COPPA Compliance Statement

Children's Online Privacy Protection Act (COPPA), as amended Last updated: July 23, 2026

Aktivate, Inc. ("Aktivate") provides an online platform that schools and districts use to manage student-athlete registration, eligibility, communications, and payments. In delivering these services, Aktivate acts as a service provider/processor handling student data on the school's or district's behalf and at its direction. Aktivate confirms the following regarding its compliance with COPPA, as amended.

1. Role and purpose of data handling

Aktivate collects and processes student personal information solely to provide the registration, eligibility, athletics, and related services contracted by the school or district, for the use and benefit of the school, and not for other commercial purposes.

2. School-authorized consent

Consistent with FTC guidance on COPPA in the educational context, Aktivate collects students' personal information at the direction of, and under the authorization of, the school or district (and participating parents and guardians) for a school-authorized educational purpose. Registration is managed through parent/guardian and school-administered accounts.

3. Use limitations - no sale; analytics use disclosed

Aktivate does not sell student personal information and does not use student personal information to serve targeted or behavioral advertising or to build advertising profiles. The platform uses standard web analytics (Google Analytics / Google Tag Manager) to understand and improve site usage, and for service operation and improvement only.

4. Data minimization

Aktivate collects only the information reasonably necessary to provide athletic registration and eligibility services (e.g., student name and date of birth, parent/guardian and emergency-contact information, and eligibility/physical-form data required by the school or athletic association) or other services specifically requested.

5. Third-party / subprocessor sharing

Aktivate limits disclosure of student data to subprocessors that support delivery of the service - for example, cloud hosting, PCI-validated payment processing, email and SMS communications, and web analytics - under contractual confidentiality and data-protection terms. Payment card data is handled by PCI DSS-validated processors; Aktivate does not store full card numbers or security codes. Aktivate does not sell student data and does not authorize subprocessors to use student data for their own independent commercial purposes.

6. Security safeguards

Aktivate maintains an industry-standard administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including hosting on Google Cloud Platform, encryption of data in transit (TLS) and at rest, role-based access controls scoped per school/district, audit logging of sensitive actions, and tokenized payment processing. Consistent with the amended COPPA Rule, Aktivate maintains these security practices and is formalizing its written information-security program.

7. Data retention and deletion

Aktivate retains student personal information only as long as reasonably necessary to fulfill the educational purpose for which it was collected, or as directed by the school or district, and supports deletion of student data upon request or contract termination. Aktivate is formalizing its written data-retention policy consistent with the amended Rule.

8. Breach notification

Aktivate will notify the school or district without undue delay of any confirmed security incident affecting student data, and will cooperate with their notification obligations under applicable law.

9. FERPA alignment

In providing these services, Aktivate operates as a "school official" with a legitimate educational interest under FERPA, using school-provided education records only for the authorized purpose and under the school's direct control.

10. Ongoing compliance

Aktivate monitors applicable regulatory developments, including the FTC's amended COPPA Rule, and updates its practices accordingly.

Contact

Questions about this statement can be directed to privacy@aktivate.com.

This statement describes Aktivate's current and in-progress practices. It is not a statement of legal conclusions. Specific contractual data-protection terms (or a Data Privacy Agreement, such as the SDPC National DPA) can be executed on request.