Private roster and consent ledger — every player’s permissions, auditable
The roster is never public or searchable. Every player in the import carries a consent flag, a depiction flag, and a delete-on-request log. Guardians opt in; the default state is no consent. A player whose guardian has not opted in does not appear in any shared gallery or team product — not by cropping, not by blurring, but by exclusion at the engine layer. The consent ledger records who consented, when, and for what purpose. A guardian can withdraw consent at any time; the ledger records the withdrawal and downstream systems are notified. A deletion request is logged at intake and processed within a stated window; completion is confirmed back to the guardian in writing. The private roster import and consent/depiction ledger are built and production-ready.
Roster + consent ledger built · production-ready
Consent-gated team galleries — locked to the team, mapped to the roster
A team gallery is unlocked only for families of players who have active consent on record. A family whose player has no consent sees no gallery — not a blurred gallery, a locked one. Photos are organised by team, season, and event; a family accesses their player’s photos from their own share link, which is revocable. No gallery is publicly accessible, indexable by search engines, or shared across teams. The gallery-to-roster mapping runs at build time: images go into the gallery only for players whose consent is confirmed in the ledger. Unconsented players are excluded before the gallery is assembled. Consent-gated private galleries mapped to the roster are built and production-ready. The parent share link is live. The checkout interface that accepts payment from a family for prints is honest-off.
Consent-gated gallery built · print checkout honest-off
Team photos, team books, and print fulfillment — professional-grade, privacy-first
Youth League Software is built by a company that operates the photography business. That is not a marketing claim; it is the reason the software and the photo service share a consent ledger rather than living in separate databases with a PDF export between them. Team photo day, team books, individual prints, and package orders are all consent-aware from the first shutter click. A team book is assembled only from players whose guardians have consented to the product; an unconsented player does not appear as a blank page or a silhouette, their record is simply not in the book. The branded parent storefront and order management layer are built and production-ready. The checkout interface that accepts payment from a family is honest-off: present in the platform, not enabled for live transactions today.
Storefront + order management built · checkout honest-off
League and club fundraising — the no-skim split engine, exact cent
The fundraising split engine divides gross proceeds with exact-cent precision. The fee is deducted from gross proceeds first, before any split is calculated, and splits are applied to the net remainder. Every party sums to exactly 10,000 basis points. A largest-remainder reconciliation pass ensures the total always equals exactly what came in, minus the fee, with no penny coerced into a platform margin. A league director sees the exact projected distribution before the charge rail runs — there is no platform skim between what a supporter contributes and what the program receives. A split can be configured to go to the league, to a specific team, or proportionally across teams. The split engine is built and production-ready. The charge rail that moves money is honest-off: present in the platform, not enabled for live fundraiser transactions today.
Split engine built · charge rail honest-off
Team and league communications — roster-based, guardian-approved
Messaging in a youth league runs through the guardian, not directly to the player. The platform’s communication layer routes team and league messages to the guardian on record for each player. No message reaches a guardian who has not opted in to communications from the organisation. Opt-in is consent-positive: the default is no message. A guardian can opt out of communications at any time. The communication channel infrastructure and templates are built on the platform. Carrier delivery — the SMS and email gateway integration that delivers messages — is early-access: the configuration layer is present, carrier delivery is not yet enabled for live use. Team and league subscription checkout is also early-access.
Channel infrastructure built · carrier delivery + subscription early-access