolevel-adjusted statsfor as long as the account existsdeleted with your account
player_goalsgoals a coach set for a player and the player's responses1:1 goal trackingfor as long as the account existsdeleted with your account
coach_endorsementsan endorsement a coach wrote for a playerthe player's profilefor as long as the account existsdeleted with your account

Usage analytics

How the site is used, without who you are.

WhereWhat it holdsWhyKeptOn deletion
eventsactions such as saving a camp or opening a plan page, with the account id while it exists, and the first marketing source you arrived from; if you answer the optional "How did you find Zionball?" question during setup, your answer and anything you type in its optional "Which one?" box (for example a coach's or club's name)funnel and attribution reportingkept, with the account reference removed on deletionkept without any reference to you
page_viewsa page path and a time — no account, no IP address, no device detailstraffic counts2 hours as raw rows, then hourly totals onlynever tied to a person
filter_usagewhich catalog filters were appliedfinding gaps in the catalogkept as countsnever tied to a person
rate_limit_eventsa request counter per key (an account id or a network address)stopping abuse1 hourexpires on its own
account_deletionsthat an account of a given type and plan was deleted, and counts of what it held — no id, no email, no nameknowing how many accounts leavekept as countsnever tied to a person

Players under 18

You must be at least 13 years old to create an account. We do not knowingly collect personal information from anyone under 13; if we learn that a profile belongs to a child under 13 we delete the profile and the account. A parent who believes a child under 13 has created an account can tell us through the contact form and we will delete it.

Most players who use Zionballare between 14 and 18. Before a player under 18 can save a profile, the site asks them to confirm that a parent or guardian is aware of it. A parent or guardian can create their own account, link it to the player's, and manage it, including deleting it. We store a player's birthdate, grades and statistics because the recruiting-need and fit-match features depend on them, and for no other reason. A player under 18 can delete anything they posted, or the whole account, at any time.

A coach sees a player's recruiting information only after both sides have agreed, and then only the fixed list of fields described above. Either side can end the link.

Payments

Subscriptions on the website are billed by Stripe; in the iPhone app they may be billed by Apple. We never see or store your card number. We store the identifiers those companies give us so we know which plan you are on. No payment card data is held by this site.

Cookies and analytics

The site sets a session cookie so you stay signed in, and a first-touch cookie that remembers which campaign brought you here (for 90 days) so we know what marketing works. There are no advertising cookies, no advertising identifiers, and we do not collect your location or your contacts. Page views are counted without who you are: no IP address and no device details are stored. We do not track you across other sites, so there is nothing for a browser's Do Not Track signal to switch off.

Email and notifications

We send account mail (confirmation, password reset), the camp alerts you asked for, and a small set of reminders about camps you saved, each of which you can turn off separately from any of those emails. If you turn on notifications on a phone, the same camp alerts arrive there.

Security

Traffic to and from Zionball is encrypted in transit, and our providers encrypt stored data at rest. Passwords are stored only as one-way hashes. Database rules restrict each account to its own rows, and the recruiting-model tables are never readable directly from a browser. No method of storage or transmission is perfectly secure; if a breach affects your information we will notify you as required by law.

Your choices

Where your information is kept

Zionball is a United States service. Our database and hosting are in the United States. If you use Zionballfrom another country, your information is transferred to and processed in the United States, where privacy law may differ from your country's.

Changes

When this policy changes, the effective date at the top changes with it. If a change materially affects how we use information you have already given us, we will email account holders before it takes effect. Because the data inventory is generated from the site's configuration, it updates the moment the site does. Our Terms of Service cover the rest of using Zionball.