Back to Home

Privacy Policy

Last updated: March 14, 2026. This policy explains what personal information Underdog Talents collects, why we collect it, how we use it, and what rights you have over your data.

01 — Who We Are

Data Controller

The data controller for this platform is Services provided by Evandro Bambirra Assessoria, operating as Underdog Talents. We are registered in Brazil under legal entity EVANDRO BARCANTE BRANDAO BAMBIRRA 01567074626, CNPJ 37.728.099/0001-52, located in Belo Horizonte, MG, Brazil.

For users in the European Economic Area, we act as the data controller under the General Data Protection Regulation (GDPR). For users in Brazil, we act as the data controller under the Lei Geral de Proteção de Dados (LGPD). For users in the United States involving children under 13, we comply with the Children's Online Privacy Protection Act (COPPA). California residents have additional rights under the California Consumer Privacy Act (CCPA/CPRA) as described in section 08.

As required by LGPD Article 41, we have designated a data protection contact (encarregado de dados). For all data protection inquiries, requests, and reports — including those from Brazilian regulators — contact us at support@underdogtalents.com.

02 — Data Collection

What Data We Collect

We collect only the data necessary to provide and operate the platform. This includes:

Account Information

Email address, display name, and date of birth. Date of birth is collected solely to determine your age tier and enforce age-appropriate access controls. It is not displayed publicly.

Profile Content

Sport, position, physical stats, goals, academic information, photos, and videos that you choose to add to your athlete profile. This content is displayed on your public profile when publishing is enabled.

Guardian Information (Under-13 accounts)

For accounts involving children under 13, we collect the guardian's email address and their stated relationship to the child (parent, legal guardian). This is required to verify parental consent before account setup is permitted.

Billing Information

Payment processing is handled by Stripe. We do not store credit card numbers or full payment card details on our servers. We retain subscription status, billing cycle, and transaction records for legal and accounting purposes.

Usage Data

Session logs, page interactions, and feature usage collected to operate the platform, detect abuse, and improve the product. This data is aggregated and anonymized where possible.

Communications

Messages sent to our support team and the content of those messages. We retain these to resolve issues and maintain a record of support interactions.

03 — Children's Privacy

Minors and Parental Consent

Protecting the privacy of children is a priority. We comply with COPPA (USA), GDPR Article 8 (EU), and LGPD (Brazil) regarding minors.

Under 13

We do not knowingly collect personal data from children under 13 without verifiable parental consent. Children cannot self-register. A parent or legal guardian must initiate and authorize account setup through our guardian verification email flow. If we discover an account was created by a child under 13 without proper consent, we will immediately suspend the account and delete the data.

Ages 13–17

Athletes between 13 and 17 may create an account and build a profile. Their profile cannot be published publicly until a parent or guardian provides explicit in-app consent. We do not use data from users under 18 for advertising or behavioral marketing.

Parental Rights

Parents and guardians may at any time request to review, correct, update, or delete their child's personal information by contacting us at support@underdogtalents.com. We will process these requests within 30 days.

04 — How We Use Data

How We Use Your Information

We use personal data only for the following purposes:

  • Creating and operating your account and athlete profile
  • Enforcing age restrictions and managing parental consent flows
  • Processing subscription payments and sending billing confirmations
  • Sending transactional emails such as guardian invitations and account confirmations
  • Preventing fraud, abuse, and unauthorized access
  • Improving and developing the platform using aggregated, anonymized usage data
  • Responding to support requests and resolving account issues

We do not sell personal data to third parties. We do not share athlete profiles with recruiters or scouts without the athlete's explicit opt-in through the platform's public visibility settings.

05 — Legal Basis (GDPR & LGPD)

Lawful Basis for Processing

For users in the European Economic Area, we process personal data under the following lawful bases as defined by GDPR Article 6:

Contract Performance (Art. 6(1)(b))

Processing account data, profile content, and billing data is necessary to deliver the service you subscribed to.

Legal Obligation (Art. 6(1)(c))

Age verification and guardian consent are required by COPPA, GDPR Article 8, and LGPD. Billing record retention is required by tax and accounting law.

Legitimate Interests (Art. 6(1)(f))

Security monitoring, fraud prevention, and abuse detection are processed on the basis of our legitimate interests in protecting the platform and its users.

Consent (Art. 6(1)(a))

Analytics and marketing cookies are processed only with your consent, which you can grant or revoke at any time through cookie preferences.

For users in Brazil, we process personal data under the following lawful bases as defined by LGPD Article 7:

Consent (Art. 7, I)

Analytics and marketing cookies, and any optional communications, are processed only with your freely given, informed consent. You may withdraw consent at any time.

Legal Obligation (Art. 7, II)

Age verification, guardian consent records, and billing record retention are required by applicable Brazilian law, including the CDC, LGPD, and tax regulations.

Contract Performance (Art. 7, V)

Account data, profile content, and billing data are processed to fulfill the service contract between you and Underdog Talents.

Legitimate Interests (Art. 7, IX)

Security monitoring, fraud prevention, and abuse detection are carried out on the basis of our legitimate interests, provided these do not override the data subject's fundamental rights.

06 — Third Parties

Data Sharing

We share data only with service providers necessary to operate the platform:

  • Stripe — payment processing. Subject to Stripe's privacy policy.
  • Supabase — database and authentication hosting. Data is stored in secure cloud infrastructure.
  • Analytics providers — only with your explicit consent via cookie preferences.

We do not sell, rent, or trade your personal data. We do not share data with advertisers or data brokers.

07 — Cookies

Cookies and Tracking

We use three categories of cookies:

Necessary

Required for login sessions and platform security. These cannot be disabled.

Analytics

Help us understand how users interact with the platform. Only active with your consent.

Marketing

Enable embedded content (such as video previews) and track campaign performance. Only active with your consent. You can change your preferences at any time.

For full details, see our Cookie Policy.

08 — Your Rights

Your Data Rights

Depending on your location, you have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you
  • Correction — request updates to inaccurate or incomplete data
  • Deletion — request that we delete your personal data (right to erasure)
  • Portability — receive your data in a structured, machine-readable format (GDPR/LGPD)
  • Withdraw consent — revoke consent for analytics or marketing cookies at any time
  • Object — object to processing based on legitimate interests

California Residents (CCPA/CPRA)

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know — request disclosure of the categories and specific pieces of personal information we have collected about you, including the sources, purposes, and third parties it is shared with
  • Right to Delete — request deletion of personal information we have collected from you, subject to certain legal exceptions
  • Right to Correct — request correction of inaccurate personal information we maintain about you
  • Right to Opt-Out of Sale or Sharing — we do not sell or share personal information for cross-context behavioral advertising. No opt-out action is required, but you may contact us to confirm this
  • Right to Limit Sensitive Personal Information — you may request that we limit the use of sensitive personal information (such as government IDs or precise geolocation) to only what is necessary to provide the service
  • Right to Non-Discrimination — we will not discriminate against you for exercising any of your CCPA/CPRA rights

EU users may lodge a complaint with their national data protection authority. Brazilian users may contact the Autoridade Nacional de Proteção de Dados (ANPD). To exercise any of these rights, contact us at support@underdogtalents.com.

09 — Retention

How Long We Keep Your Data

Account and profile data is retained while your account is active. After account deletion, personal data is removed from our systems within 30 days, except where retention is legally required.

Payment and billing records are retained for up to 7 years as required by Brazilian tax law and accounting regulations. Guardian consent records are retained for the duration of a minor's active account and for up to 2 years afterward to support compliance audits.

10 — Security

How We Protect Your Data

We use encryption in transit (TLS) for all data transfers, row-level access controls to isolate user data, and Supabase's secure cloud infrastructure. Access to personal data is restricted to team members who require it to operate the service.

No system is completely secure. If you believe your account has been compromised, contact us immediately at support@underdogtalents.com. In the event of a data breach affecting your rights, we will notify you as required by applicable law.

11 — International Transfers

International Data Transfers

Underdog Talents is operated from Brazil. Your data is processed and stored using Supabase and Stripe, whose infrastructure is hosted in the United States and other jurisdictions. By using the platform, you understand that your personal data may be transferred to and processed in countries outside your own, including countries that may have different data protection standards.

For users in the European Economic Area: your data is transferred both to Brazil (our operating jurisdiction, where the data controller is located) and to the United States (where Supabase and Stripe infrastructure is hosted). Neither Brazil nor the US has a general EU adequacy decision in place. These transfers are carried out under GDPR Chapter V, relying on Standard Contractual Clauses (SCCs) and other appropriate safeguards. Supabase and Stripe maintain their own GDPR-compliant data processing agreements. You may request information about the specific transfer mechanisms in place by contacting us at support@underdogtalents.com.

12 — Updates

Changes to This Policy

We may update this Privacy Policy when our practices change or when required by law. Material changes will be communicated to registered users via email or an in-app notice at least 14 days before taking effect. The "last updated" date at the top of this page reflects the most recent revision.

13 — Contact

Privacy Requests and Contact

For any privacy-related requests, data subject rights, or questions about this policy, contact us at support@underdogtalents.com. We respond within 48 hours for general inquiries and within 30 days for formal data rights requests.

See also our Terms of Service and Cookie Policy.