COPPA Compliance Statement
Children's Online Privacy Protection Act (COPPA), as amended Last updated: July 23, 2026
Aktivate, Inc. ("Aktivate") provides an online platform that schools and districts use to manage student-athlete registration, eligibility, communications, and payments. In delivering these services, Aktivate acts as a service provider/processor handling student data on the school's or district's behalf and at its direction. Aktivate confirms the following regarding its compliance with COPPA, as amended.
1. Role and purpose of data handling
Aktivate collects and processes student personal information solely to provide the registration, eligibility, athletics, and related services contracted by the school or district, for the use and benefit of the school, and not for other commercial purposes.
2. School-authorized consent
Consistent with FTC guidance on COPPA in the educational context, Aktivate collects students' personal information at the direction of, and under the authorization of, the school or district (and participating parents and guardians) for a school-authorized educational purpose. Registration is managed through parent/guardian and school-administered accounts.
3. Use limitations - no sale; analytics use disclosed
Aktivate does not sell student personal information and does not use student personal information to serve targeted or behavioral advertising or to build advertising profiles. The platform uses standard web analytics (Google Analytics / Google Tag Manager) to understand and improve site usage, and for service operation and improvement only.
4. Data minimization
Aktivate collects only the information reasonably necessary to provide athletic registration and eligibility services (e.g., student name and date of birth, parent/guardian and emergency-contact information, and eligibility/physical-form data required by the school or athletic association) or other services specifically requested.
5. Third-party / subprocessor sharing
Aktivate limits disclosure of student data to subprocessors that support delivery of the service - for example, cloud hosting, PCI-validated payment processing, email and SMS communications, and web analytics - under contractual confidentiality and data-protection terms. Payment card data is handled by PCI DSS-validated processors; Aktivate does not store full card numbers or security codes. Aktivate does not sell student data and does not authorize subprocessors to use student data for their own independent commercial purposes.
6. Security safeguards
Aktivate maintains an industry-standard administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including hosting on Google Cloud Platform, encryption of data in transit (TLS) and at rest, role-based access controls scoped per school/district, audit logging of sensitive actions, and tokenized payment processing. Consistent with the amended COPPA Rule, Aktivate maintains these security practices and is formalizing its written information-security program.
7. Data retention and deletion
Aktivate retains student personal information only as long as reasonably necessary to fulfill the educational purpose for which it was collected, or as directed by the school or district, and supports deletion of student data upon request or contract termination. Aktivate is formalizing its written data-retention policy consistent with the amended Rule.
8. Breach notification
Aktivate will notify the school or district without undue delay of any confirmed security incident affecting student data, and will cooperate with their notification obligations under applicable law.
9. FERPA alignment
In providing these services, Aktivate operates as a "school official" with a legitimate educational interest under FERPA, using school-provided education records only for the authorized purpose and under the school's direct control.
10. Ongoing compliance
Aktivate monitors applicable regulatory developments, including the FTC's amended COPPA Rule, and updates its practices accordingly.
Contact
Questions about this statement can be directed to privacy@aktivate.com.
This statement describes Aktivate's current and in-progress practices. It is not a statement of legal conclusions. Specific contractual data-protection terms (or a Data Privacy Agreement, such as the SDPC National DPA) can be executed on request.