Privacy Policy
Last updated: March 14, 2026. This policy explains what personal information Underdog Talents collects, why we collect it, how we use it, and what rights you have over your data.
01 — Who We Are
Data Controller
The data controller for this platform is Services provided by Evandro Bambirra Assessoria, operating as Underdog Talents. We are registered in Brazil under legal entity EVANDRO BARCANTE BRANDAO BAMBIRRA 01567074626, CNPJ 37.728.099/0001-52, located in Belo Horizonte, MG, Brazil.
For users in the European Economic Area, we act as the data controller under the General Data Protection Regulation (GDPR). For users in Brazil, we act as the data controller under the Lei Geral de Proteção de Dados (LGPD). For users in the United States involving children under 13, we comply with the Children's Online Privacy Protection Act (COPPA). California residents have additional rights under the California Consumer Privacy Act (CCPA/CPRA) as described in section 08.
As required by LGPD Article 41, we have designated a data protection contact (encarregado de dados). For all data protection inquiries, requests, and reports — including those from Brazilian regulators — contact us at support@underdogtalents.com.
02 — Data Collection
What Data We Collect
We collect only the data necessary to provide and operate the platform. This includes:
Account Information
Email address, display name, and date of birth. Date of birth is collected solely to determine your age tier and enforce age-appropriate access controls. It is not displayed publicly.
Profile Content
Sport, position, physical stats, goals, academic information, photos, and videos that you choose to add to your athlete profile. This content is displayed on your public profile when publishing is enabled.
Guardian Information (Under-13 accounts)
For accounts involving children under 13, we collect the guardian's email address and their stated relationship to the child (parent, legal guardian). This is required to verify parental consent before account setup is permitted.
Billing Information
Payment processing is handled by Stripe. We do not store credit card numbers or full payment card details on our servers. We retain subscription status, billing cycle, and transaction records for legal and accounting purposes.
Usage Data
Session logs, page interactions, and feature usage collected to operate the platform, detect abuse, and improve the product. This data is aggregated and anonymized where possible.
Communications
Messages sent to our support team and the content of those messages. We retain these to resolve issues and maintain a record of support interactions.
03 — Children's Privacy
Minors and Parental Consent
Protecting the privacy of children is a priority. We comply with COPPA (USA), GDPR Article 8 (EU), and LGPD (Brazil) regarding minors.
Under 13
We do not knowingly collect personal data from children under 13 without verifiable parental consent. Children cannot self-register. A parent or legal guardian must initiate and authorize account setup through our guardian verification email flow. If we discover an account was created by a child under 13 without proper consent, we will immediately suspend the account and delete the data.
Ages 13–17
Athletes between 13 and 17 may create an account and build a profile. Their profile cannot be published publicly until a parent or guardian provides explicit in-app consent. We do not use data from users under 18 for advertising or behavioral marketing.
Parental Rights
Parents and guardians may at any time request to review, correct, update, or delete their child's personal information by contacting us at support@underdogtalents.com. We will process these requests within 30 days.
04 — How We Use Data
How We Use Your Information
We use personal data only for the following purposes:
- Creating and operating your account and athlete profile
- Enforcing age restrictions and managing parental consent flows
- Processing subscription payments and sending billing confirmations
- Sending transactional emails such as guardian invitations and account confirmations
- Preventing fraud, abuse, and unauthorized access
- Improving and developing the platform using aggregated, anonymized usage data
- Responding to support requests and resolving account issues
We do not sell personal data to third parties. We do not share athlete profiles with recruiters or scouts without the athlete's explicit opt-in through the platform's public visibility settings.
05 — Legal Basis (GDPR & LGPD)
Lawful Basis for Processing
For users in the European Economic Area, we process personal data under the following lawful bases as defined by GDPR Article 6:
Contract Performance (Art. 6(1)(b))
Processing account data, profile content, and billing data is necessary to deliver the service you subscribed to.
Legal Obligation (Art. 6(1)(c))
Age verification and guardian consent are required by COPPA, GDPR Article 8, and LGPD. Billing record retention is required by tax and accounting law.
Legitimate Interests (Art. 6(1)(f))
Security monitoring, fraud prevention, and abuse detection are processed on the basis of our legitimate interests in protecting the platform and its users.
Consent (Art. 6(1)(a))
Analytics and marketing cookies are processed only with your consent, which you can grant or revoke at any time through cookie preferences.
For users in Brazil, we process personal data under the following lawful bases as defined by LGPD Article 7:
Consent (Art. 7, I)
Analytics and marketing cookies, and any optional communications, are processed only with your freely given, informed consent. You may withdraw consent at any time.
Legal Obligation (Art. 7, II)
Age verification, guardian consent records, and billing record retention are required by applicable Brazilian law, including the CDC, LGPD, and tax regulations.
Contract Performance (Art. 7, V)
Account data, profile content, and billing data are processed to fulfill the service contract between you and Underdog Talents.
Legitimate Interests (Art. 7, IX)
Security monitoring, fraud prevention, and abuse detection are carried out on the basis of our legitimate interests, provided these do not override the data subject's fundamental rights.
06 — Third Parties
Data Sharing
We share data only with service providers necessary to operate the platform:
- Stripe — payment processing. Subject to Stripe's privacy policy.
- Supabase — database and authentication hosting. Data is stored in secure cloud infrastructure.
- Analytics providers — only with your explicit consent via cookie preferences.
We do not sell, rent, or trade your personal data. We do not share data with advertisers or data brokers.
07 — Cookies
Cookies and Tracking
We use three categories of cookies:
Necessary
Required for login sessions and platform security. These cannot be disabled.
Analytics
Help us understand how users interact with the platform. Only active with your consent.
Marketing
Enable embedded content (such as video previews) and track campaign performance. Only active with your consent. You can change your preferences at any time.
For full details, see our Cookie Policy.
08 — Your Rights
Your Data Rights
Depending on your location, you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Correction — request updates to inaccurate or incomplete data
- Deletion — request that we delete your personal data (right to erasure)
- Portability — receive your data in a structured, machine-readable format (GDPR/LGPD)
- Withdraw consent — revoke consent for analytics or marketing cookies at any time
- Object — object to processing based on legitimate interests
California Residents (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know — request disclosure of the categories and specific pieces of personal information we have collected about you, including the sources, purposes, and third parties it is shared with
- Right to Delete — request deletion of personal information we have collected from you, subject to certain legal exceptions
- Right to Correct — request correction of inaccurate personal information we maintain about you
- Right to Opt-Out of Sale or Sharing — we do not sell or share personal information for cross-context behavioral advertising. No opt-out action is required, but you may contact us to confirm this
- Right to Limit Sensitive Personal Information — you may request that we limit the use of sensitive personal information (such as government IDs or precise geolocation) to only what is necessary to provide the service
- Right to Non-Discrimination — we will not discriminate against you for exercising any of your CCPA/CPRA rights
EU users may lodge a complaint with their national data protection authority. Brazilian users may contact the Autoridade Nacional de Proteção de Dados (ANPD). To exercise any of these rights, contact us at support@underdogtalents.com.
09 — Retention
How Long We Keep Your Data
Account and profile data is retained while your account is active. After account deletion, personal data is removed from our systems within 30 days, except where retention is legally required.
Payment and billing records are retained for up to 7 years as required by Brazilian tax law and accounting regulations. Guardian consent records are retained for the duration of a minor's active account and for up to 2 years afterward to support compliance audits.
10 — Security
How We Protect Your Data
We use encryption in transit (TLS) for all data transfers, row-level access controls to isolate user data, and Supabase's secure cloud infrastructure. Access to personal data is restricted to team members who require it to operate the service.
No system is completely secure. If you believe your account has been compromised, contact us immediately at support@underdogtalents.com. In the event of a data breach affecting your rights, we will notify you as required by applicable law.
11 — International Transfers
International Data Transfers
Underdog Talents is operated from Brazil. Your data is processed and stored using Supabase and Stripe, whose infrastructure is hosted in the United States and other jurisdictions. By using the platform, you understand that your personal data may be transferred to and processed in countries outside your own, including countries that may have different data protection standards.
For users in the European Economic Area: your data is transferred both to Brazil (our operating jurisdiction, where the data controller is located) and to the United States (where Supabase and Stripe infrastructure is hosted). Neither Brazil nor the US has a general EU adequacy decision in place. These transfers are carried out under GDPR Chapter V, relying on Standard Contractual Clauses (SCCs) and other appropriate safeguards. Supabase and Stripe maintain their own GDPR-compliant data processing agreements. You may request information about the specific transfer mechanisms in place by contacting us at support@underdogtalents.com.
12 — Updates
Changes to This Policy
We may update this Privacy Policy when our practices change or when required by law. Material changes will be communicated to registered users via email or an in-app notice at least 14 days before taking effect. The "last updated" date at the top of this page reflects the most recent revision.
13 — Contact
Privacy Requests and Contact
For any privacy-related requests, data subject rights, or questions about this policy, contact us at support@underdogtalents.com. We respond within 48 hours for general inquiries and within 30 days for formal data rights requests.
See also our Terms of Service and Cookie Policy.
