Skip to content
HockeyOS

Privacy Policy

Last updated: 16 September 2026

This policy explains what HockeyOS (Viralocity Media Ltd.), a company based in British Columbia, Canada (“HockeyOS”, “we”), collects when you use hockeyos.ca, the HockeyOS dashboard, a club’s public pages and widgets, and the emails, push notifications and text messages we send; why we collect it; who we share it with; how long we keep it; and how to exercise your rights. It is written to meet Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia’s Personal Information Protection Act, and Canada’s Anti-Spam Legislation (CASL).

HockeyOS wears two hats. For the information a club enters about its members and families, the club is the organization accountable for it and we act as its service provider, processing it only to run the Service. For our own customers and visitors — the people who create accounts, pay us, or contact us — we are the accountable organization.

1. Who we are and how to reach us

HockeyOS (Viralocity Media Ltd.), British Columbia, Canada. Privacy questions and requests: privacy@hockeyos.ca. General support: support@hockeyos.ca.

2. What we collect

The lists below are specific because they come from how the software is built. Where a club designs its own registration form, the club decides what is asked.

  • Account information (from Clerk, our sign-in provider): a user ID, email address, first and last name, profile picture URL, the last club or team you viewed, your role in each club, who invited you and when you accepted, your notification preferences, and the browsers you have subscribed for push notifications (a push endpoint, encryption keys and a device description such as “Chrome on Mac”).
  • Players (entered by club staff; most are minors): first and last name, jersey number, position, shooting hand, date of birth, headshot, action photo, highlight video link, height, weight, hometown, captaincy, an optional profile link, active/inactive status, whether the entry is a staff member, and links to the player’s own account and to parent or guardian accounts.
  • Households and guardians (entered by club staff): a household name, primary email, phone number, home address and free-text notes; for each guardian a name, email, phone number and relationship to the player. Guardian emails that match a HockeyOS account are linked to it automatically.
  • Registration (entered by the person registering on a public form): payer name, email and phone; answers to every field the club put on the form (which may include the player’s name, date of birth and anything else the club asks); the typed waiver signature and time; the fee, discounts and amount due; and the registration’s status. For paid forms we store Stripe’s payment and charge identifiers, amounts, currency, status and refund amounts. Card numbers go directly to Stripe and never touch HockeyOS.
  • Waiver signatures: the signer’s typed name and email, their relationship to the player, the player’s name as typed and the matched roster entry, the document version and a SHA-256 fingerprint of the exact text shown, the time, and the signer’s IP address and browser identifier, kept as evidence of the signature.
  • Attendance: each player’s yes / no / maybe for a game or practice, when it was given and, if a staff member entered it, who.
  • Game and statistics data: scores, goals, assists, penalties, shots, goalies, standings and derived statistics attributed to named players. Clubs may publish these.
  • Photos, videos and documents uploaded by the club: logos, headshots, action photos, team gallery photos with captions, hero images, and documents such as waivers, schedules and policies (with a name, type, description and public/private flag); plus links to videos hosted elsewhere.
  • Tryouts and tournaments: skater name, date of birth, position, jersey colour and number, evaluator scores, staff notes and outcome; tournament registrant name, date of birth, email, phone, position, skill rating and notes.
  • Messages: announcements and the in-app notification inbox (title, text, link, read time). For text messages, a log of the destination number, message type, related event, delivery status and time. Emails that our provider rejects are stored in full (recipient, subject, body) so we can retry or contact you another way.
  • Game-sheet scanner: the photographed sheet is sent to our AI provider and is not stored by HockeyOS. We store the extracted rows, the model used, the number of pages, who ran the scan, and what was committed.
  • Audit log: for changes clubs may need to trace later (score edits, roster changes, invitations, waiver edits), the acting user ID, the action, a one-line summary and time. Club admins can read it.
  • Technical information: IP address and browser identifier for rate limiting on public forms and links, and as part of a signature record; error reports (error message, stack trace, and internal IDs such as an organization or user ID — never names or form contents); and request logs kept by our hosting provider.
  • Contact form: name, email, organization, team count and message, emailed to us and not stored in the Service.

3. Where it comes from

From you, when you sign up, subscribe a device, register, sign a waiver, reply to an availability link or write to us. From your club, when staff enter rosters, households, schedules and results. From Clerk, when your account is created or updated. From Stripe, which tells us the status of subscriptions, payments, refunds and connected accounts. From your browser’s push service, which issues the push endpoint.

4. Why we use it and on what basis

  • To provide the Service the club asked for: rosters, schedules, statistics, public pages, registration, waivers, attendance, notifications and the scanner. For club Content, the club obtains consent from members and families; we process on the club’s instructions.
  • To run your account and bill for it: authentication, memberships, subscriptions and receipts. This is necessary for the contract between the club and HockeyOS.
  • To send messages the club or you have asked for: invitations, receipts, confirmations, reminders, availability requests and announcements. Email and push categories can be turned off in notification settings; text messages stop with STOP. We keep a record of consent as CASL requires: when you create an account we store your acceptance of the Terms and this policy (document version, time, IP address and browser identifier), a registration form stores the same acceptance with the registration, and we text a phone number only where the person gave express consent — by ticking the texting box on a registration form, or as recorded by club staff on the household record — with the time and source stored against the number.
  • To keep the Service secure and working: rate limiting, error monitoring, audit logging, fraud and abuse prevention, and support.
  • To meet legal obligations, including tax and payment-record requirements and responding to lawful requests.

We do not sell personal information, use it for advertising, build profiles for marketing, or use club Content to train AI models. We only collect what a reasonable person would consider appropriate for running a hockey program.

5. Minors

HockeyOS is built for minor hockey, so most players in the system are under 18. Their information is entered by the club, and the club is responsible for obtaining a parent or guardian’s consent before entering or publishing it, following the age rules of its province. We do not knowingly collect information directly from a child: registration forms and waivers are completed by the payer or signer, and waivers require a parent or guardian by default. Player accounts for minors are linked by the club. Public player profiles never show a date of birth or contact details; the roster widget shows age by default and a full birthdate only if the club turns that column on. If you believe a child’s information is in HockeyOS without consent, contact the club or privacy@hockeyos.ca and we will act promptly.

6. What is public

When a club enables its public site, the following are visible to anyone, may be indexed by search engines, and also appear in widgets the club embeds on its own website: club and team pages; player profiles (name, number, position, shooting hand, headshot, action photo, highlight video, statistics); roster tables (with the columns the club chooses); standings; game pages and live scores; tournament pages; open registration forms; waiver signing pages; and calendar feeds.

Uploaded files — logos, headshots, action photos, team photos, hero images and documents — are stored at public, unlisted URLs. Marking a document or photo as not public removes it from public pages but does not stop someone who has the link from opening it.

7. Who we share it with

Your club. Club staff see the information in their club according to their role. Parents and players see their own players.

Service providers. We use the following companies to run HockeyOS. Each processes personal information only to provide its service to us.

  • Supabase (database and file storage; hosted on Amazon Web Services in the region selected for our project) — all Service data and uploaded files.
  • Clerk (United States) — sign-in, sessions, passwords and any multi-factor settings; holds your email, name and profile picture.
  • Stripe (United States, with global operations) — subscription billing for clubs, and registration payments through each club’s own Stripe Connect account. Receives the payer’s email for receipts and the club’s billing contact.
  • Resend (United States) — delivers every email the Service sends.
  • Twilio (United States) — delivers text messages when a club has turned them on; receives the phone number and message text.
  • Anthropic (United States) — the Claude API reads photographed game sheets. Receives the photo, both teams’ names and rosters (player names and jersey numbers), the game date and period format. Also generates chat summaries if in-app chat is enabled (currently off).
  • Upstash (United States, region configurable) — short-lived counters for rate limiting, keyed by IP address or organization; entries expire within the rate-limit window, at most one hour.
  • Sentry (United States) — error monitoring in production only, with personal-information collection turned off, no session replay and no performance tracing; receives error messages, stack traces and internal IDs.
  • Vercel (United States) — hosts the application and runs the daily reminder jobs; keeps short-term request and function logs.
  • Your browser’s push service (Apple, Google or Mozilla, depending on your device) — relays push notifications to a device you subscribed.
  • Dormant integrations: Cloudflare Stream (live video) and Stream / getstream.io (in-app chat) are integrated but switched off. If either is enabled we will update this policy first.

Links to other services. “Directions” links open Google Maps in your browser with the venue address; nothing is sent by us. Highlight videos are embedded from YouTube, Vimeo or LiveBarn, which set their own cookies when you play them.

Legal and business. We will disclose information if required by law or a valid legal process, to protect the safety of a person, or to a successor if HockeyOS is sold or merged (with notice to clubs).

8. Where your information is stored

Our providers store and process information mainly in the United States, and in the region selected for our database. Information in another country is subject to that country’s laws, including lawful access by its authorities. We use written agreements with each provider that require protection comparable to what Canadian law requires. Clubs in provinces with additional rules on transfers outside the province are responsible for their own assessments; we will help with the information they need.

9. How long we keep it

The periods below are the ones our nightly purge actually applies; they are read from the same file in our code that the purge uses, so this page and the purge cannot disagree.

  • Club Content (players, households, registrations, signatures, results, photos, documents) is kept for as long as the club’s organization exists. When an admin deletes the organization, all of it is deleted immediately and permanently — there is no grace period — along with the club’s uploaded files.
  • Legal records are not purged automatically. Waiver signature records (including IP address and browser identifier), registrations, payment and refund records, and text-message consent records are kept until the organization is deleted, because they are the evidence of a signature, a payment or a consent.
  • Operational logs are deleted on a schedule, once a day, in the background:
    • audit log: 24 months
    • text-message delivery log: 12 months
    • in-app notification inbox: 6 months
    • failed-email records: 90 days
    • log of Stripe events we received: 90 days
    • game-sheet scanner results: 90 days
    • finished notification jobs (the queue behind email and push): 30 days after they finish
    A month here means 30 days. Rows are deleted in batches, so a record can outlive its period by a day or two.
  • Invitations expire after seven days but the record remains. Push subscriptions are removed when your browser revokes them. Rate-limit counters expire within one hour. Scanner photos are never stored; only the extracted result is, for the period above.
  • Accounts: when you delete your account (or it is deleted in Clerk), your account record and its memberships, devices, inbox and guardian links are deleted, and your user ID in club audit logs is replaced with “deleted-user”. Your user ID on a waiver signature record remains, as part of the signature evidence, until the club deletes it.
  • Providers: Stripe keeps payment records for its legal obligations; Resend and Twilio keep delivery logs; Sentry keeps error events; our database provider keeps backups for a limited period after deletion. Each follows its own retention policy.

10. Your rights and how to use them

You can ask to see the personal information we hold about you, have it corrected, withdraw consent, or have it deleted, and you can complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner. A parent or guardian can act for a minor.

  • Roster, household and registration information belongs to your club’s program. Ask your club first; its staff can view, correct and delete it in the dashboard. If you cannot reach the club or are not satisfied, write to privacy@hockeyos.ca; we will verify your identity, refer the request to the club and make sure it is answered.
  • Your account: change your name, email or picture in account settings; manage email and push categories in notification settings; remove a device’s push subscription from that device; leave a club from the dashboard. To delete your account, open Account in the dashboard and choose “Delete my account” (if you are the only admin of a club with other members, transfer the admin role or delete the club first), or email support@hockeyos.ca from the account’s address.
  • Text messages: reply STOP to any message. See the SMS page.
  • Club admins can export their organization’s data as JSON and CSV and delete the organization from settings; see the Terms of Service for exactly what each does.

We respond to requests within 30 days. We may need to verify your identity and may refuse a request where the law allows, in which case we will tell you why.

11. Security

Measures actually in place:

  • Sign-in and passwords are handled by Clerk; HockeyOS never stores a password. Sessions are verified server-side on every request.
  • All traffic uses HTTPS. Our providers encrypt stored data at rest.
  • Every database table has row-level security enabled and the application reads and writes only through server-side code; every server action checks the caller’s club and role, and an automated test fails the build if a new action lacks that check.
  • Public actions (registration, waiver signing, availability replies, the contact form) are rate limited by IP, and availability and signing links carry signed tokens so they cannot be guessed or reused for another player.
  • Uploads are checked for their real file type and size; webhook calls from Clerk and Stripe are signature-verified; security headers prevent our pages being framed except for the widgets designed for it.
  • Error monitoring runs with personal-information collection off and no screen recording. Changes that matter are written to a per-club audit log.

Limits you should know: uploaded files are at public URLs (section 6), and no system is perfectly secure. If a breach of security safeguards creates a real risk of significant harm, we will notify affected clubs and individuals as PIPEDA requires and keep a record of it.

12. Cookies and analytics

We do not use analytics, advertising or tracking scripts. The only cookies are: the Clerk session cookie that keeps you signed in; small preference cookies for theme, density and the season you last selected; and cookies set by third-party video players when you play an embedded video. Error reports from your browser are sent to Sentry through our own domain. See the Cookie Policy.

13. Changes to this policy

We will update this policy when the Service changes — in particular before enabling a dormant integration, adding a provider, or adopting retention limits. Material changes are announced to club admins by email and in-app at least 14 days in advance and listed on the legal changelog.

14. Contact

HockeyOS (Viralocity Media Ltd.), British Columbia, Canada.
Privacy: privacy@hockeyos.ca
Support: support@hockeyos.ca