Skip to main content

Legal

Student Data Privacy

Last updated: July 22, 2026

TrapCloud is built for scholastic and youth trap shooting, so much of the information in the Service concerns students who may be minors. This page explains, in plain language, how we handle student data for the schools, teams, leagues, and clubs that use TrapCloud, and the commitments we make under the Family Educational Rights and Privacy Act (FERPA), the Children’s Online Privacy Protection Act (COPPA), and state student-data-privacy laws. It supplements our Privacy Policy and any Data Processing Addendum we sign with your organization.

1.Our role.

When a school or organization uses TrapCloud, that organization decides what information to submit and remains responsible for it. We process student data on the organization’s behalf as a service provider — under FERPA, as a “school official” performing a service the organization would otherwise perform itself, under the organization’s direct control. We use student data only to provide and support the Service for the organization and as the organization instructs.

2.What student data we handle.

Depending on how your organization uses the Service, student data may include an athlete’s name, date of birth, gender, graduation year, governing-body membership number (such as an ATA number), classification, handicap yardage, team/school affiliation, squad and division assignments, and competition scores and history. An athlete does not need an account to appear on a roster; this information is provided to us by the organization or coach.

3.How we use — and do not use — student data.

  • We use student data only to provide and support the Service (rosters, squads, scoring, leaderboards, awards, and the reports your organization runs).
  • We do not sell student data, and we do not use it for targeted or behavioral advertising.
  • We do not build a personal profile of a student except in furtherance of the school-authorized purpose (for example, computing scores, handicaps, and standings).
  • We do not use student data to train advertising models, and we do not disclose it except to subprocessors that help us operate the Service under confidentiality and security obligations (see our Subprocessors page), within your organization, when required by law, or as your organization directs.

4.Public results and directory-type information.

By design, certain competition information — such as athlete names, schools/teams, squads, divisions, and scores — may be displayed publicly on live results, leaderboards, standings, awards, and public team pages, and recruiting profiles are shown publicly only when explicitly opted in. Your organization controls whether and when results are made public for its meets. Organizations are responsible for ensuring they have any consent or directory-information designation required before submitting or publicly displaying student information, and should not submit information they are not permitted to display in this way.

5.Children under 13 (COPPA).

TrapCloud does not knowingly permit children under 13 to create their own accounts; the registration flow asks users to confirm they are 18 or older, or a parent or legal guardian. Information about children in the Service is submitted by organizations and coaches, not collected directly from children. Where a school authorizes the collection of student information for a school-authorized educational purpose, we rely on that authorization consistent with COPPA and FTC guidance, and we use the information only to provide the Service to the school. We provide this notice and our Privacy Policy so schools and parents can review our practices.

6.Parents' Bill of Rights for Data Privacy and Security.

Consistent with laws such as New York Education Law § 2-d, we affirm the following with respect to student data we process on behalf of an educational agency:

  • A student’s personally identifiable information cannot be sold or released for any commercial or marketing purpose.
  • Parents (and eligible students) have the right to inspect and review the complete contents of the student’s education record maintained in the Service, by contacting the responsible school or organization; we will support the organization in responding.
  • State and federal laws protect the confidentiality of personally identifiable information, and safeguards — including encryption, access controls, and authentication — protect it while stored or in transit.
  • A complete list of the subprocessors that may receive student data, and the purpose for which they receive it, is available on our Subprocessors page.
  • Parents have the right to have complaints about possible breaches or unauthorized disclosure of student data addressed. Complaints may be directed to the responsible school or organization, to us at [email protected], or to the applicable state education authority.
  • Student data collected by an educational agency will be retained and protected in accordance with the agency’s policies and applicable law, and returned or deleted on expiration or termination of our agreement (see Section 9).

Where an educational agency requires additional supplemental information (for example, the exclusive purposes of data use, subcontractor oversight, the agreement’s duration and data-transition/deletion terms, and the process for challenging the accuracy of data), that information is provided in the Data Processing Addendum for that agency.

7.Security.

We use technical and organizational measures designed to protect student data, including encryption of data in transit, hashing of passwords, database-level tenant isolation so each organization’s data is segregated, role-based access controls, and audit logging of scoring activity. No method of transmission or storage is completely secure, but we work to protect information consistent with industry practice and our agreements.

8.Incident and breach notification.

If we become aware of a breach or unauthorized disclosure of student data that we process for an organization, we will notify the affected organization without unreasonable delay and consistent with applicable law and our agreement, and cooperate with the organization’s notification obligations to parents, students, and authorities.

9.Data return and deletion.

On expiration or termination of our agreement with an organization, and at the organization’s written request, we will return or delete the student data we hold for that organization, except for limited information we are required to retain by law or that remains in routine backups for a limited period before deletion.

10.Data Processing Addendum (DPA).

We are glad to enter into a Data Processing Addendum (or a state-required student-data agreement) with your school, district, or organization. A DPA supplements this page with binding, agency-specific terms — including the exclusive purposes of data use, security and confidentiality commitments, subcontractor terms, breach-notification timelines, and data-return/deletion obligations. To request a DPA or ask a question about student data, contact us at [email protected].

11.Contact.

Questions about student data privacy? Contact TrapCloud at [email protected]. Parents and eligible students who wish to review, correct, or delete a student’s information should also contact the responsible school or organization, which controls that data.