Trust & Safeguarding

Built around young players’ privacy

Last updated [DATE]

Emblem cards belong to children, so we’ve tried to design the product around that fact rather than bolt privacy on afterwards. This page explains, in plain language, what that means in practice. It doesn’t replace our full Privacy Policy, which remains the legally binding document — this page is the friendlier, parent-facing summary of it.

In short: a card belongs to one child. A parent or guardian claims it and controls what, if anything, is ever made public. Nothing is public by default. Coaches only see what a guardian connects them to, and coach-submitted content is reviewed before it appears as “verified” on a profile. We don’t sell data or use it for advertising, and a guardian can request access, correction or deletion of their child’s data at any time.

Privacy by default

A player’s digital profile (“Player OS”) is private the moment it’s created, visible only to the guardian who claimed it and any coach that guardian specifically connects. There is no public roster, leaderboard or directory of players anywhere on Emblem — a profile only becomes visible to anyone else if a guardian actively chooses to publish it.

Guardian controls

From inside Player OS, a guardian can, at any time and without contacting us:

  • remove a photo or moment;
  • unpublish a public profile, taking it down immediately;
  • remove a coach’s connection to their child;
  • request full deletion of their child’s profile.

These are guardian-only actions — a coach or Squad Invite organiser never has the ability to publish, share or delete a child’s profile on a guardian’s behalf.

Coach contributions and verification

Coaches can add moments, recognitions and season notes to a player they’re connected to, but nothing a coach submits appears as a “verified” achievement until reviewed — this is a content-review step, distinct from vetting the coach as a person. To be precise about what “verified” does and doesn’t mean here: signing in as a coach proves control of an email address, not employment, DBS status or club authority. We ask every coach and organiser to confirm their own authority as part of using the product, and we are continuing to invest in stronger verification over time. If you believe someone has connected to a child without proper authority, contact us immediately (see “How to report a concern” below) and we will investigate.

What information is collected, and why

We collect only what’s needed to build, print and connect a card:

  • Photos — to design the card itself.
  • Player details — first name, surname initial, position, squad number and team, so a card and profile can be built.
  • Order and delivery details — handled by Shopify, our checkout provider, to get the physical card to you.

We do not collect a child’s exact date of birth — a football age group (e.g. U10) is all the product needs. Full detail on every field we collect, every supplier involved and how long each is kept is in the Privacy Policy.

Sharing and profile visibility

A guardian can choose to make a player’s profile — or specific moments on it — public. Even then, only an allow-listed set of fields is ever shown, deliberately excluding anything sensitive: never a child’s exact date of birth, age, height, coach assessments, season goals, or the identity of their guardian. A guardian can switch public sharing off at any time, taking the page down immediately.

Lost cards and disabled access

If a card is lost or stolen, contact us and we can disable that specific card’s digital connection so tapping it no longer resolves to anything. Finding or tapping a lost physical card never grants access to the private Player OS or its management controls — that always requires the guardian’s own sign-in, regardless of who is holding the card.

Access, correction and deletion requests

Guardians can access, correct or delete most of their child’s information directly within Player OS. For anything else — including a request from a child old enough to make their own — contact us at hello@emblem.cards and we will respond directly.

A plain-language Children’s DPIA summary

Before building features that touch children’s data, we complete a Children’s Data Protection Impact Assessment (DPIA) — a documented process of identifying what could go wrong for a child using the product, and deciding how to reduce that risk before shipping. A DPIA is a risk-assessment exercise, not a certificate: completing one doesn’t mean a feature is risk-free, and we don’t claim Emblem is “DPIA certified,” “ICO approved,” guaranteed secure, or fully compliant with every applicable law — those aren’t things a DPIA can certify, and no organisation should claim them from one.

Our current DPIA has identified open items that still require specialist legal and safeguarding review, and we treat those as outstanding rather than resolved. We don’t publish the full internal assessment, its risk register or our security controls here, since detailing exactly what we’re still working through isn’t itself good security practice — but we’re glad to discuss our approach with a guardian, club or specialist reviewer directly on request.

How to report a privacy or safeguarding concern

If you’re worried about how a child’s data is being used on Emblem — including a coach or organiser you believe shouldn’t have access to a child, a public profile showing something it shouldn’t, or a lost card — contact us at hello@emblem.cards. We treat safeguarding-related reports as urgent and will respond as quickly as we can.

The full legal detail

This page is a summary. Our Privacy Policy and Terms of Service are the complete, binding documents covering everything above in full detail.