Straightforward about how your data is handled.
League Vitals stores rosters, schedules, stats, and player emails — not payment cards, not government IDs, not health records. Here’s exactly what we do with it and where it lives.
The short version.
Hosted in North America
Servers, databases, and encrypted backups are hosted with our cloud provider in Canadian and US regions. No offshore hops for your league’s data.
Encrypted in transit and at rest
All traffic is HTTPS (TLS 1.2+). Managed Postgres and object storage encrypt data at rest at the provider level.
Automated backups
Managed daily backups at the database level, plus per-league restore points (3 most recent per league) that any league admin can trigger and roll back to.
Role-based access control
League owner, league manager, GM, captain, scorekeeper, pickup manager, player, sysadmin — every route enforces role at the API level, not just the UI.
CSV export on every tier
Your league can leave at any time, on any tier, with a full CSV export of rosters, stats, standings, and boxscores. Your data is yours.
Audit log
League admin actions (roster changes, tier changes, restores, deletions) write to an audit log visible to league owners and sysadmins.
What we run on.
Application & database
Node.js API server and React frontend, deployed on a managed platform-as-a-service provider with automatic HTTPS termination, DDoS mitigation, and geographic redundancy. Managed Postgres for the primary datastore, with daily automated backups retained by the provider.
Storage & email
File and media uploads use encrypted object storage. Transactional email (check-in prompts, notifications, contact form, password resets) is sent through Resend. Marketing email — if any — goes through the same provider with opt-out on every message.
Payments
Paid subscription billing is handled by Stripe. We never see or store credit-card numbers. Stripe is PCI-DSS Level 1 certified.
SMS (Starter & up)
SMS notifications are sent through a compliant messaging provider with opt-in captured at signup, opt-out via reply STOP, and per-league phone number pooling. See SMS terms.
Only what we need to run the game.
Account data
Name, email, phone (optional), password hash, and roles / permissions in each league you belong to.
League and roster data
Team rosters, jersey numbers, positions, schedules, standings, boxscores, chat messages, check-ins, and awards history. Uploaded by league admins — not scraped from anywhere.
What we don’t collect
We don’t collect government IDs, addresses, health data, or payment card numbers. We don’t buy or resell player data. We don’t run third-party ad-tech pixels on the app or the marketing site.
For the full data-handling breakdown, see the Privacy Policy.
Found a security issue? Tell us first.
If you believe you’ve found a security vulnerability in League Vitals, please email us at security@leaguevitals.com instead of posting publicly. We ask that you:
- Give us reasonable time to investigate and fix the issue before disclosing it publicly.
- Avoid accessing or exfiltrating data that doesn’t belong to you.
- Avoid actions that would degrade service for legitimate league admins or players (denial-of-service, spamming, destructive testing).
We’ll acknowledge your report within 2 business days, keep you updated as we investigate, and credit you (if you’d like) once the fix is out. We’re a small team and don’t currently run a paid bug-bounty program, but a heartfelt thank-you and a mention in release notes is on offer.
What we’re not.
League Vitals is a small operator-built SaaS. That means:
- We don’t currently hold SOC 2, ISO 27001, or HIPAA certifications. If your organization requires those, we’re probably not the right fit today — ask and we’ll tell you honestly.
- We don’t offer contract-grade DPAs, SSO, or SAML today. League+ customers with association-scale requirements can talk to us about custom terms.
- We inherit security controls from our infrastructure providers (Render, Stripe, Resend, and managed Postgres). If a provider has an incident, that affects us too — we monitor their status pages and communicate downtime to affected leagues.
None of this is unusual for a small SaaS at our scale. We’re listing it here so you can decide whether it’s the right level of formality for your league.
Questions about your league’s data?
Whether it’s a specific concern about hosting location, backup retention, or data export — ask. We reply within one business day.