Back to Home
Privacy Policy

Last Updated: May 21, 2026 · Version: 2026-05-21-v2

SphereUs℠ Corporation is committed to the highest standard of privacy protection, particularly for minors enrolled in SUN Youth℠. This Policy explains how we collect, use, and safeguard your information — and specifically how we protect the personal data of youth participants ages 12–17.

NOTICE FOR PARENTS AND GUARDIANS: SUN Youth℠ knowingly collects personal information from children ages 12–13 with verified parental/guardian consent, in compliance with the Children's Online Privacy Protection Act (COPPA). See Section 4 and the Children's Privacy Notice (Section 5) for full details of your rights and our obligations.

1. Information We Collect

Personal Information (provided by you):

  • Full name, username, and email address
  • Phone number and physical address (street, city, county, state, ZIP)
  • Date of birth (for age verification, SUN Youth℠ age-band compliance, and COPPA obligations)
  • Profile information (bio, skills, profile picture)
  • Payment information (processed and stored securely by Stripe — we never store card numbers)
  • Government-issued ID (for optional Stripe Identity verification)
  • Guardian relationship documentation and custodial consent records (SUN Youth℠ only)
  • School enrollment and grade information (SUN Youth℠ school partnership participants only)
  • IEP / 504 plan status (voluntarily disclosed by guardian for Pre-ETS pathway eligibility only)

Usage & Technical Information (collected automatically):

  • Device information, browser type, operating system, and IP address
  • Pages visited, features used, and time spent on platform
  • Transaction history and marketplace activity
  • GPS location data — SUN Youth℠ safety sessions only; guardian-controlled; see Section 6

2. How We Use Your Information

  • Provide, operate, and improve SphereUs℠ services
  • Process payments and manage membership subscriptions
  • Facilitate marketplace transactions between members
  • Send transactional emails (booking confirmations, payment receipts, gig updates)
  • Send marketing communications (only with your consent; opt out at any time)
  • Enforce child labor law compliance (FLSA and state law) for SUN Youth℠ participants
  • Operate guardian oversight, school ombudsman reporting, and safety monitoring for SUN Youth℠
  • Personalize your experience and sphere-based recommendations
  • Detect fraud, prevent abuse, and ensure platform security
  • Comply with legal obligations including child labor law reporting and COPPA requirements
  • Respond to law enforcement requests and protect the safety of minors

We will never use minor participants' data for advertising, behavioral profiling, or any commercial purpose unrelated to administering the SUN Youth℠ program.

3. Information Sharing

We share your information only in these circumstances:

  • With Other Members: Your profile (name, username, location, ratings) is visible to verified members within your sphere. Minor participants' profiles are never publicly visible — they are visible only to their enrolled guardian and the specific Buyer guardian on an accepted gig.
  • Service Providers: Stripe (payments), Twilio (SMS verification), Base44 (platform infrastructure), email service providers. All service providers are contractually bound to data protection standards consistent with this Policy.
  • SUN Youth℠ — Guardian-Authorized Sharing: A minor's name, age band, and gig details are shared with the buyer and, where applicable, the school ombudsman. Financial data is never shared with the school. See Section 5 for full minor data sharing rules.
  • School Partners (FERPA): Where a school partnership is active, aggregate program participation data (not earnings, not financial data) may be shared with the designated school ombudsman under FERPA School Official authorization. Individual student data is shared only to the extent necessary for program oversight.
  • Legal Requirements: When required by law, court order, subpoena, or to protect the safety of minors or other members. SphereUs will notify affected users of such disclosures to the extent permitted by law.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets. You will be notified at least 30 days in advance, and minor data will be subject to the same protections under any successor entity.

We never sell your personal information — or any minor's personal information — to third parties. Ever.

4. Children's Privacy — COPPA & Minor Participant Protections

⚠️ SUN Youth℠ Knowingly Collects Data from Children Ages 12–13

The SUN Youth℠ program explicitly serves students ages 12–17. For participants ages 12 and 13, we are knowingly collecting personal information from children under 13 as defined by COPPA. We do so only with verifiable parental or guardian consent, as documented during the Premier guardian enrollment process.

COPPA Compliance Measures:

  • Verifiable Parental Consent: Before any data is collected from a child ages 12–13, SphereUs requires the enrolling guardian to complete a signed, documented consent process with their Premier membership account, which itself requires identity verification.
  • Data Minimization: We collect only the minimum personal data necessary to operate the SUN Youth℠ program for under-13 participants: name, date of birth, age band, state, school (optional), and guardian authorization records.
  • No Marketing to Minors: We do not send marketing communications to minor participants. We do not use minor data to build behavioral profiles, serve advertisements, or for any commercial purpose outside the program.
  • No Public Profiles for Minors: Youth participant profiles are never indexed by search engines, never publicly visible, and never shared outside the direct guardian/buyer/school relationship for a specific gig.
  • Parent/Guardian Rights (COPPA §312.6): You have the right at any time to: (a) review the personal information collected from your child; (b) request correction of inaccurate information; (c) request deletion of your child's personal information; and (d) refuse further collection of your child's information by withdrawing consent. To exercise these rights, contact privacy@sphereus.org.
  • Deletion Response Time: Upon receipt of a verified parent/guardian deletion request, we will delete the minor's personal data within 10 business days, except where retention is required by law (e.g., labor compliance records, tax records).

5. Children's Privacy Notice (SUN Youth℠ Specific)

This notice supplements Section 4 and applies specifically to SUN Youth℠ participants ages 12–17 and their guardians. It is required by COPPA and provided separately to ensure clarity.

What data we collect about SUN Youth℠ participants:

  • First and last name, date of birth, state, ZIP code
  • School name and grade (if voluntarily provided and school partnership is active)
  • Anonymous SUN Youth℠ ID (e.g., SY-2026-WA-04821) used in all school-facing reports — this ID never contains the student's real name
  • Gig history: job type, date, hours worked, completion status
  • Earnings records (visible only to guardian and SphereUs; never shared with school)
  • Academy module completions and certifications
  • GPS location snapshots during active gig safety sessions (see Section 6)
  • IEP/504 status (if disclosed by guardian for Pre-ETS eligibility; stored as a yes/no flag only)

Who can see what:

  • Guardian: Full access to all youth data including earnings, gig history, GPS, and certifications
  • School Ombudsman: Anonymous participation data only (SUN Youth ID, module completions, aggregate compliance status) — no name, no earnings, no financial data, no GPS
  • Gig Buyer: Youth's first name, age band, and job category match only — no surname, no school, no earnings history, no GPS outside active session
  • SphereUs Staff: Full access for program administration, compliance, and safety purposes only
  • Public: Nothing — no public profile exists for any youth participant

How long we keep minor data:

Active program data is retained while enrollment is active. Upon guardian withdrawal or the youth's 18th birthday, personally identifiable data is de-identified or deleted within 90 days, except: (a) gig completion records and earnings records retained 7 years for tax and labor compliance; (b) signed guardian consent and custodial consent documents retained per applicable state law; (c) safety incident records retained as required by law. GPS location data is deleted within 30 days of session completion.

California-Specific Minor Protections (SOPIPA / AB 1584):

For California students: SphereUs does not use student data to build personal profiles for non-educational purposes, does not sell student data, does not use student data for targeted advertising, and will not retain student data after withdrawal from the program beyond what is required by law. These protections apply regardless of COPPA age thresholds.

Do Not Track:

We do not track SUN Youth℠ participants across third-party websites and do not use cross-site behavioral tracking for minor participants. We honor Do Not Track signals from browsers for minor participant sessions.

5b. Time Tracking & Dual Attestation Data (SUN Youth℠)

SUN Youth℠ uses a server-side clock-in/clock-out system to enforce labor law compliance and protect youth earnings. The following data is collected for each work session:

  • Clock-in and clock-out timestamps — recorded server-side and immutable. Cannot be modified by any party after recording.
  • GPS coordinates at clock-in and clock-out — used to verify the student was at the approved job site. See Section 6 for full GPS data handling rules.
  • Computed hours worked — calculated from timestamps; used for labor law compliance enforcement and weekly cap tracking.
  • Student/guardian attestation record — digital confirmation that the guardian/student agrees the time record is accurate.
  • Buyer attestation record — digital confirmation by the buyer that the student worked the recorded hours. This is a legally significant attestation — falsification constitutes fraud.
  • Compliance window data — the legal start/end window and daily/weekly cap applicable to the student on that specific date, computed at the time of the session.
  • Discrepancy flags — automatically generated when the student's and buyer's time records differ significantly; reviewed by platform administrators.

Who can see time tracking records:

  • Guardian: Full time log including timestamps, hours, attestation status, and any flags
  • Buyer: Only the specific time log for gigs they posted — no access to other gigs or aggregate history
  • School Ombudsman: Aggregate weekly hours only, using anonymous SUN Youth℠ ID — no individual session details, no buyer information
  • SphereUs Staff: Full access for compliance, dispute resolution, and safety purposes
  • Public: None

Time log records are retained for 7 years as required for labor compliance and tax purposes. This retention applies even if the youth withdraws from the program.

6. GPS & Location Data

Location data is collected only during active SUN Youth℠ safety sessions, and only when enabled by the guardian. Specific rules by age band:

  • Ages 12–13: GPS location sharing is always active during gigs and cannot be disabled. This is a mandatory safety protection.
  • Ages 14–15: GPS is active by default during gigs. Guardians may disable on a per-gig basis from the Guardian Dashboard.
  • Ages 16–17: GPS is off by default. Guardians may enable on a per-gig basis.

Location data is used solely for guardian safety monitoring during the specific gig session. It is never shared with advertisers, never sold, never used for any purpose other than real-time guardian safety oversight. Location data is automatically deleted within 30 days of gig completion.

7. Data Security

We implement industry-standard security measures including encryption in transit (TLS 1.2+) and at rest, secure server infrastructure, role-based access controls, and regular security reviews. Payment data is handled exclusively by Stripe (PCI-DSS Level 1 compliant). Minor participant data is subject to heightened access controls — only SphereUs staff with a documented program administration need may access individual minor records.

Despite these measures, no system is completely secure. In the event of a data breach affecting minor participants, we will notify affected guardians within 72 hours of discovery, consistent with applicable state breach notification laws, and will report to the FTC as required under COPPA.

8. FERPA — Student Education Records

Where SphereUs operates in partnership with a school under a signed School Partner MOU, SphereUs acts as a "School Official" with a "legitimate educational interest" as defined under the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g. In this capacity:

  • SphereUs will not re-disclose student education records to any third party without guardian consent
  • SphereUs will use student education records only for the purpose of administering the SUN Youth℠ program
  • SphereUs will return or destroy student education records upon termination of the School Partner MOU
  • Parents/guardians retain full FERPA rights to inspect, review, and request correction of education records held by SphereUs

FERPA rights requests: privacy@sphereus.org

9. Your Rights & Choices

  • Access: Request a copy of your personal data (or your child's data if you are a guardian)
  • Correction: Update inaccurate information through your profile settings
  • Deletion: Request deletion of your account and associated data (subject to legal retention requirements). For minor data deletion requests, see Section 4.
  • Opt-Out: Unsubscribe from marketing emails at any time via the unsubscribe link in any email
  • Portability: Request your data in a portable format
  • California Residents (CCPA / CPRA): You have the right to know, delete, correct, and opt out of sale of personal information (we do not sell data). California minors under 18 may also request removal of content they posted on the platform under California Business and Professions Code § 22581.
  • Virginia, Colorado, Connecticut Residents: You have additional rights under your state privacy laws including the right to appeal our response to a rights request.

To exercise these rights: privacy@sphereus.org or our Privacy Request Page.

10. Cookies & Tracking

We use essential cookies to maintain sessions and remember preferences. We use analytics cookies (anonymized) to improve the platform. We do not use third-party advertising cookies. We do not use behavioral tracking cookies for any session where a minor participant is the authenticated user. You can control cookie settings through your browser; disabling essential cookies may affect platform functionality.

11. Data Retention

We retain your information while your account is active or as needed to provide services. After account deletion:

  • General member data: retained up to 7 years for legal, tax, and compliance purposes
  • Minor participant PII: de-identified or deleted within 90 days of withdrawal, except labor compliance and tax records (7 years)
  • GPS location data: deleted within 30 days of gig session completion
  • Signed guardian consent documents: retained per applicable state law (typically 7 years or until the minor reaches age 21, whichever is longer)
  • Safety incident records: retained as required by applicable law

12. Background Checks — Important Disclosure

SphereUs does not conduct criminal background checks on Buyers, Providers, or other adult members of the platform. We verify identity through Stripe Identity for certain membership tiers, but identity verification is not a criminal background check. Guardians should exercise independent judgment when allowing a youth participant to perform services for any community member. SphereUs is a platform intermediary and cannot guarantee the safety of any individual adult member.

13. Third-Party Links & Integrations

Our platform may link to division-specific websites and external services. These third-party sites have their own privacy policies. We are not responsible for their data practices. Always review the privacy policy of any third-party service before providing personal information. SUN Youth℠ minor participants' data is never transmitted to third-party sites other than those listed in Section 3 (Stripe, Twilio, Base44).

14. International Users

SphereUs℠ is operated in the United States and the SUN Youth℠ program is U.S.-only. If you access from outside the US, your information will be transferred to and processed in the US. By using our services, you consent to this transfer.

15. Changes to This Policy

We may update this Policy from time to time. We will notify you of material changes via email and platform notification at least 14 days before they take effect. For changes that materially affect how we treat minor participants' data, we will seek renewed guardian consent. Your continued use constitutes acceptance of the updated Policy.

16. Privacy Requests & Contact

To exercise any privacy rights — including COPPA parental rights, FERPA rights, or a formal data deletion request — visit our Privacy Request Page. Requests are processed within 10 business days for minor data requests and within 45 calendar days for all other requests.

SphereUs℠ Corporation — Privacy & Data Protection Office
Email: privacy@sphereus.org
COPPA Parent/Guardian Requests: coppa@sphereus.org
FERPA Requests: ferpa@sphereus.org
Support: Contact Page

17. Affiliated Domain Properties

The following domains are wholly owned by SphereUs Corporation and serve as alternative access points, branded landing pages, or redirects to the main SphereUs℠ platform. None of these domains operate independent databases, collect independent data, or create separate legal privacy relationships. All data collection and processing at these domains is governed exclusively by this Privacy Policy:

sphereus.com (primary)sphereus.netsphereusco.comsphereusnation.comsunyouth.comsphereusyouth.comgolfyourage.comgolfmyage.comfederalprograms.comfederalprogramsonboarding.comqualitycharters.comqualitycharters.aiqualitycharters.ionafepa.comwirks.comsphereusfoundation.comsphereusfoundation.orgsphereus.org

Users who access SphereUs services via any of these domains are subject to this Policy. No additional consent is required to use an alternative domain. For any privacy questions about a specific domain, contact privacy@sphereus.org.

Also see our Terms of Service, the SUN Youth℠ Guardian Enrollment Agreement, and the SphereUs Foundation℠ Privacy Policy. Privacy Policy version 2026-05-21-v2. This policy and all associated legal documents cover sphereus.com, sunyouth.com, sphereusyouth.com, golfyourage.com, federalprograms.com, qualitycharters.com, nafepa.com, wirks.com, and all SphereUs Corporation digital properties.