Legal
This Privacy Policy describes how Dot Win LLC, a Missouri limited liability company doing business as "SOLO" or "SOLO Soccer" ("SOLO," "we," "us," or "our"), collects, uses, discloses, retains, and otherwise processes personal information in connection with the websites, mobile experiences, applications, services, content, and tools we provide (collectively, the "Services"), including but not limited to the websites and applications located at playsolo.soccer, mysolo.team, mysolo.life, mysolo.soccer, and mysolo.id (each, a "Site" and together, the "Sites").
This Privacy Policy applies uniformly across every SOLO domain. Visiting the Services from any of the Sites listed above means you have read, understood, and agreed to the practices described here. If you do not agree, do not use the Services.
This Privacy Policy is incorporated by reference into our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.
"Personal Information" means information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device, as further defined under applicable law.
"Athlete" means an individual whose participation, profile, or activity is tracked through the Services — whether through an adult athlete account they manage themselves, or a minor player account their family manages on their behalf.
"Parent" or "Guardian" means a parent, legal guardian, or other adult who holds real family authority over an Athlete who is a minor, as recognized within the Services.
"Family" means a Parent's or Guardian's account together with the Athletes, and any other Parents or Guardians, linked to it.
"Minor Player Account" (or "player login") means an account for a minor Athlete that a Parent or Guardian creates and controls directly, as described in Section 7.5.
"Coach" means a coach, team manager, or other team staff member who uses the Services to run a team, including its roster, schedule, feed, availability, documents, and, where applicable, treasury tools. SOLO does not currently offer any tool for coaches, scouts, or recruiters to search for or browse Athletes outside of their own team; if we build one, we will update this Privacy Policy before it becomes available.
We collect information you provide when you create an account, complete profile fields, join or run a team, register for events, upload media, send messages, contact us, consent on behalf of a minor, or otherwise interact with the Services. This may include:
If your Family includes a Minor Player Account, we log activity on that account so guardians can see what their child is doing: logins, page views, messages sent, RSVP responses, and cheers given. This activity is visible to the account's linked guardian — that visibility is a feature of the product, built for family oversight, not an incidental byproduct of our systems. Section 7.5 has more detail on how Minor Player Accounts work.
If your team participates in SOLO's team debit-card program, the team's designated cardholder is invited to a dedicated enrollment page where we collect their date of birth and Social Security Number.
We collect this information because federal law governing our banking partners — specifically, the customer-identification requirements imposed by Section 326 of the USA PATRIOT Act — requires them to verify the identity of the person who will hold a debit card issued against a team's funds. Our banking partners for this program are Bluevine and Coastal Community Bank.
This data is encrypted at the application level (AES-256-GCM) before storage. It can be decrypted only by a single, specifically named account holder we've authorized to view it, and every time it is viewed, we write a record to an audit trail (Section 12 has more on how we secure this data). Once the debit card is issued, we purge the Social Security Number and date of birth from our systems — we do not retain them beyond that point. Enrollment also requires the cardholder's explicit acceptance of a Cardholder Agreement.
When you use the Services we and our service providers automatically collect:
We may receive information about you from:
We use the information we collect to provide, maintain, secure, and improve the Services and for the following purposes:
Where the General Data Protection Regulation or UK GDPR applies, we process Personal Information on the following legal bases: (a) performance of a contract with you; (b) compliance with our legal obligations; (c) your consent (which you may withdraw at any time); (d) protection of your or another person's vital interests; and (e) our legitimate interests, including operating, securing, and improving the Services, where those interests are not overridden by your rights and freedoms.
SOLO has three feeds, each with a different, fixed audience. Understanding these audiences explains who can see information you or your Family post.
The player feed is private to the Athlete and their Family. It shows upcoming items — events with your RSVP status, dues that are due — and a personal history of awards, personal records, and streaks. No one outside the Athlete's Family can see it.
The team feed is visible only to that team's active members — coaches, managers, athletes, and linked guardians. Coaches control the team's feed settings, including whether player and parent posts publish automatically or need approval first, whether comments are open, and quiet hours. Access is enforced at the database level: there is no way to read a team's feed without being an active member of that team, and every moderation decision on the team feed requires that same active membership.
The public feed is visible to signed-in SOLO users. As of today, it cannot be viewed by a logged-out visitor or indexed by a search engine — there is no public, unauthenticated view of it. If that ever changes, it will be a material change to how this Policy applies, and we will update this Policy and provide notice before making it.
Posts are limited to four categories — Highlight, Demo, Motivation, Coaching — and every post is reviewed by a human moderator before it goes live; nothing publishes automatically. Reactions are limited to a positive, high-five/cheer style; there is no negative reaction. The public feed does not support comments at all — that capability is disabled at the database level, not just hidden in the interface. Every public post carries a report button, and a report for a safety concern takes the post down immediately, pending review.
Only an adult can publish to the public feed, and only on behalf of an Athlete in their own Family — Minor Player Accounts cannot post there. Publishing also requires the Athlete's birthdate to be on file, the Athlete to be at least 13 years old, and active, recorded parental consent — all enforced by the database itself. Section 7 explains exactly how that consent works.
SOLO is built for families with youth athletes, and many of our users are minors. This section explains what that means for a child's privacy on SOLO, and is written to give parents and guardians the direct notice called for by the Children's Online Privacy Protection Act ("COPPA") and the FTC's COPPA Rule.
If your child uses SOLO, here is what we collect from them and why: an Athlete profile (name, birthdate, athletic information and, only if you choose to add it, academic information such as GPA), photos and video associated with their team or account activity, and, for a Minor Player Account, a record of that account's activity (Section 7.5). We collect only what we reasonably need to run the team, testing, and family features described in this Policy, and we do not condition your child's participation in those features on providing more Personal Information than that. Age on SOLO is based on the birthdate a parent, guardian, or the athlete provides; we do not currently use a third-party service to verify it.
An Athlete under the age of 13 has no public presence on SOLO. Their content is never eligible for the public feed, and their profile cannot be made public — only their Family, and, for team activity, their team, can see anything associated with them. This isn't a setting anyone has to turn on: both rules are enforced at the database layer itself, so there is no path — including an administrative one — for an under-13 Athlete's content to reach the public feed or for their profile to be published. The same database layer also refuses to make any Athlete's content or profile public when no birthdate is on file, so an "unknown age" can never slip through as an adult.
For an Athlete between 13 and 17, nothing about them can appear on the public feed — and their profile cannot be made public — unless a Parent or Guardian with real family authority over that Athlete has given consent first, and we have a record of it. Both rules are enforced by the database, not only by an interface setting.
Only two kinds of people can give this consent: an adult who holds real family authority over the Athlete on SOLO — the same authority check we use before letting anyone publish that Athlete's profile — or the Athlete themselves, once they turn 18, consenting for their own profile. A minor can never consent on their own behalf. SOLO staff cannot grant or manufacture this consent for you; there is deliberately no administrative override.
Giving consent requires signing in to your own Guardian account and taking an explicit, affirmative action together with your typed full legal name. We keep a record of that action as evidence it was properly given: the name you typed, the IP address and browser/device (user agent) information associated with the action, and a timestamp. Today, consent is captured this way — through an authenticated action inside your account; our systems are also built to support additional verification methods, such as card-based verification, if we adopt them in the future.
You can revoke consent at any time with a single action in Family controls. The moment you do: every public post by that Athlete is unpublished immediately, and the underlying photos or video are queued for permanent deletion within 7 days (Section 11). The system will not allow a new public post for that Athlete while consent is revoked.
You can, at any time:
You can do all of this in-app, through Family controls, or by emailing privacy@playsolo.soccer. If you believe your child has given us Personal Information without your consent, contact us at that address and we will address it.
A Minor Player Account ("player login") can only be created by a Parent or Guardian — a child cannot sign themselves up. These accounts have no email address; the Parent sets and can reset the password, and can disable the account entirely at any time. Anything that would otherwise be emailed to the child — a notification, for example — goes to the guardian instead.
Because guardians are meant to be able to see what their child is doing on SOLO, we log activity on a Minor Player Account — logins, page views, messages sent, RSVP responses, and cheers given — and that activity is visible to the account's linked guardian. This is a deliberate design choice, not an incidental log.
A Minor Player Account cannot post to the public feed or to a team's broadcast channel; its only messaging channel is a coach-family thread where guardians are present by construction. Feed participation is gated by parent permission, and billing and family-administration areas are not reachable from a Minor Player Account.
We use the following service providers to operate SOLO. Each processes Personal Information only on our instructions and only to the extent needed to perform its function.
| Vendor | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage |
| Vercel | Application hosting |
| Cloudflare R2 | Media object storage |
| Mux | Video processing and streaming |
| Stripe | Payments |
| Anthropic | Generates responses for the AI assistant (Section 10), under commercial API terms that restrict use of your data to providing that service — not for training AI models |
| Resend | Transactional email |
| OpenPhone | SMS notifications — opt-out is honored and STOP requests are processed |
| Mapbox | Event-location geocoding and maps |
We do not use advertising networks, and we do not currently run any third-party analytics SDK in the Services. We do not sell Personal Information, and we do not share Personal Information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. If that were ever to change, and it involved a consumer we know is under 16, we would first obtain the affirmative opt-in consent the law requires before any such sale or sharing.
SOLO includes an in-app AI assistant, "Ask SOLO," currently offered as a beta feature.
When you ask it a question, your query — together with the account or team context needed to answer it — is sent to our AI subprocessor, Anthropic, to generate a response. The assistant only draws on data that the person asking is already permitted to see inside SOLO; it does not answer using another user's private information. Your conversation transcript is kept in your browser's session storage for the duration of your session — we do not maintain a permanent, server-side log of assistant conversations.
We are also developing additional AI-assisted features that are not live today. That includes a planned paid feature, Composite Score, that would analyze game footage you upload — it has not launched. When it does, we will provide notice and put an appropriate consent process in place before any footage is analyzed for that purpose. Other ideas under exploration, such as practice-audio insights and AI-drafted team-treasurer summaries, are likewise not live; any feature that would process new categories of personal information (such as audio recordings) will come with its own notice and consent before it launches.
We keep Personal Information only as long as necessary for the purposes described in this Policy, to comply with our legal obligations, and to resolve disputes. For content on the team and public feeds, a daily automated process reviews a deletion queue and permanently removes the underlying files on this schedule:
| Content | When it's deleted |
|---|---|
| Rejected or removed post media (photos and video) | 30 days after the moderation decision |
| Public content after a guardian revokes consent | Unpublished immediately; underlying media deleted after 7 days |
| Posts you delete yourself | 30 days after deletion |
| Content placed under legal hold | Not deleted — preserved for as long as required by law |
| Team debit-card KYC data (Social Security Number, date of birth) | Purged once the debit card is issued |
| Parental-consent records and moderation records | Retained as evidence that consent and moderation decisions were properly made |
This deletion process runs automatically, every day — it isn't something that only happens if you ask. It removes the underlying storage objects (in Supabase Storage and Cloudflare R2) and video assets (in Mux); if a copy of a video is still in legitimate use elsewhere on the Services, that shared copy is not destroyed. The post record itself is replaced with a tombstone noting that it was deleted, rather than being erased in a way that would break other records that reference it.
Other categories of information — such as account identity records and transaction history — are retained for the life of the relevant account or team, and longer where we have a legal or accounting obligation to do so.
We maintain technical safeguards designed to protect Personal Information, including:
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a security incident affects your Personal Information, we will notify you and the appropriate regulators as required by applicable law.
Depending on your jurisdiction (including California, Virginia, Colorado, Connecticut, Utah, and similar U.S. states, as well as the European Economic Area and the United Kingdom), you may have the right to:
To exercise any of these rights, email privacy@playsolo.soccer. We handle these requests manually today: we will verify your identity before acting on the request, and we aim to respond within forty-five (45) days of receiving a verifiable request — the response window set by the California Consumer Privacy Act. SOLO is a Missouri company, and not every jurisdiction's privacy law applies to every user, but we apply this same process and timeline to privacy requests from users regardless of where they live. For rights specific to a child's information, see Section 7.4.
SOLO is based in the United States. If you access the Services from outside the United States, your information will be transferred to, processed, and stored in the United States and other countries where our service providers operate. We rely on appropriate safeguards (such as Standard Contractual Clauses) where required by law to protect such transfers.
The Services may contain links to third-party websites or services we do not own or control. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. Review the privacy policies of any third-party services before providing them with information.
California residents have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"). The categories of Personal Information we collect, use, and disclose are described in Section 3.
We do not sell Personal Information, and we do not share Personal Information for cross-context behavioral advertising, as those terms are defined by the CCPA — as described in Section 9, we don't use advertising networks and we don't run a third-party analytics SDK in the Services. Because we do not sell or share Personal Information — including that of a consumer we know is under 16 — there is currently no sale or sharing for us to obtain opt-in consent for; if that were ever to change, we would first obtain the affirmative opt-in consent the CCPA requires for a known child under 16 before doing so.
The only sensitive Personal Information we collect, as the CCPA defines it, is the Social Security Number and date of birth described in Section 3.3 — collected solely for the federal bank-verification purpose stated there, encrypted, access-audited, and purged when that purpose is complete. We use sensitive Personal Information only for purposes permitted without a right-to-limit under the CCPA, so there is no "limit use" toggle needed today. To exercise your right to know, delete, or correct, contact privacy@playsolo.soccer, as described in Section 13. You may also designate an authorized agent to act on your behalf, subject to identity verification.
We may update this Privacy Policy from time to time. When we do, we will post the revised Privacy Policy on each Site and update the "Last Updated" date above. If we make material changes, we will provide additional notice (such as by email or in-app banner). Your continued use of the Services after the effective date constitutes acceptance of the revised Privacy Policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:
d/b/a SOLO Soccer
Attn: Privacy
Kansas City, Missouri, United States
Email: privacy@playsolo.soccer