Back
Privacy
Natty Hatty — COPPA / Children’s Privacy Notice (Website)
Effective Date: November 15, 2025
Version: v1.1
Natty Hatty, Inc. (“Natty Hatty,” “we,” “our,” “us”) provides registration, payment, and digital signature tools for youth sports Organizations (“Organizations”).
We understand that many programs involve children under 13, and this notice explains how children’s information is handled on Natty Hatty–hosted public pages in compliance with the Children’s Online Privacy Protection Act (COPPA).
This notice applies only to:
Public registration pages
Public checkout pages
Public signature pages
Program listings and forms hosted on the Natty Hatty website (nattyhatty.com)
It does not apply to authenticated platform users; that is covered by the Platform Privacy Policy.
1. Natty Hatty Does Not Allow Children Under 13 to Create Accounts
Natty Hatty does not:
Allow children under 13 to create accounts
Collect login credentials from minors
Allow minors to directly manage accounts or profiles
Any information related to a minor must be submitted by a parent or legal guardian, or by the Organization with lawful authority.
2. What Information We Collect About Minors
Natty Hatty collects only limited information about a child as required to complete a registration or document, such as:
Child’s name
Child’s date of birth or age group
Program selection (team, camp, clinic, tryout, etc.)
Required waiver or participation details
Medical notes provided voluntarily by the parent or guardian (Natty Hatty does not request these directly)
Associated signature data (parent or guardian signing on behalf of the child)
Natty Hatty does not collect:
Child email addresses
Child phone numbers
Child account logins
Child biometric data
Child location tracking
Child behavioral or advertising data
We do not knowingly collect personal information directly from any child under 13.
3. Parental Consent Is Required
Because all minors participate under the authority of an adult, Natty Hatty requires:
A parent or legal guardian to complete the registration
A parent or legal guardian to submit payment
A parent or legal guardian to sign all documents
A parent or legal guardian to attest authority over the child
Natty Hatty enforces that:
Signature pages identify the adult who is signing
A parent/guardian attestation is collected
Minor acknowledgment signatures are only allowed when configured (e.g., code of conduct), never for liability waivers
Under COPPA, Natty Hatty does not rely on a child’s own consent for any purpose.
4. How We Use Minor Information
Natty Hatty uses minor information only to provide services requested by the parent/guardian or Organization, such as:
Completing a program registration
Processing payments
Linking signed waivers to a participant
Showing program rosters to the Organization
Supporting Organization administration and compliance
Protecting against fraud or unauthorized access
Securely storing signed documents for legal validity
We do not use minor data for:
Marketing
Advertising
Profiling
Selling data
Third-party behavioral tracking
AI/ML training
5. What Information We Share—and With Whom
We share minor information only with the Organization running the program.
For example:
The Organization sees the child’s name
The Organization sees the signed waiver
The Organization receives necessary registration details
Natty Hatty does not share minor information with:
Advertisers
Social media platforms
Data brokers
Other Organizations
Unrelated third parties
Our website’s third-party subprocessors (AWS, Cloudflare, Stripe, Google Analytics, SendGrid) process data only to support platform functionality.
Google Analytics is configured without advertising features and does not track minors individually.
6. COPPA-Required Parental Rights
Parents/guardians have the right to:
Request access to the child’s information
Correct inaccurate information
Request deletion of child information if allowed by law
Withdraw consent from the Organization (not Natty Hatty)
Important:
Deletion requests must be directed to the Organization, not Natty Hatty, because:
Natty Hatty does not own the data
Documents may be legally required for liability, safety, or insurance
Audit trails and signed waivers may be required to remain on file
Natty Hatty cannot delete a signed waiver unless the Organization lawfully instructs us to do so.
7. How We Protect Children’s Data
Natty Hatty uses industry-standard security protocols:
TLS 1.2+ encryption
AES-256 data encryption at rest
Tamper-evident signature hash locking
Secure AWS infrastructure
Cloudflare security layer (WAF + DDoS)
Strict access controls
Immutable audit records
No third-party advertising cookies
We never expose minor data publicly.
8. Organizations’ Responsibilities Under COPPA
Organizations using Natty Hatty must:
Obtain lawful consent
Ensure all child data they collect is COPPA-compliant
Inform parents of their own privacy practices
Maintain required safety and training policies
Ensure only lawful information is collected
Manage COPPA deletion and correction requests
Follow state and national youth-protection laws
Natty Hatty provides this website as a technical tool and does not control how Organizations manage child data.
9. Contact for COPPA or Child Privacy Concerns
For privacy or data-protection questions:
If you wish to request correction or deletion of a child’s data:
Contact the Organization that created the registration or document.