Legal

Privacy Policy

Last updated: August 5, 2026 · Effective: August 5, 2026

1. Overview

This Privacy Policy describes how Dot Win LLC, a Missouri limited liability company doing business as "SOLO" or "SOLO Soccer" ("SOLO," "we," "us," or "our"), collects, uses, discloses, retains, and otherwise processes personal information in connection with the websites, mobile experiences, applications, services, content, and tools we provide (collectively, the "Services"), including but not limited to the websites and applications located at playsolo.soccer, mysolo.team, mysolo.life, mysolo.soccer, and mysolo.id (each, a "Site" and together, the "Sites").

This Privacy Policy applies uniformly across every SOLO domain. Visiting the Services from any of the Sites listed above means you have read, understood, and agreed to the practices described here. If you do not agree, do not use the Services.

This Privacy Policy is incorporated by reference into our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.

2. Definitions

"Personal Information" means information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device, as further defined under applicable law.

"Athlete" means an individual whose participation, profile, or activity is tracked through the Services — whether through an adult athlete account they manage themselves, or a minor player account their family manages on their behalf.

"Parent" or "Guardian" means a parent, legal guardian, or other adult who holds real family authority over an Athlete who is a minor, as recognized within the Services.

"Family" means a Parent's or Guardian's account together with the Athletes, and any other Parents or Guardians, linked to it.

"Minor Player Account" (or "player login") means an account for a minor Athlete that a Parent or Guardian creates and controls directly, as described in Section 7.5.

"Coach" means a coach, team manager, or other team staff member who uses the Services to run a team, including its roster, schedule, feed, availability, documents, and, where applicable, treasury tools. SOLO does not currently offer any tool for coaches, scouts, or recruiters to search for or browse Athletes outside of their own team; if we build one, we will update this Privacy Policy before it becomes available.

3. Information We Collect

3.1 Information you and your family provide

We collect information you provide when you create an account, complete profile fields, join or run a team, register for events, upload media, send messages, contact us, consent on behalf of a minor, or otherwise interact with the Services. This may include:

  • Identity and contact information: full name, preferred name, email address, phone number, date of birth, profile photo, and a mailing address if you provide one.
  • Athletic and academic information: position, jersey number, height, weight, dominant foot, club or team, graduation year, training goals, availability, and — only if you choose to add it — academic information such as GPA.
  • Photos and video: profile photos, and any photos or video you or your family upload to a team or public feed post, including game footage. Section 10 explains how we describe an upcoming feature that would analyze uploaded game footage.
  • Team operations data: schedules and event details, RSVP responses, attendance records, team chat messages (including any automatic translations), tasks, and documents you upload or acknowledge.
  • Payment and financial data: billing information processed through Stripe on our behalf — SOLO never stores your full card number — along with transaction history, subscription status, and dues or payment-contract and installment records.
  • Team debit-card enrollment data: if your team's cardholder completes enrollment for the team debit-card program, we collect their date of birth and Social Security Number, subject to the safeguards described in Section 3.3.
  • Notification contact points: your phone number (used for SMS notifications), push-notification tokens if you enable push notifications, and your email address.
  • AI assistant activity: the questions you ask SOLO's AI assistant and the account or team context used to generate a response. See Section 10.
  • Consent, safety, and moderation records: if a guardian grants consent for a minor's public sharing (Section 7.3), we record that action — including the typed name entered, the IP address, and browser/device (user agent) information — as evidence the consent was properly given. We also keep the abuse reports you submit and the resulting moderation decisions. Section 11 describes how long we keep these records.
  • Account credentials: authentication identifiers, magic-link tokens, OAuth identifiers issued by sign-in providers (such as Google), and session cookies.

3.2 Minor player account activity

If your Family includes a Minor Player Account, we log activity on that account so guardians can see what their child is doing: logins, page views, messages sent, RSVP responses, and cheers given. This activity is visible to the account's linked guardian — that visibility is a feature of the product, built for family oversight, not an incidental byproduct of our systems. Section 7.5 has more detail on how Minor Player Accounts work.

3.3 Team debit-card enrollment (KYC data)

If your team participates in SOLO's team debit-card program, the team's designated cardholder is invited to a dedicated enrollment page where we collect their date of birth and Social Security Number.

We collect this information because federal law governing our banking partners — specifically, the customer-identification requirements imposed by Section 326 of the USA PATRIOT Act — requires them to verify the identity of the person who will hold a debit card issued against a team's funds. Our banking partners for this program are Bluevine and Coastal Community Bank.

This data is encrypted at the application level (AES-256-GCM) before storage. It can be decrypted only by a single, specifically named account holder we've authorized to view it, and every time it is viewed, we write a record to an audit trail (Section 12 has more on how we secure this data). Once the debit card is issued, we purge the Social Security Number and date of birth from our systems — we do not retain them beyond that point. Enrollment also requires the cardholder's explicit acceptance of a Cardholder Agreement.

3.4 Information collected automatically

When you use the Services we and our service providers automatically collect:

  • Device and connection information: IP address, device identifiers, browser type and version, and operating system.
  • Usage information: pages visited, features used, and the timing of your interactions with the Services.
  • Cookies and similar technologies: first-party cookies used to authenticate sessions, maintain security, and remember preferences. As described in Section 9, we do not deploy third-party advertising or analytics SDKs in the Services.
  • Geolocation: approximate location inferred from your IP address. We do not collect precise device GPS location.
  • Event-location data: addresses for events you or your team register for are geocoded and displayed on a map using Mapbox.

3.5 Information from third parties

We may receive information about you from:

  • Authentication providers (such as Google), when you sign in using a third-party identity provider — we receive your email, name, and profile picture as scoped by your consent.
  • Payment processors (Stripe), which inform us when transactions succeed, fail, or are refunded.
  • Video processors (Mux), which return processed video metadata, thumbnails, and playback assets.
  • Coaches and team managers, who add you or an Athlete in your Family to a team roster.
  • Parents and guardians, who register an Athlete on the Services and grant or manage consent on their behalf.

4. How We Use Your Information

We use the information we collect to provide, maintain, secure, and improve the Services and for the following purposes:

  • Operate the Services: create and authenticate accounts; run team operations such as schedule, roster, RSVPs, attendance, chat, tasks, and documents; operate the player, team, and public feeds described in Section 6; process payments and dues; and administer the team debit-card program described in Section 3.3.
  • Run testing events: administer standardized testing events and, where applicable, the performance data associated with them.
  • Communicate with you: respond to inquiries and support requests, and send transactional messages such as sign-in links, invites, payment receipts, and dues or event reminders, by email, SMS, and push notification.
  • Power the AI assistant: send your queries to SOLO's AI assistant, together with the account or team context needed to answer them, to our AI subprocessor as described in Section 10.
  • Maintain safety and integrity: detect, investigate, and respond to abuse reports and violations of our Community Guidelines or Terms of Service; moderate content submitted to the team and public feeds; and maintain the audit and moderation records described in Section 11.
  • Improve the Services: analyze aggregate, de-identified usage patterns to understand engagement, diagnose problems, and improve features.
  • Comply with the law: meet our obligations under applicable law — including COPPA and the bank-customer-verification requirements described in Section 3.3 — respond to lawful requests, and enforce our agreements.
  • With your consent: any other purpose disclosed to you at the time of collection or for which you give consent.

6. The SOLO Feeds: Who Can See What

SOLO has three feeds, each with a different, fixed audience. Understanding these audiences explains who can see information you or your Family post.

6.1 Player feed

The player feed is private to the Athlete and their Family. It shows upcoming items — events with your RSVP status, dues that are due — and a personal history of awards, personal records, and streaks. No one outside the Athlete's Family can see it.

6.2 Team feed

The team feed is visible only to that team's active members — coaches, managers, athletes, and linked guardians. Coaches control the team's feed settings, including whether player and parent posts publish automatically or need approval first, whether comments are open, and quiet hours. Access is enforced at the database level: there is no way to read a team's feed without being an active member of that team, and every moderation decision on the team feed requires that same active membership.

6.3 Public feed

The public feed is visible to signed-in SOLO users. As of today, it cannot be viewed by a logged-out visitor or indexed by a search engine — there is no public, unauthenticated view of it. If that ever changes, it will be a material change to how this Policy applies, and we will update this Policy and provide notice before making it.

Posts are limited to four categories — Highlight, Demo, Motivation, Coaching — and every post is reviewed by a human moderator before it goes live; nothing publishes automatically. Reactions are limited to a positive, high-five/cheer style; there is no negative reaction. The public feed does not support comments at all — that capability is disabled at the database level, not just hidden in the interface. Every public post carries a report button, and a report for a safety concern takes the post down immediately, pending review.

Only an adult can publish to the public feed, and only on behalf of an Athlete in their own Family — Minor Player Accounts cannot post there. Publishing also requires the Athlete's birthdate to be on file, the Athlete to be at least 13 years old, and active, recorded parental consent — all enforced by the database itself. Section 7 explains exactly how that consent works.

7. Children's Privacy and Parental Consent (COPPA)

SOLO is built for families with youth athletes, and many of our users are minors. This section explains what that means for a child's privacy on SOLO, and is written to give parents and guardians the direct notice called for by the Children's Online Privacy Protection Act ("COPPA") and the FTC's COPPA Rule.

7.1 Notice to parents

If your child uses SOLO, here is what we collect from them and why: an Athlete profile (name, birthdate, athletic information and, only if you choose to add it, academic information such as GPA), photos and video associated with their team or account activity, and, for a Minor Player Account, a record of that account's activity (Section 7.5). We collect only what we reasonably need to run the team, testing, and family features described in this Policy, and we do not condition your child's participation in those features on providing more Personal Information than that. Age on SOLO is based on the birthdate a parent, guardian, or the athlete provides; we do not currently use a third-party service to verify it.

7.2 Under 13: private by default

An Athlete under the age of 13 has no public presence on SOLO. Their content is never eligible for the public feed, and their profile cannot be made public — only their Family, and, for team activity, their team, can see anything associated with them. This isn't a setting anyone has to turn on: both rules are enforced at the database layer itself, so there is no path — including an administrative one — for an under-13 Athlete's content to reach the public feed or for their profile to be published. The same database layer also refuses to make any Athlete's content or profile public when no birthdate is on file, so an "unknown age" can never slip through as an adult.

7.3 13 to 17: public sharing requires your prior, recorded consent

For an Athlete between 13 and 17, nothing about them can appear on the public feed — and their profile cannot be made public — unless a Parent or Guardian with real family authority over that Athlete has given consent first, and we have a record of it. Both rules are enforced by the database, not only by an interface setting.

Only two kinds of people can give this consent: an adult who holds real family authority over the Athlete on SOLO — the same authority check we use before letting anyone publish that Athlete's profile — or the Athlete themselves, once they turn 18, consenting for their own profile. A minor can never consent on their own behalf. SOLO staff cannot grant or manufacture this consent for you; there is deliberately no administrative override.

Giving consent requires signing in to your own Guardian account and taking an explicit, affirmative action together with your typed full legal name. We keep a record of that action as evidence it was properly given: the name you typed, the IP address and browser/device (user agent) information associated with the action, and a timestamp. Today, consent is captured this way — through an authenticated action inside your account; our systems are also built to support additional verification methods, such as card-based verification, if we adopt them in the future.

You can revoke consent at any time with a single action in Family controls. The moment you do: every public post by that Athlete is unpublished immediately, and the underlying photos or video are queued for permanent deletion within 7 days (Section 11). The system will not allow a new public post for that Athlete while consent is revoked.

7.4 Your rights as a parent or guardian

You can, at any time:

  • Review the information we have collected about your child, through your Family account or by asking us directly.
  • Revoke your consent to public sharing — with the immediate unpublish and scheduled deletion described in Section 7.3.
  • Request that we delete your child's information.
  • Disable your child's Minor Player Account login, so it can no longer be used to sign in.

You can do all of this in-app, through Family controls, or by emailing privacy@playsolo.soccer. If you believe your child has given us Personal Information without your consent, contact us at that address and we will address it.

7.5 Minor player accounts

A Minor Player Account ("player login") can only be created by a Parent or Guardian — a child cannot sign themselves up. These accounts have no email address; the Parent sets and can reset the password, and can disable the account entirely at any time. Anything that would otherwise be emailed to the child — a notification, for example — goes to the guardian instead.

Because guardians are meant to be able to see what their child is doing on SOLO, we log activity on a Minor Player Account — logins, page views, messages sent, RSVP responses, and cheers given — and that activity is visible to the account's linked guardian. This is a deliberate design choice, not an incidental log.

A Minor Player Account cannot post to the public feed or to a team's broadcast channel; its only messaging channel is a coach-family thread where guardians are present by construction. Feed participation is gated by parent permission, and billing and family-administration areas are not reachable from a Minor Player Account.

8. How We Share Information

We do not sell Personal Information. We share it only as described below:

  • Within your Family: guardians on a Family account can see information associated with the Athletes in that Family, including a Minor Player Account's activity (Section 7.5).
  • With your team: when you or an Athlete in your Family joins a team, roster and team-feed information — schedule, RSVPs, attendance, chat, tasks, documents — is visible to that team's coaches, managers, and other active team members, and to linked guardians, as described in Section 6.2.
  • On the public feed: content published to the public feed — which, for a minor, requires the parental consent described in Section 7.3 — becomes visible to other signed-in SOLO users, as described in Section 6.3.
  • With service providers: we share information with the subprocessors listed in Section 9, which perform services on our behalf under contractual confidentiality and data-protection terms.
  • With legal and safety authorities: we may disclose information to comply with applicable law, lawful requests, court orders, subpoenas, or other legal process, or to protect the rights, property, or safety of SOLO, our users, or the public.
  • In connection with a business transaction: if SOLO is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, your information may be transferred to the successor entity, subject to commercially reasonable confidentiality protections.
  • With your consent: we may share information at your direction — for example, when a guardian consents to publish an Athlete's content to the public feed.

9. Service Providers (Subprocessors)

We use the following service providers to operate SOLO. Each processes Personal Information only on our instructions and only to the extent needed to perform its function.

VendorPurpose
SupabaseDatabase, authentication, and file storage
VercelApplication hosting
Cloudflare R2Media object storage
MuxVideo processing and streaming
StripePayments
AnthropicGenerates responses for the AI assistant (Section 10), under commercial API terms that restrict use of your data to providing that service — not for training AI models
ResendTransactional email
OpenPhoneSMS notifications — opt-out is honored and STOP requests are processed
MapboxEvent-location geocoding and maps

We do not use advertising networks, and we do not currently run any third-party analytics SDK in the Services. We do not sell Personal Information, and we do not share Personal Information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. If that were ever to change, and it involved a consumer we know is under 16, we would first obtain the affirmative opt-in consent the law requires before any such sale or sharing.

10. AI Processing: The 'Ask SOLO' Assistant

SOLO includes an in-app AI assistant, "Ask SOLO," currently offered as a beta feature.

When you ask it a question, your query — together with the account or team context needed to answer it — is sent to our AI subprocessor, Anthropic, to generate a response. The assistant only draws on data that the person asking is already permitted to see inside SOLO; it does not answer using another user's private information. Your conversation transcript is kept in your browser's session storage for the duration of your session — we do not maintain a permanent, server-side log of assistant conversations.

We are also developing additional AI-assisted features that are not live today. That includes a planned paid feature, Composite Score, that would analyze game footage you upload — it has not launched. When it does, we will provide notice and put an appropriate consent process in place before any footage is analyzed for that purpose. Other ideas under exploration, such as practice-audio insights and AI-drafted team-treasurer summaries, are likewise not live; any feature that would process new categories of personal information (such as audio recordings) will come with its own notice and consent before it launches.

11. Data Retention and Deletion

We keep Personal Information only as long as necessary for the purposes described in this Policy, to comply with our legal obligations, and to resolve disputes. For content on the team and public feeds, a daily automated process reviews a deletion queue and permanently removes the underlying files on this schedule:

ContentWhen it's deleted
Rejected or removed post media (photos and video)30 days after the moderation decision
Public content after a guardian revokes consentUnpublished immediately; underlying media deleted after 7 days
Posts you delete yourself30 days after deletion
Content placed under legal holdNot deleted — preserved for as long as required by law
Team debit-card KYC data (Social Security Number, date of birth)Purged once the debit card is issued
Parental-consent records and moderation recordsRetained as evidence that consent and moderation decisions were properly made

This deletion process runs automatically, every day — it isn't something that only happens if you ask. It removes the underlying storage objects (in Supabase Storage and Cloudflare R2) and video assets (in Mux); if a copy of a video is still in legitimate use elsewhere on the Services, that shared copy is not destroyed. The post record itself is replaced with a tombstone noting that it was deleted, rather than being erased in a way that would break other records that reference it.

Other categories of information — such as account identity records and transaction history — are retained for the life of the relevant account or team, and longer where we have a legal or accounting obligation to do so.

12. Security

We maintain technical safeguards designed to protect Personal Information, including:

  • Row-level security (RLS) on the database tables that hold Personal Information, and no direct access for the anonymous, unauthenticated role to those tables — where information needs to be public, such as a published public-feed post, it is served through narrowly scoped database functions that return only what's meant to be public, not open table access.
  • Authenticated, authorization-checked application routes for any operation that bypasses row-level security — never a direct path from a browser.
  • Encryption in transit (TLS) for connections to the Services.
  • Application-level encryption (AES-256-GCM) for the Social Security Number and date of birth collected for the team debit-card program (Section 3.3), independent of database-level protections, purged once their purpose is complete.
  • Audit logging of administrative access to SOLO accounts, including any use of internal tools that let SOLO staff view the Services as a user would ("impersonation").

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a security incident affects your Personal Information, we will notify you and the appropriate regulators as required by applicable law.

13. Your Rights and Choices

Depending on your jurisdiction (including California, Virginia, Colorado, Connecticut, Utah, and similar U.S. states, as well as the European Economic Area and the United Kingdom), you may have the right to:

  • Access: request a copy of the Personal Information we hold about you.
  • Correct: request correction of inaccurate or incomplete information.
  • Delete: request deletion of your Personal Information, subject to legal exceptions such as the legal-hold and record-keeping retention described in Section 11.
  • Port: request an electronic copy of your information in a portable format.
  • Restrict / Object: restrict or object to certain processing.
  • Withdraw consent: where processing is based on consent, withdraw it at any time — for a Family, this includes the parental consent described in Section 7.3.
  • Opt out of sale or sharing: as described in Section 9, we do not sell Personal Information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of today.
  • Non-discrimination: we will not discriminate against you for exercising any of these rights.

To exercise any of these rights, email privacy@playsolo.soccer. We handle these requests manually today: we will verify your identity before acting on the request, and we aim to respond within forty-five (45) days of receiving a verifiable request — the response window set by the California Consumer Privacy Act. SOLO is a Missouri company, and not every jurisdiction's privacy law applies to every user, but we apply this same process and timeline to privacy requests from users regardless of where they live. For rights specific to a child's information, see Section 7.4.

14. Cookies and Tracking

We use first-party cookies and similar technologies that are strictly necessary to operate the Services — authentication, security, and load balancing — and that help us remember your preferences. As described in Section 9, we do not use third-party advertising cookies, cross-site tracking for behavioral advertising, or a third-party analytics SDK. You can manage cookie preferences through your browser, but disabling strictly necessary cookies will prevent the Services from functioning.

Because we do not sell Personal Information or share it for cross-context behavioral advertising, there is no sale or sharing for an opt-out preference signal — such as the Global Privacy Control (GPC) — to switch off: browsers that send a GPC signal receive exactly the same treatment as browsers that don't, which is that their Personal Information is not sold or shared either way. If our practices ever changed, we would honor opt-out preference signals as required by law.

15. International Transfers

SOLO is based in the United States. If you access the Services from outside the United States, your information will be transferred to, processed, and stored in the United States and other countries where our service providers operate. We rely on appropriate safeguards (such as Standard Contractual Clauses) where required by law to protect such transfers.

17. California Privacy Notice

California residents have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"). The categories of Personal Information we collect, use, and disclose are described in Section 3.

We do not sell Personal Information, and we do not share Personal Information for cross-context behavioral advertising, as those terms are defined by the CCPA — as described in Section 9, we don't use advertising networks and we don't run a third-party analytics SDK in the Services. Because we do not sell or share Personal Information — including that of a consumer we know is under 16 — there is currently no sale or sharing for us to obtain opt-in consent for; if that were ever to change, we would first obtain the affirmative opt-in consent the CCPA requires for a known child under 16 before doing so.

The only sensitive Personal Information we collect, as the CCPA defines it, is the Social Security Number and date of birth described in Section 3.3 — collected solely for the federal bank-verification purpose stated there, encrypted, access-audited, and purged when that purpose is complete. We use sensitive Personal Information only for purposes permitted without a right-to-limit under the CCPA, so there is no "limit use" toggle needed today. To exercise your right to know, delete, or correct, contact privacy@playsolo.soccer, as described in Section 13. You may also designate an authorized agent to act on your behalf, subject to identity verification.

18. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will post the revised Privacy Policy on each Site and update the "Last Updated" date above. If we make material changes, we will provide additional notice (such as by email or in-app banner). Your continued use of the Services after the effective date constitutes acceptance of the revised Privacy Policy.

19. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:

Dot Win LLC

d/b/a SOLO Soccer

Attn: Privacy

Kansas City, Missouri, United States

Email: privacy@playsolo.soccer