Privacy Policy
Version 1. Draft, not yet in force.
This version is a draft, published so it can be read before it comes into force. Words in square brackets are still being settled.
This policy explains what [TROOPSIDE ENTITY] ("Troopside", "we") collects when you use Troopside, why, who sees it, and what you can do about it. It covers troopside.com and every Scouting unit's site Troopside hosts, whether at an address like troop123.troopside.com or at a domain the unit owns.
Two kinds of people read this: units (the troops and packs that subscribe, through their leaders) and members (the leaders, parents, guardians and scouts who use a unit's site). Where the answer differs, this policy says which.
1. Who is responsible for your information
The unit runs its own site. Its leaders decide who is on the roster, who gets an account, what is collected at sign-up, and who inside the unit can see what. Troopside provides the software and hosts it on the unit's behalf under a Master Services Agreement with the organization that charters the unit. For a member's information, the unit is the party with the relationship and the decisions; Troopside acts for the unit.
For information collected on troopside.com itself (a beta request or a signup), Troopside is the party responsible.
2. What we collect
From a unit signing up on troopside.com: the contact's name, email address and phone number if given, the unit's program, number, city and council, the chartered organization's legal name, the subdomain chosen, the agreement accepted (with the signer's name and title, the network address and browser used, and the time), and the Stripe customer and subscription identifiers for the unit's subscription. Card and bank details go to Stripe directly and never reach Troopside.
From a unit about its members, entered by the unit's leaders or imported from the unit's existing records: names, roles and positions, patrol or den, rank and advancement notes, email addresses, phone numbers, home addresses, dates of birth where the unit records them, family relationships, emergency contacts, training records the unit reports, and anything else the unit's leaders choose to record on a member's profile.
From members using a unit's site: account credentials (a password, stored only as a hash, or a Google sign-in), event sign-ups and the answers they carry (who is coming, meals, transport and seats, driving pledges), payment records for the unit (what was charged, what was paid and when, never the card or account number), files members upload (health forms, insurance cards, photographs, documents), signed unit agreements, reimbursement requests, messages sent through the site's forms, and the questions asked of the in-app assistant.
From visitors to a unit's public site: a join or contact form, if the visitor sends one, goes to the unit's leaders.
Automatically: server logs with the network address, browser, page requested and time; error reports; and a session cookie that keeps you signed in. [ANALYTICS] Troopside runs no advertising trackers and sets no third-party cookies.
From integrations a unit connects: if a unit connects GroupMe, Troopside posts the unit's announcements to the group and reads the group's messages only to relay them as the unit configures; Troopside does not keep chat history. If a unit connects Zoom, Troopside creates meeting links for the unit's events. If an event names a place, Troopside may look it up with Google Maps to show a map.
3. Children
Units enter information about the youth on their rosters, and some units allow a scout to hold an account, claimed and used on a parent's device. The unit is responsible for having a parent's or guardian's consent before a child's information is entered or an account is created, including the consent the Children's Online Privacy Protection Act requires for a child under thirteen. Troopside uses a child's information only to provide the unit's site and never for its own purposes.
Troopside does not knowingly collect information directly from a child under thirteen on troopside.com. A parent or guardian who wants to see, correct or delete their child's information should ask a leader of their unit, who can do it on the site; if you write to Troopside instead, we will refer your request to the unit and help it complete it.
4. How we use information
- To run the unit's site: the roster, calendar, sign-ups, payments, documents, reminders and the member hub.
- To send the emails the unit's settings call for: sign-in links, event reminders, payment receipts and reminders, invitations, and the unit's own announcements. Every email comes from an address you can reply to.
- To answer questions members ask the in-app assistant, using the unit's own content. Questions and the content used to answer them are sent to [AI PROVIDER], whose terms do not permit it to train on that content.
- To support units and members, investigate problems, and keep the service secure.
- To bill units for their subscriptions.
- To improve Troopside, using information that does not identify a person or a unit.
Troopside does not sell personal information, does not share it for advertising, and does not use it to train machine-learning models.
5. Who sees information
Inside the unit. A member's information is visible to the unit's leaders according to the permissions the unit configures, and some of it (name, patrol, role) to other members through the roster. Health forms and similar records are visible only to the people the unit's settings name. The unit's public site shows only what the unit chooses to publish.
Troopside. Troopside's operator can reach a unit's site to support it. Every such access is recorded and visible to the unit.
Service providers, who process information on Troopside's behalf under contracts that limit them to that: Vercel (hosting and file storage), Neon (database), Resend (email delivery), Stripe (payments and subscriptions), [AI PROVIDER] (the assistant), and Google (sign-in, if a member chooses it, and maps). GroupMe and Zoom see what a unit chooses to send them when it connects them.
When the law requires, or to protect the safety of a member, a unit or the service.
Troopside does not share personal information with anyone else.
6. How long we keep information
A unit's information is kept for as long as the unit subscribes and for twelve months after its subscription lapses or is cancelled, so the unit can export it or resume. After that Troopside deletes it on thirty days' notice to the unit. A unit's leaders can delete individual records, and archive members who leave, at any time. Backups are kept for [BACKUP WINDOW] and expire on their own schedule. Billing records and the agreement acceptance record are kept as long as the law requires.
Information from a beta request or an unfinished signup is kept for as long as the request is open and is deleted when it is declined or abandoned.
7. Security
Troopside encrypts information in transit and at rest, stores passwords only as hashes, scopes every read and write to the unit it belongs to, records operator access to a unit's site, and keeps only the information the service needs. No service is perfectly secure. If Troopside confirms that your information was accessed without authorization, it will tell your unit promptly so the unit can tell you.
8. Your choices and rights
- See and correct. Your profile on your unit's site shows what the unit holds about you and lets you correct your own contact details. Ask a leader for anything you cannot change yourself.
- Delete. Ask a leader of your unit to remove your record, or write to team@troopside.com and we will refer the request to your unit and help it.
- Email. Sign-in links, receipts and reminders about things you signed up for are part of the service. A unit's announcements and newsletters carry the unit's own unsubscribe instructions.
- Google sign-in. Optional. A password account works without it.
- State rights. [STATE RIGHTS] Residents of states with privacy laws may have rights to access, correct, delete or port their information and to appeal a refusal. Write to team@troopside.com; we will not treat you differently for asking.
10. Changes to this policy
This policy is versioned; every version stays readable at its own address. Troopside will tell units about material changes at least thirty days before they take effect.
11. Contact
[TROOPSIDE ENTITY], [ENTITY ADDRESS]. Email team@troopside.com. For questions about your own unit's site, your unit's leaders are the fastest answer.
Content hash of this version: 171dc0657720f5d2bda7139bc172be652cd4cbb93c564fb21487b920b720e749
Every version stays readable at its own address: version 1.