Privacy Policy
Effective Date: 17 June 2026
1. About This Policy
Valor Esports Pty Ltd ABN 94 648 832 080 (Australia) and its subsidiary Valor US Operations, Inc. (Delaware, United States) (together, “Valor”, “we”, “us”, or “our”) operate a browser-based esports training platform for schools (the “Platform”). This Privacy Policy explains how we collect, use, store, and disclose information when schools, teachers, and students use the Platform and our website at valoresports.com (collectively, the “Services”).
We are committed to protecting student privacy. Our Platform is designed for use in educational settings. We collect only the information necessary to provide and improve the Services, and we handle that information in accordance with applicable privacy laws, including:
- The Children’s Online Privacy Protection Act (COPPA) and the Family Educational Rights and Privacy Act (FERPA) in the United States;
- The General Data Protection Regulation (GDPR) in the European Union and European Economic Area;
- The Privacy Act 1988 (Cth) and Australian Privacy Principles in Australia.
If you have questions about this policy or wish to exercise your rights, contact our Privacy Officer at:
Email: corporate@valoresports.com
Post: Privacy Officer, Valor Esports, PO Box 1977, Sunnybank Hills QLD 4109, Australia
2. Two Ways We Handle Data
How we handle information depends on how your school accesses the Platform. There are two models, set out below. Every section of this policy that follows distinguishes between them where necessary.
2.1 Standard Accounts: No Directly Identifying Personal Information Collected
In the standard account model, students do not provide any personal identifying information to Valor.
- Students are identified by a system-generated username (a random adjective-animal combination, such as “CuriousPanda”) plus a 4-digit PIN and a school code.
- No name, email address, date of birth, physical address, phone number, photograph, or government ID is collected from students.
- Teachers create and manage student accounts. Students log in using their school code and PIN.
Under this model, the information we collect from students – gameplay performance data, session activity, wellbeing check-in responses (e.g., how “excited” vs “challenged” a student feels), IP address, browser metadata, and cookie data – is not linked to any directly identifying student information such as name, email address, or government ID. While technical identifiers such as IP addresses and cookies may constitute “personal information” under COPPA and GDPR, they are collected solely for Platform operation, security, and product improvement, and are not used to identify, track, or profile individual students across contexts. No directly identifying personal information is collected from students in the standard account model.
2.2 Single Sign-On (SSO) Accounts: District-Provided Identity
Where a school or school district connects to Valor through a single sign-on (SSO) provider (such as Clever), identity information is provided to us by the district’s Student Information System via the SSO provider. This may include:
- Student name
- Student email address
- SSO provider user ID
- Grade level
- School and district name
The specific data fields shared are configured by the district. We receive only the fields the district elects to share, and we use them solely as described in this policy and in the applicable district data privacy agreement.
For SSO-connected schools, the district acts as the data controller and Valor acts as the data processor. The district’s data privacy agreement with Valor governs the use, retention, and deletion of student data received through the SSO provider. Where required by law, the district provides consent on behalf of parents for the collection and use of student personal information under COPPA and FERPA.
2.3 Future Integrations
If we add additional SSO providers, rostering integrations, or other authentication methods in the future, the same principles apply: any identity data received from a district or school will be governed by the applicable data privacy agreement and handled in accordance with the SSO Account model described in this policy. We will update this policy to name any new integration partners.
3. What We Collect and Why
3.1 Standard Account Data
For Standard Accounts, we collect:
- Gameplay performance data (scores, completion rates, skill progression, drill results);
- Session activity data (frequency, duration, games accessed);
- Wellbeing check-in responses;
- Gamification data;
- Teacher-assigned group and class labels;
- Technical metadata (IP address, browser type, device type, operating system, referring URLs, timestamps);
- Cookie data (see Section 3.5).
We collect this data to deliver and personalise training content, track student progress, provide teachers with analytics and wellbeing dashboards, and improve the Platform. No directly identifying personal information is collected from students in this model.
3.2 SSO Account Data
For SSO Accounts, we collect:
- Identity data from the district via the SSO provider (see Section 2.2);
- All platform usage data listed in Section 3.1;
- Teacher-to-student class matching data (via email matching with teacher accounts).
We use identity data solely to associate platform activity with the correct student, place students in the correct classes, and enable automated roster synchronisation where the district has enabled rostering. All other uses are as described in the applicable district data privacy agreement.
3.3 Teacher and Administrator Data
For teachers and school administrators who create Valor accounts, we collect:
- Name and email address;
- School name and role;
- Account preferences and settings;
- Payment information (processed by Stripe – see Section 5).
3.4 Website Visitors
Visitors to our website who do not log in to the Platform contribute standard web analytics data: IP address, browser type, referring URL, pages viewed, visit duration, and exit URL. This data is not linked to any Platform account unless the visitor is logged in at the time of browsing.
3.5 Cookies
We use cookies and similar technologies to operate the Platform, maintain sessions, remember preferences, and understand how the Services are used. Our cookie consent banner on the website allows visitors to accept or reject analytics and marketing cookies. Essential cookies required for Platform operation cannot be disabled. We do not use cookies to track individual students for advertising purposes.
4. How We Use Data
4.1 Educational Purposes
We use student data (both Standard and SSO) for the following educational purposes:
- Delivering, personalising, and improving training content and the Platform experience;
- Tracking individual and cohort progress through the curriculum;
- Providing teachers and administrators with analytics, wellbeing dashboards, and class management tools;
- Enabling gamification features (Valor Coins, leaderboards, teacher-managed reward stores);
- Supporting Platform functionality and troubleshooting;
- Improving the quality, safety, and security of the Services.
4.2 No Marketing to Students
We do not use student personal information – whether from Standard or SSO Accounts – for marketing, advertising, or promotional purposes. We do not serve behavioural advertising to students and do not build advertising profiles based on student activity.
4.3 No Sale of Student Data
We do not sell, rent, trade, or otherwise disclose student personal information for monetary or other valuable consideration. We do not license student data to any third party.
4.4 Aggregated and De-Identified Data
We may create de-identified and aggregated data sets from Platform usage (e.g., “average Rocket League Beginner tier completion rates”). This data cannot be re-associated with individual students or schools. We may use this data for research, product improvement, industry reporting, and to demonstrate Platform impact. This is not personal information and is not subject to the deletion or access rights described in this policy.
4.5 Legal Compliance
We may use or disclose information where required by law, court order, or government regulation, or where necessary to protect the safety, rights, or property of Valor, our users, or the public.
5. Third-Party Subprocessors
We engage third-party service providers to support Platform operations. The table below lists our current subprocessors and indicates which data models they interact with.
Subprocessor | Purpose | Data Accessed | Location |
Amazon Web Services (AWS) | Cloud hosting and infrastructure | All Platform data (both models) | United States |
Neon | PostgreSQL database hosting | All Platform data (both models) | United States |
PostHog | Product analytics and usage monitoring | Anonymized Standard Account usage data (may include IP address for analytics purposes). No directly identifying student information. | United States / EU |
Tapfiliate | Affiliate program tracking | Anonymized affiliate IDs. No student data. | United States |
Where a district connects via an SSO provider (see Section 2.2), that provider is also a data intermediary. The district’s relationship with the SSO provider is governed by the district’s own agreement with that provider.
All subprocessors are contractually bound to data protection obligations consistent with this policy. Subprocessors that do not receive student personal information are contractually restricted from receiving it. We review subprocessor data practices before engagement and periodically thereafter.
6. Children’s Privacy (COPPA Notice)
6.1 Our Approach
Valor is an educational platform used exclusively in school settings. Our handling of children’s information differs depending on the account model (Section 2).
6.2 Standard Accounts: No Personal Information Collected from Children
Under the Standard Account model, no directly identifying personal information (such as name, email address, or government ID) as defined by COPPA (16 C.F.R. § 312.2) is collected from children. Technical identifiers such as IP addresses and cookies are collected for Platform operation, security, and product improvement, but are not used to identify, track, or profile individual students across contexts.
The AdjectiveAnimal usernames used in Standard Accounts are randomly generated, scoped to individual school codes, and are not persistent identifiers tied to a specific child across contexts. Because no directly identifying personal information is collected in this model and technical identifiers are not used for tracking or profiling, COPPA’s notice and consent requirements for directly identifying information are not triggered.
6.3 SSO Accounts: School and District Consent
For schools that use an SSO connection, the school district provides consent on behalf of parents for the collection and use of student personal information, as permitted under COPPA. The Federal Trade Commission has recognised that schools may act as parents’ agents in providing consent for the use of educational technology in the school context. The applicable district data privacy agreement memorialises this consent.
Personal information received through SSO is used solely for educational purposes as directed by the district and as described in this policy and the district agreement.
6.4 Parental Rights Under COPPA
Parents and legal guardians have the right to:
- Review the personal information collected about their child;
- Refuse further collection or use of their child’s personal information;
- Opt to consent to collection and use of their child’s information without consenting to its disclosure to third parties;
- Request deletion of their child’s personal information;
- Revoke consent and have their child’s information deleted.
To exercise these rights, contact us at corporate@valoresports.com with “COPPA Request” in the subject line. We will respond within 45 days. For SSO-connected schools, we may direct the request to the school district, as the district is the data controller and in the best position to verify the parent’s identity and relationship to the student.
6.5 Age Restriction
The Platform is designed for students 13 years of age and older. For SSO Accounts, the school district provides consent through the applicable data privacy agreement for any students under 13. For Standard Accounts, Valor does not collect age information from students; the school is responsible for ensuring that access to the Platform is appropriate under its own policies. Valor does not offer direct-to-consumer accounts to children under 13.
6.6 Data Retention for Student Data
Student data is retained for the duration of the school’s active agreement with Valor. Upon termination of that agreement, student data is deleted within 60 days unless otherwise specified in the district agreement or required by law. De-identified aggregate data (Section 4.4) may be retained after account deletion.
7. FERPA Compliance
For US schools, Valor operates as a “school official” with a legitimate educational interest under the Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g; 34 C.F.R. Part 99). As a school official, Valor:
- Performs services that the school or district would otherwise use its own employees to perform;
- Is under the direct control of the school or district with respect to the use and maintenance of education records;
- Uses education records only for authorised educational purposes as directed by the school or district;
- Maintains the confidentiality of education records and does not re-disclose them except as permitted by the district agreement or applicable law.
The district data privacy agreement (including any UDIPP or equivalent instrument) serves as the written agreement required under FERPA’s school official exception. Parents and eligible students should direct FERPA requests to their school or district, which maintains control of education records.
8. GDPR Rights (European Users)
8.1 Applicability
This section applies to users located in the European Union or European Economic Area, and to any users whose personal data is otherwise protected by the GDPR, regardless of account model.
8.2 Legal Bases for Processing
We process personal data on the following legal bases:
- Performance of a contract – providing the Platform and Services to the school;
- Legitimate interests – platform improvement, analytics (Standard Accounts only), security, and fraud prevention;
- Consent – where you have given specific consent (e.g., marketing communications to teachers and administrators, non-essential cookies).
8.3 Data Subject Rights
Under the GDPR, you have the right to:
- Access – request a copy of the personal data we hold about you;
- Rectification – correct inaccurate or incomplete personal data;
- Erasure – request deletion of your personal data where there is no overriding lawful basis for retention;
- Restriction – limit how we process your data in certain circumstances;
- Portability – receive your personal data in a structured, commonly used, machine-readable format;
- Objection – object to processing based on legitimate interests or direct marketing;
- Withdraw consent – withdraw previously given consent at any time, without affecting the lawfulness of processing before withdrawal.
To exercise these rights, contact corporate@valoresports.com. We will respond within 30 days. For SSO-connected schools, we may refer requests to the district as the data controller.
8.4 International Transfers
Personal data is stored on AWS infrastructure in the United States. For users in the EU/EEA, this means your data is transferred outside the EU. We rely on standard contractual clauses and other appropriate safeguards to ensure your data receives an adequate level of protection.
8.5 EU Representative
Our EU Representative is Valor Esports Pty Ltd, reachable at corporate@valoresports.com. You also have the right to lodge a complaint with your local supervisory authority.
9. Australian Privacy Act Rights
Valor complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Under the APPs, individuals have rights to:
- Access personal information we hold about them;
- Request correction of inaccurate, out-of-date, incomplete, irrelevant, or misleading information;
- Make a complaint about how we have handled their personal information.
Access and correction requests should be sent to corporate@valoresports.com. We will respond within 30 days. We do not charge for an initial request but reserve the right to charge a reasonable fee for additional copies.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
We may disclose personal information to overseas recipients (including our US-based subprocessors listed in Section 5) where necessary for Platform operation. We take reasonable steps to ensure those recipients handle personal information in accordance with the APPs.
10. Data Security
We implement and maintain industry-standard administrative, physical, and technical safeguards to protect the information we hold. These include:
- Encryption of data in transit (TLS) and at rest;
- Access controls limiting data access to authorised personnel with a legitimate need;
- Regular security review and monitoring of our infrastructure;
- Contractual security obligations on all subprocessors;
- Data breach response procedures, including notification to affected schools and, where required, to regulatory authorities and affected individuals.
While we take these measures, no internet-based service can guarantee absolute security. Schools and users share responsibility for security by maintaining the confidentiality of login credentials and promptly notifying us of any suspected compromise.
11. Data Retention and Deletion
11.1 Student Data
Student data (both Standard and SSO Accounts) is retained for the duration of the school’s active subscription or agreement with Valor, plus a 60-day transition period following termination or expiry. At the end of this period, student data is deleted from our systems unless the district agreement specifies otherwise or we are required by law to retain it.
For SSO Accounts, data retention and deletion are also governed by the applicable district data privacy agreement. If the district agreement specifies a shorter retention period, the shorter period applies.
11.2 Teacher and Administrator Data
Teacher and administrator account data is retained while the account is active. Accounts that have been inactive for 24 months may be deleted. You may request deletion of your account at any time by contacting us.
11.3 De-Identified Data
De-identified and aggregated data (Section 4.4) may be retained indefinitely for research, product improvement, and reporting purposes. This data cannot be re-associated with any individual.
12. Your Rights and Choices
The following rights apply regardless of your jurisdiction or account type:
- Access and correction – request access to or correction of your information (see Section 8 for GDPR, Section 9 for AU Privacy Act, Section 6.4 for COPPA parental rights);
- Deletion – request deletion of your information (subject to Section 11);
- Data portability – request your data in a portable format;
- Cookie preferences – manage cookie consent via the cookie banner on our website;
- Marketing opt-out – teachers and administrators may unsubscribe from marketing emails via the link in any marketing email. Students do not receive marketing communications.
To exercise any of these rights, contact corporate@valoresports.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The updated policy will be posted on our website at valoresports.com/privacy-policy with a revised effective date. We will notify active Platform users of material changes via the Platform or by email to the account-holder address on file.
Where a material change affects how we handle student personal information, we will notify school contacts at least 30 days before the change takes effect.
14. Contact and Complaints
For privacy inquiries, rights requests, or complaints, contact:
Email: corporate@valoresports.com
Post: Privacy Officer, Valor Esports, PO Box 1977, Sunnybank Hills QLD 4109, Australia
We will acknowledge your inquiry within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, you may have the right to lodge a complaint with the relevant supervisory authority:
- Australia: Office of the Australian Information Commissioner (oaic.gov.au)
- European Union: Your local data protection authority (a list is available at edpb.europa.eu)
- United States: The Federal Trade Commission (ftc.gov) or your state Attorney General
