Who This Notice Covers
This notice applies to sailors under 13 years of age ("children") who register for regattas through Rhumby. Youth sailing is an important part of our platform, and we take our obligations to protect children's privacy seriously.
What We Collect from Children and Why
We collect only the minimum information necessary to register a child for a regatta and maintain safety during events:
- Name and email address: Required to create an account and send race communications
- Date of birth: Required to determine age and trigger the COPPA parental consent flow
- Boat information: Sail number and class, needed for racing registration
- Medical information (optional): Voluntarily provided for on-water safety; explicit consent required from parent/guardian
- Emergency contact: Parent or guardian contact information for safety purposes
- Parental consent records: Method, timestamp, and evidence of verifiable parental consent
Verifiable Parental Consent
Before we collect any personal information from a child under 13, we obtain verifiable parental consent (VPC) using one of the following methods approved under the 2024 COPPA Rule:
- Credit/debit card pre-authorization ($0.00): The parent's card is authorized for $0 (immediately released) to confirm the parent's identity as an adult account holder.
- Signed digital consent form: The parent digitally signs a consent form sent to their email address.
- Knowledge-based authentication (KBA): The parent answers identity questions consistent with their credit bureau profile.
Until consent is received, no personal information about the child is used for any purpose other than sending the consent request to the parent.
How We Use and Disclose Children's Information
- Register the child for regattas and process entry fees
- Share race-relevant information (name, boat, fleet) with the organizing yacht club to run the event
- Share emergency contact and medical information with race committee members during events for safety only
- Publish race results and standings as part of the public regatta record
We do not:
- Use children's information for behavioral advertising
- Share children's information with marketers or data brokers
- Share information beyond what is reasonably necessary to run the regatta
- Retain children's personal information longer than necessary
Parental Rights
At any time, a parent or guardian may:
- Review the personal information we have collected from their child by emailing privacy@rhumby.com with a subject line of "COPPA Parental Access Request"
- Delete the child's information by submitting a Data Deletion Request
- Withdraw consent at any time; note that withdrawal may prevent the child from participating in future events on the platform
- Refuse further collection or use while still retaining data previously collected (contact privacy@rhumby.com)
We will verify parental identity before fulfilling these requests. Responses are sent within 45 days.
Data Security for Children's Data
Children's data is classified as Restricted tier and receives our highest level of protection: AES-256-GCM column-level encryption, access limited to authorized personnel, and separate audit logging. Medical information and emergency contacts are never visible in application logs.
Retention
Parental consent records are retained for 7 years (statute-of-limitations buffer). Other personal information for child accounts is deleted on the same schedule as adult accounts (30-day soft-delete, then hard-purge). Race results are retained indefinitely as part of the historical sporting record.
Contact
For questions about this notice or to exercise parental rights:
Email: privacy@rhumby.com (Subject: "COPPA Inquiry")
Rhumby, Inc., 123 Harbor Way, Sarasota, FL 34236
You may also file a complaint with the FTC at ftc.gov/coppa.