Security & Compliance

SphereUs℠ protects member, youth, school, and partner data across every division — SUN Youth℠, GuidedAim℠, Grade Level Up℠, SplitZen℠, Golf Your Age℠, and the SphereUs Foundation℠. This page documents our controls posture, sub-processors, data-retention schedule, and how to report a concern.

FERPA
COPPA
FLSA
PCI DSS (de-scoped)
CCPA / GDPR-ready

Controls in place

Enforced in-app and auditable today.

FLSA & State Minor Labor Law

6-gate compliance engine, age-band rules, dual-PIN check-in, school-year authorization.

FERPA

School ombudsmen see only anonymized SUN Youth IDs — never student PII.

COPPA / Guardian Consent

Minors never hold accounts. One-guardian-one-YouthProfile. Custodial consent + 2FA.

FCRA

Standalone background-check disclosure gated at SYCB and mentor applications.

Perkins V / ESSA / Title I

CLNA packets, CTE credentials, attestation gates, special-population consent.

IRS 501(c)(3) Separation

Foundation and Corporation funds are never commingled.

PCI DSS (de-scoped)

Stripe handles card data end-to-end. We never store card numbers.

Audit Logging

AdminAuditLog + UserActivityLog on all sensitive admin actions.

Remediation roadmap

Where we are on the path to full certification.

SOC 2 Type II

In progress

Controls documented (SOP §41). Observation period + external audit pending.

Annual Pen Test

Planned

Third-party penetration test to be commissioned.

HIPAA (conditional)

Under review

Counsel determining if any youth/identity data qualifies as PHI; BAAs if so.

GDPR / CCPA DSAR

Live

Data-subject request intake active at /DataPrivacyRequest (45-day SLA).

Vendor / Sub-processor Review

Annual cadence

Sub-processor list published below. Annual vendor risk review scheduled.

Sub-processors

Third parties that process member data on our behalf (GDPR Art. 28 transparency).

VendorPurposeData touched
Base44App hosting, auth, database, serverless functionsAll application data
StripePayments & identity verificationCard data (Stripe-held), identity docs
TwilioSMS — 2FA, safety alerts, outreachPhone numbers, SMS content
ResendTransactional emailEmail addresses, email content
Solana (devnet)SU token ledgerWallet addresses, token balances
VirusTotalMalware scanning of uploaded filesFile hashes

Data retention schedule

How long we keep each class of data, and what happens when the period ends.

Data classRetentionDisposition
Youth time logs / earnings7 yearsAnonymize aggregate; delete PII
YouthProfile + minor PIIUntil age 18 + 2 yrsHard delete; keep de-identified cert records
Account deletion requestsIndefinite (audit)DeletedAccount record retained
Location snapshots30 days post-sessionAuto-purge
Identity verification docs1 year post-verificationPer Stripe Identity retention policy
Admin audit logs7 yearsAppend-only; no deletion
Marketing / email engagement2 yearsDelete on unsubscribe
Exercise your privacy rights

Access, correct, delete, or export your data — or opt out of marketing. CCPA/GDPR requests answered within 45 days.

Submit a privacy request
Report a security incident

Suspect a data breach, vulnerability, or safety issue? Email our security team immediately — we triage within 24 hours.

security@sphereus.org

Full controls detail in SOP §41 (Information Security & Compliance Program). Last reviewed: August 2026.