Privacy Policy
Volley Pool ("Volley Pool", "we", "us") is an app that helps parents on a youth sports team coordinate carpools. This policy explains what we collect, why, where it is stored, who can see it, how we protect it, how long we keep it, and the choices you have. We collect only what the app needs to do its job (data minimization), and we do not sell personal information or show advertising.
- We collect your name, email, phone and home address, your child's name, and the ride information you create. Nothing else.
- We do not collect your device's location, contacts, photos, or advertising identifiers, and the app has no analytics or advertising software.
- Only approved members of your own team can see your name, phone and address. Gate codes and notes are visible only to the people they're for.
- Your data is stored with Google Cloud (Firebase) in the United States, encrypted in transit and at rest.
- You can delete your account yourself, in the app, at any time: Profile → Delete My Account.
- What we collect
- Why we collect it
- Who can see what
- Who we share it with
- Where and how it's stored
- How we protect it
- How long we keep it
- Your choices and rights
- Children's information
- If something goes wrong
- Changes to this policy
- Contact us
- Appendix: ISO/IEC 27001 alignment
1. What we collect
| Information | Details | Who provides it |
|---|---|---|
| Account | Email address; password (we never see it — Google's authentication service stores only a salted hash); whether your email is verified; sign-in times. | You |
| Profile | First name, last name, phone number, your role (parent or team admin), and when you accepted these terms. | You (an admin may pre-fill your phone when reserving a spot for your child) |
| Household | Home address (street, unit, city, state, ZIP, and map coordinates from the address lookup); optional private notes such as a gate code. | You, or a team admin on your behalf |
| Players | Your child's first and last name, which household they belong to, and a photo-consent preference. We do not store photos. | You or a team admin |
| Team | Team and league name, activation code, time zone, and who the administrators are. | Team administrators |
| Events | Practices, games and trainings: title, venue name and address, times, drop-off notes. | Team administrators |
| Rides | Ride offers (seats, notes), ride requests (which players, pickup or drop-off address, notes), and claims between two households (players, meeting spot, notes, estimated time, status and timestamps). | Parents |
| Invitations | Household invite codes you generate; an email address (and optional phone) an administrator enters to reserve a spot for you. | You / administrators |
| Technical | Request logs kept by Google Cloud (which can include IP address and timestamps) and error logs from our server functions. | Generated automatically |
What we do not collect
- Your device's location (GPS). Addresses you type are looked up as text; the app never reads your location.
- Your contacts, photos, microphone, camera, health data, or advertising identifiers.
- Analytics, tracking, or advertising data. The app contains no third-party analytics or advertising software.
- Payment information. Volley Pool is currently free.
2. Why we collect it
- To run the service: create and secure your account, keep teams closed to invited families, and let parents offer, request, confirm and cancel rides.
- To let families contact each other: names and phone numbers are shared inside a team so a parent can talk to a driver before trusting them with their child.
- To show where to meet: addresses are used to display pickup and drop-off locations and to open them in a maps app you choose.
- To keep the service safe and working: verify email addresses, prevent misuse, fix errors, and keep an audit trail of who changed what.
- To meet legal obligations and resolve disputes.
We do not use your information for advertising, profiling, or automated decisions about you, and we do not sell it.
3. Who can see what
Access is limited by role and enforced on our servers, not just in the app.
| Information | Visible to |
|---|---|
| Your name, phone number and home address; players' names | Approved members of your own team and its administrators. Never other teams. |
| Ride offers and ride requests (without notes) | Approved members of your own team. |
| A ride claim (the arrangement between a rider's household and a driver's), including the meeting spot and notes | Only the two households involved. |
| Notes on a ride request (for example a gate code) | Only the household that wrote them, until a driver responds; then the claim's two households. |
| Household notes and access information | Your household, team administrators, and a driver whose claim for your household is confirmed. |
| Your password | No one, including us. |
Team administrators can approve families, manage the roster and events, move a person between households, and delete accounts or players. A league-level administrator can do the same across the teams in their league. Administrators cannot read ride claims they are not part of.
4. Who we share it with
We share personal information only with the service providers needed to run Volley Pool, under their data-processing terms, and when the law requires.
- Google Cloud / Firebase — hosts the database, sign-in, server functions, and this website. Google acts as our processor. Google Cloud maintains ISO/IEC 27001, 27017 and 27018 certifications and SOC 2 reports.
- Apple — address search uses Apple Maps (MapKit): the text you type into an address field is sent to Apple to suggest and validate addresses. Apple also provides the App Store and TestFlight; any diagnostics you opt into sharing with Apple are governed by Apple's policies, not ours.
- Maps apps you choose — when you tap an address and choose Apple Maps or Google Maps, that address is passed to that app at your request.
- Other teams, advertisers, data brokers — never.
- Legal and safety — we may disclose information if required by law or valid legal process, or to protect someone's safety, after reviewing the request.
5. Where and how it's stored
- Data is stored in Google Cloud Firestore in the United States (Iowa,
us-central1); sign-in is handled by Firebase Authentication; server logic runs on Cloud Functions in the same region. - Separate environments are kept for testing and production; production data is not used for testing.
- Because the data is processed in the United States, people using Volley Pool from elsewhere are transferring their information there. The service is intended for teams in the United States.
6. How we protect it
Our security practices are designed around the control framework of ISO/IEC 27001 and 27002 (see the appendix).
- Encryption: all traffic between the app, this site and our servers uses TLS; stored data is encrypted at rest by Google.
- Authentication: accounts require a verified email address. Deleting an account requires you to re-enter your password.
- Closed teams: joining requires a team activation code or an administrator's invitation, and a family's household must be approved by a team administrator before it can see the team.
- Least privilege: the app can read only what your role allows. Anything sensitive — creating teams and households, confirming rides, deleting accounts, changing roles — can be done only by our server functions, which re-check who is asking. A person cannot grant themselves access.
- Separation of sensitive data: gate codes, household notes and ride notes live in separately protected records readable only by the people they are for.
- Input validation: every request to our servers is validated for type, size and format before it touches the database.
- Testing: we maintain automated tests that attempt unauthorized access, privilege escalation and malformed or oversized input against our access rules and server functions.
- Backups and recovery: the production database has point-in-time recovery (seven days) and daily backups kept for 14 days.
- Abuse and cost controls: server functions have capped capacity, and errors are logged and reviewed.
- Vulnerability reports: please email security@volleypool.com (see also our security.txt). We will acknowledge good-faith reports promptly and will not pursue researchers who follow responsible disclosure.
No system is perfectly secure. You can help: use a strong, unique password, keep your phone's software up to date, and share team and invite codes only with people who should have them.
7. How long we keep it
| Information | Kept |
|---|---|
| Account and profile | Until you delete your account (Profile → Delete My Account) or an administrator removes it. We do not delete accounts for inactivity. |
| Household and players | While on the team roster. Deleting your account does not remove your child from the roster; a team administrator manages the roster. Removing a player deletes their record, and, if it was the household's last player, the household's guardian accounts as well (administrators are kept). |
| Rides (events, legs, offers, requests, claims) | Automatically deleted 12 months after the event or ride, a period we keep for safety and to resolve disputes. When an account is deleted, its rides are removed (if it was its household's last guardian) or continue under the remaining guardian. |
| Invite codes | Expire after 14 days; expired codes are deleted about 30 days later. |
| Spots an administrator reserved for a family | Until claimed, or deleted after 12 months. |
| Server logs | About 30 days, then deleted by Google Cloud's default log retention. |
| Backups | Deleted data can remain in encrypted backups for up to 14 days before it is permanently removed. |
8. Your choices and rights
- See and correct: edit your name, phone, address and players in Profile. Ask us (below) for a copy of everything we hold about you.
- Delete: use Profile → Delete My Account, which explains exactly what will happen, or ask us.
- Object or restrict: tell us if you'd like us to stop using certain information; some information is needed for the service to work.
- Portability: we'll provide your information in a common format on request.
- Complaints: contact us first; you may also contact your local data-protection or consumer-protection authority.
We respond to requests within 30 days. If you are a California, Nevada or other U.S. state resident with additional statutory rights, we honor them. We do not sell or share personal information for advertising, so there is nothing to opt out of.
9. Children's information
Volley Pool is for parents and guardians (18 and over) and team administrators. Children do not have accounts and the app is not directed at children. A child's first and last name appears only because a parent or team administrator adds them to the roster so rides can be arranged. We do not collect anything else about children, do not collect it from children, and do not use it for anything except coordinating rides for their team. A parent can have their child's record corrected or removed by contacting a team administrator or us.
10. If something goes wrong
If we learn of a security incident affecting personal information, we will contain it, investigate it, and notify affected people and the relevant authorities without undue delay and as the law requires, describing what happened, what information was involved, and what you can do.
11. Changes to this policy
When we change this policy in a meaningful way we update the version and effective date above and tell you in the app. If a change requires your agreement, you will be asked to accept it before continuing.
12. Contact us
Privacy requests and questions: privacy@volleypool.com
Security reports: security@volleypool.com
General support: support@volleypool.com
Appendix: ISO/IEC 27001 alignment
Volley Pool's information-security practices are designed to align with the control themes of ISO/IEC 27001:2022 (Annex A) and ISO/IEC 27002. This is a description of our approach, not a certification; our hosting provider, Google Cloud, is independently certified for the infrastructure it operates.
| Control theme | How we address it |
|---|---|
| Policies and roles (A.5.1–5.4) | This policy and the Terms of Use; defined roles (parent, team administrator, league administrator) with separation of duties enforced by the system. |
| Inventory and classification (A.5.9–5.13) | The data inventory in section 1 and the visibility tiers in section 3 classify information by sensitivity (roster-visible, household-private, party-only). |
| Access control and identity (A.5.15–5.18, A.8.2–8.5) | Verified-email authentication; role- and household-based access enforced server-side; privileged actions only through server functions that re-check authorization; invite codes expire; recent sign-in required for account deletion. |
| Supplier relationships (A.5.19–5.23) | Google Cloud (hosting, database, authentication) and Apple (address search, distribution) are the only suppliers that handle personal data, under their standard data-processing terms. |
| Incident management (A.5.24–5.28) | Section 10; a published security contact; error logging. |
| Legal and privacy compliance (A.5.31, A.5.34) | Data minimization, purpose limitation, retention limits, and individual rights as described in this policy. |
| People (A.6) | Access to production systems is limited to the people who operate the service. |
| Physical (A.7) | Inherited from Google Cloud's certified data centres; no on-premises storage of personal data. |
| Cryptography (A.8.24) | TLS in transit; encryption at rest by Google; passwords stored only as salted hashes by Firebase Authentication. |
| Backup and continuity (A.5.30, A.8.13) | Point-in-time recovery and daily backups of the production database. |
| Logging and monitoring (A.8.15–8.16) | Request and error logs retained by Google Cloud; function errors monitored. |
| Secure development (A.8.25–8.29, A.8.31) | Input validation on every server entry point; automated security tests (access control, escalation, malformed input); separate test and production environments; version-controlled, tagged releases. |
| Data deletion and retention (A.8.10) | In-app account deletion, administrator removal with cascading cleanup, and automatic deletion of ride records after 12 months. |