Privacy Policy

Privacy Policy

Last updated [DATE]

Emblem (“we”, “us”) operates emblem.cards, including the Player OS, Coach OS and Squad Invite features described below. This policy explains what we collect across the whole product — not just the shop — and what we do with it. Emblem is currently operated as a trading name; formal company registration details will be added here once finalised.

In short, for families: a card belongs to one child. Whoever claims it controls it — usually a parent or guardian — and decides what, if anything, is ever made public. Nothing is public by default. Coaches only see what you connect them to. We don’t sell data or use it for advertising. A child’s exact date of birth, height, and any coach assessment are never shown publicly, ever. You can ask us to delete a child’s data at any time — see “Your rights” below.

What we collect

To build and produce a card

  • Photos you upload — used to build the card design and, where AI-styled processing is used, sent to a third-party AI image service to generate that styling. A non-AI option is available for this.
  • Player details — first name, surname initial, position, squad number, team/club, and (where a coach adds it) exact date of birth, height, preferred foot and similar sporting details.
  • Order and shipping information — purchaser name, email and delivery address, handled by Shopify, our checkout provider.
  • Generated print files — rendered from your design and stored privately on Amazon S3 solely to produce and ship the order.

Once a card is claimed — Player OS

Tapping or claiming a card creates a private profile (“Player OS”) for that child, visible only to the guardian(s) who claimed it and any coach the guardian specifically connects. It can include:

  • moments, photos and videos a guardian or connected coach adds;
  • coach assessments, recognised strengths and season focus areas;
  • goals set by the guardian or a connected coach;
  • the guardian and coach accounts linked to that child, and their relationship to them.

None of this is visible to anyone outside that circle unless a guardian explicitly makes a specific moment public (see “Public profiles” below) — and even then, exact date of birth, height, coach assessments, goals and season focus are never included in what’s shown publicly, under any setting.

Coach and organiser accounts

Coaches and Squad Invite organisers sign in with their own email (verified with a one-time code). We do not verify employment, DBS status, safeguarding clearance, or that someone claiming to be a child’s parent actually is — see “A note on identity verification” below for what we do check.

Squad Invite

Squad Invite lets a team organiser (coach or club representative) request one shared link that each parent uses independently to build their own child’s card. The organiser never sees child names, photos or a roster — only their own request details (team name, estimated squad size, delivery contact) and, once parents start joining, a running count and each joined child’s first name and surname initial only, so the organiser can confirm the names actually belong to their own team. Each parent’s photo, full name and any other detail stays private to that parent and to Emblem staff reviewing the request.

A note on identity verification

Signing in with an email and one-time code proves control of that email address — it does not prove you are a child’s parent or legal guardian, that you are an authorised coach, or that a club representative genuinely represents that club. We ask everyone to confirm their authority as part of using the product, and for Squad Invite, the team organiser can see enough (first name and surname initial only) to notice if a name doesn’t belong to their real squad and flag it to us. We are continuing to build stronger verification; if you believe someone has claimed a child without proper authority, contact us immediately (see “Contact” below) and we will investigate and can freeze the record in question.

Public profiles

A player’s profile is private by default. A guardian can choose to make specific, individual moments public, and can choose whether the player has any public page at all. Even when enabled, a public profile only ever shows an allow-listed set of fields chosen to exclude anything sensitive — never exact date of birth, age, height, preferred foot, ambitions, assessments, goals, season focus, guardian identity, or the claim token itself. A guardian can disable public sharing at any time, which takes the page down immediately.

We do not currently apply search-engine no-index protection to every public profile page — we are working on this. Until it is in place, treat a public profile as potentially discoverable by search engines and plan accordingly (for example, delaying enabling it, or keeping it off entirely).

The physical NFC card

NFC-enabled products contain a passive chip carrying a web link with a unique claim code. Tapping it opens that link; the chip itself stores no personal data and transmits nothing on its own. If a card is lost or stolen before being claimed, contact us and we will not activate it under that reference. If a card is lost or stolen after being claimed, contact us immediately — today we can disable or rotate its public profile, and a fuller card-level revocation process is actively being built. Until then, anyone who taps a lost claimed card cannot see the private Player OS (that requires the guardian’s own sign-in) but could reach a public profile if one was enabled for that child.

Who we share data with

  • Shopify — processes orders, payment and shipping details under their own privacy policy.
  • Supabase — hosts our database and handles sign-in (including one-time email codes).
  • Amazon Web Services (S3) — stores photos and print files privately; access is signed and time-limited.
  • Vercel — hosts the website and app.
  • Google (Gemini) — processes a photo only when AI-styled background removal or styling is used for that specific upload; a non-AI option is always available.
  • Resend — sends transactional email (sign-in codes, order and account notifications) on our behalf.

We do not sell data, and we do not share it with anyone for marketing purposes. Some of these suppliers may process data outside the UK; we are reviewing each supplier’s terms and will update this section with specifics.

How long we keep it

Retention periods below are our current proposal and are still under review — treat them as indicative, not final:

  • Print files and production photos: fulfilment plus a short dispute window (proposed 30–90 days), unless kept as part of an active Player OS profile.
  • An active player profile and its moments: for as long as the profile is active, reviewed periodically.
  • Sign-in and claim-attempt security logs: a short window (proposed 30–90 days).
  • Order and payment records: retained by Shopify as required by law (e.g. tax records).

You can ask us to delete a player’s profile, a specific moment or photo, or a whole guardian account at any time — see “Your rights” below.

Your rights (UK GDPR)

If you’re in the UK or EU, you have the right to access, correct, or request deletion of personal data, and to object to how we process it. Many of these you can do yourself: guardians can remove a photo, unpublish a moment, disable public sharing, remove a coach connection, or request full deletion of a child’s profile from within Player OS. For anything else, or if you’re a child old enough to make your own request, contact us at hello@emblem.cards.

Children using this service

Emblem is designed around football-playing children, but accounts, sign-in and uploads are performed by adults (guardians, coaches, organisers) on a child’s behalf. We do not knowingly collect account sign-in information directly from a child. If a child themselves contacts us with a question or request about their own data, we will respond directly and will not require a guardian to be involved to hear that request, though we may need to verify it before acting on it.

Security

Player and guardian data is protected by row-level access controls in our database, private (never public-by-default) file storage with time-limited signed links, and staff access that is separately authorised and logged. No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we work to protect your data using industry-standard practices and are continuing to invest in this as the product grows.

Changes to this policy

We may update this policy as the product changes. Material changes affecting children’s data will be reviewed before publishing, and we’ll update the date at the top of this page.

Contact

Questions, concerns, or a request about a child’s data: hello@emblem.cards