Youth Safety First

Compliance isn't an afterthought. It's our architecture.

Every decision we make starts with one question: how does this protect the kids in your care? Five regulations. Built in from day one.

COPPA
GDPR
CCPA
KOSA
UK Code

Every major regulation. Built in, not bolted on.

We don't treat compliance as a checkbox. These are architectural constraints.

COPPA

Under 13

Children's Online Privacy Protection Act · United States

Children under 13 require verifiable parental consent before we collect any data. Guardian approval gates all account creation for this age group.

Compliant

GDPR Art. 8

Under 16

General Data Protection Regulation, Article 8 · EU / EEA

Children 13-15 in EU/EEA require parental consent. Our locale-aware consent flows adapt automatically based on the child's country of residence.

Compliant

UK Children's Code

Under 18

Age Appropriate Design Code · United Kingdom

Children under 18 receive age-appropriate design and maximum privacy by default. No dark patterns. Data minimization enforced throughout.

Compliant

CCPA/CPRA

Under 16

California Consumer Privacy Act / Privacy Rights Act · California, USA

Children under 16 must opt-in to any data sale. We don't sell data — period. California residents have full DSAR rights.

Compliant

KOSA

Under 17

Kids Online Safety Act · United States

Duty of care for users under 17. No harmful content recommendations, no behavioral advertising for minors, transparent algorithms.

Compliant
How it works

Guardian-routed messaging

Messages to your youngest players always go through a parent first. No exceptions.

Under 13

All messages blocked

Parents communicate on their behalf

Ages 13–15

Guardian approval required

Direct messages need guardian review before delivery

Ages 16–17

Guardian-visible

Messages visible in parent's feed

18+

Standard messaging

Direct messaging enabled

Age group is determined at registration and automatically enforced throughout the platform. Guardians can upgrade a child's age category with verification — never downgrade without admin approval.

Data protection

Your data, protected at every tier

Not all data is equal. We encrypt and protect each type appropriately.

T1

Most Protected

Passwords, API keys, encryption keys

AES-256-GCM encryption
T2

Child PII

Child personal data, health info, guardian links

AES-256-GCM + field-level security
T3

Adult PII

Adult personal data, payment details, messages

Access control lists + audit logging
T4

Club Data

Events, rosters, schedules

Role-based access control

Accountability you can trust

Every action that touches personal data is logged. Immutably.

  • Append-only audit logs with hash-chain integrity
  • Every PII access and modification is logged
  • DSAR deletion and portability workflows built in
  • Safeguarding records retained until age 25+7
  • Guardian consent changes are immutably recorded
  • Auth events logged for every account

DSAR-ready by default

When a family requests their data or deletion under GDPR or CCPA, we have automated workflows for that. No manual scrambling. No compliance exposure.

Data access requests
Deletion workflows
Data portability export
Consent audit trails

See how ClubOS protects your community.

Every club on ClubOS gets the same compliance architecture. No upgrades required.

ClubOS - Transform Your Sports Club