Privacy Policy
Last updated: August 27, 2026
1. Introduction
Sideline Captions LLC (“Sideline Captions,” “we,” “our,” or “us”) respects your privacy and is committed to protecting your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our website, application, and related services (collectively, the “Service”).
Regional supplements: if you are in the EEA, UK, or Switzerland, see our GDPR Privacy Notice. If you are a California resident, see our California Privacy Notice (CCPA). To opt out of sale/sharing, manage cookies, or submit a privacy request, visit Your Privacy Choices.
By using the Service, you consent to the practices described in this Policy.
2. Information We Collect
2.1 Contact and Support Information
When you contact us or request support, we collect information such as your name, email address, message content, and related details to respond to your inquiry.
When you use the optional on-site chat widget, we process your name and email (if you provide them), your messages, any images you attach, a conversation identifier stored in your browser (for example in local storage), the page you were on, and related technical metadata needed to operate the chat. Chat images are stored in a dedicated storage bucket so they can be displayed in the conversation. Anyone who has the image URL can view that file. The chat is staffed by our team; it is not an automated AI chatbot.
2.2 Purchase and License Information
When you purchase a Sideline Captions license, we collect:
- Email address
- License key and referral code (if applicable)
- Payment details provided via Stripe (we do not store credit card numbers)
- Transaction identifiers, amount, and receipt URLs
2.3 Usage and Analytics Data
We automatically collect certain data to improve performance and reliability, including:
- Application performance metrics from the desktop app (e.g., number of images processed, success/failure rates)
- Basic technical data such as browser type, operating system, and app version
- Website and marketing analytics via Google Analytics 4 on our domains (page views, events such as form submissions, and related usage data)
- Conversion and advertising measurement via the Meta Pixel on select website and landing pages
- Application performance monitoring via New Relic on Sideline Live web properties (technical diagnostics; we may associate an internal user identifier with monitoring data to troubleshoot issues)
- Browser local storage and session storage on Sideline Live (for example to keep you signed in and remember UI preferences)
- When a Sideline Live customer configures a Google Analytics 4 measurement ID for a shared gallery, that third-party analytics service may collect data from visitors to the gallery page under the customer’s configuration (in addition to our own analytics where loaded)
2.4 Caption and Metadata Processing
When you use Sideline Captions to generate captions, a resized preview of each photo is sent to our AI providers so they can write the caption. We may also retain that preview and related records for service functionality, debugging, and quality assurance. This data is never sold or used for advertising.
For captioning we may collect and store:
- The generated caption text
- A resized JPEG preview of the image sent to the AI provider (not your original full-resolution file)
- Original filename
- Sport, caption style, processing mode, app version, and model used
- License code (to associate the job with your account)
- Processing time and confidence scores
- Detected jersey numbers, jersey colors, team names, and player-name candidates
- Selected player name, if you choose one
- Whether an XMP sidecar was present
- IPTC/XMP fields already on the file, when present: copyright, credit, city, state, country, location, event, and date created
- The original XMP sidecar text, when present
We do not keep your original full-resolution photo from desktop captioning on our servers. Full-resolution files you upload to Sideline Live galleries are stored separately as described in Section 2.5. Files you send from your Mac to your own FTP, SFTP, or Dropbox destination are not stored on our servers (Section 2.9).
2.5 Sideline Live Gallery Data
When you use Sideline Live, we collect and store:
- Gallery metadata (name, description, creation date, settings)
- Images uploaded via FTP (full-resolution files and thumbnails)
- Image metadata (EXIF data, filename, upload timestamp)
- FTP credentials (username and encrypted password)
- FTP session logs (connection times, IP addresses, upload activity)
- Gallery access logs (views, downloads, visitor IP addresses)
- Gallery passwords (encrypted)
2.6 Payment and Transaction Data (Sideline Live Sales)
When you enable payment features in Sideline Live to sell images to customers, we collect and process:
- Photographer Data: Email address, Stripe Connect account ID, payout status, and transaction history
- Customer Data: Email address, name (if provided), purchase history, and order details
- Transaction Metadata: Order ID, transaction amount, platform fees, Stripe fees, payment status, timestamps, and receipt URLs
- Financial Information (via Stripe): Customer payment information (credit card details, billing address) is collected and processed directly by Stripe. We never receive or store full credit card numbers, bank account details, or other sensitive financial information
All payment processing is handled through Stripe Connect. Photographers must create a Stripe Connect account to receive payouts, and all sensitive financial data (bank accounts, tax IDs, etc.) is stored exclusively by Stripe, not by Sideline Captions LLC.
2.7 Sideline Live Team Data
When you use or administer a Sideline Live Team, we collect and store:
- Team name and settings, owner email, plan type, seat count, and subscription status
- For each member: email, role (owner or member), invite and join timestamps, and (for invites) invite status and expiry
We do not sell this data and use it only to provide the service and enforce access.
2.8 Roster Database Access
When you use the roster generator service (which creates Photo Mechanic code replacement files), we collect:
- Email address for authentication
- Search queries and team selections
- Downloaded roster files (for rate limiting and analytics)
- Access timestamps and usage patterns
Note: The roster data itself (player names, numbers, positions) is publicly available information. We do not collect or store any personal information about the athletes beyond what is publicly available.
2.9 Desktop Outbound Photo Upload (FTP, SFTP, and Dropbox)
When you use the desktop application’s optional outbound upload feature to send approved photos from your Mac to a destination you configure, we process:
- Destination settings: Connection labels, protocol (FTP or SFTP), hostnames, ports, usernames, remote paths, and related configuration stored locally on your device
- Credentials: FTP and SFTP passwords stored in your Mac’s secure Keychain (not in plain-text app settings). Dropbox OAuth access and refresh tokens stored in Keychain after you authorize the app
- Dropbox account metadata: Account identifier, display name or email, and the folder path you select for uploads (used to show your connected account and destination in the app)
- Upload activity: Local records of which files were queued, succeeded, or failed, including filenames and timestamps (stored on your device to show upload status in the app)
- Transferred files: Original image files (and matching XMP sidecar files for RAW images, when present) that you choose to upload are transmitted directly from your Mac to the destination you select
Sideline Captions does not receive, store, or host the full-resolution files you upload through this feature on our servers. Upload traffic goes from your device to your FTP/SFTP server or to Dropbox’s services. This outbound upload feature is separate from Sideline Live gallery hosting (Section 2.5), which uses FTP credentials and storage on our infrastructure.
2.10 Sideline Wire (Remote FTP/SFTP Auto-Download)
When you use Sideline Wire to monitor a remote FTP or SFTP server and download new files to a folder on your Mac, we process:
- Connection settings: Server hostname, port, protocol, username, and local download folder (stored locally on your device)
- Credentials: FTP/SFTP password stored in your Mac’s secure Keychain
- Download activity: Local logs of connection attempts, file listings, and downloaded filenames (stored on your device for status display and troubleshooting)
Files downloaded through Sideline Wire are saved to the folder you choose on your Mac. We do not upload those files to Sideline Captions servers as part of this feature.
3. How We Use Your Information
We use collected information to:
- Provide, operate, and improve the Service
- Process your purchase and deliver license information
- Authenticate users and prevent fraud
- Respond to customer inquiries and support requests
- Analyze trends and usage for product improvement
- Store and serve gallery images via Sideline Live
- Manage Sideline Live Teams (members, roles, seat count, invites) and enforce access
- Generate thumbnails and optimized versions of gallery images
- Monitor FTP activity to prevent abuse and ensure service reliability
- Provide access to generate Photo Mechanic code replacement files
- Track gallery views and downloads for analytics
- Process payments for image sales through Sideline Live
- Calculate and distribute platform fees and payouts to photographers
- Facilitate customer purchases and deliver digital downloads
- Send transactional emails related to purchases (order confirmations, download links, receipts)
- Maintain transaction records for tax and legal compliance
- Enforce rate limits and prevent service abuse
- Transmit approved photos from your Mac to FTP, SFTP, or Dropbox destinations you configure
- Authenticate and maintain Dropbox connections for outbound uploads when you authorize them
- Monitor remote FTP/SFTP servers and download new files through Sideline Wire to your local folder
- Comply with legal and regulatory obligations
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases:
- Performance of a contract (to provide access to purchased software)
- Legitimate interests (to improve and maintain the Service)
- Consent (for analytics and cookies)
- Legal obligations (to comply with applicable law or enforce agreements)
5. Third-Party Services
We use trusted third parties to process and store data securely:
5.1 Stripe and Stripe Connect
Handles all payment transactions for subscription purchases and Sideline Live image sales. When you use payment features in Sideline Live:
- Photographers: Must create a Stripe Connect account to receive payouts. Stripe collects and stores your bank account information, tax identification, and other financial details directly. We never receive or store this sensitive information.
- Customers: Payment information (credit card details, billing addresses) is processed and stored by Stripe. Sideline never receives full card details or other sensitive financial information.
- Payout Processing: Stripe controls the payout schedule (typically 3-9 business days) and transfers funds directly to photographers' bank accounts.
Stripe is PCI-DSS Level 1 certified and maintains industry-leading security standards. Stripe Privacy Policy | Stripe Connect Terms
5.2 Google Gemini
We use Google's Gemini API to generate captions from user-provided content. Data sent to Google Gemini is processed in accordance with their privacy policy and is not used to train their models. Google Gemini API Terms | Google Privacy Policy
5.3 OpenAI
We use the OpenAI API to generate captions from user-provided content. Data sent to OpenAI is processed in accordance with their privacy policy and is not used to train their models. OpenAI Privacy Policy
5.4 Google Analytics, Meta Pixel, and related measurement
We use Google Analytics 4 on many of our web pages to understand how the site and certain in-page actions are used. Google may collect identifiers and usage data subject to Google’s Privacy Policy. We use Meta Pixel on some marketing and conversion pages to measure ad effectiveness and site interactions; Meta may use data for measurement and, in accordance with Meta’s policies, for advertising-related purposes. See Meta’s Privacy Policy. Where Sideline Live gallery pages load a customer-provided Google Analytics 4 property, that processing occurs under the photographer’s configuration and Google’s terms.
5.5 Google reCAPTCHA
We use Google reCAPTCHA on forms (such as contact and sign-in flows) to reduce spam and abuse. Google may collect hardware and software information and other data as described in Google’s terms. Google Privacy Policy
5.6 New Relic
We use New Relic for performance monitoring and error diagnostics on Sideline Live and related web apps. New Relic may process IP addresses, device and browser data, and technical telemetry. We may set an internal user identifier in monitoring tools to investigate issues. New Relic Privacy Notice
5.7 Supabase
Stores license, analytics, gallery metadata, transaction data, and support chat–related data (such as conversation records used for the website chat widget) in secure cloud infrastructure. Supabase Privacy Policy
5.8 Resend
Sends transactional emails like license keys, download links, gallery notifications, order confirmations, order download links, and purchase receipts. Resend Privacy Policy
5.9 DigitalOcean
Provides cloud-based VPS servers, web hosting, and DigitalOcean Spaces object storage for Sideline Live gallery images (full-resolution files, previews, and thumbnails). Gallery objects are stored as private files and served with time-limited signed URLs. DigitalOcean Privacy Policy
5.10 Dropbox
When you connect a Dropbox account for outbound photo uploads, the desktop app uses Dropbox’s OAuth service and API to authenticate you and upload files you approve to the folder you select. Dropbox receives the files and account-related data needed to complete those uploads. We do not store your Dropbox password. Dropbox Privacy Policy | Dropbox Terms of Service
5.11 User-Configured FTP and SFTP Servers
When you upload photos via FTP or SFTP, or download files through Sideline Wire, your device connects directly to servers you specify. Those servers (and their operators) receive connection data, credentials you provide, and the files transferred. We do not control those servers and are not responsible for their privacy or security practices.
5.12 Sentry
We use Sentry for application error monitoring on our APIs and apps. Sentry may process technical diagnostics such as error messages, stack traces, device or browser data, and (when available) an account or request identifier needed to investigate failures. Sentry Privacy Policy
5.13 Vercel
Hosts our API and related backend functions. Vercel may process request logs, IP addresses, and other technical data as part of providing that infrastructure. Vercel Privacy Policy
5.14 Apple
If you subscribe or purchase through the Apple App Store, Apple processes your payment and App Store account information. We receive subscription status from Apple; we do not receive your full payment card details. Apple Privacy Policy
5.15 Cal.com
If you book a call through the scheduling link on our website, Cal.com processes your name, email, and meeting details to complete the booking. Cal.com Privacy Policy
6. Data Retention
We retain data only as long as necessary for operational or legal purposes. Examples include:
- License and payment records: Retained indefinitely for proof of purchase and support.
- Analytics and diagnostic data: Retained for up to 12 months and aggregated for performance monitoring.
- Caption analytics and resized previews: Generated captions, related metadata (Section 2.4), and resized preview images are retained for quality assurance, debugging, and product improvement. They are deleted when you request deletion of your data, and we periodically remove older preview files. Original full-resolution files from desktop captioning are not stored on our servers.
- Website chat messages and chat images: Retained so we can continue a conversation and follow up on support requests. Chat images are stored so they can be shown in the thread. You may request deletion.
- Transaction and sales data: Retained indefinitely for tax compliance, financial reporting, and dispute resolution. This includes order details, payment amounts, platform fees, and payout records.
- Sideline Live gallery images: Retained as long as your subscription is active and you choose to keep them. Deleted galleries are permanently removed immediately upon deletion. If your subscription is cancelled, galleries are deleted after 30 days. If your subscription lapses due to payment failure, galleries are deleted after 30 days unless reactivated.
- Sideline Live FTP session logs: Retained for up to 90 days for security and troubleshooting purposes.
- Desktop outbound upload and Sideline Wire data: Destination settings, credentials in Keychain, upload/download status, and local activity logs remain on your device until you remove them, disconnect an account, or uninstall the app.
- Gallery access logs: Retained for up to 90 days for analytics and security.
- Customer purchase information: Email addresses and order history for customers who purchase images through Sideline Live are retained for up to 7 years for tax and legal compliance.
- Support correspondence: Retained up to 90 days for issue resolution.
- Sideline Live Team data: Team and member records are retained while the team is active and for a reasonable period after cancellation for support and compliance.
7. Data Sharing and Disclosure
We do not sell or rent personal data for money. We may use analytics and advertising measurement tools (such as Google Analytics and Meta Pixel) on some pages; under California law, some of that activity may count as “sharing.” You can opt out anytime on Your Privacy Choices. We may disclose limited information only:
- To service providers and partners who perform services on our behalf (such as Stripe for payment processing)
- To comply with legal obligations or government requests
- To enforce our Terms of Service or protect our rights, property, or safety
- In connection with payment processing: We share transaction data with Stripe to facilitate payments and payouts
- With photographers: When a customer purchases an image, we share the customer's email address and order details with the photographer for fulfillment and customer service purposes
- With Dropbox: When you use outbound Dropbox uploads, files and related API data are sent to Dropbox to complete the upload at your direction
- With FTP/SFTP servers you configure: Files and credentials are sent directly from your device to those servers when you use outbound upload or Sideline Wire
We do not sell Team membership or contact data.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we ensure that appropriate safeguards are in place when transferring your personal data internationally, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Reliance on our service providers' compliance with applicable data protection frameworks
- Adequacy decisions by the European Commission where applicable
By using our Service, you understand that your information may be transferred internationally as described above.
9. Cookies and Tracking Technologies
We use cookies, local storage, session storage, and similar technologies for analytics, security, and site functionality:
- Analytics and measurement: Third-party scripts (such as Google Analytics and Meta Pixel) may set cookies or use similar storage to attribute traffic and measure conversions.
- Functional storage: We use local and session storage (including on Sideline Live) to maintain login sessions and preferences.
- Security: Google reCAPTCHA may set cookies or read device data to prevent spam and abuse.
You can control cookies through your browser settings. Disabling cookies or storage may affect site functionality.
Do Not Track Signals: Our Service does not currently respond to legacy “Do Not Track” (DNT) signals. We do honor Global Privacy Control (GPC) signals as an opt-out of sale/sharing (analytics and advertising pixels stay off). Manage preferences anytime on Your Privacy Choices or via Cookie settings in the footer.
10. Data Security
We use reasonable administrative, technical, and physical safeguards to protect personal information, including:
- Encrypted transmission of data over HTTPS/TLS
- Encrypted storage of FTP passwords for Sideline Live galleries on our servers
- macOS Keychain storage for desktop FTP/SFTP passwords, Dropbox OAuth tokens, and related outbound-upload credentials on your device
- Encrypted storage of gallery passwords
- All payment processing handled through PCI-DSS Level 1 certified Stripe infrastructure
- We never store credit card numbers, CVV codes, or full bank account details
- Stripe Connect securely stores all sensitive financial information (bank accounts, tax IDs) outside of our systems
- Regular security updates and patches to server infrastructure
- Access controls and authentication for all administrative functions
While we strive to protect your data, no method of transmission over the Internet is entirely secure, and we cannot guarantee absolute protection. You are responsible for maintaining the security of your FTP and SFTP credentials (including for Sideline Live, outbound uploads, and Sideline Wire), Dropbox account access, gallery passwords, license keys, and Stripe Connect account credentials.
Security Breach Notification: In the event of a data breach that compromises your personal information, we will notify affected users within 72 hours of discovering the breach via email to the address associated with your account. We will also notify relevant supervisory authorities as required by applicable law.
11. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Right to Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Right to Restrict Processing: Request that we limit how we use your data
- Right to Data Portability: Receive your data in a structured, commonly used format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for processing that requires it (without affecting prior lawful processing)
To exercise these rights, submit a request on Your Privacy Choices. We aim to respond within 45 days (or sooner where required by law).
Additional detail for EEA, UK, and Swiss users: see our GDPR Privacy Notice. For California residents: see our California Privacy Notice.
Supervisory Authority: If you are located in the EEA or UK, you have the right to lodge a complaint with your local data protection authority if you believe we have not handled your personal data appropriately.
Automated Decision-Making: We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
12. Children's Privacy
The Service is not directed to children under 13 (or under 16 where that age applies under local law, including in parts of the EEA/UK). We do not knowingly collect personal data from children under those ages. If you believe a child has provided personal data, please tell us through Your Privacy Choices and we will remove it promptly.
13. Additional Information for Specific Features
13.1 Sideline Live Gallery Sharing
When you share a Sideline Live gallery link:
- Anyone with the gallery link and password can view and download images
- We log IP addresses of gallery visitors for security and analytics purposes
- Gallery viewing data is associated with your account, not with individual viewers
- You control who has access by managing gallery passwords and links
- Deleted galleries and their viewing logs are immediately and permanently removed upon gallery deletion
13.2 Payment Processing for Image Sales
When photographers enable payment features in Sideline Live:
- Customer Data: When a customer purchases an image, we collect their email address, name (if provided), and order details. This information is shared with the photographer for order fulfillment.
- Payment Information: All payment card data is collected and processed directly by Stripe. We never see or store full credit card numbers, CVV codes, or other sensitive payment information.
- Photographer Payouts: We store transaction metadata (amounts, fees, payout status) but do not have access to photographers' bank account details, which are stored exclusively by Stripe.
- Transaction History: Both photographers and customers can view their transaction history through their respective accounts or Stripe Dashboard.
- Tax Reporting: Photographers are responsible for their own tax reporting. We do not issue 1099 forms unless legally required based on transaction volume thresholds.
13.3 Stripe Connect Accounts
When you create a Stripe Connect account to receive payouts:
- Stripe collects and stores your banking information, tax identification number, date of birth, address, and other identity verification details
- This information is stored exclusively by Stripe and is not accessible to Sideline Captions
- We only receive a Stripe Connect account ID that links your Sideline Captions account to your Stripe account
- Your relationship with Stripe is governed by Stripe's Terms of Service and Privacy Policy
- You can manage your Stripe account information directly through the Stripe Dashboard
13.4 Desktop Outbound Photo Upload
When you upload approved photos from the desktop app to FTP, SFTP, or Dropbox:
- Only photos you explicitly select and approve for upload are transmitted
- Original files are sent as-is (JPEG files as JPEG; RAW files with their matching XMP sidecar when available)
- Uploads originate from your Mac and are not routed through Sideline Captions servers for storage
- You can disconnect Dropbox or remove saved FTP/SFTP destinations at any time; disconnecting removes OAuth tokens or Keychain credentials associated with that destination from your device
- Upload success and failure status is stored locally on your device and may be cleared when you re-caption or delete photos
13.5 Sideline Wire
When you use Sideline Wire to auto-download from a remote FTP or SFTP server:
- Downloaded files are saved only to the local folder you designate
- Connection credentials remain on your device in Keychain until you remove them
- We do not retain copies of downloaded images on our servers
- Diagnostic information about connections may be included if you choose to send feedback from the app (passwords are never included)
13.6 What We Delete for Uploads
Depending on how you send us photos:
- Desktop AI captioning: We do not store your original full-resolution file. We may keep a resized preview, the generated caption, and the metadata listed in Section 2.4 for quality assurance until you request deletion or we remove older previews.
- Sideline Live galleries: Full-resolution images and thumbnails stay while the gallery exists and your subscription is active. Deleting a gallery removes its images immediately. After a cancelled or lapsed subscription, galleries are deleted after a 30-day grace period (Section 6).
- Outbound FTP, SFTP, or Dropbox from your Mac: Files go from your device to the destination you choose. We do not keep a copy on Sideline servers.
- Sideline Wire downloads: Files are saved only to the folder you choose on your Mac. We do not keep a copy on Sideline servers.
- Website chat image attachments: Stored so they can be displayed in the conversation until you request deletion or the conversation is removed.
14. Changes to This Policy
We may update this Privacy Policy periodically. Updates take effect immediately upon posting, as indicated by the “Last updated” date above. Continued use of the Service constitutes acceptance of the revised Policy.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
- Privacy requests: Your Privacy Choices (access, delete, correct, Do Not Sell or Share)
- General contact: Use the contact form on our website
- Website: sidelinecaptions.com