PinchHitterPoolPinchHitterPool
Menu

Privacy Policy

PinchHitterPool is operated by SoftTelRG LLC (7300 State Highway 121, Suite 300, McKinney, Texas 75070, USA). Last updated: August 22, 2026.

Our privacy-first commitments, in plain language:
  • We store personal data only when we have told you about it — everything we keep is listed on this page.
  • You control what you share and how long we keep it; you can ask us to delete your data at any time.
  • We never sell personal data and we never share it for cross-context behavioral advertising.
  • The most sensitive data is deliberately handled by specialized third parties, not by us: sign-in credentials (Microsoft), payment cards (Stripe), identity/background checks (verification providers), and map locations (Google). We store outcomes and references — not the sensitive material itself.
  • We do not collect or store home addresses of workers or volunteers. Matching uses only the postal codes you choose as your work territory.

1. Who this covers

This policy applies to pinchhitterpool.com, the PinchHitterPool portal and applications, and related communications (together, the “Service”). It covers everyone who uses the Service: workers and side-hustlers, volunteers, interns, employers, organizations, households, and visitors. For people in the European Economic Area, the United Kingdom, and Switzerland, SoftTelRG LLC is the data controller. For Canada, SoftTelRG LLC is the organization accountable under PIPEDA. Questions and requests: support@softtelrg.com or the contact page.

2. What we collect — and only this

  • Account basics via secure sign-in (SSO):your name and email address. We do not receive or store your password — sign-in is handled by Microsoft’s identity platform.
  • Profile data you choose to provide: display name, skills, work preferences, weekly availability, pay-rate range, external professional links you add, and your work territory (up to five postal codes). No street address is requested or stored for workers or volunteers.
  • Work activity generated by using the Service: applications, offers, placements, shift engagements, attendance check-in/out timestamps, references you request, and certificates issued to you.
  • Organization data (employers/entities): organization name, type, business contact details, and the work locations you publish with a job post. Posted work locations are public-by-nature posting data.
  • Billing status only: your plan, its status, and Stripe reference IDs. Card numbers, bank details, and billing addresses live with Stripe — they never touch our systems.
  • Verification outcomes only:when identity or background verification is required, a specialized provider performs it; we store the status (for example “verified” and an expiry date) and a provider reference — never your documents or ID numbers.
  • Messages you send us: contact-form submissions and notification/email delivery records needed to run the inbox you see in the portal.
  • Technical data: server logs (IP address, browser type, timestamps) for security and abuse prevention, and the cookies described in section 6.

3. What we deliberately do not store

  • Worker or volunteer home addresses — not collected, not stored, by design.
  • Passwords for regular accounts (SSO handles sign-in; platform-admin passwords are salted and hashed, never stored in readable form).
  • Payment card or bank account numbers (Stripe only).
  • Identity documents, government ID numbers, or background-check reports (verification providers only).
  • Advertising profiles — we run no ads and build none.

4. How we use personal data

  • To match people to opportunities and run shifts, applications, offers, and placements you take part in.
  • To operate attendance, certificates, references, and trust features you invoke.
  • To process subscriptions and credits (through Stripe) and enforce the pricing you agreed to.
  • To send the notifications and emails the Service is built around, and to answer your messages.
  • To keep the Service secure — fraud, spam, and abuse prevention (including reCAPTCHA and rate limits).
  • To comply with law and enforce our Terms.

Legal bases (GDPR/UK GDPR): performance of a contract (running your account and engagements), legitimate interests (security, service improvement, defending claims), consent (where we ask for it — for example optional profile fields), and legal obligation (tax and accounting records tied to payments). We do not use automated decision-making that produces legal or similarly significant effects without human review.

5. Who we share data with (processors and partners)

We share personal data only with the service providers needed to run the platform:

  • Microsoft — sign-in (Entra ID) and Azure hosting/database (United States regions).
  • Stripe — payments, subscriptions, and card verification.
  • Google — reCAPTCHA (spam protection), optional analytics, email delivery for support messages, and Google Maps links for posted work locations (opening a map link is governed by Google’s own privacy policy).
  • Vercel — website hosting and delivery.
  • Verification providers — identity/background checks, only when you start one.
  • Other users, only as the product requires: your public profile appears in search when you enable it; organizations you apply to see your application; certificates you share are publicly verifiable by design.
  • Authorities, only where the law requires it, and successors in a merger or acquisition (with this policy continuing to apply).

We do not sell personal data, and we do not share it for cross-context behavioral advertising.

6. Cookies

  • Strictly necessary: httpOnly session cookies that keep you signed in (regular session and, for platform admins, a separate admin session). These cannot be read by page scripts.
  • Security: Google reCAPTCHA sets cookies to distinguish humans from bots on our public forms.
  • Analytics (optional): if enabled, Google Analytics helps us understand aggregate product usage. We honor Global Privacy Control (GPC) signals for any non-essential cookies.

We use no advertising or cross-site tracking cookies.

7. How long we keep data — you decide

  • Account and profile data: for as long as your account exists. Delete your account (or ask us to) and we delete or irreversibly anonymize your personal data, except the minimum we must keep for legal, tax, or dispute-resolution obligations.
  • Free tier: finished job posts may be archived after roughly 30 days (the current number is always shown on the pricing page); paid plans keep history for the life of the subscription.
  • Certificates and references are trust records that other people rely on; if you delete your account, we anonymize rather than falsify them.
  • Security logs are kept for a short rolling window, then deleted.

Deleting your account is self-service. You do not need to email us and you do not need the mobile app — open pinchhitterpool.com/delete-account for the steps, or go straight to Account → Delete your account. We confirm by email first, because deletion cannot be undone. If you pay for a subscription, deleting cancels it in the same step so you are not billed again.

After a deletion we keep one record of the deletion itself: the date, counts of what was removed, and a one-way hash of your email address. A hash cannot be reversed into your email; it exists so we can show an account was deleted, and so a cancelled subscription can be traced if a payment provider queries it. It does not identify you and is never used to contact you.

8. Your rights

Everyone: you can delete your account yourself at any time from Account → Delete your account. You can also access, correct, download, or delete your personal data, and object to or restrict certain processing, by emailing support@softtelrg.com. We respond within 30 days, verify requests to protect your data, and never discriminate against you for exercising rights.

  • EEA/UK/Switzerland (GDPR): rights of access, rectification, erasure, restriction, portability, and objection; the right to withdraw consent at any time; and the right to lodge a complaint with your local supervisory authority. Data is processed in the United States under appropriate safeguards, including Standard Contractual Clauses with our processors.
  • Canada (PIPEDA and provincial laws): rights to access and correct your personal information and to withdraw consent (subject to legal or contractual restrictions). You may complain to the Office of the Privacy Commissioner of Canada.
  • United States (CCPA/CPRA and similar state laws): rights to know, access, correct, delete, and port your personal information, and to opt out of sale or sharing — noting that we do not sell or share personal information as those laws define it, and we do not use or disclose sensitive personal information beyond what those laws permit for service delivery.

9. Security

Data is encrypted in transit (TLS) and at rest; particularly sensitive fields are additionally encrypted at the field level. Access is role-based and least-privilege, admin sign-in requires two passwords plus a one-time email code, and privileged actions are audit-logged. No system is perfectly secure; if a breach affects your data we will notify you and regulators as the law requires.

10. Youth and children

Accounts require you to be at least 18. Youth participation in volunteer activities is possible only through supervised organization programs with guardian consent, with youth-mode restrictions applied. We do not knowingly collect personal data from children; if you believe a child has provided data, contact us and we will delete it.

11. Changes and contact

If we change this policy in a material way we will post the update here and notify active accounts before it takes effect. Continued use after the effective date means the updated policy applies. Reach us any time at support@softtelrg.com, via the contact page, or by mail at SoftTelRG LLC, 7300 State Highway 121, Suite 300, McKinney, Texas 75070, USA.