Skip to main content
Club staff reviewing registration paperwork and consent forms at a check-in table
Operating controlsRecords Room · Season Archive

How ClubOS handles safety and data

A factual look at the age-aware access, consent, audit, and data controls operating in ClubOS.

COPPA
GDPR
CCPA
KOSA
UK Code

Controls informed by youth-privacy requirements

These laws and frameworks inform product design. Whether they apply depends on the club, user, location, and processing involved.

COPPA

Under 13

Children's Online Privacy Protection Act · United States

Registration collects date of birth and routes under-13 accounts into guardian-consent workflows.

Control documented

GDPR Art. 8

Under 16

General Data Protection Regulation, Article 8 · EU / EEA

Age and guardian workflows support consent handling for younger users in the EU and EEA.

Control documented

UK Children's Code

Under 18

Age Appropriate Design Code · United Kingdom

ClubOS uses age-aware experiences and conservative defaults for younger users.

Control documented

CCPA/CPRA

Under 16

California Consumer Privacy Act / Privacy Rights Act · California, USA

ClubOS does not sell personal data. Account workflows support access, deletion, and portability requests.

Control documented

KOSA

Under 17

Kids Online Safety Act · United States

Youth-safety principles inform messaging, access, reporting, and content controls.

Control documented
Operating controls

Guardian-routed messaging

Age and verified guardian relationships determine how direct communication is routed.

Under 13

All messages blocked

All messages blocked. Parents communicate on their behalf.

Ages 13-15

Guardian approval required

Direct messages require guardian approval before delivery.

Ages 16-17

Guardian-visible

Direct messages visible to guardians in their feed.

18+

Standard messaging

Standard direct messaging.

Age group is derived from the date of birth provided at registration. Guardian changes and age-category corrections follow authenticated workflows and create audit evidence.

Data protection

Your data, protected at every tier

Data classification determines required encryption, access, audit, and retention controls.

T1

Tier 1 — Most Protected

Passwords, API keys, encryption keys

AES-256-GCM encryption
T2

Tier 2 — Child PII

Child personal data, health information, guardian links

AES-256-GCM encryption + field-level security
T3

Tier 3 — Adult PII

Adult personal data, payment details, messages

Access control lists + audit logging
T4

Tier 4 — Club Data

Events, rosters, schedules

Role-based access control

Accountability you can trust

Sensitive administrative and data-rights actions create append-only, tamper-evident evidence.

  • Append-only audit logs with hash-chain integrity
  • Sensitive administrative actions recorded with actor and scope
  • DSAR deletion and portability workflows
  • Retention rules vary by record type and legal obligation

DSAR-ready by default

Verified access, export, and deletion requests enter tracked workflows. Completion depends on identity checks, service coverage, lawful retention, safety, and the rights of others.

Data access requests
Deletion workflows
Data portability export
Consent audit trails

See how ClubOS protects your community

Talk to us about the operating controls behind ClubOS.