
How ClubOS handles safety and data
A factual look at the age-aware access, consent, audit, and data controls operating in ClubOS.
Controls informed by youth-privacy requirements
These laws and frameworks inform product design. Whether they apply depends on the club, user, location, and processing involved.
COPPA
Under 13Children's Online Privacy Protection Act · United States
Registration collects date of birth and routes under-13 accounts into guardian-consent workflows.
GDPR Art. 8
Under 16General Data Protection Regulation, Article 8 · EU / EEA
Age and guardian workflows support consent handling for younger users in the EU and EEA.
UK Children's Code
Under 18Age Appropriate Design Code · United Kingdom
ClubOS uses age-aware experiences and conservative defaults for younger users.
CCPA/CPRA
Under 16California Consumer Privacy Act / Privacy Rights Act · California, USA
ClubOS does not sell personal data. Account workflows support access, deletion, and portability requests.
KOSA
Under 17Kids Online Safety Act · United States
Youth-safety principles inform messaging, access, reporting, and content controls.
Guardian-routed messaging
Age and verified guardian relationships determine how direct communication is routed.
All messages blocked
All messages blocked. Parents communicate on their behalf.
Guardian approval required
Direct messages require guardian approval before delivery.
Guardian-visible
Direct messages visible to guardians in their feed.
Standard messaging
Standard direct messaging.
Age group is derived from the date of birth provided at registration. Guardian changes and age-category corrections follow authenticated workflows and create audit evidence.
Your data, protected at every tier
Data classification determines required encryption, access, audit, and retention controls.
Tier 1 — Most Protected
Passwords, API keys, encryption keys
Tier 2 — Child PII
Child personal data, health information, guardian links
Tier 3 — Adult PII
Adult personal data, payment details, messages
Tier 4 — Club Data
Events, rosters, schedules
Accountability you can trust
Sensitive administrative and data-rights actions create append-only, tamper-evident evidence.
- Append-only audit logs with hash-chain integrity
- Sensitive administrative actions recorded with actor and scope
- DSAR deletion and portability workflows
- Retention rules vary by record type and legal obligation
DSAR-ready by default
Verified access, export, and deletion requests enter tracked workflows. Completion depends on identity checks, service coverage, lawful retention, safety, and the rights of others.
See how ClubOS protects your community
Talk to us about the operating controls behind ClubOS.