Privacy Policy
SportsSignup takes privacy and data protection issues seriously.
We have designed this Privacy Policy to explain how we handle personally identifiable
information collected from participants who register for services and submit information
to SportsSignup through the Internet.
As the SportsSignup services evolve, we may revise this policy, so
please check back frequently. If you have questions about SportsSignup’s privacy
practices please contact us at privacy@sportssignup.com.
SportsSignup is committed to
safeguarding your privacy online. Our Privacy Policy is posted below to help
you understand the care with which personal information is treated whenever you use our
web site.
Scope of this Privacy Policy
This Privacy Policy covers SportsSignup’s treatment of personally
identifiable information collected from individuals, families and teams (hereafter
“Registrant” or “Registrants”) who use the SportsSignup services, as well as consumer
information that we acquire in the course of our business.
This Policy does not apply to the practices of companies that SportsSignup
does not own or control, or to people that SportsSignup does not employ or manage.
Personal Information
The SportsSignup system collects information about Registrants on behalf of the
organization (“Customer”) in which a Registrant is participating. SportsSignup acts as an agent in collecting information from Registrant for the Customer and produces a variety of reports and
notification for the Customer about Registrants.
The information collected will not be shared with
any party other than the authorized representatives of the Customer,
unless we are required to do so to complete a requirement for a Customer,
such as when team information is sent to a separate scheduling program, personal information is sent to a background check company with the applicant's
permission, or unless authorization is granted and
explicitly defined in SportsSignup’s Service Agreement with Customer. For
example, Registrant information may be sent as part of a roster submission process
from the Customer to Customer’s parent organization(s). Registrants
are advised to check with their organization regarding the use and privacy of personal
information collected on behalf of the Customer.
Registrant information is protected by a password that Registrant chooses. Users should assure that the password selection is not
obvious (birthdate, name, address, etc.) and should change it periodically.
Registrant information is stored in Microsoft's
SQL Server Database, which supports industry standard security. The
Database is hosted by Logical Net, a top-grade hosting company and
Microsoft Certified Partner. Logical Net uses the latest technologies available when ensuring data
security and database availability.
Credit Card Information
When Registrants use the SportsSignup system to make payment
via credit card, the payment information is entered on a secure web page, using
SSL encryption (see Web Security section) and processed via the Customer’s merchant
account. Only the last 4 digits of the credit card number are stored in the SportsSignup
system. The Customer name (e.g. Springfield Soccer League”) will appear on the Registrant’s
credit card statement.
For Customer’s electing to have SportsSignup process credit cards
on their behalf, payment information is entered on a secure web page, using SSL
encryption (see Web Security section) and processed by Authorize.Net, a leader in
secure payment processing. Only the last 4 digits of the credit card number are
stored in the SportsSignup system. A charge from www.SportsSignup.com will appear
on the Registrant’s credit card statement.
Social Security Numbers
SportsSignup provides a service, called KidSafePlus, to help manage the background check process for Customer’s
volunteers. While it is understandable that consumers are reluctant to disclose
their Social Security numbers, it is a crucial piece of information to help ensure
the name being provided will match potential criminal records. Social Security
numbers are captured as part of a volunteer's profile, and passed on to ChoicePoint
Corporation (via secure communications), who performs the background check.
The Social Security numbers are deleted from the SportsSignup system once the results
are returned from ChoicePoint (often minutes after the user supplies the information).
Mailing Lists
E-mailing Registrants is the primary method by which Customers
communicate with Registrants - and a vital component of the SportsSignup system. Therefore, Registrants can expect to receive periodic e-mails from the Customer
regarding sign-up deadlines, meeting
notices, and other timely notifications.
E-mail information collected will not be shared with any other
party, unless authorization is granted and explicitly defined in SportsSignup’s
Service Agreement with Customer. Registrants are advised to check with their organization
regarding the use and privacy of personal information collected on behalf of the
Customer.
Security Policy
SportsSignup and our partners commit to the highest level of security
available. This statement covers the following topics, and what SportsSignup
and our partners are doing to ensure the security of your information and the availability
of our application:
Web Security
It is important and expected that the link between the end user’s Browser and our
Web Site (web server) is secure – that the information remains private and integral.
Our application uses Secure Sockets Layer, SSL, the standard security technology
for creating an encrypted link between a web server and a browser. SSL is an industry
standard that uses 128 bit key encryption, and is used by millions of websites in
the protection of their online transactions with their customers.
In order to be able to generate an SSL link, a web server requires an SSL Certificate
(X.509). Our certificate is provided by Comodo Group (comodogroup.com).
The complexities of the SSL protocol remain invisible to your customers. Instead
their browsers provide them with a key indicator to let them know they are currently
protected by an SSL encrypted session - the Padlock:

( As seen by users of Internet Explorer 6.0 )
Clicking on the Padlock displays our SSL Certificate and details. When a browser
connects to a secure site it will retrieve the site's SSL Certificate and check
that it has not expired, it has been issued by a Certification Authority the browser
trusts, and that it is being used by the website for which it has been issued. If
it fails on any one of these checks the browser will display a warning to the end
user.
Transaction Security
When Registrants use the SportsSignup system to make payment via credit card, the
payment information is entered on a secure web page, using SSL encryption (see Web
Security section) and processed via the Customer’s merchant account. Only
the last 4 digits of the credit card number are stored in the SportsSignup system.
The Customer name (e.g. Springfield Soccer League”) will appear on the Registrant’s
credit card statement.
For Customer’s electing to have SportsSignup process credit cards on their behalf,
payment information is entered on a secure web page, using SSL encryption (see Web
Security section) and processed by Authorize.Net, a leader in secure payment
processing. Only the last 4 digits of the credit card number are stored in the SportsSignup
system. A charge from www.SportsSignup.com will appear on the Registrant’s credit
card statement.
Application Security
Our application is running on computers hosted and managed by Logical Net (www.logical.net).
To ensure application security, the following is in place:
- Cisco routers with advanced port blocking.
- All ports except 80 and 443 blocked to the public
- Maintenance access to server only via VPN
- Intrusion Detectoin
- Security auditing
- All usernames/passwords are changed from their default values
- All applicable Patches and updates are run after testing and approval
Database Security
Data is stored in Microsoft’s SQL Server database. There are several keys to managing
a secure database that Logical Net performs:
- Advanced SQL Server Security Configuration
- Installing SQL Server Patches
- No default database passwords
- Run on a dedicated machine with no external visibility
Application Availability
Logical Net has invested in many areas to ensure very high availability (up time).
The key to high availability is redundant systems, such that if one fails, another
is available to keep the system going while the repair is made.
The data center
has fully redundant T-3 links to the Internet. The links
are provided by Time Warner and Verizon. The Internet bandwidth
providers are Sprint and AT&T.
The core network uses redundant Cisco 7700 series routers and redundant Cisco switches
The data center is controlled and protected with redundant 22-Ton Liebert cooling
units, redundant FM200 automatic fire suppression systems, a
room-sized UPS, and a generator which starts automatically
if power is interrupted. It has fuel sufficient for
The servers have RAID 1 disks (mirrors).
Changes to this Privacy Policy
SportsSignup reserves the right to modify or amend this Privacy Policy at any time and for any reason. If there are material changes to this statement or in how SportsSignup
will use personally identifiable information, SportsSignup will post notice on the
SportsSignup homepage at www.sportssignup.com prior to implementing the change.
The amended Terms shall automatically become effective immediately after they are
posted. Your continued use of the site or SportsSignup services after the posting
of the amended Terms on the Site constitutes your affirmative: (a) acknowledgement
of the terms and its modifications; and (b) agreement to abide and be bound by the
terms, as amended. If you have additional questions about this
Policy, please contact
privacy@SportsSignup.com.