MVPLedger policy

Privacy Policy

Last updated September 17, 2026

This Privacy Policy describes how MVPLedger LLC (“MVPLedger,” “we,” or “us”) handles information when organizations and authorized users use the MVPLedger Service.

1. Information we process

  • Account and access information: names, email addresses, organization memberships, roles, authentication-related identifiers, and security events.
  • Organization and operations data: seasons, programs, teams, staff assignments, facilities, schedules, attendance, communications, documents, compliance records, and related operational data.
  • Household and youth-participant data: parent or guardian contact information; player names; date of birth or age-related eligibility information where entered; roster assignments; registration responses; waiver evidence; RSVP and attendance; and evaluation or development records entered by authorized adults.
  • Financial and payment metadata: dues, balances, expenses, receipts, payment amounts, dates, methods, statuses, reconciliation records, and audit history. Card and bank-login credentials are handled by the applicable payment or bank-linking provider rather than entered into MVPLedger.
  • Bank-link information: when an organization connects a bank through Plaid, MVPLedger may receive account and transaction information needed for reconciliation. Bank login credentials are entered with Plaid, not MVPLedger.
  • Imported data: records organizations choose to import from spreadsheets, sports-management systems, payment services, or financial exports.
  • Technical and usage data: browser/device information, IP address, timestamps, application activity, diagnostics, security events, and similar data used to operate and protect the Service.

2. How we use information

  • Provide, secure, maintain, troubleshoot, and improve the Service.
  • Operate registration, scheduling, communications, documents, finance, fundraising, reporting, and other Club OS workflows requested by authorized users.
  • Send transactional and operational messages such as invitations, registration notices, schedule updates, payment reminders, support replies, and security notices.
  • Detect abuse, investigate incidents, preserve auditability, and comply with legal obligations.
  • Provide AI-assisted features when invoked or configured, subject to the Service’s role and workflow controls.

MVPLedger does not sell Customer Data. Customer Data is not used to train a shared AI model for the benefit of unrelated customers.

3. Youth participant data

MVPLedger accounts are intended for adults such as organization staff, coaches, parents, and guardians. The Service is not designed for a child under 13 to create an independent account. Youth participants may exist as records managed by authorized adults as part of a sports organization’s operations.

The organization determines what participant information it collects and is responsible for having an appropriate basis and any consent or permission required for that collection and use. Organizations should collect only information reasonably needed for their operations.

4. How information is shared

Information may be disclosed to:

  • Authorized users in the same organization according to role, team, household, and other access controls.
  • Service providers that help operate hosting, authentication, payment processing, bank linking, email delivery, monitoring, AI-assisted features, scheduling, and related infrastructure, only as needed to provide those services.
  • The public only when an organization intentionally enables a public surface such as public registration, transparency, or fundraising and configures information for that surface.
  • Authorities or counterparties when disclosure is required by valid legal process, necessary to protect rights or safety, or part of a lawful corporate transaction.

5. Role-based visibility

MVPLedger is designed so users receive access appropriate to their role and relationship to an organization, team, or household. Financial-aid, hardship, payment, contact, youth, document, and other sensitive records should not be exposed outside authorized scopes. Public transparency features are designed for aggregate or deliberately published information rather than private household records.

6. Data access, correction, export, and deletion

Authorized organization users can correct many records in the Service and may use available export tools to retrieve organization data. Requests concerning access or deletion may also be sent to support@mvpledger.com.

Deletion is subject to authorization, financial-record and legal retention needs, provider backup lifecycles, fraud/security preservation, and technical recovery requirements. We do not promise immediate physical deletion from every backup copy where the underlying infrastructure does not support that behavior.

7. Payment and banking providers

Organizations may use providers such as Stripe and Plaid. Those providers process information under their own terms and privacy notices. MVPLedger is designed not to store raw card numbers, card verification codes, or a user’s bank-login credentials.

8. Security

We use technical and organizational controls such as encrypted network connections, role-based authorization, database row-level security, private storage controls, audit logging, source-controlled changes, and recovery procedures. No service can guarantee absolute security. See the Security & Trust page for more detail about the current architecture.

9. Cookies and local storage

The Service uses browser storage and cookies that are necessary for authentication, security, preferences, and operation. Additional analytics or similar technologies, when configured, are described in the Cookie Policy.

10. Changes and contact

We may update this Policy as the Service, providers, or legal requirements change. Material updates will be communicated as required by law. Privacy questions may be sent to support@mvpledger.com.