SportsX — Privacy Policy
Version: 1.3 Effective Date: 2026-06-13 Last Updated: 2026-06-13 Jurisdiction: Province of Ontario, Canada (Phase 1) Operator: Next Play AI Inc. (operating as "SportsX") ("Next Play AI," "SportsX," "we," "us," "our") Privacy Officer: privacy@nextplayai.xyz
PLAIN-LANGUAGE SUMMARY — PLEASE READ
What this policy covers. It explains how Next Play AI collects, uses, shares, stores, and protects your personal information when you visit our website, create an account, use the SportsX service, or sign documents through our service.
Two relationships. Your relationship with us depends on the role you are in:
Club operator, administrator, or staff member — we are directly responsible for your personal information.
Member, parent, or guardian using the service through a Club's invitation — the Club is the organization responsible for your information held in connection with that Club's programs; we process it on the Club's behalf.
Where your data is stored. Primarily in Canada (Amazon Web Services, Montréal). Some processing occurs in the United States (AI inference, error monitoring, edge security). The full list is in Section 8.
Your rights under PIPEDA. You have the right to know what personal information we have, ask us to correct it, withdraw consent, request deletion, and complain to a regulator. See Section 11.
Children. If you are under 18, a parent or guardian must consent before any personal information is submitted. See Section 13.
Health information. If you have a concussion history, allergy, or medical condition recorded through our service, that information is sensitive personal information handled by your Club as a PIPEDA organization, and processed by us on the Club's behalf. In limited circumstances, Ontario's PHIPA also applies — see Section 14.
Questions. Email our Privacy Officer at privacy@nextplayai.xyz.
Complaints. You can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, for matters involving personal health information received from a health information custodian, the Information and Privacy Commissioner of Ontario (ipc.on.ca).
SECTION 1 — WHO WE ARE
Next Play AI Inc. (operating as "SportsX") is a Canadian corporation headquartered in Oakville, Ontario, Canada. We operate the SportsX software-as-a-service platform (the "Service"), which is used by Ontario youth sports clubs to manage member registration, intake of consents and signed documents, scheduling, attendance, payments, and communications.
This Privacy Policy applies to:
- our public website at www.sportsx.ai and any sub-domains;
- the SportsX web application;
- any mobile application we publish;
- any account-creation, registration, and signing flow we operate;
- any communication you send us by email, contact form, or phone.
This Privacy Policy does not apply to:
- websites or services operated by Clubs themselves (those are governed by the Club's own privacy policy);
- third-party websites or services we link to;
- any data you provide directly to a Club outside our Service.
SECTION 2 — TWO ROLES, TWO LEVELS OF RESPONSIBILITY
Under Canadian privacy law, an organization that decides why and how personal information is collected is the "controller" under the Personal Information Protection and Electronic Documents Act (PIPEDA). An organization that handles personal information on behalf of another organization is a "processor" (also called a "service provider") under PIPEDA.
Our role depends on which of two relationships you are in: your relationship with us directly (as a Club operator, administrator, or staff member, or as a website visitor), or your relationship with your Club (because you participate in the Club's programs through our Service).
2.1 You are a Club Operator, Administrator, or Authorized User
If you operate a Club, administer a Club account, or are a staff member with login credentials ("Authorized User"), we are the controller of the personal information you provide to us directly to create and manage your relationship with us. This includes your contact information, billing information, account credentials, and the records of how you use the Service.
In this role, we make the decisions about how your personal information is used, and we have direct accountability to you under PIPEDA.
2.2 You are a Member, Parent, or Guardian — data collected through a Club
If you are an athlete, learner, parent, or guardian using the Service because a Club invited you to ("Member"), and you are providing information to the Club through the Service (for example, completing the Club's intake forms, signing the Club's PDSA / Liability Waiver / Parental Indemnity / Rowan's Law documents, providing health information for safe sport participation), the Club is the controller of that information, and we are the processor acting on the Club's behalf. The Club decides what information it collects, what it uses it for, and how long it keeps it. We process the information only on the Club's instructions and as described in our Data Processing Addendum with the Club.
In this role:
The Club's own privacy policy governs how your personal information is used by the Club. SportsX requires every Club, by contract, to maintain its own public privacy policy (or notice) and to handle personal information to a PIPEDA-equivalent standard. This Policy describes SportsX's own practices as the Club's service provider; it does not replace the Club's privacy policy.
You should direct privacy requests (access, correction, deletion, withdrawal of consent) to the Club in the first instance.
If you direct a request to us instead, we will inform the Club and (with the Club's involvement) will help facilitate it. See Section 11.
Health-related information collected from Members and their parents or guardians — including allergies, medical conditions material to participation, current medications, concussion and injury history, and emergency-contact and emergency-treatment information — is sensitive personal information. The Club collects and handles it as an organization subject to PIPEDA — or, where PIPEDA does not directly apply to the Club, to an equivalent privacy standard the Club is contractually required to meet — and treats it as sensitive information requiring express consent and enhanced safeguards. The Club is not a "health information custodian" within the meaning of section 3 of the Personal Health Information Protection Act, 2004 (PHIPA), and Next Play AI Inc. acts as the Club's service provider (processor) under PIPEDA, not as an "agent" under PHIPA. PHIPA applies only in the limited circumstances described in Section 14.
2.3 You are a Website Visitor
If you visit our public website without creating an account (for example, to read marketing material), we are the controller of any limited information collected (such as cookies, IP address, and any contact form you submit). See Section 12 for cookies.
2.4 Read-only oversight access by an affiliated Association
This subsection applies only where your Club is affiliated with a provincial or multi-club sport organization (an "Association"). Members of unaffiliated Clubs are not affected by it.
Read-only oversight access by an affiliated Association. Some Clubs that use SportsX are affiliated with a provincial or multi-club sport organization (an "Association," such as a provincial sport organization). Where your Club is affiliated with an Association, the Association is given a read-only view of certain Club information so it can carry out its governance, safety, and reporting role.
- The Association is a separate organization responsible under PIPEDA for the information it reads. It is not a "health information custodian" under PHIPA and is not your Club's agent. SportsX acts as the service provider (processor) that enforces the access controls.
- The Association's access is read-only — it cannot create, change, or delete any Club information.
- Access is tiered and minimized: aggregate/de-identified statistics by default; identifiable information only for safety/incident, eligibility, and discipline purposes.
- The Association never receives doctor's notes or other personal health information that your Club received from a health information custodian; that information remains with your Club's designated personnel only, consistent with section 49 of PHIPA.
- The Association may use the information only for its oversight, governance, safety, and reporting purposes, and may not sell it, use it for advertising, or re-disclose it except as required by law or as your Club separately authorizes.
You are asked to consent to this access in your PIPEDA Standalone Consent. To exercise privacy rights over information held by your Club, contact your Club first (the Club is the controller of the source record); you may also contact SportsX's Privacy Officer at privacy@nextplayai.xyz, or the Office of the Privacy Commissioner of Canada or the Information and Privacy Commissioner of Ontario.
SECTION 3 — WHAT THIS POLICY COVERS — A QUICK MAP
| Section | Topic |
|---|---|
| 4 | Personal information we collect |
| 5 | How we use it |
| 6 | Legal basis under PIPEDA Schedule 1 |
| 7 | Sharing — Service Providers and Subprocessors |
| 8 | Cross-border processing |
| 9 | Retention |
| 10 | Security |
| 11 | Your rights |
| 12 | Cookies |
| 13 | Children and minors |
| 14 | Health-related information (PIPEDA and, where applicable, PHIPA) |
| 15 | Updates |
| 16 | Contact |
| 17 | Complaints |
| 18 | Definitions |
SECTION 4 — PERSONAL INFORMATION WE COLLECT
4.1 When you visit our public website
- Technical metadata: IP address, device type, browser, operating system, referring URL, pages visited, time on page
- Cookies (see Section 12)
- Contact form information if you submit it (name, email, message)
4.2 When you create or use an Authorized User account (Club operator / administrator / staff)
- Identity: name, role at the Club, date of birth (if required for screening)
- Contact: email, phone, work address
- Account credentials: hashed password, multi-factor-authentication token
- Billing: payment-method tokens (we do not store full card numbers — those are handled and tokenized by Stripe), billing history, invoices
- Audit-trail metadata: IP, timestamp, device fingerprint, document version hashes for any document you sign in your role
4.3 When you are a Member (athlete / learner / parent / guardian) — collected on behalf of the Club
- Identity: full legal name, preferred name, date of birth
- Contact: email, phone, postal address
- Family relationship (for minor Members): parent or guardian name, relationship, contact, confirmation of legal authority to consent
- Health-related information (where the Club's program design records it): allergies, medical conditions material to participation, current medications, concussion history, removal-from-sport / return-to-sport notations, emergency contact, emergency medical-treatment authorization
- Program participation: enrolment, level, schedule, attendance, coach assignment, performance / progress notes, certifications, make-up class history
- Financial: Stripe-tokenized payment-method, billing history, refund records
- Documents and consents: signed PDSA / Course Contract, Liability Waiver, Parental Indemnity Agreement, Rowan's Law Code of Conduct, Rowan's Law Cognitive Resources Acknowledgment, PIPEDA Standalone Consent, Electronic Signature Consent, photo / video / case-study consent
- Audit-trail metadata: IP address, timestamp (UTC), device fingerprint, scroll-to-bottom completion timestamp (where the document type requires "reasonable steps" under the Occupiers' Liability Act), document version hash (SHA-256), email / SMS delivery confirmation IDs, signing method
- Photo and video: profile photographs, program / event photos and videos (where consent is captured separately), case-study photos and videos (subject to separate consent under any agreement between the Club and Next Play AI)
4.4 What we deliberately do not collect
We do not collect, and the Club is contractually prohibited from uploading, the following sensitive identifiers:
- Social Insurance Number
- Full credit-card or bank-account number outside the tokenized Stripe / payment-processor flow
- Driver's license, passport, or other government-issued identification number
- Biometric data (fingerprint, facial geometry, voice print)
- Sexual orientation, religion, ethnic origin, political opinion, or trade-union membership
If you discover that any of the above has been uploaded to the Service, please email privacy@nextplayai.xyz immediately.
SECTION 5 — HOW WE USE YOUR PERSONAL INFORMATION
We use personal information for the following purposes, depending on your relationship with us:
5.1 To provide the Service
- Create and authenticate accounts
- Process registrations, intake forms, and signed documents
- Schedule programs, manage attendance, generate rosters
- Route payments through Stripe Connect
- Send transactional and operational communications (account verification, security alerts, document-delivery confirmations, scheduling reminders, payment receipts)
- Provide customer support
5.2 To meet legal and regulatory requirements
- Generate audit trails for electronically signed documents under the Electronic Commerce Act, 2000 (Ontario)
- Retain signed documents and financial records for the periods required by Ontario law (see Section 9)
- Cooperate with valid legal process (lawful court orders, subpoenas, regulator requests, law-enforcement requests with proper legal basis)
- Operate our anti-fraud, anti-abuse, and account-security functions
5.3 To improve and protect the Service
- Detect and respond to security incidents
- Diagnose application errors (with limited content captured by Sentry — see Section 7)
- Compile aggregated, irreversibly anonymized analytics on Service usage (no individual is identifiable; this is not personal information)
5.4 For our own communications (Authorized Users only — not Members)
- Onboarding emails about your Club account
- Product updates and new-feature announcements
- Legal-update notices (changes in Ontario consumer or sports law)
- Marketing emails (only with your express, separately captured opt-in consent under Canada's Anti-Spam Legislation; you can withdraw consent at any time)
5.5 What we do not do
We do not sell personal information to anyone, ever.
We do not use personal information for advertising targeting.
We do not use personal information you upload as a Club to train any general-purpose machine-learning model without the Club's prior written consent.
We do not use Member personal information for any purpose beyond the Club's instructions and as described in our Data Processing Addendum with the Club.
SECTION 6 — LEGAL BASIS UNDER PIPEDA SCHEDULE 1
Canadian privacy law is built around ten principles in Schedule 1 of the Personal Information Protection and Electronic Documents Act:
| Principle | How we apply it |
|---|---|
| 1 — Accountability | We have a designated Privacy Officer (privacy@nextplayai.xyz) and have implemented the policies, procedures, and security measures described in this Privacy Policy and our Data Processing Addendum. |
| 2 — Identifying Purposes | The purposes for which we collect personal information are described in Section 5 and, for Member information, in the Club's PIPEDA Standalone Consent. |
| 3 — Consent | Knowledge and consent are obtained before collection. For Members, the Club obtains consent through its PIPEDA Standalone Consent and any sport-specific waiver / parental indemnity. For Authorized Users, consent is obtained at account creation. |
| 4 — Limiting Collection | Collection is limited to what is necessary for the stated purposes (see Section 4.4). |
| 5 — Limiting Use, Disclosure, Retention | Use is limited to the stated purposes; disclosure is limited to the categories in Section 7; retention follows Section 9. |
| 6 — Accuracy | Personal information is kept reasonably accurate, complete, and current. You can correct your information using your account or by contacting us. |
| 7 — Safeguards | Technical and organizational security measures are described in our Data Processing Addendum, Schedule 4. Summary in Section 10. |
| 8 — Openness | This Privacy Policy and our Subprocessor list (Section 7) are made publicly available. |
| 9 — Individual Access | Access and correction rights are described in Section 11. PIPEDA generally requires response within 30 days. |
| 10 — Challenging Compliance | You may complain to our Privacy Officer (Section 16) and, if not satisfied, to the OPC or IPC (Section 17). |
SECTION 7 — SHARING — SERVICE PROVIDERS AND SUBPROCESSORS
We share personal information only as described in this section.
7.1 With your Club (if you are a Member)
If you are a Member, your personal information is collected on behalf of, and shared with, the Club that invited you. The Club's privacy policy governs what the Club does with it.
7.2 With our Service Providers (Subprocessors)
We engage the following Service Providers ("Subprocessors") to operate the Service. Each is bound by a written agreement that imposes data-protection obligations no less protective than those required by PIPEDA.
| # | Subprocessor | Role | Country of processing |
|---|---|---|---|
| 1 | Amazon Web Services Canada, Inc. | Cloud hosting (compute, storage, database, backup) | Canada (Montréal primary, Calgary secondary backup) |
| 2 | Anthropic, PBC | Large-language-model inference for AI-assisted document generation and AI Agent workflows | United States |
| 3 | Stripe Payments Canada, Ltd. | Payment processing | Canada (with parent infrastructure in the United States) |
| 4 | Twilio SendGrid, Inc. | Transactional email delivery | United States |
| 5 | Twilio, Inc. | SMS delivery | United States |
| 6 | Cloudflare, Inc. | Content-delivery network, security at the network edge | Global edge nodes |
| 7 | Sentry, Inc. (Functional Software, Inc.) | Application error monitoring | United States |
Payment processing is performed by Stripe. Full card data (the primary account number and related card details) is collected, processed, and stored by Stripe under Stripe's own terms and PCI-DSS compliance program; SportsX does not store full card numbers — we hold only Stripe-issued tokens and limited transaction metadata.
Phase 1 specifically does not use general-purpose marketing or analytics services such as Google Analytics 4, Meta Pixel, TikTok Pixel, HubSpot, or Segment for Member-facing analytics. We will update this list before adding any new Subprocessor and notify Clubs in accordance with our Data Processing Addendum.
7.3 With professional advisors
We may share personal information with our legal, accounting, audit, insurance, and IT-security advisors when reasonably necessary for them to provide their services. They are bound by professional confidentiality obligations.
7.4 With regulators or law enforcement
We may disclose personal information when required to do so by valid legal process (court order, subpoena, regulator request, law-enforcement request with proper legal basis) or to protect the safety of any person. Where legally permitted, we will notify the affected individual.
7.5 With an affiliated Association
Where your Club is affiliated with an Association, the Association is given a read-only, tiered, and minimized oversight view of certain Club information, and is a separate recipient and controller for its own oversight purposes. Doctor's notes and other personal health information the Club received from a health information custodian are never disclosed to the Association (PHIPA section 49). See Section 2.4.
7.6 In a corporate transaction
If we are involved in a merger, acquisition, financing, corporate reorganization, or sale of all or substantially all assets, personal information may be transferred to the successor entity, subject to that entity assuming this Privacy Policy and providing notice. Any such transfer will comply with PIPEDA.
7.7 With your express consent
For any disclosure not described above, we will ask for your express consent.
SECTION 8 — CROSS-BORDER PROCESSING
8.1 Where your information is processed
Our primary hosting is in Canada (Amazon Web Services Canada, Montréal region). The primary database storing personal information is in Canada.
Some of our Subprocessors process limited categories of personal information outside Canada, primarily in the United States:
- Anthropic processes prompts and Template inputs (which may contain personal information) in the US
- Sentry stores error logs (which may incidentally include personal information) in the US
- Cloudflare processes technical metadata (IP, headers) at edge nodes globally
- Stripe processes payment data primarily in Canada with parent infrastructure in the US
8.2 Comparable level of protection
Each cross-border Subprocessor is bound by a written agreement that imposes data-protection obligations no less protective than those required by PIPEDA. We rely on contractual protections (rather than government-to-government transfer mechanisms, since Canadian law does not impose them in the way GDPR does).
8.3 Foreign-government access risk
Personal information processed outside Canada may be subject to lawful access requests by foreign government authorities. We cannot prevent such access where required by foreign law. The Office of the Privacy Commissioner of Canada has issued guidance acknowledging that cross-border transfers are permitted where comparable protection is in place; we believe our practices meet that standard.
8.4 Your right to know
This Privacy Policy is the public disclosure of our cross-border processing under PIPEDA Schedule 1 Principle 8 (Openness).
SECTION 9 — RETENTION
We retain personal information only as long as necessary for the purposes for which it was collected, and as required by Ontario law.
9.1 During your active use of the Service
Active records are retained for the duration of your account or program participation.
9.2 After your account or program participation ends
| Category | Retention period |
|---|---|
| Account login records, technical metadata | 30 days (export window) + 60 days (deletion buffer) |
| Signed PDSA / Course Contract | Not less than 7 years from the date of the most recent program participation (CRA + general statute of frauds) |
| Signed Liability Waiver, Parental Indemnity, Rowan's Law documents, PIPEDA Consent, Electronic Signature Consent | Not less than 7 years from the date of the most recent program participation |
| Records involving minors | Until the minor reaches the age of majority (18) plus the limitation period applicable to a tort claim under the Limitations Act, 2002 (typically 2 years for adult tort claims, but the clock for a minor's claim does not start running until majority — meaning effective retention can extend significantly beyond age 20) |
| Health-related records | Retained under the PIPEDA limiting-retention principle (Schedule 1 Principle 5) — kept only as long as necessary for the purpose collected — together with the Income Tax Act (7 years, where the record is also a financial record) and the Limitations Act, 2002 (where the record involves a minor, retained until the minor reaches the age of majority plus the applicable limitation period), and any retention schedule the Club has adopted for its own records |
| Financial records | Minimum 7 years per the Income Tax Act and CRA guidance |
| Encrypted backup media | Standard backup-rotation cycle (typically 30–90 days); after which backup data is overwritten in the ordinary course |
| Anonymized aggregate data | Indefinitely (no longer personal information) |
9.3 Deletion on request
You can request deletion of your personal information using the rights described in Section 11, subject to the legal-retention requirements above. We will explain which items can be deleted and which must be retained, and we will delete items as soon as the legal-retention period ends.
SECTION 10 — SECURITY
We maintain technical and organizational security measures appropriate to the sensitivity of the personal information we hold. The full description is in our Data Processing Addendum, Schedule 4. Summary:
- Encryption: TLS 1.2+ in transit; AES-256 at rest for production database, object storage, and backups
- Access control: role-based access, multi-factor authentication for all our personnel, principle of least privilege, just-in-time access for production with audit logging
- Network and infrastructure: VPC isolation, web-application firewall, DDoS protection, intrusion-detection
- Application security: secure-development-lifecycle, code review, static security analysis, dependency vulnerability scanning, parameterized queries, rate limiting on sensitive endpoints
- Resilience: daily encrypted backups, point-in-time recovery, multi-AZ deployment within Canada, documented incident-response plan
- Audit logging: account creation, login, permission change, document signing (with scroll completion, IP, device, hash), data export, data deletion, payment events — retained at least 2 years
- Personnel: confidentiality agreements, privacy and security training annually, background checks for elevated production access (subject to provincial employment-screening law), 24-hour access revocation on departure
- Incident response: documented Security Incident response plan; we aim to notify affected Clubs without undue delay, within 72 hours of confirming a reportable incident
- Compliance posture: SportsX intends to pursue a SOC 2 Type II audit on a commercially reasonable timeline as the business scales; this is a statement of intent and not a representation that the audit is complete or in progress as at the effective date
No security system is perfect. If we discover a security incident affecting your personal information, we will follow the breach-notification process described in our Data Processing Addendum (notification to the affected Club, and the Club is responsible for notifying you and the regulator as required by PIPEDA's Breach of Security Safeguards Regulations). For our own breach notifications (where we are the controller — for example, an Authorized User account compromise), we will notify you and the OPC as required by PIPEDA.
SECTION 11 — YOUR RIGHTS
11.1 Rights you have under PIPEDA
You have the right to:
- Know what personal information we hold about you, why, and to whom we have disclosed it;
- Access your personal information (PIPEDA section 8 — generally responded to within 30 days);
- Correct your personal information if it is inaccurate, incomplete, or out of date;
- Withdraw consent for any future processing (subject to legal or contractual restrictions, such as a signed contract that cannot be unilaterally rescinded);
- Request deletion of your personal information (subject to the legal-retention exceptions in Section 9.2);
- Lodge a complaint with our Privacy Officer or with the regulator (Section 17).
11.2 Rights in respect of health-related information
Your health-related information is handled by your Club as a PIPEDA organization, and the PIPEDA rights described in Section 11.1 (access, correction, withdrawal of consent, deletion) apply to it. Because the Club is the controller of this information, please direct these requests to your Club in the first instance.
In the limited circumstances where PHIPA applies (see Section 14) — in particular, where your Club has received personal health information about you from a health information custodian (such as a physician's concussion-clearance note) — additional PHIPA rights of access and correction may be available from the custodian who created the record. Your Club can direct you to the appropriate custodian.
11.3 How to exercise your rights
If you are a Member, your Club is the controller of your information (including your health-related information). Please direct requests to your Club in the first instance. You may also email us at privacy@nextplayai.xyz; we will inform the Club and help facilitate the request.
If you are an Authorized User, you may exercise your rights by emailing privacy@nextplayai.xyz. Some self-service controls are available through your account settings; for any right not exercisable through your account settings, we handle the request on receipt of your email. We aim to add additional self-service privacy tools over time, but you do not need to wait for them — the email path above is available now.
Identity verification. Before responding to a request, we may need to verify your identity (for example, by confirming login from an authenticated session, by emailing a verification code to the address on file, or by other reasonable means). This is to protect your information from unauthorized access.
No charge. PIPEDA section 8 prohibits an unreasonable charge for access. We do not charge for routine access, correction, or withdrawal-of-consent requests. If a request is unusually complex or large, we may, after consultation with you, charge a reasonable cost-recovery fee.
Our response timelines. We aim to respond to access requests within 30 days of receipt. If we need more time, we will tell you why and when you can expect our response.
If we refuse a request. We will tell you in writing the reason for the refusal, the section of PIPEDA (or, where applicable, PHIPA) we rely on, and how to complain to the regulator.
11.4 How to exercise your rights — choosing the right path
Because of the two-role framework described in Section 2, the path for exercising your rights depends on which information you are asking about:
| Information type | Path | Why |
|---|---|---|
| Authorized User account data | Direct to Next Play AI | We are controller |
| Member data the Club holds (intake forms, signed compliance documents, attendance, health-related information, coach notes) | Direct to the Club | Club is controller |
If you direct a request about Member data to us, we will inform the Club and (with the Club's involvement) help facilitate it, coordinating in good faith.
SECTION 12 — COOKIES AND SIMILAR TECHNOLOGIES
Our Cookie Policy (A3) describes the cookies we use, why, and how to manage them. Phase 1 uses a deliberately minimal cookie set: strictly-necessary cookies (session, security, CSRF) and limited functional cookies (login persistence, language preference). Phase 1 does not use marketing or third-party advertising cookies (no Google Analytics 4, Meta Pixel, TikTok Pixel, HubSpot, or Segment).
If we add analytics or advertising cookies in a future Phase, we will update the Cookie Policy and obtain consent through a cookie banner that complies with PIPEDA, the IPC's Guidance on Cookie Use, and any other applicable Ontario authority guidance.
SECTION 13 — CHILDREN AND MINORS
The Service is used by youth athletes and learners, including those under 18.
For any Member under 18, we require that a parent or guardian with legal authority to consent complete the registration, sign the PDSA / Course Contract, sign any Liability Waiver, sign the Parental Indemnity Agreement, sign the Rowan's Law Code of Conduct (where applicable for athletes 26 and under), sign the Rowan's Law Cognitive Resources Acknowledgment (where applicable), and sign the PIPEDA Standalone Consent.
Under PIPEDA, the OPC has indicated that children under 13 generally lack capacity to provide meaningful consent and that parental / guardian consent is required for any non-trivial use of their personal information. For children between 13 and 18, capacity is assessed based on the maturity of the child and the nature of the information. Out of caution, the Service requires parental / guardian consent for all Members under 18.
For all Members under 18, the Club requires the consent of a parent or guardian with legal authority to consent. This is a conservative operational default under PIPEDA; it is not a requirement of PHIPA. A parent or guardian who holds only a right of access to the child (and not decision-making authority) may not provide this consent. Where a capable young person has, on their own, made a decision about their own health care or counselling, a parent's consent does not extend to information about that decision, and the capable young person's own decision prevails over a substitute decision-maker's. PIPEDA and PHIPA recognise no fixed age band of capacity — capacity, not age, governs.
If you are a parent or guardian and believe a child's personal information has been collected without your consent, please email privacy@nextplayai.xyz and we will investigate and, if appropriate, delete the information.
SECTION 14 — HEALTH-RELATED INFORMATION (PIPEDA AND, WHERE APPLICABLE, PHIPA)
Health-related information collected from Members and their parents or guardians — including allergies, medical conditions material to participation, current medications, concussion and injury history, and emergency-contact and emergency-treatment information — is sensitive personal information. The Club collects and handles it as an organization subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and treats it as sensitive information requiring express consent and enhanced safeguards. The Club is not a "health information custodian" within the meaning of section 3 of the Personal Health Information Protection Act, 2004 (PHIPA), and Next Play AI Inc. acts as the Club's service provider (processor) under PIPEDA, not as an "agent" under PHIPA.
PHIPA applies in three defined circumstances: (a) where the Club receives personal health information from a health information custodian (for example, a physician's concussion-clearance or return-to-sport note), the Club is a "recipient" and, under PHIPA section 49, may use or disclose that information only for the purpose for which it was disclosed or as permitted or required by law; (b) where a regulated health-care practitioner (such as a team physician or physiotherapist) delivers health care through the Club, that practitioner is the custodian, and where Next Play AI hosts those records it acts as an electronic service provider to that custodian; and (c) health-card (OHIP) numbers, if collected at all, are collected only voluntarily for emergency-identification purposes, are never required, and are never used as a general identifier.
AI and health-information carve-out. Where the Service uses large-language-model inference (Anthropic, PBC — see Section 7) for AI-assisted document generation and AI Agent workflows, the Club's sensitive health-related information described in this Section is excluded from those AI workflows: it is not sent to the large-language-model provider for inference and is not used to train any model. This carve-out operates at the Club layer and protects the Member health-related information the Club controls.
Your rights in respect of health-related information:
Because your Club handles your health-related information as a PIPEDA organization, the PIPEDA rights of access, correction, withdrawal of consent, and deletion described in Section 11 apply to it. Please direct these requests to your Club in the first instance.
Where PHIPA applies because your Club received personal health information from a health information custodian (paragraph (a) above), rights of access and correction to that record may be exercised against the custodian who created it; your Club can direct you to the appropriate custodian.
To exercise any of these rights, please contact your Club's Privacy Contact Person in the first instance. You may also email privacy@nextplayai.xyz.
SECTION 15 — UPDATES TO THIS POLICY
We may update this Privacy Policy from time to time to reflect changes in law, our Service, or our Subprocessor list.
Material changes will be communicated by email (to Authorized Users) and by an in-product banner at next login. We will provide at least 30 days' notice for material adverse changes.
Non-material changes (such as Subprocessor list updates that do not change the categories of personal information processed or the countries of processing) will be reflected by updating the "Last Updated" date at the top of this policy.
The current version is always available at our public website at www.sportsx.ai.
Last Updated: 2026-06-13
SECTION 16 — CONTACT
Privacy Officer
Next Play AI Inc. (operating as "SportsX")
Attention: Privacy Officer
2030 Bristol Circle, Suite 210, Oakville, Ontario, Canada L6H 6P5
Email: privacy@nextplayai.xyz
Legal: legal@nextplayai.xyz
We aim to respond to privacy inquiries within five (5) business days of receipt.
SECTION 17 — COMPLAINTS
If you are not satisfied with our response to a privacy inquiry or request, you may complain to the regulator with appropriate jurisdiction.
17.1 Office of the Privacy Commissioner of Canada (OPC)
For complaints under PIPEDA:
Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, QC K1A 1H3
Toll-free: 1-800-282-1376
Website: priv.gc.ca
17.2 Information and Privacy Commissioner of Ontario (IPC)
For complaints involving personal health information received from a health information custodian, where PHIPA applies (see Section 14):
Information and Privacy Commissioner of Ontario
2 Bloor Street East, Suite 1400
Toronto, ON M4W 1A8
Toll-free: 1-800-387-0073
Website: ipc.on.ca
You may also have remedies in the courts of Ontario; PIPEDA section 14 provides a right of application to the Federal Court following an OPC investigation in certain circumstances, and the Privacy Act and Ontario common-law privacy torts (such as intrusion upon seclusion, recognized in Jones v. Tsige, 2012 ONCA 32) may provide additional remedies.
SECTION 18 — DEFINITIONS
"Association" means a provincial or multi-club sport organization (such as a provincial sport organization) with which a Club is affiliated and which is given read-only oversight access as described in Section 2.4.
"Authorized User" means a person we authorize to access the Service through a Club's account, including the Club's operators, administrators, staff members, and front-desk personnel.
"Club" means a youth sports organization that has subscribed to the Service.
"Member" means an athlete, learner, parent, or guardian using the Service because a Club has invited them to.
"Personal Health Information" has the meaning given in section 4 of PHIPA.
"Personal Information" has the meaning given in PIPEDA (information about an identifiable individual).
"PHIPA" means the Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sch. A.
"PIPEDA" means the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5.
"Service" means the SportsX software-as-a-service platform operated by Next Play AI Inc., including the public website, web application, mobile application (where published), and any related communications and signing flows.
"Service Providers" or "Subprocessors" has the meaning in Section 7.2.
ELECTRONIC ACKNOWLEDGMENT
By using the Service, by creating an account, or by signing any document through the Service, you acknowledge that you have read this Privacy Policy and understand how your personal information is collected, used, shared, stored, and protected. If you do not agree with this Privacy Policy, please do not use the Service.
Privacy Policy v1.3 — effective 2026-06-13. Phase 1 jurisdiction: Ontario only. The English text governs in all cases. A French version may be provided in a future Phase as a voluntary accessibility measure; this is a business and accessibility choice and is not required by the Accessibility for Ontarians with Disabilities Act, 2005 (AODA), which does not mandate French-language translation.