Straight answers about your data.
Effective August 27, 2026 · Last updated August 27, 2026 · Contact our Privacy Officer
TL;DR
- We collect what we need to run your league — account, roster, schedules, chat, and (if you turn it on) SMS.
- We don’t sell your data. We don’t share it with advertisers. We don’t run analytics or ad-tech cookies.
- We store data on managed infrastructure in North America. Some sub-processors are US-based — listed below.
- You can access, correct, or delete your data by emailing privacy@leaguevitals.com. We reply within 30 days.
- Under Quebec Law 25, our Privacy Officer is named below. Under GDPR / CCPA, we honour access, correction, deletion, and portability requests.
1. Who we are
League Vitals is a hockey-league management platform operated by Praxis Modern Business Solutions (an Ontario, Canada business) under the brand “League Vitals.” This policy covers leaguevitals.com, the League Vitals portal at portal.leaguevitals.com, and the League Vitals Android application (com.leaguevitals.app). We collectively refer to these as “League Vitals” or “we” in this policy.
2. What we collect
We collect only what’s needed to run the service. Concretely:
- Account data. Name, email, hashed password. Optional phone number (only if you opt into SMS).
- League & roster data. League name, team names, player names, positions, jersey numbers, and (if the league captures it) date of birth. This data is entered by league operators or captains, not by players directly.
- Schedules, boxscores & standings. Games, results, goals, assists, shots, plus/minus, and derived leaderboards.
- Chat & messages. Messages you send in team chat, league broadcast messages, and captain-triggered game-night check-ins.
- Waivers. If your league uses waivers, signed PDFs (with signature timestamps) are stored on our behalf.
- Push notifications. If you opt into web push, your browser gives us a subscription endpoint (VAPID keys) so we can deliver notifications. We can’t read your push endpoint back to identify you personally — it’s a delivery address.
- SMS opt-in & delivery logs. If you opt into SMS, we log the consent event (date, time, IP, wording), your phone number, and message-delivery status. See SMS Terms.
- Basic technical logs. Server logs record IP address, user agent, request path, and timestamps — used for security, debugging, and abuse prevention.
3. What we don’t collect
- We don’t use analytics, tracking pixels, session replay, or advertising SDKs. (See § 7 on cookies.)
- We don’t collect location data.
- We don’t collect contact lists, calendar contents, microphone, or camera data.
- We don’t collect government ID numbers, health records, financial account numbers, or sensitive category data under GDPR Art. 9.
- We don’t sell your data. We don’t share it with data brokers or for cross-context behavioural advertising.
4. Why we collect it (purposes)
We use the data above only for these purposes:
- To run the service — authenticate you, show your league, deliver notifications, keep your data available across devices.
- To keep it secure — abuse detection, rate limiting, fraud prevention, and honouring deletion requests.
- To bill you — for paid tiers, we hand off checkout to Stripe (see § 8). We do not store credit-card numbers on our systems.
- To communicate with you — transactional email (account verification, waiver notifications, password reset) via Resend, and (if you opt in) SMS via Telnyx.
- To meet our legal obligations — tax records, breach records, and lawful requests from Canadian authorities.
We do not make any decision based exclusively on automated processing that produces legal or similarly significant effects on you.
5. Legal basis (Canada, EU, Quebec)
Under Canadian federal law (PIPEDA), we rely on your consent to collect and use personal information. For EU visitors, our lawful bases under GDPR Article 6 are (a) contract — to provide the service you signed up for, (b) legitimate interests — to secure and maintain the service, and (c) consent — for anything outside those (e.g., SMS opt-in). For Quebec residents, we collect only for the specific purposes identified above and request separate consent for anything beyond that scope.
6. Where we store your data & sub-processors
Your data is hosted on managed infrastructure in North America (primarily United States). Backups are handled by our infrastructure providers per their standard policies. Some sub-processors are US-based, which means your personal information is transferred outside of Canada. For Quebec residents, this transfer is disclosed here and we have taken commercially reasonable steps to ensure adequate protection.
| Sub-processor | Purpose | Location |
|---|---|---|
| Render | Application hosting & compute | United States |
| Managed Postgres provider (Neon or equivalent) | Primary database | United States |
| Cloudflare | DNS, CDN, TLS, image storage, and waiver PDF storage | Global edge (US-primary) |
| Resend | Transactional email delivery | United States |
| Telnyx | SMS delivery (Canadian phone numbers only in current rollout) | United States (Canada routing) |
| Google — Firebase Cloud Messaging | Web Push delivery path (Chrome only) | Global |
| Stripe | Card payments (coming soon — not live at time of writing) | United States |
We update this list when we add or remove a sub-processor. If a change materially affects your data, we’ll notify affected users.
7. Cookies
We use only strictly necessary cookies — the kind required to sign you in, keep your session, and protect the site against abuse (including Cloudflare’s __cf_bm bot-management cookie). We do not use analytics, advertising, or cross-site tracking cookies. Because our cookies are strictly necessary, we do not require a consent banner under GDPR / Quebec Law 25 to set them. If we ever add non-essential cookies (e.g., analytics), we’ll surface a consent banner and update this section before doing so.
8. Payments
Paid tiers on League Vitals use Stripe for checkout and billing when it goes live. We do not store credit-card numbers or CVCs on our systems — Stripe handles that end-to-end. We store the plan, the amount charged, and payment history (last-4 digits + card brand only) associated with your account.
9. Minors on rosters
League Vitals is not directed to children. We do not knowingly permit anyone under 13 to create an account. Minors are added to rosters by adult league operators, captains, or parents — not by the minors themselves. If your league captures date of birth for a minor, that information is used only to run the league (age divisions, waivers) and is not used for marketing. If you believe a child under 13 has provided us personal information directly, contact privacy@leaguevitals.com and we’ll delete it. Under Quebec Law 25, we treat data about minors under 14 as requiring parental consent, and expect league operators to have that authority.
10. Your privacy rights
Depending on where you live, you have some or all of these rights:
- Access. Get a copy of the personal information we hold about you.
- Correction / rectification. Fix inaccurate or incomplete data.
- Deletion / erasure. Delete your account and personal data, subject to legal retention (e.g., tax records).
- Portability. Get your data in a structured, machine-readable format (CSV export is available in-app on every tier).
- Withdraw consent. Withdraw any consent you gave (e.g., SMS opt-in). For SMS, we honour STOP requests within 10 business days per CASL.
- Complain. Complain to your privacy regulator — the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, your EU supervisory authority, or the California Attorney General.
To exercise any of these rights, email privacy@leaguevitals.com. We respond within 30 days (15 business days for CCPA opt-out requests). We may ask you to verify your identity by signing in or providing information tied to your account — we won’t require you to create an account just to opt out.
11. California residents
League Vitals does not sell your personal information and does not share it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA). Because we do not sell or share, no “Do Not Sell or Share My Personal Information” link is required. We honour the Global Privacy Control (GPC) signal even though it doesn’t change anything for us today, because we don’t sell or share. If this ever changes, we’ll update this policy and provide the required opt-out.
12. Quebec residents (Law 25)
Under Quebec’s Act respecting the protection of personal information in the private sector (Law 25):
- Our Privacy Officer is named in § 15 below.
- We collect personal information only for the specific purposes described in § 4.
- We do not use identification, location, or profiling functions by default. If we ever add any, they will be off by default and require your explicit opt-in.
- Some of your data is transferred outside Quebec (to US-based sub-processors listed in § 6). We assess adequate protection before transferring.
- You have rights of access, correction, portability, and de-indexation. Contact our Privacy Officer to exercise them.
13. How long we keep your data
- Account credentials: for the life of your account, plus 24 months of security audit logs.
- Roster PII (adults): the current season plus 2 years.
- Roster PII & waivers (minors): longer — typically until the minor reaches age of majority plus 2 years — because civil-limitations periods run from age of majority.
- Finance records: 7 years post-transaction, per Canada Revenue Agency requirements.
- Chat messages: deleted messages are tombstoned for 30 days then permanently removed.
- SMS consent logs: duration of consent plus 3 years after withdrawal (for CASL evidence).
- SMS delivery logs: 24 months.
- Error logs: 90 days.
When you delete your account, we delete or anonymize your personal data on this schedule. Deletion propagates through backups over the next backup rotation cycle.
14. Security
We use TLS 1.2+ for data in transit and encryption at rest on our managed database and object storage. Access to production data is role-restricted and audit-logged. See our security page for the full posture, including what we don’t hold (no SOC 2 today, no SSO). If you discover a security vulnerability, please email security@leaguevitals.com — we acknowledge within 2 business days.
15. Breach notification
If we experience a breach of security safeguards involving personal information that creates a real risk of significant harm to you, we will:
- Notify the Office of the Privacy Commissioner of Canada as soon as feasible (PIPEDA s. 10.1);
- Notify affected individuals directly — typically by email — with a plain-language description of what happened and what you can do;
- Notify the Commission d’accès à l’information du Québec where a “risk of serious injury” is present, and comply with the CAI’s prescribed notice content;
- Retain a record of every breach of security safeguards for at least 24 months, whether or not it met the notification threshold.
16. Changes to this policy
We may update this policy from time to time. If we make material changes, we’ll notify you by email or in-app before they take effect. The “Last updated” date at the top of this page tells you the current version.
17. Contact our Privacy Officer
You can reach our Privacy Officer at:
- Email: privacy@leaguevitals.com
- Mail: Privacy Officer, Praxis Modern Business Solutions, Toronto, Ontario, Canada
For general support, use support@leaguevitals.com. For security disclosure, use security@leaguevitals.com.
This policy is provided for informational purposes and is not legal advice. If a specific provision here conflicts with mandatory local law that applies to you, the mandatory local law prevails.