Security & Compliance
SphereUs℠ protects member, youth, school, and partner data across every division — SUN Youth℠, GuidedAim℠, Grade Level Up℠, SplitZen℠, Golf Your Age℠, and the SphereUs Foundation℠. This page documents our controls posture, sub-processors, data-retention schedule, and how to report a concern.
Controls in place
Enforced in-app and auditable today.
FLSA & State Minor Labor Law
6-gate compliance engine, age-band rules, dual-PIN check-in, school-year authorization.
FERPA
School ombudsmen see only anonymized SUN Youth IDs — never student PII.
COPPA / Guardian Consent
Minors never hold accounts. One-guardian-one-YouthProfile. Custodial consent + 2FA.
FCRA
Standalone background-check disclosure gated at SYCB and mentor applications.
Perkins V / ESSA / Title I
CLNA packets, CTE credentials, attestation gates, special-population consent.
IRS 501(c)(3) Separation
Foundation and Corporation funds are never commingled.
PCI DSS (de-scoped)
Stripe handles card data end-to-end. We never store card numbers.
Audit Logging
AdminAuditLog + UserActivityLog on all sensitive admin actions.
Remediation roadmap
Where we are on the path to full certification.
SOC 2 Type II
Controls documented (SOP §41). Observation period + external audit pending.
Annual Pen Test
Third-party penetration test to be commissioned.
HIPAA (conditional)
Counsel determining if any youth/identity data qualifies as PHI; BAAs if so.
GDPR / CCPA DSAR
Data-subject request intake active at /DataPrivacyRequest (45-day SLA).
Vendor / Sub-processor Review
Sub-processor list published below. Annual vendor risk review scheduled.
Sub-processors
Third parties that process member data on our behalf (GDPR Art. 28 transparency).
| Vendor | Purpose | Data touched |
|---|---|---|
| Base44 | App hosting, auth, database, serverless functions | All application data |
| Stripe | Payments & identity verification | Card data (Stripe-held), identity docs |
| Twilio | SMS — 2FA, safety alerts, outreach | Phone numbers, SMS content |
| Resend | Transactional email | Email addresses, email content |
| Solana (devnet) | SU token ledger | Wallet addresses, token balances |
| VirusTotal | Malware scanning of uploaded files | File hashes |
Data retention schedule
How long we keep each class of data, and what happens when the period ends.
| Data class | Retention | Disposition |
|---|---|---|
| Youth time logs / earnings | 7 years | Anonymize aggregate; delete PII |
| YouthProfile + minor PII | Until age 18 + 2 yrs | Hard delete; keep de-identified cert records |
| Account deletion requests | Indefinite (audit) | DeletedAccount record retained |
| Location snapshots | 30 days post-session | Auto-purge |
| Identity verification docs | 1 year post-verification | Per Stripe Identity retention policy |
| Admin audit logs | 7 years | Append-only; no deletion |
| Marketing / email engagement | 2 years | Delete on unsubscribe |
Access, correct, delete, or export your data — or opt out of marketing. CCPA/GDPR requests answered within 45 days.
Submit a privacy requestSuspect a data breach, vulnerability, or safety issue? Email our security team immediately — we triage within 24 hours.
security@sphereus.orgFull controls detail in SOP §41 (Information Security & Compliance Program). Last reviewed: August 2026.