Privacy Policy
Last updated: July 21, 2026
This Privacy Policy explains how ALIEN LAB LLC ("Hoops", "we", "us", or "our") collects, uses, shares, and protects personal information when you use the Hoops mobile application and website (together, the "Service"). Hoops is a basketball academy and club-management platform used by organizations, managers, accountants, coaches, parents/guardians, players (students), and guests.
Because Hoops is used by youth sports organizations, we knowingly process personal information about children. Please read the section "Children's Privacy" carefully.
If you do not agree with this Policy, please do not use the Service.
1. Who we are and how to contact us
The data controller is ALIEN LAB LLC. For any privacy question, or to exercise your rights, contact us at teopile.bibiluri@gmail.com (this address also serves as our data-protection contact).
Where an organization (club/academy) uses Hoops to manage its members, that organization is an independent controller of the data it enters about its members, and we act as a processor on its behalf for that data. This Policy covers our own processing; your organization may have its own privacy notice.
2. Information we collect
Information you provide when you create or use an account:
- Identity & contact: first and last name, email address, phone number, and a password (which we store only as a salted hash — never in plain text).
- Role profile, depending on your account type:
- Player (Student): date of birth, gender, skill level, playing position, jersey number, emergency contact, team, and training goals.
- Parent/Guardian: your relationship to the child and the children linked to you.
- Coach: biography, coaching types, specialties, certifications, hourly rate, a coaching-license document you upload for verification, and your government ID number — which we store only as a keyed hash plus its last digits (never the full number), used solely to match you to your organization's roster.
- Manager/Accountant: job title and financial scope; any payout reference is stored only as a tokenized reference, never as raw bank details.
- Organization: organization name, registration number, address, and billing email; any billing reference is tokenized — we do not collect or store raw payment-card or bank-account numbers.
- Content you create: posts, comments, likes, saves, direct and group messages, reactions, and any photos or videos you upload.
- Training and performance data: training sessions (minutes, intensity, drills, shots attempted/made), routines, rest days, coach assignments, skill ratings, attendance, and coach notes.
- Financial records: invoices/fees your organization issues to you (amount, due date, status). Actual payment is handled by your organization outside the app.
Information we collect automatically:
- Usage & device data: approximate activity (e.g., days you used the app), device push-notification tokens, app version, and technical logs.
- IP address, used transiently for security, abuse prevention, and rate limiting.
- Location (mobile): if you use the in-app map or directions, the app accesses your device location to show nearby courts/venues and routes. This is used on your device to power those features; we do not build a location history profile of you.
- Local storage/cookies (web): we use device storage to keep you signed in and to remember preferences. See "Cookies and local storage."
We do not use third-party advertising trackers, and we do not sell your personal information.
3. How we use your information and our legal bases
We use personal information to:
- Provide the Service — create and manage your account, teams, schedules, messaging, training logs, rankings, and fees. (Legal basis: performance of a contract.)
- Authenticate and secure — sign-in, email verification, password reset, rate-limiting, and preventing fraud and abuse. (Legal basis: contract; legitimate interests in keeping the Service secure.)
- Communicate with you — verification codes, service notices, and (where enabled) notifications about your teams, games, training, and fees. (Legal basis: contract; legitimate interests; consent where required for push notifications.)
- Improve and maintain the Service and troubleshoot problems. (Legal basis: legitimate interests.)
- Comply with law and enforce our Terms. (Legal basis: legal obligation; legitimate interests.)
- Process children's data only as described below. (Legal basis: parental consent and/or the organization's lawful basis; contract.)
Where we rely on legitimate interests, we have balanced those interests against your rights. You can object at any time (see "Your rights").
4. Children's Privacy (COPPA, UK/EU children's data)
Hoops is designed for youth sports and knowingly collects personal information from children, including players who are under the age of 13 (US) and under 16 (EU/UK).
Parental involvement is built into the product:
- A child under 13 cannot create their own account. An under-13 Student account is created by a parent/guardian (or by the child's organization) and is linked to a guardian account; the sign-up flow rejects self-registration below that age. Players 13 and over may join through their club's invite code under the club's authorization.
- We record that a guardian stands behind a minor's account, and a parent/guardian can access, correct, download, or delete their child's information at any time through the app or by contacting us.
We limit children's data to what is needed to run the sports program (roster, attendance, training, scheduling, communications, and fees) and we do not condition a child's participation on disclosing more than is reasonably necessary.
COPPA (United States). For children under 13, we rely on verifiable parental consent, obtained by the parent creating or approving the child's account (and, where an organization enrolls a child, on the organization's authorization consistent with the school/COPPA "school consent" framework). Parents may review their child's information, refuse further collection, and request deletion by contacting teopile.bibiluri@gmail.com.
UK/EU (GDPR "children's" rules). For children below the age of digital consent (16), we rely on consent given or authorized by the holder of parental responsibility, and/or the organization's lawful basis.
If you believe a child has provided us personal information without appropriate parental consent, contact teopile.bibiluri@gmail.com and we will delete it.
5. How we share information
We do not sell personal information. We share it only:
- With your organization and the people within it who need it to run the program (e.g., your coach sees your team roster and attendance; a manager/accountant sees fees). Access is controlled by role.
- With other users, as you direct — e.g., posts you publish, messages you send, and profile information you choose to show.
- With service providers (sub-processors) that operate the Service under contract
and may only process data on our instructions:
- Supabase — database hosting (personal data is stored in the EU/Frankfurt region).
- Vercel — application hosting and media storage (Vercel Blob) for images/videos you upload.
- Maileroo — sending transactional emails (verification and password-reset codes).
- Expo — delivering push notifications to your device.
- Google Maps — powering maps and directions in the mobile app (subject to Google's privacy policy).
- Upstash — rate-limiting infrastructure that transiently processes request metadata (e.g., IP), where enabled.
- For legal reasons — to comply with law, respond to lawful requests, or protect the rights, safety, and property of our users, the public, or us.
- In a business transfer — if we are involved in a merger, acquisition, or sale of assets, subject to this Policy.
6. International data transfers
We host data in the EU (Frankfurt). Some of our service providers may process data in other countries. Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. Contact us for details.
7. How long we keep information
We keep personal information for as long as your account is active and as needed to provide the Service, then delete or anonymize it within a reasonable period, unless a longer retention is required for legal, accounting, safety, or dispute-resolution purposes. When you delete your account, we delete your personal data and content that is not required to be retained by law (see "Your rights"). Backups are purged on a rolling schedule.
8. How we protect information
We use technical and organizational measures including encryption in transit (HTTPS), hashed passwords (bcrypt), short-lived access tokens with rotating refresh tokens, role-based access control, database row-level security, upload validation, rate limiting, and audit logging. No method of transmission or storage is completely secure, but we work to protect your information and continuously improve our safeguards.
9. Your rights and choices
Depending on where you live (e.g., UK/EU GDPR, or US state privacy laws), you may have the right to:
- Access the personal information we hold about you — the app provides a "Download my data" export in Settings.
- Correct inaccurate information — edit your profile in the app.
- Delete your account and personal data — use "Delete account" in Settings, or contact us. This is irreversible.
- Port your data — via the export above.
- Restrict or object to certain processing, and withdraw consent at any time (e.g., disable push notifications on your device).
- Complain to your data-protection authority (in the UK, the ICO).
To exercise any right, use the in-app controls or contact teopile.bibiluri@gmail.com. We will respond within the time required by applicable law. We will not discriminate against you for exercising your rights.
Parents/guardians may exercise these rights on behalf of their child.
10. Cookies and local storage
On the web app we use device storage (localStorage/sessionStorage) to keep you signed in and remember preferences; these are essential to the Service. We do not use advertising or cross-site tracking cookies. The mobile app stores your session securely in the device keychain.
11. Third-party links and services
The Service may link to third-party sites or use third-party services (e.g., Google Maps). We are not responsible for their privacy practices; review their policies.
12. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice. Your continued use after changes take effect constitutes acceptance.
13. Contact us
Questions or requests: ALIEN LAB LLC, teopile.bibiluri@gmail.com.
Hoops — Privacy Policy · Terms of Service