BagTag guide
Privacy and safety, in plain language
BagTag is designed for adult-operated youth recognition. It limits what each role can see, separates optional media permissions, and gives families a verified request path.
The minimum-data path
- 1
Adult enters
A parent or guardian provides the minimum details needed to match and verify the award.
- 2
BagTag protects
Names and contact details are encrypted; email matching uses a non-reversible lookup value.
- 3
Roles are limited
Leagues operate claims; partners see only redemption details; sponsors receive aggregate results.
- 4
Family controls
Verified adults can request correction, eligible deletion, or media withdrawal.
Data by purpose
- Award verification
- Player and adult names, adult email, league, team, game, award slot, attestation, and security tokens are used to prevent duplicate or false claims and deliver the reward.
- Reward confirmation
- A limited player display, selected offer, location, status, expiration, and confirmation audit are used to ensure one in-person redemption.
- Optional story and media
- Story, display name, and photo are separate from receiving the reward. Upload rights and website/social use are separately recorded. Production video submission is currently disabled.
- Program measurement
- Anonymous or pseudonymous page and program events support aggregate sponsor and league reporting. An approved sponsor link receives only a separate destination-scoped pseudonym, never the BagTag identifier or family data. Reports suppress small groups where practical.
- Staff operations
- Staff names, work emails, roles, invitations, sessions, audit events, and limited device/network context protect administrative workspaces.
- Legal and safety
- Consents, attestations, moderation decisions, reversals, privacy requests, and audit evidence may be retained when needed for accountability or legal obligations.
Optional media permissions
| Choice | What it means | Required for a reward? |
|---|---|---|
| Upload rights | The adult confirms they have authority to submit the content and permissions for recognizable people. | No |
| Photo | The photo stays in private quarantine until an authenticated moderator inspects it. Production video submission is currently disabled. | No |
| Display name | The league may use the selected public display, normally first name and last initial—not a player profile. | No |
| League website | Approved content may appear in an intentionally published league highlight. | No |
| Social channels | The league may separately use eligible content on approved social channels; website permission alone is not social permission. | No |
Safety habits for every role
- Use a personal staff account; never forward sign-in, verification, authorization, or media links.
- Treat player, parent, claim, media, PIN, and privacy-request information as need-to-know.
- Confirm the BagTag HTTPS address before entering information or a location PIN.
- Do not copy family details into spreadsheets, messaging channels, sponsor systems, or POS notes.
- Remove staff promptly, rotate exposed PINs, and report unusual emails or redemptions.
- Never post a child's full name, direct contact, school schedule, precise routine, or unapproved media.
- Do not ask a child to complete a claim; the flow is for an adult parent or legal guardian.
- Use the built-in privacy request, moderation, reversal, and audit paths so actions remain traceable.