Privacy Policy

Last updated: June 19, 2026

Core Registration (“Core Registration,” “we,” “us,” or “our”), a Delaware company, provides a registration and program-management platform used by camps, schools, churches, clubs, and similar organizations. This Privacy Policy explains how we collect, use, share, and protect personal information across our marketing website, staff/administrator application, and registrant/family portal (together, the “Services”).

Because organizations use our platform to run their own registrations, our role depends on the context — please read Section 2 carefully.

1. Scope

This policy covers personal information we handle through the Services. It does not cover the independent privacy practices of the organizations that use our platform, your device or operating system providers, or third-party sites we link to.

2. Our role: controller vs. service provider

For our direct customers (organizations and the staff who create accounts) and for website visitors, we act as a controller of personal information.

For the personal information an organization collects from its registrants and families and stores in our platform — such as attendee profiles, health forms, photos, and payment records — the organization is the controller and we act as a service provider / processor that handles that data on the organization’s behalf and under its instructions. If you are a parent or registrant and wish to access or delete that information, please contact the organization you registered with first; we will support their request.

3. Information we collect

  • Account & contact information — name, email, phone, role, and authentication credentials.
  • Registration & attendee information, including information about children submitted by a parent/guardian or organization — names, dates of birth, grade, gender, emergency contacts, and program preferences.
  • Sensitive information — health and medical details (allergies, medications, conditions, immunizations) and, where an organization requires it, government identifiers and financial information. We apply heightened safeguards to this data.
  • Photos, video & media — uploaded by organizations or families, which may be processed by an optional automated face-grouping feature (see Section 5).
  • Payment information — processed by our third-party payment processor. We do not store full payment-card numbers.
  • Communications — emails, SMS/text messages, in-app messages, and support requests.
  • Technical & usage data — IP address, device and browser details, log data, and cookies (see Section 12).

4. Children's privacy (COPPA & FERPA)

The Services are designed for use by organizations and adults (staff and parents/guardians). We do not knowingly collect personal information directly from children under 13. Information about a minor is provided by a parent/guardian or by the organization responsible for the child’s program.

Organizations are responsible for obtaining any parental consent required by law — including the Children’s Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), and applicable state laws — before submitting a child’s information. If you believe a child has provided us personal information without appropriate consent, contact us at privacy@coreregistration.com and we will delete it.

5. Photos, media & biometric information

Some organizations use photo galleries and an optional automated face-matching feature that analyzes facial geometry to group photos and help families find images of their own registrant. Depending on configuration, this may involve biometric identifiers, which are subject to special laws in certain jurisdictions (for example, the Illinois Biometric Information Privacy Act and similar laws in Texas and Washington).

Where face-matching is enabled, it is used only to match and surface photos, only where the organization has enabled it and obtained any required consent. Biometric templates are used solely for that purpose and retained only as long as necessary, then deleted. You may decline face-matching where it is offered.

6. How we use information

  • Provide, operate, and secure the Services.
  • Process registrations, payments, check-in, communications, and program operations.
  • Provide customer support and respond to requests.
  • Detect, prevent, and address fraud, abuse, and security incidents.
  • Improve and develop our products, including analytics.
  • Comply with legal obligations and enforce our agreements.
  • With consent where required, provide optional features (such as face-matching) and send marketing communications.

7. How we share information

  • With the organization you registered with and its authorized staff.
  • With service providers and subprocessors that help us operate the platform — including cloud hosting and database providers (e.g., Amazon Web Services, Supabase), email and SMS delivery (e.g., SendGrid, Twilio), payment processing, and analytics — under contracts that restrict their use of the data.
  • For legal reasons — to comply with law, respond to lawful requests, protect safety, or enforce rights.
  • In connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

8. Data security

We use technical and organizational safeguards designed to protect personal information, including encryption in transit and at rest, tenant data isolation (row-level security), role-based access controls, multi-factor authentication for sensitive data, monitoring, and malware scanning of uploaded files. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Data retention

We retain personal information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Organizations control the retention of their registrants’ data; when an organization deletes data or closes its account, we delete or de-identify the associated personal information within a commercially reasonable period, subject to backups and legal requirements.

10. Your rights & choices

Depending on where you live, you may have rights to access, correct, delete, port, or restrict your personal information, and to opt out of certain processing, under laws such as the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA). For information an organization controls, please direct your request to that organization. For information we control, contact us at privacy@coreregistration.com. We will not discriminate against you for exercising these rights. You can opt out of marketing emails at any time using the unsubscribe link.

11. International data transfers

We operate primarily in the United States. If you access the Services from outside the United States, your information may be transferred to, stored, and processed in the United States and other countries under appropriate safeguards.

12. Cookies & tracking technologies

We use cookies and similar technologies for authentication, security, remembering preferences, and analytics. Some are necessary for the Services to function; others help us understand usage. You can control cookies through your browser settings, though disabling some may affect functionality.

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated “Last updated” date, and where required we will provide additional notice.

15. Contact us

Questions about this policy or your information? Contact us at privacy@coreregistration.com.