Trust
Trust & Security
Last updated: July 25, 2026
Seven Point Lead is built for youth sports, so protecting families’ information is foundational, not an afterthought. This page summarizes how the Service is hosted and secured, who our sub-processors are, how data is owned and deleted, and how we respond to incidents. It is written so a league, association, or governing body can complete a vendor review without waiting on us. Items already in place are marked In place; items we are still building toward are marked Roadmap — honestly, so you can see exactly where we stand.
What Seven Point Lead does and doesn’t hold
Seven Point Lead is a supplemental coaching tool. It holds coaching data — rosters, practice plans, playbooks, evaluations, schedules, and adult-to-adult messages. It does not process payments, so it never handles card data and is out of PCI-DSS scope. It is not your system of record: official registration, participant records, consent forms, and payments stay on your league’s sanctioned platform, and background screening stays with your league’s designated vendor.
Hosting & infrastructure
- In place The application is hosted on Vercel; data is stored in a managed PostgreSQL database (Supabase). Both are established managed-cloud providers.
- In place U.S. data residency: the Service runs on U.S.-based managed cloud infrastructure.
- In place Encryption in transit: all connections use HTTPS/TLS. Data at rest is stored within our managed providers’ encrypted infrastructure.
Access control
- In place Access to information is controlled by role within the app (coach, team staff, parent, league official), on a least-privilege basis.
- In place Users see only the teams and data they are authorized for. League officials can be granted read-only oversight of team communications for safety.
- In place Children have no accounts and no login; a child’s read-only view is launched by a parent from the parent’s own device.
Sub-processors
We use the following service providers to operate the Service, each under confidentiality obligations:
- Supabase — managed PostgreSQL database (primary data store).
- Vercel — application hosting and delivery.
- Resend — transactional email delivery.
- Web-push services — delivery of push notifications a user has opted into.
- Anthropic (Claude) — generates coaching content (such as practice plans) from team and practice parameters; not used to make decisions about a child and not sent identifying child data for that purpose.
- Open-Meteo — weather for heat-safety guidance; receives only a practice location and time.
No payment processor is used. A signed sub-processor list is included in our Data Processing Agreement (see below).
Data ownership, portability & deletion
- In place The league and its families own their data. We act as a processor of that data to operate the Service.
- In place Export: a team or organization may request an export of its data.
- In place Deletion: a parent or coach may request deletion of their (or their child’s) information at hello@sevenpointlead.com; we delete or de-identify it when it is no longer needed to run the team.
Incident response & breach notification
- In place We maintain an incident-response practice: contain, investigate, remediate, and document.
- In place Breach notification: in the event of a data breach affecting personal information, we will notify affected organizations and, where required, individuals and regulators, consistent with applicable federal and state breach-notification laws, and cooperate with your league’s obligations.
Children’s privacy & SafeSport
Our approach to children’s data (COPPA) and to safe communication (U.S. Center for SafeSport) is detailed in our Privacy Policy: no child accounts, no direct messaging of minors, data minimization, and reviewable adult-to-adult communication.
Compliance posture & roadmap
We are candid about what is done and what is in progress:
- In place Privacy Policy in force; U.S. hosting; TLS in transit; role-based access; no payment/PCI scope.
- Roadmap Independent security attestation (SOC 2 Type II).
- Roadmap Formal WCAG 2.1 AA accessibility audit.
- Roadmap Finalized COPPA verifiable-parental-consent mechanism with recorded consent, with counsel.
- Roadmap Errors-&-omissions and cyber-liability insurance for organizational partners, with certificates on request.
Data Processing Agreement
A Data Processing Agreement (DPA) — covering roles, scope, the sub-processor list, security measures, breach notice, data-subject rights, and deletion/return of data — is available to organizations on request at hello@sevenpointlead.com.
Contact
Security questions, a copy of the DPA, or a fuller written security summary: Roc City Mining Corp, 5997 Onyx Drive, Farmington, NY 14425 — hello@sevenpointlead.com or 585-770-0996.