COPPA Compliant
BagEquity Privacy Policy
Effective: April 23, 2026 · Version 1.0
Bag Equity LLC ("BagEquity," "we," "our," or "us") is committed to protecting your privacy
and your family's data. This policy explains what information we collect, how we use it,
and how we keep it safe.
1. Information We Collect
Account Information
- Name, email address, and phone number (parents and guardians only)
- Account login details
Financial Information
- Bank account details are collected through Plaid. We never store your full account or routing numbers.
- Transaction data for spending categorization
- Contribution amounts and investment records
- Payment details are processed by Stripe. We never see your credit card number.
Information About Your Athlete
- First name, sport, and team (provided by you, the parent or guardian)
- We collect only what is needed to set up their custodial account
Technical Information
- Device type and operating system
- IP address and usage data
What We Do NOT Collect
- Social Security numbers are passed directly to Unit.co for identity verification. We never store, log, or have access to them.
2. How We Use Your Information
- Create and manage your account
- Verify your identity (required by law for financial services)
- Process contributions and ACH transfers
- Categorize your sports-related spending
- Bill your subscription through Stripe
- Provide customer support
- Monitor for fraud and keep your account secure
- Improve the app experience
3. Children's Privacy (COPPA)
Protecting kids is a top priority for us.
- We do not collect personal information directly from children under 13
- All accounts for minors are created and managed by a parent or legal guardian
- Parents provide only limited information about their child (first name and sport)
- No child can independently create an account or give us personal information
- We do not ask for more information than what is needed
- We get parental consent through the parent's own authenticated account
As a parent or guardian, you can review, change, correct, or delete information about your child at any time. Email privacy@bagequity.com with the subject line "COPPA Request."
4. UTMA Custodial Accounts
Accounts for minors are set up as UTMA (Uniform Transfers to Minors Act) custodial accounts under Colorado law.
- The parent or guardian acts as the custodian with legal responsibility
- Investment decisions are made by the custodian, not the minor
- Under Colorado law, the account transfers to the minor at age 21
- Custodial accounts have restrictions on withdrawals to protect the minor's interests
5. Who We Share Information With
We share data only with partners that are required to run the service:
- Unit.co — Banking services, identity verification, and ACH transfers
- Plaid — Secure bank account linking and transaction data
- Stripe — Subscription billing
- Supabase — Cloud database and user authentication
- Vercel — Web hosting
We do NOT sell your personal information. Ever.
We do not share your data for advertising.
We may share information with law enforcement only when required by a valid legal process, such as a court order or subpoena.
6. How We Protect Your Data
- All data is encrypted when stored (AES-256 encryption at rest)
- All data is encrypted when sent over the internet (TLS 1.2 or higher)
- Multi-factor authentication (TOTP) is required before linking a bank account
- Row-level security restricts data access to your family only
- Rate limiting protects against automated attacks
- Personal information is stripped from system logs
- We run regular security reviews and automated vulnerability scans
Bank credentials are handled exclusively by Plaid and are never sent to or stored on BagEquity servers.
7. How Long We Keep Your Data
Active Accounts
Your data is kept as long as your account is active.
Closed Accounts
- Financial records are kept for 7 years (required by federal regulations)
- Transaction data is kept as required by BSA/AML law
- Technical logs are kept for 90 days
Deletion Requests
Honored within 30 days, except for data we are legally required to keep. To request deletion, email privacy@bagequity.com.
8. Your Rights
- Access — Ask for a copy of your personal data
- Correction — Fix information that is wrong
- Deletion — Ask us to delete your data (subject to legal requirements)
- Portability — Get your data in a format you can take elsewhere
- Opt Out — Unsubscribe from marketing emails
California Residents (CCPA)
- Right to know what data we collect and why
- Right to delete your data
- Right to opt out of the sale of your data (we do not sell data)
- We will not treat you differently for exercising your rights
To exercise any right, email privacy@bagequity.com.
9. Cookies and Tracking
- We use only essential cookies needed for the app to work
- No advertising cookies or third-party trackers
- Analytics data is used only to improve the app
10. Changes to This Policy
If we make important changes to this policy, we will notify you by email and in the app. You will have 30 days to review changes before they take effect.
11. Contact Us
Email: privacy@bagequity.com
Mail: Bag Equity LLC, 1001 Bannock Street, Denver, CO 80204
For COPPA requests: privacy@bagequity.com (subject line: "COPPA Request")