TipThePlay Privacy Policy

Last Updated: August 12, 2025

1. Overview

This Privacy Policy explains how TipThePlay ("TipThePlay", "we", "our", or "us") collects, uses, discloses, and protects personal information when supporters engage with athletes and athletes manage their profiles through our platform. By using the platform you agree to the practices described here.

2. Information We Collect

  • Account Data: Email address, hashed password, authentication identifiers, account type, creation timestamps.
  • Athlete Profile Data: Display name, sport, position, height, weight, academic program, school year, jersey number, organization affiliation, biography/media you voluntarily provide.
  • Support / Transaction Data: Tip amounts, currency, payment processor references, payout status, aggregated totals (e.g., total tipped, biggest tip).
  • Technical & Usage Data: Log entries (IP address, browser/user agent, device type), request metadata, session events, feature usage, referral URLs.
  • Cookies & Similar Technologies:Session cookies, authentication tokens, analytics identifiers, anti‑fraud signals.
  • Communications: Support requests, feedback, in‑platform messages, email interaction metadata (open / bounce events) where available.
  • Optional Media: Profile images or other media you upload (subject to content guidelines).

3. How We Use Information

  • Provide, operate, secure, and optimize the platform.
  • Authenticate users and maintain sessions.
  • Process Tips and facilitate payouts (via third‑party payment processors).
  • Generate aggregated, anonymized platform metrics and insights.
  • Detect, prevent, and investigate fraud, abuse, or policy violations.
  • Respond to inquiries and provide support.
  • Deliver service notifications, transactional emails, and optional product updates (you can opt out of non‑essential communications).
  • Comply with legal, regulatory, and eligibility verification obligations (e.g., NIL compliance checks).

4. Legal Bases (EEA / UK / Similar Jurisdictions)

Where applicable law requires a legal basis, we rely on: (a) contract performance; (b) legitimate interests (platform security, fraud prevention, improvement, limited analytics); (c) consent (where explicitly obtained); and (d) legal obligations.

5. Cookies & Tracking

We use strictly necessary cookies for authentication and security, plus limited analytics to understand feature adoption and stability. Browser settings may block some cookies, but essential features may not function without them.

6. Payment Processing

Payments and payouts are handled by third‑party processors (e.g., Stripe). We do not store full payment card numbers. Processor terms and privacy policies govern their handling of payment data. We receive and retain reference IDs, partial metadata, and settlement status to reconcile transactions.

7. Sharing & Disclosure

  • Service Providers: Hosting, authentication, analytics, email delivery, fraud detection, and payment vendors under contractual confidentiality obligations.
  • Public / Athlete Profiles:Athlete‑submitted profile fields you choose to make public may be visible to supporters and visitors.
  • Legal & Compliance: Lawful requests, regulatory requirements, enforcement of Terms, protection of rights, safety, and integrity.
  • Business Events: Mergers, acquisitions, financing, or asset transfers (subject to continued protection of personal data).
  • Aggregated Data: Non‑identifiable statistics (e.g., total tips by sport) that do not identify individuals.

8. Data Retention

We retain personal data as long as needed for active accounts, legitimate business purposes (audit, security, accounting), and legal obligations. When no longer required we use reasonable measures to delete, de‑identify, or archive data securely.

9. International Transfers

Data may be processed in jurisdictions with different data protection laws. Where required, we implement safeguards such as contractual clauses or equivalent mechanisms to protect transferred data.

10. Security

We employ administrative, technical, and organizational controls (least‑privilege access, encryption in transit, monitoring). No system is perfectly secure; users should also protect their credentials and devices.

11. Your Choices & Rights

  • Update profile data in your account dashboard.
  • Request deletion or deactivation (subject to legal or fraud‑prevention retention requirements).
  • Opt out of non‑essential marketing emails via unsubscribe links.
  • Request access, correction, portability, or restriction where applicable by law (EEA/UK/CA/other users may have enhanced rights).
  • Exercise rights by contacting: privacy@tiptheplay.com. We may require verification.

12. Children & Young Athletes

We do not knowingly collect personal data from children under 13 (or lower age thresholds where local law applies) without appropriate consent. If you believe unauthorized data was provided, contact us for removal. Under‑majority athletes should involve a parent or guardian for compliance and oversight.

13. Third‑Party Links & Embedded Content

Links to external sites or embedded media are governed by their own privacy policies. We are not responsible for third‑party practices. Review their policies before sharing data or interacting.

14. Changes to This Policy

We may revise this Privacy Policy periodically. Material updates will be indicated by updating the Last Updated date or by reasonable notice. Continued use after changes signifies acceptance.

15. Contact

Questions, requests, or complaints: privacy@tiptheplay.com. For unresolved EU/EEA or UK issues you may contact your local data protection authority.

By using TipThePlay you acknowledge this Privacy Policy. If you do not agree, discontinue use of the platform.