OneClub OS Privacy Notice
Version 2026-09-10 · Effective September 10, 2026
What changed
- Staff and player users aged 13 to 17 accept their own account terms without parent onboarding for basic access. The parent-operated player flow remains for children under 13. Adult-only responsibilities and separate optional permissions remain protected.
Effective September 10, 2026. This version does not amend a signed club agreement or change a historical acceptance. Restricted features remain unavailable until the required controls and permissions are verified.
Go Maximus Enterprises LLC operates OneClub OS and provides club-management software to sports organizations ("clubs"). Your club decides what information to enter into the platform and how it is used inside the club; OneClub OS processes that information to provide the platform. In the language of U.S. state privacy laws, your club generally directs its club data and we process it to provide the service. We separately determine purposes for our account security, service administration and consent records; these descriptions do not remove either party’s legal duties.
This notice explains what we collect, where it comes from, how it is used and protected, who we share it with, how long we keep it, and the rights available to you. Two companion notices cover specific categories in more detail: the Consumer Health Data Privacy Policy for wellness, injury, and treatment information, and the Children’s Privacy Notice for players under 18.
Questions or requests: legal@oneclubos.com. Legal notices: legal@oneclubos.com.
We reuse current valid permissions for their covered purposes. Existing signed adult-player or guardian permission can be assessed against the actual current collection, sharing, recipients and processors, with evidence of the original notice and the current notice provided. The original document, signature date and versions are preserved; the current assessment and its reasons are recorded separately. An approved assessment supports only its identified scope and period, and does not establish legal sufficiency merely because a form was completed. Missing, expired, withdrawn or materially changed coverage remains restricted until resolved.
1. What we collect and where it comes from
We collect and retain age information, its source and review history to decide whether account access is permitted. Staff age confirmations distinguish ages 13 to 17 from adults without requiring a birthdate. A staff role alone does not establish age. Staff aged 13 to 17 can accept for basic access without a parent flow; adult-only responsibilities, including guardian verification, independent privacy review and staff health workspaces, still require adulthood. Player birthdate routing and staff account confirmation are separate. Player account setup uses the player’s birthdate already recorded by the club. If it is missing, the person setting up the player profile is asked for the player’s birthdate before age-based player routing can be completed. The birthdate remains separate from the parent’s own identity and age. We retain the supplied information, its source and time; supplying it is not independent age or guardian verification. Existing authoritative age information and contradictions cannot be bypassed by a new entry. The server evaluates eligibility from the recorded player birthdate and current restrictions; staff do not complete this player setup. You may request correction of your own inaccurate birthdate. Routine corrections may pass an automated review without a club administrator when the change does not override conflicting authoritative evidence or make a current or future access restriction less protective. We preserve the original information, its source and the correction decision. An accepted routine correction updates your own recorded birthdate and any player record already securely linked to your account, with a correction receipt. It cannot move an eligibility date earlier, extend a permission, override conflicting club age information or establish guardian authority. Conflicts and changes that would increase access need appropriate additional review or verification. Account setup also asks for your name, email, identity-provider credentials and the access code your club gave you where applicable. Clubs and authorized users supply the other information below. Do not create a direct account for a child under 13; use the parent’s own account and a separate child profile.
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, email, optional phone; recorded or supplied player birthdate for player setup, or the applicable staff age statement; role, club and team membership. Sign-in events are held by our identity provider | You; your club; our identity provider |
| Player profile | Name, preferred name, date of birth, jersey number, positions, preferred foot, height, weight, nationality, photograph, status, trial details, and where the club records them, contract, compensation, and valuation details | Your club’s staff; imports the club runs |
| Contacts and guardians | Player email and phone, parent or guardian name, relationship, email, and phone | Your club’s staff; you, from your own account settings |
| Wellness and availability | Self-reported readiness, sleep, soreness, mood, and body-map indicators; availability status | Players; club staff |
| Injury and availability | Availability, restrictions and return-to-play status and dates; separate confidential clinical notes restricted to authorized athletic trainers. | Players; athletic trainers and authorized staff |
| Performance and load | Authorized, necessary performance and load metrics from approved imports; source and participant provenance; evaluations and development records. Unnecessary raw fields, identifiers and coordinates must be excluded. | Club imports; coaches; players |
| Video and media | Match and training footage, clips, markers, and tags that may show players, including minors | Club uploads and connected video sources |
| Communications | Messages, group chat, posts, reactions, notification preferences, push subscription tokens, and the read-only audit view of club messaging that directors and designated staff can open | You; your club |
| Coaches Corner | Content interactions, quiz results, and coaching development records | Coaches; club administrators |
| Technical | IP address, browser and device information, timestamps, request identifiers, and error diagnostics in server logs; page analytics scrubbed of record identifiers | Automatically, when you use the platform |
| Legal records | Your acceptance of our Terms and notices: version, a fingerprint of the text you saw, time, IP address, browser, and the age statement you selected | You, at the consent step |
Our account and player forms do not request payment card data, Social Security or other government identifiers, precise device location, or biometric identifiers. Clubs must remove unnecessary sensitive information and location coordinates from uploaded files and free text. Video is stored as ordinary media and is not processed for facial recognition or other biometric identification.
2. How we use information
- To provide club membership, schedules, development, coaching and other selected functions within authorized roles, teams and purposes.
- To maintain age, guardian, permission and source-rights evidence, and protect account and participant safety.
- To send generic reminders or service notifications. Health values, diagnoses and clinical notes do not belong in email, push, general messaging or notification previews. Authorized detail is accessed in its restricted workspace.
- To provide support, investigate security incidents and fulfill lawful rights requests.
We do not sell personal information, use it for targeted advertising or train or fine-tune models on it. Staff help and optional coaching-content drafting are restricted to approved non-personal coaching content. Player data, health, private messages, video and GPS must not be sent to AI providers. Staff free-text AI is unavailable when the approved content policy or provider controls are missing. A staff role or a prompt warning alone does not establish that input is safe.
No current acceptance authorizes player-data AI, independent-player AI, historical-data reuse, model training or cross-club datasets. Those features remain deferred.
Planned independent-player and AI features
We plan a player experience for people without an affiliated club. It may use information a player chooses to enter to produce personal summaries, comparisons and AI-assisted sporting insights. This experience, player-data AI and model training are not enabled by this policy update. Before launch, we will explain the actual inputs, purposes, recipients, retention and choices for the selected feature.
For a direct player service, OneClub OS would be responsible for its own processing decisions and for handling rights requests directly, rather than routing them to a club you do not have. Independent-player information would not automatically become visible to a club. Moving or sharing information with a club would require an authorized, specific action.
Generating an answer for you, building comparison statistics and training or improving a model are different uses. Accepting these notices does not authorize future training on your information or reuse of historical club records. Health-related inferences receive health-data protections. Any new use that requires consent will have a separate, specific choice before it starts, with parental permission where required. Contact legal@oneclubos.com with questions.
4. Google user data
A club administrator may optionally connect a Google Drive folder to the Coaches Corner asset library. When connected, OneClub OS accesses only file metadata (file name, type, size, link, modified time, and the owner’s display name) through the read-only scope drive.metadata.readonly; we do not read, download, or store file contents. Metadata is stored scoped to the connecting club and refreshed when an administrator syncs, when the Coaches Corner portal opens, and by a daily scheduled refresh that keeps the connection current. OAuth refresh tokens are encrypted at rest with a key held outside the database.
OneClub OS’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only for the connected feature and necessary service processing, never for advertising or model training. Do not select private Drive content for an external AI workflow unless that transfer is permitted and disclosed. A club can disconnect its Drive folder at any time inside Coaches Corner (which deletes the stored tokens) or revoke access from its Google account permissions.
5. How we protect information
- Server authorization and database row-level policies restrict access to club data. Team, purpose and age restrictions also apply; administrative status is not blanket health or guardian authority.
- Providers protect data in transit and at rest. Private storage and expiring links limit access; previously downloaded copies cannot be recalled by changing an account setting.
- Health records and access evidence require restricted review. Notifications use generic content, and detailed health information is viewed only after current authorization.
- Support access and administrative changes require their own authorization and audit trail. No system guarantees absolute security.
If we learn of a breach of security involving personal information, we will notify the club and affected people as required by applicable law, without unreasonable delay. This draft does not claim an unverified certification or service level.
6. How long we keep information
| Information | Policy and activation condition |
|---|---|
| Club records and restricted historical health records | A documented purpose, accountable reviewer and bounded deletion schedule are required. New clinical notes and player status history are retained for 24 calendar months after the player’s departure from the club, subject to an earlier valid erasure requirement or shorter source permission and any specific lawful hold. Existing records stay restricted pending review and are not automatically deleted. An open account or annual review alone does not justify indefinite storage. |
| Own match film | Approved target: eight calendar months after the game. Deletion requires a verified authorized export and delivery receipt. This draft is not proof that a scheduled provider deletion has completed. |
| Opponent/scouting film | Source use remains disabled. The approved policy, if separately authorized in future, is 48 hours after the game; expiry of a scouting copy must not delete an authorized own-film original. |
| Clips | Approved target: 12 calendar months from clip creation. Provide seven days’ advance export notice. Source rights and participant permissions apply independently. |
| Export packages | Private authorized delivery only. Deletion of hosted footage waits for verified export and delivery receipts. Archive availability ends 30 days after confirmed deletion from the streaming provider; a scheduled date does not start that clock. A delivery failure does not authorize ordinary retention deletion. A lawful deletion or revoked right must be assessed separately and cannot be blocked indefinitely by an export promise. |
| Training video and footage without a recorded match date | No automatic match deadline is assumed. New use requires an approved bounded retention schedule. Existing items stay restricted pending a specific review and lawful deletion or authorized disposition. |
| New wellness, health measurements, GPS and sanitized import records | Approved policy: new wellness, health measurements (height and weight), and GPS records are retained for 24 calendar months from collection. Sanitized import files are retained for 90 days after successful import. A shorter source permission or a valid erasure requirement takes priority. Failed or incomplete imports require restricted review; the successful-import clock must not be fabricated. Existing records stay restricted pending review and are not automatically deleted under this new schedule. |
| Acceptance and guardian evidence | Retained while needed to evidence the agreement or a specific permission, dispute or legal duty under a documented bounded schedule. Append-only history is not blanket permission for perpetual retention. |
| Accounts | Deactivation ends access; it does not prove identity-provider erasure, file deletion or removal from club records. A verified erasure request tracks those separately and explains any lawful scoped hold. |
| Staff AI conversations | Application conversation history has a maximum of 30 days in active storage, with clear-history controls. Provider logs and other retained records are separate and follow the verified provider configuration described above. |
| Backups and operational logs | Actual provider windows and request-specific deletion deadlines must be verified before real-data activation. Restored data must be screened against prior deletions and withdrawals before use. Applicable legal deadlines control; this is not an unspecified backup exception. |
7. Your U.S. state privacy rights
Depending on where you live, state law may give you rights over personal information, including to know what is held about you, to access it, to correct it, to delete it, to receive a portable copy, to opt out of its sale, of sharing for targeted advertising, and of profiling that produces legal or similarly significant effects, and not to be discriminated against for exercising those rights. We honor these rights for every user in every state, whether or not a particular statute applies to us, and regardless of the applicability thresholds in those statutes.
Contact legal@oneclubos.com or your club. You may request access, correction, withdrawal or deletion without accepting a new notice or opening a new account. We verify identity and authority using proportionate evidence, route club-controlled requests and perform our own duties. We respond within 45 days; where law permits, one additional 45-day extension requires notice and reasons during the initial period. Appeals receive a written response within 45 days; a denial explains how to contact the applicable attorney general. Requests, downstream recipient notices, provider completion and any narrowly justified hold are tracked separately.
We do not sell personal information and do not share it for targeted advertising, so there is nothing to opt out of; we treat browser Global Privacy Control signals as an opt-out request in any case. We do not use personal information for profiling that produces legal or similarly significant effects.
State-specific notes:
- California. This notice serves as our notice at collection. The categories in Section 1 map to the CCPA categories of identifiers, personal records, protected classifications (age and, where a club records it, nationality), commercial information, internet activity, geolocation (none precise), audio and visual information, professional information, and sensitive personal information (health, and precise data about children). We do not sell or share personal information and have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16. California residents may also request a list of third parties to whom we disclosed personal information for their direct marketing purposes; we make no such disclosures.
- Washington, Nevada, and Connecticut. Wellness, injury, and treatment information is consumer health data under the Washington My Health My Data Act, Nevada SB 370, and Connecticut law. The Consumer Health Data Privacy Policy explains the consents we obtain, how to withdraw them, and how to request deletion.
- Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. The rights above apply, including the right to appeal a denial. Health information and personal information of a known child are sensitive data; we process sensitive data only with the consent your club obtains and records, as described in the companion notices.
- Maryland. We do not sell, and do not process for targeted advertising, the personal data of anyone we know to be under 18, and we collect only the data reasonably necessary for the platform.
- Texas. Where we know a user is a minor, we support parents and guardians through the club in supervising the minor’s use, as described in the Children’s Privacy Notice.
- Illinois and Texas biometrics. We do not collect biometric identifiers or biometric information.
- New York and Massachusetts. Additional security requirements may apply to covered information. Contact us about the safeguards described in this notice; additional requirements depend on the circumstances.
- Nevada. We do not sell covered information as defined in NRS 603A.
8. Children
For children under 13, the parent or legal guardian operates their own account with a separate child profile. The parent overview uses the player dashboard’s presentation with parent-specific wording. It currently shows authorized teams, upcoming team events and completed shared development plans; it does not yet provide every player-portal feature. The child must not use the parent’s credentials. A parent confirmation records the statement but does not establish identity, parental authority or required permission.
Direct accounts for children under 13 are not available, including when a guardian permission record exists. Adult guardians use a separate channel under their own identity; entry confirmation does not establish a child-specific relationship or permission. Players aged 13 to 17 may accept for basic personal account access, subject to current club membership, age information and applicable restrictions. Optional health, media, messaging and external-delivery permissions remain separate, and player-data AI remains unavailable. Known minor staff remain subject to existing staff eligibility and safeguarding restrictions. A player’s acceptance or age correction cannot override a verified parent’s withdrawal, an account restriction, an unresolved age or safeguarding hold, or inactive club membership. Verified guardians retain their available supervision, privacy-request and withdrawal rights. A missing optional permission restricts the affected purpose; it does not by itself require a new signature for an already permitted purpose. Additional restrictions apply where required by law or an applicable club safeguarding policy. See the Children’s Privacy Notice.
The planned handover will be available only after its account and permission controls have been implemented and verified. When the server establishes that the player has reached 13 and meets the current account requirements, a popup will offer the verified parent a handover to the player’s own email and account. The player must verify their own email and accept the current terms before the new player access is activated. The parent’s identity and personal account, the player’s history and original evidence remain intact. Handover grants no optional permissions. Valid guardian-controlled permissions remain subject to their original scope, expiry and withdrawal. A pending, expired or canceled handover does not change existing account control.
10. Where information is processed
We operate from the United States. Our providers may store or process information in the United States and other countries as needed to deliver their services. Locations depend on the service, configured hosting region and global delivery or support infrastructure. Contact us for information about the services used by your club and applicable transfer safeguards.
11. Changes to this notice
We will update this notice as the platform evolves. Material changes are announced to club administrators and, because acceptance is recorded per version, every user is shown the new version with a summary of changes at their next sign-in. Use of the platform is also governed by our Terms of Service.