IT Overview
Last updated: September 8, 2026
This overview describes how Ballfrog handles information for school IT and privacy reviewers. It summarizes our Privacy Policy, which is the governing document, and is a companion to our FERPA Statement.
What Ballfrog Is
Ballfrog is a communications platform for school athletics and activities: schedules, scores, rosters, news, photos, and team and group chats, delivered through the Ballfrog mobile app or a school-branded edition of it, and an optional companion website.
Ballfrog does not sell personal information and does not serve targeted advertising. Sponsor content shown in a school’s app is selected by the school and is not targeted using personal information.
Accounts and Student Information
For self-service registration, accounts are created with a name and mobile phone number, verified by a one-time SMS code. Users may add an email address, profile photo, and preferred language. Schools may also create accounts for members of their community through the administrative portal. Ballfrog does not use passwords and does not collect dates of birth.
Each account has an account type (Player, Staff, Parent, or Other), chosen by the user at registration or assigned by the school when it creates the account. It is a label and is not verified against school records.
Ballfrog does not require schools to provide education records or data from student information systems, and does not collect grades, student home or mailing addresses, student IDs, or academic records. Rosters may include a player’s graduation year when a school supplies it.
Information a school provides or publishes is controlled by the school, and Ballfrog uses it only to provide the Services. Our FERPA Statement describes how education records are handled when a school provides them.
Names, phone numbers, photos, chat messages, and device identifiers are personal information under COPPA and state privacy laws, and Ballfrog treats them as such. The Privacy Policy describes what is collected and how it is used.
Children Under 13
Ballfrog is not for children under 13. No one under 13 may create an account or use the Services, including through a school-provided account, and schools must not provision accounts for students under 13. Self-service registration requires the user to affirm they are 13 or older, and administrators creating an account must confirm the same. Accounts found to belong to children under 13 are removed.
Security and Infrastructure
Ballfrog’s primary infrastructure runs on Amazon Web Services (AWS) in the US-East (Virginia) region. Encrypted backups are also maintained with a second cloud storage provider in the United States.
Data is encrypted in transit over public networks and at rest in Ballfrog’s databases and storage.
Access to administrative tools requires authenticated login and is role-based. School administrators can act only within their own school. Ballfrog personnel access is limited to authorized staff and is subject to confidentiality obligations.
Ballfrog uses established service providers for hosting and encrypted backups, SMS and push delivery, email, translation, image descriptions for accessibility, address lookup, security and abuse prevention, error monitoring, and sponsorship payments. Providers receive only the information needed to perform their function and may not use it for their own purposes.
If a security incident affects personal information, Ballfrog notifies affected schools and users as required by applicable law.
Messages, Retention, and Deletion
Chat messages are visible to the members of the chat, to the school’s administrators for team chats, to chat monitors the school designates for its group chats, and to Ballfrog personnel when necessary for support, safety, or moderation. There are no public chats.
Messages a user deletes are hidden from other users immediately. The underlying record may be retained for safety, legal, or support purposes.
Ballfrog retains chat messages and other school community data for as long as the school uses Ballfrog, or for the period set in the school’s agreement, and then deletes or de-identifies it at the school’s direction. Schools can request deletion or return of their data.
Users can delete their own accounts in the app or at ballfrog.com/account-deletion. Deleted accounts are deactivated immediately, and their personal information is then deleted or de-identified except where retention is required by law or requested by the school.
Agreements and Contact
Schools or districts that require a signed data privacy agreement, or supporting documentation for their records, can contact us at questions@ballfrog.com.