Privacy Policy

Last updated: May 1, 2026

1. Introduction

YourNextPlay ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our college soccer recruitment platform.

YourNextPlay is operated as a sole proprietorship by Samantha Merlin in California, USA. For privacy questions or to exercise the rights described in this policy, contact support@yournextplay.ai.

By using YourNextPlay, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide

  • Account information (name, email address, password)
  • Player profile information (graduation year, position, club team, league)
  • Academic information (high school, GPA, intended major)
  • Contact information (email, city, state)
  • Social media links (YouTube, Instagram, Facebook)
  • Coach reference information (coach names and emails)

2.2 Information from Google Services

If you choose to sign in with Google or connect your Gmail account:

  • Basic profile information (name, email, profile picture)
  • Gmail send capability (only when you explicitly connect Gmail)

Important: We only request the "gmail.send" permission, which allows you to send emails to college coaches through our platform. We do not read, access, or store any of your existing emails.

2.3 Automatically Collected Information

  • Device and browser information
  • IP address
  • Usage data and analytics

We log basic activity data on the platform — including pages visited, timestamps, and request metadata such as IP address — for security, abuse-detection, and platform-integrity purposes. This data is retained for up to 90 days, is never shared with third parties, and is never used for marketing. We use this activity data to detect unusual behavior such as automated scraping or other violations of our Terms of Service, and to take appropriate action when violations occur.

3. How We Use Your Information

We use your information to:

  • Create and manage your player profile
  • Match you with college soccer programs based on your stated preferences
  • Send emails to college coaches on your behalf when you explicitly trigger a send
  • Process subscription payments through Stripe
  • Send transactional and account communications (welcome, payment receipts, event reminders, password resets)
  • Provide customer support and respond to your inquiries
  • Detect and prevent fraud, abuse, and violations of our Terms of Service
  • Comply with legal obligations and respond to lawful requests
  • Improve the Service through aggregated, non-identifying usage analysis

We do not use your information to build advertising profiles, sell to data brokers, or train machine-learning models that would expose your data outside the Service.

4. Gmail API Usage & Limited Use Disclosure

Google API Services User Data Policy Compliance

YourNextPlay's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

For detailed information about how we use Gmail integration, please see our Gmail Usage Policy.

Our Gmail integration is limited to:

  • Sending emails on your behalf only when you explicitly click "Send" to contact a college coach
  • We request only the gmail.send permission — we cannot read, scan, or access any of your existing emails
  • We do not use Gmail data for advertising, marketing, or any purpose other than sending your requested emails
  • We do not share, sell, or transfer Gmail data to any third parties
  • All Gmail authentication tokens are encrypted using AES-256-GCM encryption
  • Sending is rate-limited to 100 emails per day per connected Gmail account to protect your sender reputation. Larger batches are automatically scheduled across multiple days. See the Gmail Usage Policy for details on how the queue works.
  • You can disconnect Gmail and revoke access at any time from your Settings page

5. Data Sharing & Subprocessors

We do not sell, trade, or rent your personal information to third parties.

We share your information only in these cases:

  • When you send a coach email: the email content (which may include your name, contact details, profile information, and references) is delivered to the coach you select via your connected Gmail account.
  • With operational subprocessors who help us run the Service (see list below).
  • Where required by law, court order, or to investigate fraud, abuse, or violations of our Terms of Service.
  • In connection with a business transfer (e.g., merger, acquisition, sale of assets), in which case we will notify you and any successor entity will be bound by this Privacy Policy.

Current subprocessors:

  • Stripe — payment processing. We do not store credit card numbers; Stripe handles all card data per PCI-DSS standards.
  • Google (Gmail API + OAuth) — sign-in and sending coach emails from your personal Gmail account.
  • Resend — transactional email delivery (welcome emails, password resets, event reminders, account notifications).
  • Render — application and database hosting (United States, Oregon region).
  • Cloudflare — content delivery network and DDoS protection.
  • Microsoft 365 — operator-side support inbox for handling your customer-support replies.
  • ZeroBounce — email-address verification used to maintain coach-data hygiene (does not process your personal data).

6. Coach Contact Data

The college coach contact information shown in the Service (names, roles, work email addresses, public team and roster pages) is collected from publicly accessible university athletic department websites and verified through standard email deliverability checks. We do not collect coach personal information from private sources.

Coaches may contact us at support@yournextplay.ai to request removal of their listing or correction of their information.

7. Data Retention

We retain personal data for the duration described below or until you delete your account, whichever is shorter. You can request deletion at any time by emailing support@yournextplay.ai.

  • Account & profile data — kept for the lifetime of your active account; deleted within 30 days of account-deletion request.
  • Email send history — kept for up to 18 months for delivery troubleshooting and Gmail reputation monitoring, then anonymized.
  • Subscription & billing records — retained for at least 7 years to comply with U.S. tax and accounting requirements.
  • Gmail OAuth tokens — deleted immediately when you disconnect Gmail or delete your account.
  • Operational logs — retained 30–90 days for security and debugging.

8. Data Security

We use industry-standard technical and organizational safeguards to protect personal data, including encryption of OAuth tokens at rest using AES-256-GCM, HTTPS for all network traffic, hashed password storage (where applicable), and access controls limiting which personnel can view production data. No system can be guaranteed 100% secure; we will notify affected users in accordance with applicable breach-notification laws if a security incident affects your personal data.

9. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data through your profile or by contacting us
  • Request deletion of your data (subject to legal retention requirements)
  • Export your data in a portable format on request
  • Disconnect your Gmail account at any time from your Settings page
  • Revoke Google permissions through your Google Account permissions page
  • Lodge a complaint with your local data-protection authority where applicable

10. California Residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you additional rights, including the right to know what personal information we collect, the right to delete personal information, the right to correct inaccurate information, and the right to opt out of any "sale" or "sharing" of personal information.

We do not sell or share personal information as those terms are defined under CCPA. To exercise any CCPA right, email support@yournextplay.ai with the subject line "CCPA Request." We will respond within the timelines required by law.

11. Children's Privacy

YourNextPlay is intended for users who are at least 13 years of age. We do not knowingly collect personal information from children under the age of 13. If we learn that we have collected personal information from a child under 13 without verified parental consent, we will delete that information promptly.

If you are between 13 and 17 years old, you must have a parent or legal guardian review and approve your use of YourNextPlay before creating an account. By using the Service while under 18, you represent that a parent or guardian has consented to your use of YourNextPlay and to the data practices described in this policy.

Parents who believe their child under 13 may have created an account, or who wish to review or delete their child's information, can contact support@yournextplay.ai.

12. International Users

YourNextPlay is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country. By using the Service, you consent to this transfer.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will post any changes on this page and update the "Last updated" date at the top. Material changes will be communicated by email to active users at least 14 days before they take effect.

14. Contact Us

For privacy questions, data requests, or any concerns about this policy, contact:

Email: support@yournextplay.ai