Privacy Policy
Last updated: September 2, 2026
This Privacy Policy explains what information CT Soccer ("CT Soccer," "we," "us") collects when you use ctsoccerhub.com and its
features — including club profiles, the Dashboard, News, Tournaments, Coaching Clinics, the Soccer Assistant, and the
Community feed — how we use it, and the choices you have. By using the site, you agree to the practices described here.
1. Information We Collect
Account & profile information
When you register or edit your profile, CT Soccer collects the information you provide directly. This
information is stored server-side, using Google Firebase Authentication
(to manage your login credentials) and Cloud Firestore (to store your profile and other
account data). That means your account is tied to you, not a single device or browser — once you're
logged in, your profile and data are accessible across any device or browser you sign in from. The
information stored this way includes:
- Registration details — first and last name and email address. Your password is managed directly by Firebase Authentication and is never stored by us in readable form.
- If you sign in with Google — we receive your Google account's email address, display name (which we split into a first and last name), and profile photo URL, and store them in the profile record described above. We never receive your Google password, and we don't ask Google for anything beyond that basic profile — no Gmail, Drive, Calendar or contacts access. You can revoke CT Soccer's access at any time from your Google account permissions page; doing so stops you signing in with Google but does not by itself delete your CT Soccer account.
- Profile details — username, bio, CT town/location, profile photo, and your selected role (Player, Team Manager, or Fan). A restricted copy of some of these fields (username, role, club, avatar — never your email) is also kept in a separate "public profile" record, which powers the People directory so other users can find and follow you without exposing your full account data.
- Player details — position, jersey number, preferred foot, and stats you enter (goals, assists, appearances), plus the club you follow or play for.
- Team manager details — managing club, club website, contact email, roster entries, and match results you submit. Match results are stored under the relevant club and are visible to other signed-in users viewing that club's page. If you request Team Manager access for a club, we store that request and our approval/denial decision so we can review and audit who has manager access to which club.
- Following relationships — the clubs you follow (stored on your profile) and the other CT Soccer users you follow or who follow you (stored separately, to power the People directory's follower/following counts and feeds).
- Match reactions — if you react to a club's match result (🔥/👏/😢), we store which emoji you picked, tied to your account and that specific match, so we can show reaction counts and remember your own reaction. There's no comment or text field — a reaction is the only user-generated content this feature collects.
- Security settings — if you enable two-factor authentication, we store an authenticator secret key and one-time backup codes in your Firestore profile record. This is real, standards-based verification (TOTP, RFC 6238) — after your password, signing in genuinely requires a current code from your authenticator app or an unused backup code, checked with real cryptographic math. Honestly, one limitation worth knowing: this site has no paid backend, so that check runs client-side rather than being enforced by a server — real protection against the vast majority of account-takeover attempts, but not a strictly unbypassable guarantee the way a server-enforced check would be. The secret and backup codes themselves are protected by the same account-level Firestore access rules as the rest of your data, not by separate field-level encryption — a deliberate choice, not an oversight, since a password-derived encryption key would break irrecoverably (and silently) on password reset. We never store your password itself — that's handled entirely by Firebase Authentication.
Content you post
The Community feed is designed to let you upload photos or videos and write captions. Uploads require Firebase Cloud Storage, which isn't active yet (see Section 4), so as of this writing you can't upload photos or videos there, and no post content is currently being collected or stored. When Storage goes live, we'll describe here where and how that content is stored.
Automatically collected information
We use Vercel Web Analytics and Vercel Speed Insights (loaded on every
page) to understand aggregate traffic and page performance — things like which pages are visited, how
fast they load, and approximate geographic region. Vercel describes these tools as privacy-friendly and
not reliant on tracking cookies to identify individual visitors; see
Vercel's own documentation
for the specifics of what they collect and how. We don't use this data to identify you individually.
On our current Vercel plan, this aggregate analytics data has a guaranteed one-month reporting window,
and individual visitor session identifiers are discarded after 24 hours. See
Vercel's pricing documentation
for their most current retention specifics, since this can change if our plan does.
Like most websites, we and our third-party providers may also automatically receive some technical information when you visit — browser type, device type, general region (from IP address), pages viewed, and referring pages.
Cookies & local storage
We use your browser's local storage to remember your theme preference (light/dark) and to keep you signed in between visits. Google AdSense is active on some pages of the site (see Section 3), and Google and its advertising partners set their own cookies through it.
2. How We Use Information
- Create and secure your account, and authenticate you when you log in.
- Operate core features — showing your followed clubs on the Dashboard, letting you follow and be followed by other users in People, powering match reactions, and (once Community is fully live) displaying your posts.
- Communicate with you about your account (e.g., security alerts).
- Maintain the safety and integrity of the platform, including detecting abuse.
- Understand aggregate usage, via Vercel Analytics, so we can improve the site.
- Serve and measure advertising through Google AdSense (see Section 3), and — once the Amazon Associates program is active — affiliate links.
We do not sell your personal information.
3. Advertising & Affiliate Links
Ads are live; affiliate links are not. Google AdSense has been active on some pages of
CT Soccer since August 22, 2026, and ad-related cookies are set through it — see below
for what that involves and how to opt out. The Amazon Associates affiliate program is still
pending activation, and no affiliate links appear anywhere on the site today. We'll
update this notice if either changes.
Google AdSense (active)
CT Soccer displays ads served by Google AdSense on some pages. Google and its
advertising partners use cookies and similar technologies to serve ads based on your prior visits to
this and other websites.
You can opt out of personalized advertising by visiting
Google Ads Settings,
or opt out of a participating third-party vendor's use of cookies for personalized advertising at
aboutads.info/choices.
You can also block cookies generally through your browser settings at any time, though some site features may not work as well as a result.
For more detail on how Google uses information from sites that use its services, see How Google uses information from sites or apps that use our services.
Amazon Associates (pending)
CT Soccer also plans to participate in the Amazon Associates affiliate program. Once
active, some links on the site (for example, recommended gear) may be affiliate links — if you click one
and go on to make a qualifying purchase, we may earn a small commission at no extra cost to you. We'll
clearly label affiliate links as such once this is live, consistent with FTC endorsement-disclosure
guidelines.
4. Third-Party Services
We rely on the following third parties to operate CT Soccer. Each processes data under its own privacy policy:
- Google Firebase — CT Soccer actively uses Firebase Authentication (including Google Sign-In, where Google acts as the identity provider and passes us the profile fields listed in Section 1) and Cloud Firestore to store and manage the account, profile, and match data described in Section 1. Firebase Cloud Storage (which would be used for Community photo/video uploads) is not yet active — no photo or video content is presently stored there. See Firebase's privacy policy for reference.
- Vercel — hosts the site and provides Vercel Web Analytics and Speed Insights, described in Section 1. See Vercel's privacy policy.
- Google AdSense — active since August 22, 2026; serves the ads described in Section 3 and sets its own cookies. See Google's privacy policy.
- Amazon Associates — pending activation; see Section 3 for how it will work once live. See Amazon's privacy notice.
- FormSubmit — the contact form on the home page and the correction/suggestion form on Suggest a Club are delivered by FormSubmit, a third-party form-relay service. What you type into those forms — your name, email address, and message — passes through FormSubmit's servers on the way to our inbox. Worth knowing: this is also the channel Sections 8 and 10 point you to for data-rights requests, so a request sent that way reaches us through FormSubmit as well. If you would rather not use a relay for a data-rights request, you can email us directly at privacy@ctsoccerhub.com.
- Google Fonts & Tailwind CSS (jsDelivr/CDN) — loaded from Google's and other CDN servers to render page styling and typography; these requests can expose your IP address to the host, like any web request.
- TheSportsDB — a public sports-data API we use to pull real match results and fixtures for Hartford Athletic, AC Connecticut, and CT Rush. We only send match/team lookups to this API — no personal or account information is shared with it.
5. How We Share Information
We don't sell your personal information. We may share it only:
- With the service providers listed in Section 4, to the extent necessary for them to provide their service to us.
- Publicly, when you choose to make it public — for example, a Community post, or your public profile fields (username, photo, bio).
- If required to comply with a legal obligation, protect the rights and safety of CT Soccer or its users, or investigate abuse.
- In connection with a merger, acquisition, or sale of assets, in which case this policy would continue to apply to your information.
6. Data Retention & Security
Your account and profile information (see Section 1) is stored server-side using Firebase and persists for as long as your account is active, or until you delete it. This includes your two-factor authentication secret and backup codes, if you've enabled that feature. Deleting your account (available in Account Settings) removes your profile data from Firebase — this may take up to 30 days to fully propagate, though in practice it happens immediately.
We rely on Firebase's server-side security infrastructure, including access-control rules that restrict who can read or write your data, to protect your account and profile information. No method of storage is 100% secure, and we can't guarantee absolute security.
Firebase and Vercel, both active today, may process and store data on servers located outside your country of residence, including in the United States. By using the Service, you consent to this kind of international transfer where applicable.
Team Manager data
If a Team Manager's access to a club is approved, their submitted match results are stored in a record
tied to that club (tagged with their name and account for attribution) and remain on the club's page
even if that person's Team Manager status later changes. Roster entries a manager adds are stored on
their own account rather than in a separate club-wide record, so they're removed only if that manager
deletes their account. Honestly: as of this policy's date, we don't yet have an in-app way to revoke an
already-approved manager's access, or to review or remove their previously-submitted data as a distinct
action. If we build that capability, we'll update this section to describe what happens to existing
data when it's used.
If the Service is discontinued
If we ever stop maintaining or operating CT Soccer Hub, we intend to post advance notice on the site
and give you a reasonable opportunity to export or request deletion of your data before shutdown, where
practical. We can't guarantee this in every circumstance — for example, a sudden, unplanned shutdown —
but it's our stated intent and commitment.
7. Children's Privacy
We're reviewing this section with legal counsel. The disclosures below reflect our
current, honest understanding of what the Children's Online Privacy Protection Act (COPPA) requires —
but whether and how COPPA applies to this specific site is a legal judgment call we haven't finalized
with a lawyer yet. We'd rather tell you plainly where things stand than overstate protections we
haven't actually built.
Our audience
CT Soccer covers everything from professional and semi-pro Connecticut clubs to youth academies for
players as young as 5, so our audience spans adults and minors alike. Our Terms of Service
ask that account holders be at least 13, and roster information for younger players (name, position,
jersey number, stats) is meant to be entered by an authorized Team Manager or coach on that player's
behalf, not by the child directly.
The gap, stated plainly
As of this policy's date, our registration process does not include an age-verification
step. Nothing currently stops someone under 13 from registering their own account — for
example, as a "Player" — and entering their own profile information directly, which our
Team-Manager-entry design doesn't cover. We don't have a reliable way to confirm anyone's age today, and
we don't collect verifiable parental consent from anyone before an account is created. We'd rather say
this plainly than claim a protection that isn't really there.
What we'd do if we learn an account belongs to a child under 13
If we become aware — through a report, a support request, or otherwise — that we've collected personal information directly from a child under 13 without a parent or guardian's verifiable consent, we will:
- Not use that information for anything beyond what's necessary to respond to the parent or guardian and address the account.
- Delete the information and/or the account promptly, or work with the parent or guardian to obtain proper consent to keep it — whichever they prefer.
- Not disclose that information to any third party in the meantime.
What COPPA would require of us if it applies
COPPA and its implementing rule (16 CFR Part 312) place specific obligations on operators that are
"directed to children under 13" or that have "actual knowledge" they're collecting personal information
from a child under 13. In plain terms, if COPPA applies to a given account or feature, we would be
required to:
- Give parents direct notice of what we collect, how we use it, and whether we disclose it, before collecting it.
- Obtain verifiable parental consent — through a method like a signed form, a payment-card transaction, a toll-free call, or an ID-verification method — before collecting, using, or disclosing the child's personal information.
- Let a parent review the information we've collected about their child, have it deleted, and refuse further collection.
- Collect no more information than is reasonably necessary for the activity.
- Maintain a stated data-retention and deletion policy for children's information, and not keep it longer than necessary.
- Get separate parental consent before disclosing a child's information to a third party, if we ever needed to.
We don't have this infrastructure built today. There's no parental-consent flow, no
child-specific data-retention schedule, and no verified-parent review/deletion process anywhere on the
site right now. This section describes what the law would require, not a system we're claiming already
exists.
A decision we haven't made yet, and won't make unilaterally here: COPPA has a "mixed
audience" framework that would let a general-audience site like this one — which covers everything from
professional clubs to 5-year-olds' academies — screen a visitor's age at the point of collection and
apply child-specific protections only to whoever says they're under 13, rather than treating the whole
site as "directed to children." Formally adopting that posture (versus some other approach) is a legal
determination that depends on facts and judgment calls we're not in a position to make in this document
— it's something our operator and a lawyer need to decide together, and it would likely mean building a
real age-screen and a parental-consent flow to back it up. Until that's decided and built, treat
everything above as our honest current state, not a settled compliance position.
If you're a parent or guardian
If you believe your child has created their own account, or that their information appears on the
platform in a way you're not comfortable with — whether entered by a Team Manager or by the child
themselves — contact us using the details in Section 10. We'll act on it promptly, including reviewing,
correcting, or removing the account or information.
8. Your Choices & Rights
- Access & update — review and edit your profile information anytime from Account Settings.
- Delete your account — use the "Delete Account" option in Account Settings to permanently remove your profile and associated data.
- Turn off two-factor authentication — disabling 2FA in Account Settings removes your stored authenticator secret and backup codes.
- Unfollow clubs or people — manage who and what you follow anytime from the Dashboard or People.
- Delete individual posts — once Community is live (see Section 1), you'll be able to remove your own posts at any time.
- Ad personalization — opt out of personalized ads via the links in Section 3.
- Cookies — control or clear cookies and local storage through your browser settings.
If you're in a jurisdiction that grants additional data rights (such as the EU/UK GDPR or the California CPRA), contact us and we'll do our best to accommodate applicable requests. We aim to respond to data-rights requests — including access, deletion, and correction — within 30 days.
9. Changes to This Policy
We may update this Privacy Policy from time to time as the site changes. We'll update the "Last updated" date above when we do. Material changes will be reflected here — we encourage you to review this page periodically.