Privacy Policy
Last updated: August 17, 2026 · Draft - pending legal review, not yet final.
1. What this covers
This Privacy Policy explains what data Hoopers Lists (hooperslist.com, operated under the trade name "Hoopers Lists" - DTI trade-name registration pending) collects, how it's used, and who can see it - for league staff, players, and visitors alike.
2. What we collect
Depending on how you use the platform:
- Account data - email address and password (hashed, never stored in plain text) for anyone who logs in.
- Player data - name, date of birth, photo, position, and stats entered by league staff (Commissioner/Admin/Coach). A player may also have their own account linked, in which case they can edit their own bio/photo.
- League/team data - league and team names, logos, division assignments, sponsor information, and schedules, entered by league staff.
- Payment records - dues amount, status (pending/paid/overdue/waived), and payment method (e.g. cash, bank transfer, GCash) as recorded by league staff. We do not collect or store card numbers or bank credentials - dues are tracked manually, not processed through the platform.
- Uploaded files - player/team/league/sponsor photos and logos, and any waiver documents a league chooses to upload, stored in object storage via a pre-signed upload URL.
- Usage data - standard server logs (IP address, request timestamps) for security and troubleshooting.
3. Minors' data
Many league players are minors. Their data (name, stats, photo) is entered and managed by league staff, not by the platform reaching out to minors directly - we don't operate a public sign-up flow for players. If you're a parent/guardian with questions about your child's data on a league's roster, contact that league's Commissioner first, or reach us directly (Section 9).
4. What's public versus restricted
By design, some league data is publicly viewable without logging in - so fans, players, and family can follow a league without needing an account:
- Public: league home page, standings, schedule/calendar, player profiles (name, position, career/season stats, photo), team pages, awards, sponsor showcase.
- Restricted to logged-in league members/staff: a player's date of birth, payment/dues records, attendance records, and any internal roster-management or stat-correction history.
- Restricted to that league only: every league's data is isolated from every other league at both the application and database level - staff in one league cannot see another league's rosters, payments, or stats.
If you're a player (or a minor's guardian) and want data removed from a public page, contact your league's Commissioner, who controls the roster, or reach us directly.
5. Cookies
We use a session cookie to keep you logged in - that's required for the platform to function and isn't optional/tracking-based. On our public pages we also measure aggregate traffic - which pages are visited, and from which referrer, approximate country, and device type - using a privacy-focused analytics service that sets no cookies, doesn't build a profile of you or follow you across other sites, and isn't used for advertising. It isn't loaded when you're logged in, or on the login, invite, and account pages.
6. How we use data
To operate the platform (render pages, calculate standings, generate shareable stat cards), to maintain security (audit logs of stat corrections and league activity, restricted to league staff; and a log of sign-in attempts and password resets - the email address entered and the IP address, whether or not it succeeded - visible only to platform administrators and deleted after 90 days, used to detect and block password-guessing), and to communicate with league staff about their account or league. We don't sell player or league data, and we don't use it for advertising.
7. Where data is stored
Application data lives in a Postgres database; uploaded files (photos, logos, waivers) live in S3-compatible object storage. Both run on Akamai Cloud infrastructure.
8. Your choices
You can ask to see, correct, or delete the personal data associated with your account by contacting us (Section 9) or your league's Commissioner. Removing a player from an active roster deactivates their roster entry rather than deleting their historical game stats, so past box scores and standings stay accurate - see us if you specifically need historical personal data removed.
9. Contact
Questions about this policy or your data: [email protected].