Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches

Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches
Natty Hatty Signature logo

Back

Security

icon

Natty Hatty — Data Classification Policy

Version: v1.0

Effective Date: November 15, 2025

Natty Hatty, Inc. (“Natty Hatty”) classifies all data it processes to ensure appropriate protection, access control, retention, and handling. Because Natty Hatty manages youth-sports data—including minors’ information—this policy defines strict standards that govern how sensitive data must be secured.

This Data Classification Policy applies to:

  • Natty Hatty employees

  • Contractors

  • Infrastructure systems

  • APIs and integrations

  • All organizations using Natty Hatty’s platform

1. Data Classification Categories

Natty Hatty uses a four-tier classification model:

  • Restricted Data (Tier 1 — Highest Sensitivity)

  • Confidential Data (Tier 2)

  • Internal Data (Tier 3)

  • Public Data (Tier 4 — Lowest Sensitivity)

Each category has defined storage, access, handling, and transmission rules.

2. Tier 1 — Restricted Data

Highest sensitivity — strict security controls required.

Restricted Data includes any information that could:

  • Identify or endanger a minor

  • Impact payment security

  • Cause legal, financial, or compliance harm if exposed

  • Affect youth-sports safety

Examples of Restricted Data

2.1 Minors’ Personal Information (COPPA-Regulated)

  • Full name of a minor

  • Date of birth

  • Guardian relationships

  • Contact information

  • Player profile details

  • Attendance, roster, or team assignments

  • Medical/allergy notes (if entered)

2.2 Payment & Financial Data

  • Payment tokens (Stripe)

  • Last 4 of card numbers

  • Transaction metadata

  • Refund/dispute logs

  • Payout metadata

(Natty Hatty does NOT store full card numbers or CVV.)

2.3 Signature & Legal Document Data

  • Signed waivers

  • Signing audit trails (IP, device ID, hash)

  • Contract metadata

  • Document storage paths

2.4 Authentication Data

  • Passwords (hashed + salted)

  • MFA tokens

  • Session identifiers

  • Device fingerprints

2.5 System Secrets & Keys

  • AWS credentials

  • API keys

  • Encryption keys

  • Internal tokens

2.6 Safety & Incident Data

  • Reports involving minors

  • Abuse or misconduct flags

  • Law enforcement escalation data

Required Controls

  • AES-256 encryption at rest

  • TLS 1.2+ in transit

  • Strict role-based access control

  • Multi-factor authentication

  • Zero sharing outside need-to-know

  • Logging and monitoring

  • No AI or ML model ingestion

  • No export without encryption

  • Must never be stored on employee personal devices

3. Tier 2 — Confidential Data

High sensitivity — protected but less regulated than Tier 1.

Confidential Data includes information that affects security, operations, or business viability but does not directly endanger minors.

Examples

  • Organization administrator information

  • Coach accounts (adult data)

  • Program pricing and configurations

  • Payment settings (non-sensitive)

  • Internal dashboards

  • Analytics and usage data

  • Performance logs without identifiers

  • Support tickets

  • Marketing contact lists

  • Access and event logs

  • Internal API documentation

Required Controls

  • Encryption at rest and in transit

  • Role-based access

  • Stored only on approved systems

  • Not shareable outside Natty Hatty or contracted org

  • No personal device storage

  • Optional MFA for partner access

4. Tier 3 — Internal Data

Internal-use information not harmful if disclosed in limited form.

This category includes general business operations data.

Examples

  • Company policies

  • Product roadmaps

  • Operational documentation

  • Development notes

  • Internal-only feature specs

  • Slack messages (non-sensitive)

  • HR non-confidential notices

Required Controls

  • Access limited to Natty Hatty staff

  • Internal distribution only

  • No external publication

  • Can be stored on secure employee devices

5. Tier 4 — Public Data

Safe for public release.

Data approved for public visibility.

Examples

  • Marketing website content

  • Legal policies (ToS, Privacy Policy, etc.)

  • Public API documentation

  • Help Center articles

  • Press statements

  • Public roadmap (if applicable)

Required Controls

  • No special restrictions

  • Must be approved by authorized personnel before publishing

6. Data Handling Requirements Per Tier

Activity

Restricted

Confidential

Internal

Public

Encryption at Rest

Required

Required

Recommended

Optional

Encryption in Transit

Required

Required

Recommended

Recommended

RBAC Access

Strict

Controlled

Moderate

None

MFA

Mandatory

Strongly recommended

Optional

Not required

Cloud Storage

Approved only

Approved only

Allowed

Allowed

Email Transmission

Prohibited unless encrypted

Allowed with caution

Allowed

Allowed

Backup Retention

Mandatory with rotation

Mandatory

Recommended

Optional

AI/ML Processing

Not allowed

Not allowed

Allowed with review

Allowed

Export / Download

Highly restricted

Controlled

Allowed

Allowed

Deletion Requests

Follows COPPA/CPRA + legal retention

Per policy

Standard

N/A

7. Third-Party and Vendor Handling

Natty Hatty uses Stripe, AWS, and other sub-processors. Vendors must:

  • Meet Tier 1 data protection standards for payment and minors data

  • Provide SOC 2 or equivalent assurances

  • Sign Data Processing Agreements (DPAs)

  • Use encryption in transit and at rest

  • Meet contract-based retention and deletion requirements

Natty Hatty must approve any vendor with access to Restricted or Confidential data.

8. Retention Rules by Data Type

Aligns with your other signed policies.

Tier 1

  • Legal documents / waivers → Permanent or org-defined

  • Payments → 5–7 years (Stripe rules)

  • Safety records → As required by law

  • Minor personal data → Until program completion + retention window

Tier 2

  • Admin data → Duration of account

  • Logs → 30–180 days depending on type

  • Analytics → Aggregated & anonymized

Tier 3

  • Internal docs → Until superseded

Tier 4

  • Public content → As long as published

9. Data Transmission Restrictions

Restricted Data may NOT be sent through:

  • Unencrypted email

  • SMS or WhatsApp

  • External messaging apps

  • Non-Natty Hatty systems

  • Insecure file uploads

  • AI/ML training systems

  • Personal employee devices

Allowed Transmission Channels

  • Natty Hatty infrastructure

  • Encrypted AWS services

  • Encrypted backups

  • Encrypted emails using approved methods (if absolutely necessary)

10. Enforcement & Violations

Violations of this policy may result in:

  • Account suspension

  • Access removal

  • Termination of contractor agreements

  • Legal reporting when minors’ data is at risk

  • Organization account termination

Natty Hatty will always prioritize child safety in enforcement actions.

11. Contact

For questions, security review, or classification issues:

security@nattyhatty.comlegal@nattyhatty.com