Privacy notice
Beestera runs football camps and training for children. To do that we ask families for personal information about their children — including health and disability information. This page explains exactly what we collect, why, who else sees it, and when it is deleted.
It describes what the product does today. Where something is kept rather than deleted, this notice says so.
Information about children
Most of the information in this product is about a child: their name, date of birth, gender, photograph, and — if you tell us — their medical conditions, medications, and any IEP or 504 plan. That last group is health and disability information, and we treat it as the most sensitive thing we hold.
Why we ask for health and disability information
Camp staff need it to keep your child safe while they are with us — to recognise a condition, to know about a medication, and to make the accommodations a plan sets out. We ask for it because we cannot supervise a child safely without it, and we use it for that and nothing else.
You choose what to tell us. A profile saves without the health questions answered; leaving them blank means staff will not have that information on site.
What we collect, and why
Account and sign-in
Email address, name, and the sign-in credentials you set.
Why: To create and secure your account. Sign-in is handled by Clerk, which holds your credentials — we never see or store your password.
Guardian contact details
Your name, email address, phone number, mailing address, and occupation.
Why: To reach you about your registrations, to confirm who is responsible for a player, and to send receipts.
Player profile
A player's name, date of birth, gender, kit sizes, club or team, and playing positions.
Why: To place a player in the right age group and session, and to order the right kit. Staff screens are sent a player's age, calculated on our server from the date of birth — not the date itself. The one exception is the admin form used to correct a player's details, which is sent the date because it is what that form writes back.
Health, medication and disability information
Whether a player has a medical condition, takes medication, or has an IEP or 504 plan — and, where you answer yes, the detail you write describing it. Plus any additional notes you add to a profile.
Why: So camp staff can keep a player safe on site: recognising a condition, knowing about a medication, and making the accommodations a plan calls for. It is used for on-site safety and accessibility, and for nothing else — it is never used for marketing, never sold, and never shared with anyone outside the staff running your sessions.
Photographs
A profile photograph, where you choose to upload one for a player or guardian.
Why: So staff can identify a player at check-in and at pickup. A photograph is optional — a profile works without one, and shows initials instead.
Emergency and pickup contacts
The name, relationship and phone number of the people you nominate as a player's emergency contact or authorised pickup.
Why: So we can reach someone if there is an incident, and so we only release a child to an adult you have named.
Forms you complete
The answers you give on a required form (waivers, policies, medical questionnaires) and the name you type as an electronic signature.
Why: To record that the policy a session requires was read and agreed, and to hold what you told us on it.
Documents you upload
Files you attach to a required form — for example a physician's physical, an insurance card, or an immunisation record.
Why: To hold the document a session requires, so staff can confirm it was provided. A document you upload is stored as a file rather than as text in our database.
Payments
What you bought, when, and the amount. Card details are entered directly into Stripe and never reach our servers — we store only the opaque Stripe identifier for your household.
Why: To take payment for registrations and to show you your own payment history.
Email and messaging records
A record of the emails and notifications we sent you, and whether you opted in to marketing email.
Why: To prove we had a basis for contacting you, to honour an unsubscribe, and to avoid emailing someone who has opted out. Marketing email is optional and off unless you opt in; service messages about your active registrations are always sent.
How long we keep it
We keep your information while your account is open. When the last account holder on a household deletes their account, that household — the account holder, the players on it, and the household record — is marked for erasure. If a household has more than one guardian and only one of them leaves, only that guardian's own record is marked.
Erasure does not happen immediately. There is a grace period of 30 days, so an account deleted by mistake can be restored. After that the record is due for erasure, and is erased the next time the erasure process runs. That process is currently run by an operator rather than on a fixed schedule, so we say at least 30 days, not exactly 30 days.
What erasure deletes
- Names, email addresses, phone numbers, dates of birth and gender on the guardian and player records themselves.
- Guardian mailing addresses and occupations.
- The free-text detail you wrote about a medical condition, a medication, an IEP or 504 plan, and any additional profile notes.
- The household name and city.
- Emergency contacts and authorised pickup contacts — these records are deleted outright, not blanked.
- The name you typed as a signature on a required form, and the answers you gave on it.
- The recipient address on our record of each email we sent you, and the subject and body of each notification.
- Profile photographs — the image is deleted from Cloudflare Images, and the reference to it is cleared only once that deletion is confirmed. If the deletion fails, the reference is deliberately kept so the next run tries again rather than losing track of the image.
- Documents you attached to a required form — the stored file is destroyed, and the reference to it is cleared only for the files whose deletion actually succeeded. As with photographs, a failed deletion keeps its reference so the next run retries it rather than leaving a document nobody can find.
- The link between your account and your Clerk sign-in.
- Invitations you sent to a co-guardian — the invited email address and the unused claim link are deleted outright, not blanked.
What erasure does not delete
Erasure blanks the personal information on a record rather than deleting the record itself, so that registrations, guardianship links and completed-policy records from before the deletion do not break. What is left behind is:
- A skeleton record with no personal detail on it: internal identifiers, the link between a player and a household, and the dates a record was created, deleted and erased. This is kept so historical registrations do not break.
- The yes/no answers to the medical-condition, medication and IEP/504 questions. The detail you wrote is deleted; the bare answer is not.
- Non-identifying profile attributes such as kit sizes, playing positions and club name.
- The fact that a required form was completed, and when — but not what you wrote on it.
- A record that an email or notification was sent, with the address and the content removed.
- Your email address on our suppression list, if you unsubscribed. We keep it precisely so we do not email you again.
- Payment records held by Stripe under its own retention rules, and the identifier that links your household to them. Our erasure does not reach into Stripe.
Who else receives your information
We do not sell personal information. We use the following services to run the product, and each of them receives some of your information in order to do its job.
Clerk — Accounts and sign-in
Your email address, your name, and your sign-in credentials. Clerk, not Beestera, holds your password.
Stripe — Payments
Your card details (entered directly into Stripe, never through our servers), your name and email, and the amount of each purchase.
Resend — Email delivery
The email address a message is sent to and the content of that message.
Cloudflare — Hosting, images, video and bot protection
Every request to this site, including your IP address — Cloudflare runs the servers this product is served from. Cloudflare Images stores any profile photograph you upload, and Cloudflare R2 stores any document you attach to a required form. Cloudflare Stream is our video platform (no video of a player is collected today). Cloudflare Turnstile runs the anti-bot challenge on sign-in.
Turso — Database hosting
Everything in the "what we collect" table above — Turso hosts the database the product stores it in.
Sentry — Error monitoring
Diagnostic reports when something goes wrong, including the page address and technical request details. It is not sent your profile, health or payment data.
YouTube (Google) — Training video thumbnails
Your IP address and browser details, when you open the Resources page. The training videos listed there are hosted on YouTube and their thumbnail images load directly from Google in your browser. No account, profile or health data is sent.
Beyond these services, information is seen by the Beestera staff running the sessions your child is registered for.
Your choices
- You can view and edit everything on your household's profiles from My Family and Account Settings while you are signed in.
- You can remove a player, a photograph, an emergency contact or a pickup contact at any time.
- You can turn marketing email off at any time from your email preferences. Service messages about your active registrations are not marketing and continue.
- Deleting your account starts the erasure described above.
Asking us about your data
If you want to know what we hold about your household, have it corrected, or have it erased sooner than the process above, email us at privacy@beestera.com. We aim to acknowledge within 5 business days and to respond in full within 45 days, which is the deadline the privacy laws covering our region set.