Legal
Privacy Policy
Plain-language answers about the information Keep Stats handles for clubs, teams and players.
Who we are
Keep Stats is operated by Westvold Development, LLC (westvold.com). In this policy, "we", "us" and "our" mean Westvold Development, LLC. Keep Stats is made up of this website (getkeepstats.com), the Keep Stats web app (keepstats.app) and its API (api.keepstats.app).
What we collect
Accounts. You need an account to coach, to keep stats as a club member, or to follow a team as a parent. For an account we store your name, your email address, whether you have confirmed it, and when the account was created and last changed. If you sign in with a password, we store a one-way hash of the password (Argon2id), never the password itself. When you choose a password, we may check it against Have I Been Pwned's list of breached passwords; only the first five characters of the password's hash leave our servers. If we offer sign-in with Google or GitHub and you use it, we store which provider it is and that provider's ID for your account, and the provider shares your name and email address with us under its own privacy policy.
Signing in and your devices. When you sign in, your browser creates its own security key, and the key never leaves your device. Your session is tied to that key, so a stolen sign-in token is useless on another device. For each signed-in session we store hashes of the session's tokens, the public fingerprint of that device key, the IP address and browser type (user agent) the session was created from, the IP address and a one-way hash of the browser type from its last token refresh, and when it was created, last used and expires. You can see and end your signed-in devices from your account page.
Security records. To protect accounts, we record security events such as sign-ins, failed sign-ins, password and email changes, sign-in lockouts, invitations and billing changes. Each one has the IP address and browser type it came from. A club's members can see the security events of their club.
Clubs, members and teams. A club (an "organization" in the app) has a name, a short web address name (slug), its display settings (accent colour, recording mode, live counts, opponent detail), its plan, and a count of the games it has created. Its members are the coaches and staff the club invites by email, each with a role (owner, admin or member). A club's teams have a name, a sport and a field size. Every new club also gets a demo team and demo game with made-up players.
Players (rosters). Coaches enter their players, and most of them are minors. For each player we store their name, jersey number and positions, and, if the coach chooses to enter them, their school grade (K–12) and birth year. We don't ask for a player's full date of birth, address, photo, email or any contact details, and the app has no place to enter them. The age group shown in the app (for example "U12") is calculated from the birth year and isn't stored.
Games and stats. For each game we store the opponent's name, the date and optional kickoff time, the clock settings, who is keeping stats, the game's live state (status, period, clock and which players are on the field), and the events recorded: shots, shots on goal, goals, assists, saves, steals, and yellow and red cards. Each event has the player or the opponent's jersey number, the period, the game clock for cards, and when it was recorded. A club may also enter the opponent's players by jersey number with an optional name. Undone events are kept and marked as undone.
Parents (team followers). A parent follows a team through a link or QR code that a coach shares, and needs a Keep Stats account to do so. We store which teams each account follows and when it joined. If a coach removes a parent, we record the time of the removal so that the old link no longer lets them back in. Parents can see the team's name, schedule, player names, jersey numbers and stats (including players since removed from the roster, because their stats are part of past games). Parents never see members' or other parents' email addresses. The club's coaches can see each following parent's name and email address.
Helpers. A coach can invite someone outside the club to keep stats for one game. Helpers don't create an account. We store the name the coach gives them, the join code, who created it and when, whether the helper has been retired or removed, and which events their phone recorded. A helper's phone keeps a sign-in token for that one game only.
Billing. Keep Stats doesn't take payments yet. Once it does, payments are processed by Stripe. When a club buys a plan or a game pass, Stripe collects the card details and the billing name, email address and billing address, under Stripe's own privacy policy. We never see or store card numbers. We store the Stripe customer, subscription, Checkout session and payment IDs, the plan's team count, billing period and renewal date, and a record of each game pass (amount, the program year it was bought in, and when it was used, credited toward a plan, refunded or disputed). We use the billing address only so Stripe can calculate sales tax.
Email. We send account email (confirming your address, password resets, email changes, invitations to a club, and account deletion) from noreply@keepstats.app, through our email delivery provider, Resend. We keep each outgoing message, including its recipient, subject and body, in a queue until it is sent. Email that can't be delivered is kept until we remove it.
Server logs. Our API servers log every request they receive: the address requested (query parameters are redacted, except a short list we know are not sensitive), the response status and timing, the IP address and the browser type. We also record the timing of a sample of requests. We use these records for security and to keep the service running. Our monitoring provider keeps them for 14 days; the copy on our own servers is overwritten as newer logs arrive. The pages of this website and the web app's files are served without a request log.
Data on your device. So it can work with no signal at the field, the app keeps a copy of your clubs, teams, rosters and games, and the stats waiting to upload, in your browser's storage on your device. It also keeps your sign-in there. Signing out removes the sign-in, but not the copy of the data: to remove it, clear the site's data in your browser. Do that when you're done on a shared device.
This website. getkeepstats.com has no forms and no accounts. If you email us at hello@getkeepstats.com, it reaches us through our email forwarding provider, ImprovMX, and we keep your message and our reply as long as we need them to help you.
How we use it
We use this information to run Keep Stats: to record and sync a game's stats across devices, even when a phone was offline; to show schedules, summaries and season totals; to let coaches share a team with parents and invite helpers; to take payments and apply a club's plan; to send the account email described above; and to keep accounts and the service secure.
We don't sell personal information. We don't share it for targeted advertising, and we don't use player data for advertising or to build profiles of players.
Who we share it with
We share information only with the service providers that help us run Keep Stats, and only as needed for that purpose: DigitalOcean hosts our servers and database in the United States; Cloudflare R2 stores our encrypted backups; Resend sends our email; ImprovMX forwards email sent to hello@getkeepstats.com; Grafana Cloud, our monitoring provider, keeps our server metrics and logs; and Cloudflare Web Analytics counts visits to this website. Once Keep Stats takes payments, Stripe processes them and calculates sales tax. If you sign in with Google or GitHub, that provider handles the sign-in.
We may also disclose information if the law requires it, or to protect the safety of people or of Keep Stats. If our business or Keep Stats is sold or transferred, the information goes with it, and this policy continues to apply to it.
Inside a club, information is visible according to the app's roles: the club's members see its teams, rosters, games and members; parents see only the teams they follow; helpers see only the game they were invited to.
Website analytics
This website uses Cloudflare Web Analytics to count page views, so we can see which pages are visited. It collects the page address and referrer, the time of the visit, your browser, operating system and device type (from its user agent), your country (worked out from your IP address, which isn't stored), and how quickly the page loaded. We only see the totals.
Cloudflare Web Analytics doesn't use cookies or local storage, doesn't fingerprint your browser, and doesn't track you across other websites. Visits are recorded anonymously and aren't tied to you or your IP address.
The Keep Stats web app has no analytics and no advertising trackers, and it doesn't send us error or usage reports.
Player information
Keep Stats is for coaches and clubs. Accounts are for adults, and Keep Stats is not directed to children under 13. The player information in Keep Stats is entered by a coach or club staff member, not collected from the children themselves. By entering a player, or a helper's name, the club and coach confirm that they have the right to do so, including any permission from parents or guardians that their league, school or the law requires. For an opponent's players, we recommend jersey numbers alone.
We treat player information as sensitive. It is visible only to the club's members, to the parents the club invites to follow that team, and to helpers for the game they keep. We use it only to provide Keep Stats to the club. A parent or guardian who wants a child's information corrected or removed can ask the child's coach or club, or email us at hello@getkeepstats.com. We may need to confirm that you are the child's parent or guardian, and we will work with the club to handle it. On request, we remove a player's name so it no longer appears; recorded stats stay, without the name, because the team's game records depend on them.
Your choices and rights
You can update your name and email address and end signed-in sessions from your account page. You can delete your account at any time from the app. Club owners can delete their club, which deletes its teams, players, games and stats. A coach can edit a player's details at any time.
To ask for a copy of your information, a correction, or deletion of anything you can't remove yourself, email hello@getkeepstats.com. We may need to confirm the request comes from you.
Data retention
Club data (teams, rosters, games and stats) is kept for as long as the club exists, so season history stays intact, including after a plan ends: a club whose plan ends becomes read-only, not deleted. Removing a player from a roster hides them from the current roster, but their name stays attached to the stats they already recorded. Archiving a team keeps its roster and games. Deleting a game deletes its stats. Deleting a club deletes its teams, players, games, stats, helpers, parent links and memberships.
When you delete your account, we delete your account, sign-in methods, sessions, pending email links and any queued email to your address. If you're the only member of a club, the club is deleted with your account. If others remain, only your membership is removed (an only owner has to hand over ownership or delete the club first). Security events tied to a club that still exists are kept for that club's audit log, but your user ID, IP address and browser type are removed from them. Any other security events of yours are deleted. When a club is deleted, its Stripe subscription is cancelled and its Stripe customer record is deleted. Stripe keeps invoices as financial records.
Some records are deleted automatically: expired sessions a day after they expire, expired email links seven days after they expire, security events after 90 days, sent email seven days after it was queued, and payment-processor event records 30 days after they're processed.
Deleted data stays in our encrypted backups until they age out, within about 30 days. If we ever restore a backup, we delete again anything that was deleted after it was made.
Security
Information is encrypted in transit between your device and our servers, and our backups are encrypted. Sign-in tokens are tied to your device's own key, passwords are stored only as strong one-way hashes, repeated failed sign-ins lock an account for a while, and each club's data is kept separate from every other club's. No system is perfectly secure, but we work to protect the information you trust us with.
Changes to this policy
We may update this policy as Keep Stats changes. We'll change the date at the top, and we'll tell club owners by email before a material change takes effect.
Contact
Questions about privacy? Email us at hello@getkeepstats.com and we'll get back to you.