Privacy Policy
Effective July 20, 2026
Who we are
TalentTap is a scoring tool that sports organizations (leagues, clubs, and their administrators) use to run player tryouts, evaluations, and drafts. It is operated by VARRStack.
When a league uses TalentTap, the league is the controller of the player and evaluation data it enters. TalentTap acts as a service provider that processes that data on the league’s behalf and under its instructions. If you are a parent or player with a question about your data, please contact the league or organization that invited you; you may also reach us at the support contact listed on our support page.
Information we process
Account data for evaluators and administrators: an email address and, when they choose password sign-in, a password. Staff may also request a one-time magic sign-in link. Supabase Authentication stores passwords as one-way hashes; TalentTap does not store or expose plaintext passwords.
Player and evaluation data entered by the organization and, during registration, by parents: a player’s first and last name, birthdate, jersey number, division/team, throwing hand, batting side, pitcher and catcher interest, and the evaluation scores and notes recorded during tryouts. This data describes youth-sports participants and belongs to the organization.
Limited technical data: for public parent registration, we store a one-way hashed (non-reversible) form of the visitor’s IP address and browser user-agent. These hashes are used to prevent abuse and rate-limit requests; we do not retain the raw IP address for this flow.
Mobile notification data for invited staff who enable alerts: an opaque Apple or Google push token, device platform, app version, scoring-ready preference, and delivery status. The token is linked to the signed-in staff account so the service can reach the correct device; it is not shown in the app or included in ordinary logs.
Children’s privacy
TalentTap is built for use by sports organizations and the adults who run them. Records about minors are entered and controlled by the organization, not created by children. We do not knowingly allow children to create accounts.
We minimize the child data we handle. Public registration does not ask for parent contact details or parent-submitted free-form notes. Authorized adult staff may record evaluation notes needed to run the tryout. A player’s personal details are hidden from evaluators (blind evaluation) until the organization chooses to reveal them.
A parent or guardian may request access to, correction of, or deletion of their child’s data. Requests are handled together with the organization through our deletion process described below.
How we use information
We use the information solely to provide the scoring, evaluation, and draft service to the organization. We do not sell personal data, we do not use it for advertising, and we do not share it with third parties except the infrastructure providers listed below that are required to operate the service.
If invited staff opt in, TalentTap sends a generic alert when scoring opens or reopens for an assigned event. Notifications do not contain a player name, tryout number, score, team, parent information, or evaluation result. Staff can change the scoring-alert preference or disable notifications in the app.
Service providers
We rely on a small set of sub-processors that handle data on our behalf: Supabase (database, authentication, and storage) and Vercel (web hosting). For opted-in mobile alerts, Apple Push Notification service and Google Firebase Cloud Messaging process the device token and generic notification. Where an organization enables them, we also use Resend (transactional email), Upstash (rate-limiting), and Sentry (error monitoring). Each provider processes data only to deliver its part of the service.
How we protect data
All traffic is encrypted in transit using TLS. Each organization’s data is isolated from every other organization by database row-level security. Ordinary evaluator and manager score entries cannot be silently overwritten; authorized corrections are restricted to the Player Agent path and recorded in the audit trail.
Data retention and deletion
We retain organization and evaluation data while the related account and event remain active, and for the period the organization requires to run its programs. Parents and organizations may request deletion of a player’s data; verified requests are processed through our parent-initiated deletion flow, which removes the player record from the active system.
For opted-in staff alerts, we retain a device push token only while notifications remain enabled for that account. Disabling notifications deletes the account’s stored tokens; the app also unregisters the current phone when the account signs out. Tokens rejected by Apple or Google are deleted automatically. Delivery records never contain the token or notification contents.
To request deletion or ask a data question, contact your league administrator or use the support contact on our support page.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with a revised effective date.