Legal

Privacy Policy

Written from what the platform actually does — what it collects, why, who else sees it, and how to get it removed.

Last updated August 23, 2026

01Who this covers

Garden Heights Community runs a basketball league and the software the league runs on — the website you are reading, the player app at /dashboard, and the server behind them. This policy describes what that software collects about you, why it collects it, who else it reaches, and what you can ask us to do about it.

It is written from the code, not from a template. Every detail below is stated plainly rather than guessed.

The organisation responsible for this data is Garden Heights Community, a community basketball league in New Jersey.

02Information you give us

Creating an account

Registration asks for your name, your email address and a password. Accounts are handled by Supabase Auth. Your password is sent to Supabase and is never stored on our own servers — our database has no password column. Email verification uses a six-digit code sent by Supabase.

If you sign in with Google instead, Google returns your name, email address and the URL of your Google profile photo, and we store those three things.

Your player profile

Onboarding and profile editing collect your first and last name, position, height, weight, an optional profile photo, and the leagues you want to join. A jersey number is added when you are placed on a roster.

League waivers

Signing a league waiver is the most detailed form on the platform. It collects your full legal name, phone number, an optional Instagram handle, your emergency contact’s name and phone number, height, weight, position, jersey size, a small number of league questions, and your typed electronic signature.

When you submit it we also record the IP address you signed from and the time you signed, and we generate a signed PDF containing all of the above plus your account email. This is the one place on the platform where an IP address is stored, and it is stored because it is part of what makes an electronic signature evidentially useful.

Messages and posts

Direct messages, group messages, league feed posts and comments are stored as you wrote them, in ordinary readable text. They are not end-to-end encrypted. Anyone with administrative access to the database can read them.

Uploads

Profile photos, and — for league commissioners — team and league logos, game photos and video, are uploaded to our file storage. See Photos, video and your likeness below.

What we never ask for

There is no field anywhere on the platform for a home address, a date of birth, a government ID number, or payment card details. The platform takes no payments and has no payment processor connected to it.

03Information the platform creates about you

  • Game statistics. Every scoring play, rebound, assist, steal, block, turnover, foul, substitution, ejection and minute played is recorded live by a commissioner and rolled into box scores, season averages, career totals and standings.
  • Ratings, awards and cards. Derived ratings, award records and player-card data built on top of those statistics.
  • Activity. We store the last time your account was active, so the app can show who is online. We do not keep a per-person log of what you looked at. Media items carry aggregate view and download counters that are not linked to individual users.
  • Notifications. Notification records for approvals, trades, game reminders, tags and messages. A notification about a direct message includes the sender’s name and the first 120 characters of that message.
  • Push subscriptions. If you allow browser notifications, we store the push endpoint your browser gives us, the two encryption keys that go with it, and your browser’s user-agent string.
  • Administrative audit records. When a commissioner makes a significant change, we record who did it and what changed.

04Photos, video and your likeness

League commissioners can upload photos and video from games and tag the players who appear in them. That means media of you can be uploaded and tagged by someone other than you, and it will appear on your player profile, in the league media library and in the league feed.

Commissioners can also set a profile photo on your behalf, including on player records that have not yet been claimed by an account.

If you want a photo or video of you removed, ask — see Your choices below. There is no self-service way to untag yourself today.

05AI-generated scouting reports

The platform generates written player reports — a private development report for you, and, when a league enables it, a public scouting report other members of your league can read. These are written by a Claude model from Anthropic.

To produce them, we send Anthropic a snapshot containing:

  • your first and last name, position, height and weight;
  • your season and career statistics, shot profile, recent form, clutch splits, foul data, plus-minus impact and league percentiles;
  • the full names of teammates you most often play with, alongside assist counts, so the report can describe on-court chemistry.

We do not send your email address, phone number, IP address, waiver answers or photographs to Anthropic. Generation runs when a game is finalised, or when you or a commissioner asks for a refresh. The snapshot we sent and the report that came back are both stored.

Reports are automated summaries of recorded statistics. They are not a professional evaluation of you as an athlete, and they are not used to make any decision about you that has a legal effect.

06Who else your information reaches

We do not sell your information and we do not share it for advertising. There is no advertising, analytics or tracking product anywhere in this application. The following services process data because the platform needs them to work:

  • Supabase — authentication, the database, and file storage. Effectively everything described on this page is stored here. Supabase also sends the verification and password-reset emails.
  • Google — only if you choose to sign in with Google. Separately, the site loads the Google Maps script on every page, including this one, which means Google receives a request from your browser containing your IP address and user-agent. Maps itself is only used by commissioners looking up a game venue.
  • Anthropic — receives the scouting snapshot described above, and nothing else.
  • Your browser’s push service (Google, Mozilla or Apple, depending on your browser) — if you enable notifications, it relays them to your device. Notification contents are encrypted to your device’s keys before they leave our server, but the push service does see that a message is being delivered to your endpoint.

We may also disclose information if we are legally required to, or where it is necessary to protect the safety of a league member.

07Who can see what inside the league

  • Other signed-in members can see your name, photo, position, height, weight, jersey number, team, statistics, awards, tagged media, and — where a league has enabled it — your public scouting report.
  • Your private development report is visible to you and to league commissioners.
  • League commissioners can additionally see your email address, your signed waiver — including your phone number, emergency contact and the IP address you signed from — and administrative records for your account.
  • Direct and group messages are visible to their participants, and to anyone with administrative access to the database.

Uploaded files are served from public links

Profile photos, logos, game media and signed waiver PDFs are stored in a storage bucket and served over long, unguessable but public URLs. The link itself is the only thing protecting the file: anyone who has the URL can open it without signing in, and links can be forwarded. Treat anything uploaded to the platform as shareable, and please do not upload anything you would not want seen outside the league.

08Cookies and browser storage

We use a small number of first-party cookies and browser storage keys to keep you signed in and to remember interface preferences. There are no advertising or analytics cookies. The Cookie Policy lists every one of them by name.

09How long we keep things

Being straightforward about this: the platform has no automatic deletion. Accounts, player profiles, statistics, messages, notifications, waiver signatures, scouting snapshots and uploaded files are kept indefinitely unless somebody removes them.

The one exception is push subscriptions, which are deleted automatically as soon as your browser tells us they are no longer valid.

We keep your account and its history for as long as you are a member. Signed waivers are kept for the season they cover and the season after it. Ask us and we will delete your account and personal details.

10Your choices and how to make a request

Things you can do yourself

  • Edit your name, position, height, weight and profile photo from your profile at any time.
  • Turn browser notifications off from Profile → Settings, or in your browser’s site settings.

Things you have to ask us for

There is currently no self-service button for these. Email [email protected] and a commissioner will action it manually:

  • a copy of the information we hold about you;
  • correction of anything that is wrong;
  • removal of a photo or video you appear in;
  • deletion of your account and player record.

Two honest caveats on deletion. First, some records are shared history rather than personal profile data — a box score from a game you played in, or a message you sent to someone else, remains part of that game or that conversation. Second, deleting a player record does not currently remove already-uploaded image files from storage; that is a separate step, and we will do it on request.

We aim to respond to requests within within 30 days.

11Age

The platform does not ask for a date of birth and has no age verification. It cannot tell an adult member from a minor.

The platform is intended for members aged 18 and over. A member under 18 needs a parent or guardian to sign their waiver. If you believe a child has registered without the appropriate consent, contact us at [email protected] and we will remove the account.

12How the platform is protected

Plainly, and without overstating it:

  • The site and API are served over HTTPS.
  • Sign-in is handled by Supabase Auth. Passwords never reach our own database.
  • Using the app requires a signed token, and commissioner-only actions are checked against your role on the server.
  • As described above, uploaded files are protected only by the obscurity of their URL, not by an access check.

We have not undergone any third-party security audit or certification, and we make no claim of compliance with any particular security or privacy framework. No system is perfectly secure. If you find a problem, please tell us at [email protected] rather than posting it publicly.

13Changes to this policy

When this policy changes materially we will update the date at the top of the page and, where the change affects how your information is used, notify members in the app. Continuing to use the platform after a change means you accept the updated policy.

14Contact

Questions about this policy, or any request described above, go to [email protected].

Postal address: