Privacy
Privacy Policy
Last updated September 14, 2026
This Privacy Policy describes how JM Photography LLC (“we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with Lineup, our desktop application for youth sports photography businesses, including its optional Coordinator Portal, Parent Verification, and other relay features; this website; Roll Call, our hosted barcode renamer at lineupcentral.com/roll-call; and Sidelines, our hosted parent sign-up page at lineupcentral.com/sidelines.
These are different shapes, and the difference matters here. Lineup is installed on the operator’s own Mac. Roll Call is a website: it holds an account, an email address and a record of what each job cost, because it is a paid service and those records are what let somebody argue about a charge. What all three have in common is the thing that matters most — photographs stay on the operator’s computer. Roll Call reads the metadata header of each image in the browser and never receives the image itself, and Sidelines handles no photographs at all.
Sidelines is the one place where we do hold athlete and parent information on our own servers, and it is worth being plain about that. It exists for leagues that give a photographer a list of athlete names and no way to reach the families. A parent opens a password-protected page, finds their athlete, and leaves their own name, email address and (optionally) phone number. Those contact details are stored — for a limited and stated time — rather than passing through. The children’s full names are not. A roster is reduced, on the photographer’s own computer and before any part of it is sent, to a first name and the first two letters of the surname — “Joe Sm” — which is what a parent sees and all that we ever receive. The Sidelines section below says exactly what is held, for how long, and how to have it removed sooner.
Lineup is a product of JM Photography LLC, which also operates The Picture Day Rig, a separate photography business at thepicturedayrig.com. That business has its own privacy policy for its own website and photography services. If you’re a family whose picture day was run by a business using Lineup, this is the policy that applies to you.
If you are a parent, guardian, league coordinator, or athlete interacting with a Lineup-operated relay link, this policy explains what happens to your information. If you are a photography business that purchases or uses Lineup, this policy also explains what we collect about you as our direct customer.
One important distinction that runs through this whole policy: Lineup is a locally installed application. For photography businesses using Lineup, most production data — athlete rosters, photos, local databases — stays on the business’s own computer and is never received by us. The business (the “Operator”) controls that data and is responsible, as the data controller, for its own notices and consents to the families it serves. Sections below are marked where this local-first design applies.
Information We Collect
- Account, license, and subscription information collected when you purchase or activate Lineup — name, business name, billing email, License Key, subscription and renewal status, purchase date, payment status, and a basic machine fingerprint used to enforce activation limits.
- Support communications you voluntarily send us — name, email, business name, License Key, issue description, and any files or screenshots you choose to share.
- Only if you connect Google: a Google refresh token, stored only in your Mac’s Keychain and never transmitted to or stored on our servers. See the Google API Services section below for full detail.
- Athlete and roster data — names, jersey numbers, team assignments, roster files, parent/guardian contact details, order and delivery records — which by default stays on the Operator’s own computer and is not received by us. A narrow slice of this data may transit our optional relay service if the Operator enables it; see Data Retention below for exactly what and for how long.
- For Sidelines: the reduced athlete roster a photographer’s browser sends for a league — team, first name, the first two letters of the surname and no more, and where the league supplies them a jersey number and the league’s own reference — and, from each parent who signs up, their name, their relationship to the athlete, an email address, an optional phone number, the time they submitted, and a truncated form of their network address (the first three parts of an IPv4 address, ending in .0/24). The Sidelines section below itemises this.
- For Roll Call: the email address you sign in with, your credit balance and the ledger of every credit bought, granted or spent, and a record of each rename plan — how many files, how many matched, what it cost, the name pattern used, and the resolved frame order. Roster rows pass through to be matched and are not stored. Image data is never received at all. The Roll Call section below itemises this.
Roll Call
Roll Call renames a picture-day folder by matching the subject barcode written into each image against your roster. It runs in your browser and on our servers, and the split between the two is the whole point of the design.
What never reaches us
Your photographs. Roll Call reads roughly the first 256 KB of each file — enough to reach the metadata block — inside your browser. It does not upload the file, a thumbnail, a hash of the pixels, or a dimension. The renaming itself happens on your own disk, through your browser’s file access, and we never see the result.
What reaches us, and is not kept
Your roster. Matching against it is the job, so the rows you load — whatever columns your gallery platform exported, which usually includes children’s names — are sent with each plan request. They are not stored. They exist for the length of the request, are used to compute the plan, and the reply hands them back to your browser. Per image, the request also carries the filename, the barcode read from its metadata, and its timestamps, plus the list of filenames in the folder (which is what lets Roll Call refuse to overwrite a file that is already there).
What we do keep
- Your account — the email address you sign in with, your credit balance, and when the account was created. There is no password, because Roll Call does not use one.
- The credit ledger — one row for every credit granted, bought or spent, with the reason, the plan it belongs to, and for a purchase the Stripe payment identifier. This is the record you would point at in a dispute about a charge, which is why it is kept rather than a running total alone.
- A record of each plan — how many files it covered, how many matched, what it cost, the name pattern you used, a fingerprint of the job, and the resolved frame order. That order lists each subject’s barcode against a one-way key for each of their frames, not the filename, so that adding a file to a folder later cannot renumber a frame you have already checked. The key is deliberate: if you rename a folder to include children’s names and then re-plan it, storing the filenames would have written those names into our database. It stores a key computed from them instead, which cannot be read back. A barcode is a pseudonymous identifier: we hold no name, team or contact detail against it.
- Sign-in tokens — when you ask for a sign-in link we store a one-way hash of that token alongside the email address it was issued for. The token is single-use and expires in 20 minutes. Your signed-in session is a signed cookie in your own browser, valid for up to 30 days; we do not keep a copy of it.
Roll Call is hosted on Cloudflare (Pages and the D1 database). Payments, when credit sales open, are processed by Stripe. Sign-in emails are sent through Resend from our own account. Roll Call’s own pages load no analytics and no third-party scripts of any kind — no counter, no tag manager, no font or script CDN. That is a deliberate limit rather than an omission: those pages hold a read-write handle on a folder of children’s photographs and the roster naming every child, and anyone who could serve a script to them could read and rewrite both.
To delete a Roll Call account and everything above, email support@lineupcentral.com from the address on it.
Sidelines
Some leagues give a photographer a list of athlete names and nothing else — no way to reach the families whose children are being photographed. Sidelines is the page that asks the families directly: a parent opens a link from their league, enters the league password, finds their athlete, and leaves their contact details.
This is the one part of our software where we collect information directly from parents. Everywhere else, information about athletes and families reaches the photography business without passing through us, or passes through and is not kept.
What is held
- The league’s roster, shortened — each athlete’s team, first name, and the first two letters of their surname, plus a jersey number and the league’s own reference number where the league supplied them. We do not receive or store children’s full surnames. The shortening happens in the photographer’s own browser, before anything is sent; the rest of the name stays in the file on their computer. Nothing else about the athlete either: no age, no date of birth, no address, no school.
- A one-way key per athlete — a short code calculated in the photographer’s browser from the athlete’s full roster entry. It cannot be turned back into a name, and it exists so that the contacts collected here can be matched back to the photographer’s own roster on their own computer afterwards. It is also what tells two children with the same first name and same two letters apart, without our knowing either name.
- What each parent types — their own name, their relationship to the athlete if they give one, an email address, and a phone number if they choose to give one. The phone number is optional; the email address is required, because it is how picture day information and the photo gallery reach them.
- A record that the submission happened — the time, and a truncated form of the network address it came from: the first three parts of an IPv4 address with the last replaced by zero (for example 203.0.113.0/24), or the first four groups of an IPv6 address. That is enough to show a submission came from a plausible place and not enough to identify a household. The full address is never stored.
- A counter for wrong passwords — so that the page cannot be guessed at all night. It holds a one-way keyed hash of the network address rather than the address itself, and a count within a fifteen-minute window. It is not a log of who visited.
What is not held
No photographs — Sidelines never receives an image of any kind. No child’s full surname. No date of birth, age, address, school or any other detail about a child beyond the shortened name and the team. No marketing or messaging preference: the photographer’s gallery platform carries those, along with its own unsubscribe, and a second copy stored here would only go stale. No password of yours: the league password is stored as a keyed one-way hash and cannot be read back out.
How long it is kept
Usually days, not months. The photographer can confirm, on their own screen, that a download of this data has been imported into their own software — and that confirmation deletes from our servers exactly what that download contained, immediately. Anyone who signed up after that download is untouched, because they were not in it.
Failing that, there are two automatic deadlines. Every Sidelines page has a closing date, set when it is created and shown to the photographer. After it closes, the shortened athlete names and every parent’s contact details are deleted automatically: fourteen (14) days after the later of that closing date and the photographer’s most recent export of the data, or ninety (90) days after the closing date if the data was never exported. Deletion is carried out by an automated sweep and cannot be deferred by anyone. The photographer can also delete a league’s names and contacts immediately from their own screen, and a record that the league existed — its name, its code and its dates — is all that remains afterwards.
The point of that arrangement is that the data is here to be moved, not to be stored: once the photographer has downloaded it into their own systems, our copy is on a two-week timer.
Who it goes to
The photography business that created the page, and nobody else. They download it and load it into the software they use to run picture day and deliver galleries. We do not sell it, rent it, or use it to market anything to you, and it is not used to train AI or machine-learning models. The photography business is the data controller for what parents submit and is responsible for its own notices and consents to the families it serves; we process it on their behalf.
Sidelines is hosted on Cloudflare (Pages and the D1 database). Its pages load no analytics and no third-party scripts of any kind, and they are marked so that search engines do not index them.
To correct or remove what you submitted, contact the photography business running your picture day, or write to support@lineupcentral.com and we will remove it.
Google API Services Data Use Disclosure
Lineup optionally connects to a Google account, at the operator’s initiation, to draft email replies and deliver finished photos to the operator’s own Google Drive. This section discloses exactly what we access and why, in compliance with the Google API Services User Data Policy.
Scopes requested
drive.file
- What it’s for
- Uploading finished photo deliveries to a folder Lineup creates in the operator’s Drive (“Lineup Delivery”).
- What happens to the data
- Lineup can only see and write files it created itself — never the operator’s existing Drive contents. Files are uploaded directly from the operator’s device to the operator’s own Drive; we do not receive or store them.
gmail.send
- What it’s for
- Sending transactional emails (access codes, delivery notifications, roster reminders) from the operator’s own Gmail account, when the operator selects Gmail as their email provider in Settings.
- What happens to the data
- Sent directly from the operator’s Gmail account to the recipient; we do not receive or store the message content on our servers.
gmail.compose
- What it’s for
- Creating draft replies to parent emails in the Parent Inbox Responder feature.
- What happens to the data
- Drafts are created in the operator’s own Gmail account for the operator to review and send themselves; Lineup does not send on the operator’s behalf via this scope.
gmail.readonly
- What it’s for
- Reading parent emails so the Parent Inbox Responder can track conversation state and, if AI-assisted classification is enabled, suggest what an email is about.
- What happens to the data
- Read-only — Lineup never modifies, labels, archives, or deletes mail. See “AI-Assisted Features” below for the one case where message content leaves the operator’s device.
Storage. The Google authorization token is stored only in the operator’s macOS Keychain, on the operator’s own computer. It is never transmitted to or stored on our servers.
Sharing. Data obtained via these scopes generally flows only between the operator’s device and the operator’s own Google account, with one opt-in exception, described in full in the next section: if the operator turns on AI-assisted reply classification, the subject and body of unread parent emails are sent to Anthropic to classify intent. That is the only third party that ever receives Google-scoped data, and only for operators who opt in.
Revocation and deletion. Operators can revoke Lineup’s access at any time from their Google Account permissions (myaccount.google.com/permissions) or by disconnecting Google within Lineup’s Settings. Revoking access deletes the local token from Keychain; it does not delete anything from the operator’s own Gmail or Drive, since Lineup never held a separate copy of that data.
Compliance note. Lineup’s access to and use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Restricted scope.
gmail.readonly is classified by Google as a
restricted scope, not merely sensitive. Google’s published
guidance is that its annual CASA (Cloud Application Security Assessment) requirement applies to
applications that access restricted data “from or through a third-party server” —
which describes the AI-classification flow in the next section, for operators who enable it.
AI-Assisted Features (Anthropic)
If a Lineup operator chooses to enable AI-assisted features (Settings → AI Features, using the operator’s own Anthropic API key, stored in the operator’s macOS Keychain — never on our servers), Lineup sends limited data to Anthropic (anthropic.com) for three specific purposes. Every feature below is off unless the operator turns it on, and each is independently optional.
1. Parent Inbox Responder — reply classification. When
enabled, the subject and body of each unread parent email (read via the
gmail.readonly scope above) is sent to
Anthropic solely to classify what the message is likely about (for example, a schedule question vs.
an order question). Lineup never asks Anthropic to draft or send a reply through this feature, and
the classification never causes mail to be modified, labeled, archived, or deleted. If classification
fails or is disabled, the message is simply flagged for the operator to handle manually.
2. Zoe, the voice assistant. When the operator talks to Zoe, what they say (converted to text) and related job/roster information from the operator’s own Lineup database are sent to Anthropic so Zoe can respond and, only after the operator confirms out loud, carry out an action — such as sending an access-code email, sending a delivery notification, or sending a roster reminder, through whichever email provider the operator has configured. If the action involves a Google Drive delivery, a confirmation (such as a delivery link) may be included in what’s sent back to Anthropic as part of the conversation. Zoe cannot change a picture day’s date on its own — that always requires a manual, on-screen confirmation.
3. Field-corrections extraction. Free-text or transcribed correction notes the operator types or dictates (for example, “his jersey number is actually 23”) are sent to Anthropic to turn them into structured, operator-reviewable roster corrections. This feature only ever sees text the operator directly entered — it does not read Gmail or Google Drive data.
Model training. By default, Anthropic does not use API inputs or outputs to train its models. Lineup’s use of the Anthropic API does not opt in to any exception to this.
Retention. Anthropic automatically deletes API inputs and outputs within 30 days under standard operation. If content is flagged by Anthropic’s own automated trust-and-safety systems as violating its Usage Policy, that content may be retained longer — up to 2 years for the input/output itself, and up to 7 years for the safety classification score. We do not separately store the content of these requests on our servers beyond what is needed to display the result to the operator in the moment.
Payments
Payment for Lineup software purchases is handled by our Merchant of Record, Lemon Squeezy. Lemon Squeezy processes billing information necessary for your subscription and license — payment card information is processed by Lemon Squeezy and is not received or stored by us.
Roll Call credits are separate, and are processed by Stripe. Card details go to Stripe directly; we never receive or store them. What we keep of a purchase is the ledger row and Stripe’s payment identifier, which is what lets a charge be traced back if you query it. Credit sales are closed during the Roll Call beta, so nothing is charged today.
How We Use Information
- To provide your software license, subscription, and customer support.
- To provide the optional features described in the Google API Services and AI-Assisted Features sections above, only when you turn them on.
- To operate, secure, and improve the Software and its optional relay features.
- To run Roll Call: to match a roster against a folder, to price and record what a job cost, to keep a frame’s sequence position stable when a file is added later, and to sign you in.
- To communicate with you about your license, subscription, support requests, and material changes to this policy.
You choose your own transactional email provider for parent- and coordinator-facing mail — Gmail, Postmark, or Resend — in Settings. This determines which provider handles access-code emails, delivery notifications, and roster reminders on your behalf, as described in How Information Is Shared above.
Roll Call is different: its sign-in links, and the confirmation sent when you use a “notify me” form on this site, are sent through our own Resend account rather than one you configure. Those are transactional emails — we do not send marketing to a Roll Call account address, and the “notify me” list exists to tell you when the product it was for actually launches.
You can contact us to update an email address on your own account or support communications with us.
Children And Athlete Information
Lineup is software used by youth sports photography businesses. Athlete information may be submitted by a parent, guardian, league, coach, or authorized organizer — or entered directly by the photography business using Lineup — so that the business can run picture day, identify galleries, fulfill orders, and support families.
Sidelines is the exception to the local-first design described below. A league’s athlete names and the contact details its parents submit are stored on our servers, for a stated and short time, because that is the only way a page can collect them at all. The Sidelines section above is the detail, including the deletion clocks.
Roll Call handles the same kind of information and holds less of it. The roster a photographer loads is usually a list of children’s names, and it reaches our servers so that it can be matched against the barcodes in their photographs. It is not stored. The photographs themselves are never transmitted at all. What survives a job is a count, a price, and a list of subject barcodes against a one-way key for each frame — no filenames, no names, no teams, no contact details. The photography business running Roll Call is the data controller for the roster it uploads, and is responsible for its own notices and consents to the families it serves.
The photography business using the software is the data controller for athlete, parent, and guardian information, and is responsible for the privacy notices, consents, and legal basis (including COPPA) for processing that information with the families it serves.
Our design and practices with respect to minors’ information follow these principles:
Local-first, by default. Athlete and roster data entered into Lineup stays on the operator’s own computer unless the operator turns on an optional relay feature.
Data minimization on the relay. Only the narrow contact/roster data needed to route a coordinator or parent submission ever transits our relay, and only when the operator enables it. Emails inviting parents to verify their child’s information contain no athlete details; athlete information is shown only within the secure relay portal behind a unique token-protected link.
Minimal retention on the relay. Relay data is deleted immediately on retrieval or pickup by the operator. Data that is never retrieved is excluded from active use once it expires, and is cleared by a daily automated deletion sweep; see the Data Retention table below for specifics by data type.
No profiling, no AI training. We do not analyze or profile athlete, parent, or guardian information beyond transiently transmitting it to the operator’s installation, and we do not use it to train AI or machine-learning models. (The AI-assisted features described above are about an operator’s own inbox, voice, and correction-entry content, not about analyzing athletes.)
Direct collection, in one place only. Lineup and Roll Call collect nothing directly from athletes, parents, or guardians. Sidelines does, and only this: a parent’s own name, relationship, email address and optional phone number, typed by that parent, for an athlete they select from their league’s roster. We never collect information from a child, and a child has no reason to use the page. The roster of names behind the league password comes from the league, by way of the photographer.
Parents, guardians, and league organizers with questions about athlete information, opt-outs, corrections, or deletion requests should contact the photography business running their picture day, or reach us directly at support@lineupcentral.com.
Data Retention, Correction, And Deletion
| Information | Retention |
|---|---|
| License and subscription records | In accordance with Lemon Squeezy’s business and legal retention requirements |
| Google authorization token | Stored only in the operator’s macOS Keychain; never on our servers; removed on disconnect |
| Postmark / Resend API keys (if configured) | Stored only in the operator’s macOS Keychain; never on our servers |
| Coordinator roster files (relay) | Deleted immediately on retrieval; swept within 24 hours at most |
| Coordinator corrections (relay) | Deleted immediately on pickup; unretrieved corrections cleared by expiry sweep |
| Parent verification submissions (relay) | Deleted immediately upon pickup by the operator. Submissions that are never picked up are excluded from active use once expired, and are cleared by an automated deletion sweep that runs daily. |
| Fly.io encrypted backups (relay) | Up to 5 days, encrypted at rest with Linux LUKS, inaccessible without Fly.io’s cryptographic keys |
| Sidelines shortened athlete names and parent contact details | Deleted immediately when the photographer confirms a download has been imported (scoped to exactly what that download held), or when they or we delete them on request. Otherwise by automated sweep: 14 days after the later of the page’s closing date and the most recent export, or 90 days after the closing date if never exported |
| Sidelines download record | One row per download — when, what kind, how many rows, and when it was confirmed as imported. Holds no personal information, and is deleted with the league |
| Sidelines league record (name, code, dates) | Kept after the names and contacts are deleted, as a business record of a job. Holds no personal information |
| Sidelines wrong-password counter | A keyed one-way hash of the network address and a count, within a rolling 15-minute window; cleared on a correct password and with the league’s data |
| Sidelines parent session | A signed cookie in the parent’s own browser, valid 12 hours, naming only which league it opened. No server-side copy |
| Roll Call roster rows | Not retained. Held for the length of the request that matches them, then discarded |
| Roll Call image data | Never received |
| Roll Call account, credit ledger and plan records | For as long as the account exists, and deleted with it on request. The ledger is a financial record: where tax or accounting law requires a longer hold, that governs |
| Roll Call sign-in tokens | Stored as a one-way hash; single use; expire 20 minutes after they are issued |
| Roll Call session | A signed cookie in your own browser, up to 30 days. No server-side copy |
| “Notify me” signups | Kept until the product launches or you ask us to remove the address |
| Customer support communications | Three (3) years |
| Legal compliance records | As required by applicable law |
We have no ability to retain production databases, athlete information, photographs, or other data stored solely on an Operator’s computer. The same is true of every folder Roll Call renames: the files, and the changes made to them, only ever exist on the computer that ran it.
To request correction, deletion, or a copy of information connected to you, email support@lineupcentral.com. Requests concerning athlete/parent data collected through Lineup should be directed to the photography business operating it, as the data controller.
Security
For Lineup and its optional relay, we use TLS encryption for data in transit, Keychain storage for tokens and API keys (never plaintext on our servers), AES-256 encryption at rest for the brief window a relay file is held pending retrieval, Linux LUKS encryption for Fly.io backup snapshots, non-root hardened container deployment, authenticated internal endpoints gated by an operator-held shared secret, and personal-information scrubbing from relay logs.
For Roll Call: TLS in transit; no password to steal, because sign-in is a single-use link whose token we store only as a one-way hash and which expires in 20 minutes; a session cookie signed with a server-held secret, so it cannot be forged; and account, ledger and plan records held in Cloudflare D1. Two consequences worth stating plainly rather than leaving to be discovered. Anyone who can read your email can sign in as you, so the mailbox is the thing to protect. And signing out clears the cookie in that browser but does not invalidate a copy of it taken elsewhere before it expires.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If you believe information has been exposed or used incorrectly, contact us promptly. Operators are responsible for protecting their own computers, backups, databases, passwords, and local storage.
Your Privacy Rights
Depending on your state of residence, you may have rights under state privacy laws, which may include the right to know, access, correct, delete, and obtain a portable copy of personal information, and to opt out of sale/sharing or targeted advertising (we do not sell, share for targeted advertising, or engage in such activities). These laws include, among others:
California’s Consumer Privacy Act (CCPA), as amended by the CPRA; Virginia’s Consumer Data Protection Act (VCDPA); Colorado’s Privacy Act (CPA); Connecticut’s Data Privacy Act (CTDPA); and Texas’s Data Privacy and Security Act (TDPSA).
To exercise any available right, contact support@lineupcentral.com. We will not discriminate against you for exercising your rights.
International Users
Lineup is operated from the United States. If you access our services from another country, your information may be transferred to and processed in the United States where permitted by applicable law. Because production data generally remains on the Operator’s own computer, international transfers by us are limited primarily to licensing, billing, and support information an Operator voluntarily provides.
Changes To This Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. Continued use after the effective date constitutes acceptance where permitted by applicable law.
Questions about this policy? Email support@lineupcentral.com.