Privacy Policy

Effective date: August 20, 2026
Last updated: August 2026

Raybin Management, LLC operates Greenwich Stars and the website at https://www.greenwichstars.com/ (collectively, “Greenwich Stars,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, and retain personal information when you visit our website, register or pay for a program, purchase merchandise or a gift card, submit a waiver or other form, subscribe to communications, or otherwise interact with us online or in connection with our basketball programs (collectively, the “Services”).

Greenwich Stars programs serve youth participants, but the Site itself is an adult-facing parent and guardian portal. Our online registration, purchasing, waiver, subscription, and contact functions are intended to be used only by an adult parent, legal guardian, or other authorized adult—not by a youth participant. Please read Children and Minors below carefully.

1. Who We Are

The business responsible for the personal information described in this Policy is:

Raybin Management, LLC
Operator of Greenwich Stars
Attn: Mr. John Raybin, Principal Contact
15 East Putnam Avenue, Suite 450
Greenwich, CT 06830
Email: info@greenwichstars.com

2. Information We Collect

The information we collect depends on how you interact with us. It may include the following categories:

Adult, parent, and guardian information

  • Name, email address, mobile and other telephone numbers, signature, mailing and billing address, and relationship to a participant.
  • Account, registration, waiver, consent, communication, and marketing-preference records.
  • The substance of messages, questions, feedback, and other information submitted in contact or free-text fields.

Participant information

  • Name, date of birth, age, gender, grade, school, town or home address, team, tryout selection, program interest, skill or eligibility information, attendance, roster status, and related registration details.
  • Information included in a participant agreement, waiver, code-of-conduct record, or other program document.
  • Health, injury, allergy, medication, disability, accommodation, emergency-contact, insurance, or similar safety information, but only if requested for a particular program or voluntarily provided to us.
  • Photographs, video, audio, testimonials, and related identifying information when separately authorized or otherwise permitted by law.
  • Ticket or attendee details and an attendee-list privacy preference where an event-registration form includes that option. Some forms present an unchecked option labeled “Opt-out from being displayed in the public list of attendees.” Selecting it requests exclusion from any provider-generated public attendee list, and we will honor that request. If it is not selected, attendee information configured for a list could be eligible for display. An adult may also contact us to request privacy or removal.

Purchases and transactions

  • Products and programs viewed, cart contents, order and registration details, price, discounts, billing and shipping details, transaction identifiers, payment status, refund or credit information, and fraud-prevention signals.
  • Payment providers receive payment-card, bank, or wallet credentials directly. We ordinarily receive limited payment confirmation and transaction information rather than a complete payment-card number.

Device, network, and activity information

  • Internet Protocol address, approximate location inferred from the IP address, device and advertising identifiers, browser and device type, operating system, language, screen information, user-agent string, and similar technical data.
  • Information necessarily generated when a browser requests a page or when an adult uses a form, registration, cart, checkout, payment, account, or security function, such as requested URL, referring page, timestamp, transaction or form status, and fraud or security signals.
  • On eligible, reviewed informational pages only, optional technologies may collect cookie, local-storage, or session-storage identifiers; referring and exit pages; pages and links viewed; files downloaded; videos viewed; scrolling, mouse movement, and time or engagement signals—but only after the applicable adult privacy choice described below.
  • Advertising and attribution information on eligible informational pages, including campaign or click identifiers, referring source, and interests inferred from the content viewed. Optional advertising and analytics vendors do not receive form contents, registration records, searches, query-string URLs, product/cart/checkout activity, or staff-session activity through our governed tag loaders.
  • Server, security, error, and administrative activity logs.

Inferences

We and our analytics or advertising providers may derive inferences about interests, likely program preferences, engagement, marketing attribution, or the effectiveness of an advertisement from the information above. We do not use personal information collected through the Services to train a large language model or generative-AI foundation model.

3. Sources of Information

We collect information:

  • Directly from an adult parent, guardian, or other adult user, such as when the adult registers a participant, signs a form, completes checkout, contacts us, or subscribes. Participant information entered by a parent or guardian is collected from that adult, even though it relates to a child.
  • Automatically from a browser or device, through server logs, cookies, pixels, software development kits, local or session storage, tags, and similar technologies.
  • From our personnel and program operations, such as coaches, administrators, tryout evaluators, or staff who create roster, attendance, safety, or communication records.
  • From service providers and integrations, such as payment, ecommerce, registration, email, anti-spam, analytics, advertising, social-media, and security providers.
  • From referrals and publicly available sources, when appropriate and lawful.

4. How We Use Information

We may use personal information to:

  • Provide tryouts, teams, leagues, camps, clinics, training, merchandise, gift cards, and other requested Services.
  • Determine program eligibility, age or grade placement, capacity, team formation, and scheduling.
  • Process registrations, orders, payments, credits, refunds, waivers, and electronic signatures.
  • Communicate about registrations, schedules, venues, practices, games, weather, cancellations, safety, account or order status, and customer support.
  • Support participant health, safety, accommodations, and emergency response where relevant.
  • Operate, maintain, troubleshoot, secure, and improve the website and Services.
  • Measure traffic and informational-page performance through optional analytics on eligible pages after the applicable choice.
  • Market Greenwich Stars programs and measure advertising on eligible informational pages after the applicable Advertising choice, subject to Global Privacy Control and the page restrictions described below.
  • Send newsletters or promotional communications and measure their delivery, opens, or clicks, where our provider enables that functionality.
  • Prevent spam, fraud, abuse, security incidents, and unlawful activity.
  • Enforce agreements, protect participants and others, comply with law, maintain business and tax records, and establish, exercise, or defend legal claims.

5. Cookies, Analytics, Advertising, and Tracking Technologies

The Services use first-party and third-party cookies, pixels, tags, scripts, local storage, session storage, and server-side systems. A cookie is a small text file stored by a browser. Similar technologies may recognize a browser or device without using a traditional cookie. Necessary technologies support security, forms, cart, checkout, payments, and the storage of your privacy choice. Optional Analytics and Advertising technologies are off unless and until an adult makes the applicable choice.

Protected pages and sessions. A saved choice never overrides our page restrictions. Optional Analytics and Advertising vendors do not load on registration, waiver, contact, or other form pages; product, cart, checkout, or account pages; searches, archives, 404 pages, previews, or feeds; URLs containing a query string; logged-in or staff sessions; or any page that has not been affirmatively reviewed and allowlisted. Necessary processors and ordinary security or server logs may still operate on those pages.

Current optional-technology consent matrix
Choice on an eligible page What may load
No choice, or Reject nonessential No optional Analytics or Advertising vendor.
Analytics only Browser-based Microsoft Clarity. Google Analytics does not load by itself because the current Google Tag Manager container combines Analytics and Advertising destinations.
Advertising only Browser-based Meta Pixel, after our no-store server check confirms that no Global Privacy Control signal is present. Google advertising does not load by itself because of the combined container.
Analytics and Advertising Microsoft Clarity and Google Tag Manager. The current container may deploy Google Analytics, Google advertising, and Meta tags. Meta browser events may also be routed through Meta’s configured Conversions API Gateway.
Global Privacy Control Advertising remains off. If Analytics was separately allowed, browser-based Clarity may still load on an eligible page; the combined Google container remains off.

The table below describes the technologies currently used in connection with the Services. Providers may change their cookie names or storage periods. “Up to” periods are typical or configured maximums and may be shorter because of browser settings, consent choices, provider configuration, or deletion.

Tracking and related technology inventory
Provider and tool Category and purpose Information and events Storage examples and controls
WordPress and WooCommerce Strictly necessary site, cart, checkout, login, preference, and fraud-prevention functions. Session, cart contents, checkout state, login/security status, orders, browser and device information. Examples include gs_privacy_preferences, wordpress_test_cookie, wordpress_logged_in_*, wordpress_sec_*, wp-settings-*, woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*, and wc_fragments_*. The privacy-preference cookie stores the policy revision, category choices, choice source, whether GPC was observed, and an update time for up to 180 days. Necessary storage cannot always be disabled without breaking requested functions. See WooCommerce cookie documentation.
Google Tag Manager Combined Analytics and Advertising tag management on eligible informational pages. Loads only when both Analytics and Advertising are allowed and the GPC check permits Advertising. It may supply eligible-page URL/path and engagement context to the Google and Meta destinations configured in the container. It does not load on protected pages or sessions. Google Site Kit remains available for administration but does not emit front-end tags; our first-party consent manager is the only permitted loader. Destination tags may use the storage described in their rows. See Google’s Privacy Policy.
Google Analytics 4 and Google tag Analytics, audience measurement, and informational-page improvement. On eligible pages, page views, sessions, first visits, engagement, scroll, outbound clicks, downloads, and video interactions. Google Analytics loads only when both Analytics and Advertising are allowed; it does not receive governed form, search, product, cart, checkout, purchase, query-URL, or staff-session events. Examples include _ga and _ga_*, which may persist for up to two years depending on configuration. Reject either optional category in Cookie Settings, use the Google Analytics opt-out add-on, or use browser controls.
Google Ads conversion and remarketing Advertising attribution, conversion measurement, audience creation, and remarketing. Eligible informational-page activity; ad-click and cookie identifiers; IP address; and device/browser information. The live Google configuration retains automatic email, telephone, and address detection and automatic user-provided-data flags for enhanced advertising measurement. Our governed Google loader is not permitted on any form, registration, product, cart, checkout, account, query-string, or other protected page, so those fields are not available to the tag on protected routes. Examples may include _gcl_au, _gcl_aw, Google/DoubleClick identifiers, and ad-click identifiers. Google Ads loads only when both optional categories are allowed. Reject either category, use Google My Ad Center, or submit an opt-out request below. Learn more from Google’s partner-sites notice.
Meta Pixel and configured Conversions API Gateway Advertising attribution, conversion measurement, audience creation, and remarketing. On eligible informational pages, PageView and, through the combined container, configured time, scroll, or engagement events; page URL and referrer; IP and browser/device information; and Meta click or cookie identifiers. Advertising-only uses an isolated browser Pixel. When both categories are allowed, the combined container may deploy Meta, and its current configuration may route Meta browser events through an active Meta Conversions API Gateway/OpenBridge endpoint. No governed Meta tag receives registration, form, product, cart, checkout, purchase, query-URL, or staff-session events. Examples include _fbp and _fbc. Reject Advertising, adjust Meta Ad Preferences, or submit an opt-out request below. Facebook for WooCommerce browser signals and its WordPress-to-Graph CAPI sender are disabled; the separately configured Meta gateway described here is not categorically disabled. See Meta’s Privacy Policy.
Microsoft Clarity Browser-based session replay, heatmaps, diagnostics, and interaction analytics on eligible pages after Analytics is allowed. Reconstructed sessions and rendered page context, clicks, mouse movement, scrolling, navigation, timing, device/browser information, IP-derived location, and diagnostic data. The document is marked for masking. Clarity does not load on protected pages or sessions. Examples include _clck, _clsk, CLID, ANONCHK, MR, MUID, SM, and session storage _cltk. Provider periods range from a session or minutes to approximately 13 months. Reject Analytics or use browser controls. The Clarity WordPress/server collector is disabled. See Microsoft’s Privacy Statement and Clarity cookie documentation.
Google reCAPTCHA v3 Security, bot detection, and spam/fraud prevention on forms or commerce pages. Browser and device characteristics, IP address, page and interaction signals, Google cookies, and a risk score. Google may use information from visitors who are signed into Google subject to its policies. May use Google cookies such as _GRECAPTCHA and existing Google account cookies. This security technology may be necessary for protected functions. See the Google Privacy Policy and Terms.
Akismet Spam and abuse prevention for supported forms. IP address, user agent, referrer, page URL, interaction or timing signals, and submitted form information needed to evaluate spam. May use local or cookie-based interaction data. See Akismet’s Privacy Notice.
Constant Contact Email subscription, customer-list management, campaign delivery, and campaign measurement. Email address, subscription/source information, and, depending on the connected form, name and mobile telephone number. Our integrations can transfer adult contact details from newsletter, contact, tryout, waiver, event, program, and completed-order flows. Campaigns may measure delivery, opens, clicks, device, and approximate location. Use the unsubscribe link in a marketing email or contact us. Transactional program and order messages may continue. See Constant Contact’s Privacy Notice.
WP Mail SMTP Pro and Amazon Simple Email Service (SES) Delivery, troubleshooting, and measurement of transactional, program, form, waiver, order, and marketing email. Recipients, sender, subject, headers, plain-text or HTML message content where message logging is enabled, delivery status, error data, mailer, initiator, message ID, tracked links, opens, clicks, IP/device data associated with an open or click, and timestamps. Server-side email and tracking records are not controlled by browser Cookie Settings. Marketing tracking ends when you unsubscribe from marketing; contact us regarding other email records. See the AWS Privacy Notice.
Facebook and Instagram links Links to Greenwich Stars profiles on external social platforms. Embedded social feeds are replaced by a privacy-safe placeholder and do not make an automatic social-network request. If you choose an external social link, that platform receives information associated with the visit and may recognize a signed-in user. Social-platform cookies and account settings apply after you leave the Site. See Meta’s Privacy Policy.
PayPal Commerce, Venmo, hosted cards, Apple Pay, and Google Pay Checkout, payment authorization, fraud prevention, and transaction processing. Billing, transaction, device, network, fraud, and payment information. The selected payment provider receives the credentials needed to complete payment. Provider cookies and storage are generally necessary when that payment option is selected. See PayPal’s Privacy Statement; wallet providers apply their own notices.
Gravity Forms, Gravity Forms Signature, and WooCommerce Box Office Forms, electronic signatures, registrations, tickets, and attendee management. Submitted fields; IP address; source URL; user agent; timestamps; form, payment, and transaction metadata; electronic signature; and ticket or attendee details where an event-registration function is used. Certain event forms include an unchecked attendee-list opt-out. Certain forms also capture UTM attribution and fbclid. Form entries and signatures are stored in WordPress; selected tryout fields are also duplicated in a custom table. These records are not controlled by browser Cookie Settings. Select the attendee-list opt-out where offered if you do not want possible display, or submit a privacy or guardian request below. We will honor a selected opt-out or removal request.
First-party aggregate page-view counter Basic operational analytics. Counts visits to individual posts, pages, and products after screening the user-agent string for common bots. Daily records store a content ID, date, and aggregate view count rather than a visitor profile. Stored in the Greenwich Stars WordPress database. It does not use a dedicated visitor cookie.
Web server and WordPress activity logs Hosting, reliability, security, diagnostics, and administration. IP address, timestamp, requested URL, response, referrer, user agent, errors, and—primarily for authorized personnel—WordPress administrative activity. Server-side records; controlled through our security, hosting, and retention practices rather than browser-cookie settings.
Wordfence, Jetpack, 301 Redirects, and WordPress Stream Security, account protection, uptime monitoring, content delivery, redirect/404 diagnostics, subscriptions, WooCommerce support analytics, and authorized-user audit logging. IP address, requested and destination URL, referrer, user agent, inferred location, browser/OS/device, bot classification, login username or user ID, success/failure, administrative action, role, timestamp, and security status. Jetpack may also receive CDN image requests and subscription information when its relevant feature is used. Server-side security and operational records. Redirect/404 logs are configured for approximately 30 days; Stream records are generally retained for approximately 30 days; other security and provider periods vary. See Wordfence privacy information and Automattic’s Privacy Notice.
External asset and content delivery Delivery of icons, fonts, scripts, or media. Font Awesome, Icons8/Line Awesome, unpkg, WordPress s.w.org, Jetpack/Photon and similar hosts may receive IP address, user-agent, referrer, URL, and request time when the browser requests an asset or image. These providers control their own network logs. Browser content-blocking controls may limit requests but can affect display.

Historical technologies and records. Records created by analytics, advertising, attribution, social-feed, abandoned-cart, or similar integrations that are no longer active may remain until deleted under the applicable retention process. Current optional technologies and controls are described in the table above. If a materially different technology is enabled, we will update this Policy and apply any required notice or choice.

Email tracking. Marketing emails sent through Constant Contact may contain pixels and tracked links that tell us whether a message was delivered, opened, or clicked. You can stop marketing emails by using the unsubscribe link in any such email.

Emails sent through our WordPress mail system may also contain open pixels and tracked links where described. An email-delivery log can contain the message body, recipient, headers, delivery/error information, and engagement events. Because program, waiver, order, and form emails may contain participant information, we treat these records as personal information and apply the retention principles below.

Tag changes. We may add, remove, or reconfigure technologies as the Services change. We will update this table when a change is material. You can also inspect your browser’s cookie and site-data controls for currently stored identifiers.

6. How We Disclose Information

We may disclose personal information to the following categories of recipients for the purposes described in this Policy:

  • Website, hosting, ecommerce, form, and security providers, including Amazon Web Services, WordPress/Automattic, WooCommerce, Gravity Forms, WooCommerce Box Office, Wordfence, Jetpack, redirect/diagnostic tools, anti-spam, CAPTCHA, backup, administration, and technical-support providers.
  • Analytics and advertising providers, including Google, Meta, and Microsoft, as detailed above.
  • Payment and commerce providers, such as PayPal, enabled wallet providers, ecommerce plugins, fraud-prevention providers, and financial institutions.
  • Communications providers, including Constant Contact, WP Mail SMTP, Amazon SES, and providers used for necessary email, telephone, text, or push communications. If you use a related mobile application and enable push notifications, a device push token and delivery data may be processed through Google Firebase Cloud Messaging.
  • Program operations recipients, such as authorized coaches, staff, evaluators, facilities, leagues, tournament organizers, insurers, emergency responders, or health professionals where reasonably necessary to administer a program or protect a participant.
  • Social-media and content providers, including Facebook and Instagram when you choose to follow an external social link. Social feeds are not automatically embedded.
  • Professional advisers, such as attorneys, accountants, auditors, consultants, and insurers.
  • Authorities and protective recipients, when we reasonably believe disclosure is required by law or necessary to protect rights, safety, property, participants, users, or the public; investigate fraud or abuse; or respond to lawful process.
  • Transaction parties, in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar actual or proposed business transaction, subject to appropriate safeguards.
  • Recipients you direct or authorize, or as otherwise disclosed when information is collected.

Service-provider labels do not necessarily determine a recipient’s legal role. Some recipients act only on our instructions; others may process information for their own purposes under their own privacy notices.

7. Sale, Sharing, and Targeted Advertising

We do not sell personal information for money. On expressly reviewed informational pages only, and only after an adult allows Advertising and no Global Privacy Control signal is detected, the Meta browser tag and its configured gateway and—when Analytics is also allowed—tags in our Google Tag Manager container may receive online identifiers and page or engagement information for measurement or advertising. Depending on the law and the provider’s role, these disclosures may be considered a “sale,” “sharing,” or processing for “targeted advertising,” even when no money changes hands.

Optional advertising tags do not load on protected pages or sessions. We do not intentionally provide participant registration fields, form contents, searches, query-string URLs, product/cart/checkout information, payment information, or staff-session activity to them through our governed tag loaders.

Categories used for sale, sharing, or targeted advertising
Personal-information category Recipient categories Purpose
Online identifiers from an eligible informational-page visit, such as IP address, cookie or advertising IDs, and Meta or Google ad-click IDs. Advertising platforms, principally Google and Meta, only after the applicable choice. Campaign attribution, audience creation, frequency or performance measurement, and targeted advertising.
Internet activity and related inferences from eligible informational pages, such as page or link views, scrolling, time or engagement signals, and interests inferred from the content viewed. Advertising platforms, principally Google and Meta, only after the applicable choice. Measurement, audience creation, inference of interests, and targeted advertising.

Historical advertising practices. If a legally required lookback period includes an earlier Site configuration, prior Google, Meta, ecommerce-attribution, or server-conversion features may have disclosed broader page, form, product, cart, checkout, purchase, or matching information for measurement or advertising. Those disclosures may have constituted sale, sharing, or targeted advertising under some laws. Current practices are described above, and historical provider or transaction records may remain for an applicable retention period.

We do not knowingly sell personal information of children or minors, and we do not permit targeted advertising based on personal information of a visitor we know or willfully disregard is under 18. Optional advertising tags are excluded from every participant registration, waiver, form, product, cart, and checkout page. See Your Privacy Choices to opt out of adult targeted-advertising processing.

8. Your Privacy Choices

  • Cookie Settings: Use the persistent “Cookie Settings” control to allow or reject Analytics and Advertising separately. No optional vendor loads before a valid choice. A saved choice lasts for up to 180 days unless you change it, the policy revision changes, or the cookie is deleted. Necessary technologies remain active because the requested website, form, security, cart, checkout, or payment function may depend on them.
  • Targeted advertising / sale / sharing: Use the same persistent “Cookie Settings” control or email info@greenwichstars.com with the subject “Opt Out of Targeted Advertising.”
  • Global Privacy Control: When a browser sends Global Privacy Control, Advertising is kept off regardless of a saved choice. We check both the browser signal and a same-origin, no-store server endpoint before permitting Advertising. If the server check fails, is malformed, or cannot confirm that GPC is absent, Advertising remains off. GPC does not itself withdraw a separate Analytics choice; turn Analytics off in Cookie Settings if that is also your preference. The signal applies to the browser or device that sends it. Learn more at globalprivacycontrol.org.
  • Marketing email: Use the unsubscribe link in a marketing email or contact us. We may still send nonmarketing messages about an order, registration, schedule, safety matter, or other requested service.
  • Browser controls: Most browsers allow you to block or delete cookies and site data. Blocking necessary storage can prevent cart, checkout, form, or login functions from working.
  • Provider controls: You may also use Google, Meta, Microsoft, and other provider controls linked in the table above. Provider choices do not necessarily communicate a request directly to us.
  • Push notifications: If you use a related mobile application, you can disable push notifications in device settings.

Do Not Track. Some browsers transmit a legacy “Do Not Track” signal, for which there is no uniform industry response. The Site does not respond to legacy Do Not Track signals. This is different from Global Privacy Control and other opt-out preference signals that applicable law requires us to honor.

9. Privacy Rights and Appeals

Depending on your residence and subject to applicable law and exceptions, you may have the right to:

  • Confirm whether we process your personal information and access it, including certain inferences or profiling information.
  • Correct inaccurate personal information.
  • Delete personal information provided by or obtained about you.
  • Receive a portable copy of certain personal information.
  • Opt out of targeted advertising, a sale or sharing of personal information, or certain automated profiling.
  • Obtain information about certain third parties to which personal information was sold, where applicable.
  • Withdraw consent to processing that relies on consent.
  • Not be discriminated against for exercising a privacy right.

A parent or legal guardian may submit a request concerning a child’s information. An authorized agent may submit a request where applicable law permits. We may ask for information reasonably necessary to verify identity, authority, and the information to which the request relates. We will not require you to create a new account solely to make a request. We may deny or limit a request when permitted by law, including where we cannot verify it, must retain information, or an exception applies.

How to submit a request

Email info@greenwichstars.com with the subject “Privacy Rights Request,” or mail the request to the address in Contact Us. Please identify the right you wish to exercise and provide enough information for us to locate the relevant record. Do not send a Social Security number, complete payment-card number, government ID, medical record, or other unnecessary sensitive document by ordinary email.

Appeals

If we decline to act on a request, you may appeal by emailing info@greenwichstars.com with the subject “Privacy Appeal” within a reasonable time after receiving our decision. Include the request number or a copy of the decision and explain why you believe it should be reconsidered. We will respond within the period required by applicable law. If we deny an appeal from a Connecticut resident, we will provide a way to contact the Connecticut Attorney General; you may also visit the Connecticut Attorney General’s website.

California disclosures

For purposes of California law, the categories collected in the preceding 12 months are the categories described in Information We Collect. The business or commercial purposes and recipient categories are described in How We Use Information, Tracking Technologies, and How We Disclose Information. The current and prior-12-month categories that may have been sold or shared for cross-context behavioral advertising, and their recipients, are identified in Sale, Sharing, and Targeted Advertising. We do not use or disclose sensitive personal information to infer characteristics about a person in a manner that creates a right to limit under California law. We do not knowingly sell or share the personal information of consumers under 16.

10. Children and Minors

Greenwich Stars programs are for children and teenagers, but the Site is directed to their parents, guardians, and other adults. The participant is not the online user merely because a parent provides information about that participant. A parent or legal guardian—not the child participant—must complete registration, ecommerce, waiver, subscription, and contact functions and provide any participant information.

The Site does not offer youth participant accounts, child-directed chat or messaging, or a function through which a child is expected to register, purchase, sign, subscribe, or upload information. If you are under 18, do not submit a form, create an account, make a purchase, sign a waiver, subscribe, or provide personal information through the Site yourself. Ask a parent or legal guardian to act for you. Parents and guardians should not allow a child to complete an adult-facing form on their device.

The Children’s Online Privacy Protection Act generally addresses personal information collected online from a child; it does not ordinarily apply merely because an adult parent provides information that relates to a child. Consistent with our parent-only model, we do not knowingly ask a child under 13 to submit personal information directly through the Site. If we learn that a child under 13 used an adult-facing function and submitted information directly, we will take appropriate steps to delete it or satisfy any notice and verifiable-parental-consent requirement that applies. A parent or guardian may contact us to review, correct, delete, or stop further collection or use of participant information, subject to applicable law.

Attendee-list preference. Some adult registration forms present an unchecked option labeled “Opt-out from being displayed in the public list of attendees.” Select it if you do not want attendee information to be eligible for possible display, or contact us to request privacy or removal. We will honor the selected opt-out or request. The existence and contents of any provider-generated list depend on the applicable event configuration.

Necessary site, security, and server systems can receive technical information from any device that requests a page. Optional Analytics and Advertising technologies run only after an adult choice on reviewed informational pages and never on protected pages or sessions. Our intended and expected online user is an adult, but if we learn that a particular visitor is a child, or if applicable law otherwise treats a page or interaction as child-directed, we will not use that visitor’s information for targeted advertising or sale and will apply the additional protections required by law. Participant records supplied by a parent are used only for disclosed and compatible program purposes and retained no longer than reasonably necessary for those purposes and applicable legal or safety obligations.

If you believe a child submitted information directly, or if you want to exercise rights for a child, contact info@greenwichstars.com with the subject “Child Privacy Request.” We will take reasonable steps to verify that the requester is the child’s parent or legal guardian before disclosing or changing a child’s record.

11. Health and Safety Information

If a program asks an adult guardian for health, injury, allergy, medication, disability, accommodation, emergency, or insurance information, we use it only as reasonably necessary to evaluate or provide an accommodation, administer the program, support participant safety, respond to an emergency, meet legal or insurance obligations, or establish or defend a claim. We may make it available to authorized personnel, coaches, facilities, insurers, emergency responders, or health professionals who reasonably need it for those purposes.

Where required, we will request a separate, specific guardian consent close to the relevant fields. Acceptance of general website Terms is not consent to unrelated processing of sensitive information. Greenwich Stars is not necessarily a healthcare provider or entity covered by the Health Insurance Portability and Accountability Act merely because it receives health-related information; we protect that information under applicable privacy, security, and consumer-protection laws.

12. Photos and Media

We may photograph or record programs and events, but promotional use of an identifiable participant should be addressed in a separate media release or other legally sufficient authorization. The media choice is separate from this Privacy Policy and from consent to process health or other sensitive information. Where a withdrawal right applies, a guardian may contact us to withdraw future use; withdrawal may not require recall of material already lawfully printed, posted, distributed, or incorporated into completed media.

13. Retention

Our retention policy is to keep personal information no longer than reasonably necessary for the purpose for which it was collected and for legitimate legal, safety, accounting, dispute, and security needs. Our criteria include program duration, the participant’s age, the nature and sensitivity of the record, statutory limitation periods, tax and accounting requirements, insurance or incident needs, consent status, active disputes, and provider settings. Some legacy form, tryout, email, abandoned-cart, attribution, security, or related records may remain under older retention settings while they are reviewed for deletion or minimization or retained for a documented legal, safety, accounting, security, or dispute need.

Retention criteria by record type
Record type General retention approach
Inquiries and support For the time needed to respond and maintain an appropriate history, then deleted or minimized unless needed for another disclosed purpose.
Tryout, registration, roster, attendance, and participant records Through the relevant selection or program cycle and a limited administrative, safety, dispute, and legal period afterward. Information not needed after an unsuccessful tryout should be deleted or minimized on a defined schedule.
Health, accommodation, and emergency information Through the relevant program and only for the shortest additional period justified by safety, incident, insurance, or legal needs; then securely deleted or de-identified.
Waivers, consents, and agreements For the relevant program and the period reasonably necessary to document the authorization, satisfy insurance or legal requirements, and address disputes.
Orders, payments, credits, and tax records For the periods required by tax, accounting, payment, fraud, chargeback, and commercial-record laws. Payment providers retain their own records under their policies.
Marketing records Until you unsubscribe or we stop the relevant program, plus a minimal suppression record so we can honor the opt-out.
Email delivery, content, open, and click logs For delivery, troubleshooting, security, required communications, campaign measurement where permitted, and legal needs. Older complete-message and engagement records may remain under legacy settings while they are reviewed for deletion, minimization, and an appropriate retention period.
Historical abandoned carts New guest abandoned-cart capture and recovery are disabled. Records created before the feature was disabled may remain until reviewed and deleted or minimized, unless the cart became an order or a documented security or legal obligation justifies retention.
Cookies, analytics, advertising, and session replay Current browser-based optional tools operate only under the consent matrix and protected-route rules above. Provider records and historical records from disabled implementations follow applicable provider settings and deletion processes. Aggregate reports may be retained longer when they no longer reasonably identify a person.
Server, security, and backup records On rotating schedules appropriate to security, reliability, incident response, and backup recovery, with longer retention when an incident, dispute, or law requires it.

When retention is no longer justified, we delete, de-identify, or securely dispose of the information. A deletion request may be subject to lawful retention exceptions and the technical timing of backup rotation.

14. Security

We use reasonable administrative, technical, and physical safeguards designed for the nature and sensitivity of the information we maintain. No website, email, database, or transmission method is completely secure, and we cannot guarantee absolute security. Please do not send highly sensitive information through a general contact field or ordinary email. If you believe information provided to us has been compromised, contact us promptly.

15. Processing in the United States

Greenwich Stars operates in the United States. We and our providers may process information in the United States and other locations where they operate. Privacy laws in those locations may differ from those where you live.

16. Changes to This Policy

We may update this Policy prospectively to reflect changes in the Services, technology, law, or our practices. We will post the updated version with a revised “Last updated” month and year. If a change is material or applies materially and retroactively to previously collected information, we will provide additional notice and an opportunity to withdraw consent where required. We encourage you to review this page periodically.

17. Contact Us

Questions, privacy requests, guardian requests, consent withdrawals, and complaints may be directed to:

Raybin Management, LLC
Operator of Greenwich Stars
Attn: Mr. John Raybin, Principal Contact / Privacy
15 East Putnam Avenue, Suite 450
Greenwich, CT 06830
Email: info@greenwichstars.com