Volley Pool

Privacy Policy

Version 1 · Effective October 1, 2026

Volley Pool ("Volley Pool", "we", "us") is an app that helps parents on a youth sports team coordinate carpools. This policy explains what we collect, why, where it is stored, who can see it, how we protect it, how long we keep it, and the choices you have. We collect only what the app needs to do its job (data minimization), and we do not sell personal information or show advertising.

The short version.
  1. What we collect
  2. Why we collect it
  3. Who can see what
  4. Who we share it with
  5. Where and how it's stored
  6. How we protect it
  7. How long we keep it
  8. Your choices and rights
  9. Children's information
  10. If something goes wrong
  11. Changes to this policy
  12. Contact us
  13. Appendix: ISO/IEC 27001 alignment

1. What we collect

InformationDetailsWho provides it
AccountEmail address; password (we never see it — Google's authentication service stores only a salted hash); whether your email is verified; sign-in times.You
ProfileFirst name, last name, phone number, your role (parent or team admin), and when you accepted these terms.You (an admin may pre-fill your phone when reserving a spot for your child)
HouseholdHome address (street, unit, city, state, ZIP, and map coordinates from the address lookup); optional private notes such as a gate code.You, or a team admin on your behalf
PlayersYour child's first and last name, which household they belong to, and a photo-consent preference. We do not store photos.You or a team admin
TeamTeam and league name, activation code, time zone, and who the administrators are.Team administrators
EventsPractices, games and trainings: title, venue name and address, times, drop-off notes.Team administrators
RidesRide offers (seats, notes), ride requests (which players, pickup or drop-off address, notes), and claims between two households (players, meeting spot, notes, estimated time, status and timestamps).Parents
InvitationsHousehold invite codes you generate; an email address (and optional phone) an administrator enters to reserve a spot for you.You / administrators
TechnicalRequest logs kept by Google Cloud (which can include IP address and timestamps) and error logs from our server functions.Generated automatically

What we do not collect

2. Why we collect it

We do not use your information for advertising, profiling, or automated decisions about you, and we do not sell it.

3. Who can see what

Access is limited by role and enforced on our servers, not just in the app.

InformationVisible to
Your name, phone number and home address; players' namesApproved members of your own team and its administrators. Never other teams.
Ride offers and ride requests (without notes)Approved members of your own team.
A ride claim (the arrangement between a rider's household and a driver's), including the meeting spot and notesOnly the two households involved.
Notes on a ride request (for example a gate code)Only the household that wrote them, until a driver responds; then the claim's two households.
Household notes and access informationYour household, team administrators, and a driver whose claim for your household is confirmed.
Your passwordNo one, including us.

Team administrators can approve families, manage the roster and events, move a person between households, and delete accounts or players. A league-level administrator can do the same across the teams in their league. Administrators cannot read ride claims they are not part of.

4. Who we share it with

We share personal information only with the service providers needed to run Volley Pool, under their data-processing terms, and when the law requires.

5. Where and how it's stored

6. How we protect it

Our security practices are designed around the control framework of ISO/IEC 27001 and 27002 (see the appendix).

No system is perfectly secure. You can help: use a strong, unique password, keep your phone's software up to date, and share team and invite codes only with people who should have them.

7. How long we keep it

InformationKept
Account and profileUntil you delete your account (Profile → Delete My Account) or an administrator removes it. We do not delete accounts for inactivity.
Household and playersWhile on the team roster. Deleting your account does not remove your child from the roster; a team administrator manages the roster. Removing a player deletes their record, and, if it was the household's last player, the household's guardian accounts as well (administrators are kept).
Rides (events, legs, offers, requests, claims)Automatically deleted 12 months after the event or ride, a period we keep for safety and to resolve disputes. When an account is deleted, its rides are removed (if it was its household's last guardian) or continue under the remaining guardian.
Invite codesExpire after 14 days; expired codes are deleted about 30 days later.
Spots an administrator reserved for a familyUntil claimed, or deleted after 12 months.
Server logsAbout 30 days, then deleted by Google Cloud's default log retention.
BackupsDeleted data can remain in encrypted backups for up to 14 days before it is permanently removed.

8. Your choices and rights

We respond to requests within 30 days. If you are a California, Nevada or other U.S. state resident with additional statutory rights, we honor them. We do not sell or share personal information for advertising, so there is nothing to opt out of.

9. Children's information

Volley Pool is for parents and guardians (18 and over) and team administrators. Children do not have accounts and the app is not directed at children. A child's first and last name appears only because a parent or team administrator adds them to the roster so rides can be arranged. We do not collect anything else about children, do not collect it from children, and do not use it for anything except coordinating rides for their team. A parent can have their child's record corrected or removed by contacting a team administrator or us.

10. If something goes wrong

If we learn of a security incident affecting personal information, we will contain it, investigate it, and notify affected people and the relevant authorities without undue delay and as the law requires, describing what happened, what information was involved, and what you can do.

11. Changes to this policy

When we change this policy in a meaningful way we update the version and effective date above and tell you in the app. If a change requires your agreement, you will be asked to accept it before continuing.

12. Contact us

Privacy requests and questions: privacy@volleypool.com
Security reports: security@volleypool.com
General support: support@volleypool.com

Appendix: ISO/IEC 27001 alignment

Volley Pool's information-security practices are designed to align with the control themes of ISO/IEC 27001:2022 (Annex A) and ISO/IEC 27002. This is a description of our approach, not a certification; our hosting provider, Google Cloud, is independently certified for the infrastructure it operates.

Control themeHow we address it
Policies and roles (A.5.1–5.4)This policy and the Terms of Use; defined roles (parent, team administrator, league administrator) with separation of duties enforced by the system.
Inventory and classification (A.5.9–5.13)The data inventory in section 1 and the visibility tiers in section 3 classify information by sensitivity (roster-visible, household-private, party-only).
Access control and identity (A.5.15–5.18, A.8.2–8.5)Verified-email authentication; role- and household-based access enforced server-side; privileged actions only through server functions that re-check authorization; invite codes expire; recent sign-in required for account deletion.
Supplier relationships (A.5.19–5.23)Google Cloud (hosting, database, authentication) and Apple (address search, distribution) are the only suppliers that handle personal data, under their standard data-processing terms.
Incident management (A.5.24–5.28)Section 10; a published security contact; error logging.
Legal and privacy compliance (A.5.31, A.5.34)Data minimization, purpose limitation, retention limits, and individual rights as described in this policy.
People (A.6)Access to production systems is limited to the people who operate the service.
Physical (A.7)Inherited from Google Cloud's certified data centres; no on-premises storage of personal data.
Cryptography (A.8.24)TLS in transit; encryption at rest by Google; passwords stored only as salted hashes by Firebase Authentication.
Backup and continuity (A.5.30, A.8.13)Point-in-time recovery and daily backups of the production database.
Logging and monitoring (A.8.15–8.16)Request and error logs retained by Google Cloud; function errors monitored.
Secure development (A.8.25–8.29, A.8.31)Input validation on every server entry point; automated security tests (access control, escalation, malformed input); separate test and production environments; version-controlled, tagged releases.
Data deletion and retention (A.8.10)In-app account deletion, administrator removal with cascading cleanup, and automatic deletion of ride records after 12 months.