Privacy Policy
Last updated: March 29, 2026
What Data We Collect
When institutions use Eagles Recruiting, the following data may be collected and stored:
- Staff account information (name, email, role, department)
- Player roster data (name, position, academic status, eligibility)
- Inter-department messages and communications
- Compliance records and audit logs
- Scheduling, travel, and operational data
- Usage analytics and access logs
How We Use Your Data
Data is used exclusively to provide athletic department operations services to your institution. This includes:
- Powering the operations platform (roster, eligibility, compliance, messaging)
- Maintaining audit trails for NCAA compliance
- Enforcing role-based access controls (HIPAA/FERPA scoping)
- Generating analytics and reports for your department
Data Protection
We implement industry-standard security measures including:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption at rest
- Row-Level Security on all database tables
- Immutable audit logs (append-only, no edits or deletions)
- Role-based access controls enforced at the database level
- Signed URLs for file attachments (time-limited access)
FERPA & HIPAA Compliance
Eagles Recruiting is designed to support institutional compliance with FERPA (academic records) and HIPAA (medical information). Academic data is visible only to authorized academic advisors and compliance officers. Medical data is visible only to athletic trainers, team physicians, and compliance officers (read-only). Coaching staff receives binary clearance/eligibility status only. Never raw diagnoses or grades.
Data Retention
Messages and compliance records are retained for a minimum of seven (7) years in accordance with NCAA record-keeping standards. After the retention period, player data is anonymized (PII removed) rather than deleted, preserving audit trail integrity. Institutions may request extended retention for active investigations.
Third Parties
We do not sell, share, or distribute institutional or personal data to any third parties. Data is hosted on Supabase (SOC 2 compliant) infrastructure in the United States.
Contact
For privacy-related questions or data requests, contact us at clayton@lasierraeaglesbasketball.com.
