Legal

Privacy Policy

Last updated: May 5, 2026

NextSigned ("NextSigned," "we," "us," or "our") operates nextsigned.com and related services. This Privacy Policy explains how we collect, use, and protect your personal information when you use our platform.

By using NextSigned you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

We collect the following types of information:

Account information: When you create an account we collect your name, email address, and password. Athletes also provide their school, sport, position, and social media handles. Brands provide their company name, website, and industry.

Profile information: Athletes may upload profile photos, banner images, and gallery photos. This content is publicly visible on your profile page.

Financial information: We use Stripe to process payments. When athletes connect their bank account, Stripe collects and stores their banking details directly — NextSigned never sees or stores bank account numbers or routing numbers. When brands pay for deals, card information is processed directly by Stripe.

Deal information: We store information about deals posted, applications submitted, messages sent between users, and payment transactions.

Usage information: We collect standard web analytics including pages visited, time spent on the platform, and device information to improve our service.

Communications: If you contact us for support we retain those communications.

2. How We Use Your Information

We use the information we collect to:

— Operate and maintain the NextSigned platform — Process NIL deal applications and payments — Send transactional emails (deal accepted, rejected, payment confirmed) — Provide Athlete Shield call screening services via IntelliLine — Improve the platform based on usage patterns — Comply with legal obligations including NIL compliance requirements — Detect and prevent fraud or misuse of the platform

We do not sell your personal information to third parties. We do not use your information for advertising purposes.

3. Information Shared With Third Parties

We share your information with the following service providers:

Supabase: Our database and authentication provider stores your account data and profile information on secure servers.

Stripe: Our payment processor handles all financial transactions. Stripe's privacy policy governs their use of your financial data. Athletes who connect their bank account are subject to Stripe's Connected Account Agreement.

Resend: Our email delivery provider sends transactional emails on our behalf.

IntelliLine: Powers the Athlete Shield answering service. Athletes who subscribe to Shield have their dedicated phone number managed by IntelliLine.

Vercel: Hosts the NextSigned platform and may process request logs.

We require all service providers to maintain appropriate security standards and only use your information to provide services to NextSigned.

4. Public Information

The following athlete profile information is publicly visible to anyone who visits nextsigned.com:

— Name, sport, school, position — Profile photo and banner image — Gallery photos (if uploaded) — Follower count and base rate per post — Social media handles — Shield active status

Your email address, phone number, banking information, and deal negotiation details are never publicly visible.

Brands' company name, logo, and posted deals are publicly visible. Brand email addresses and payment information are never publicly visible.

5. Data Security

We implement industry-standard security measures to protect your information:

— All data is encrypted in transit using HTTPS/TLS — Passwords are hashed using bcrypt via Supabase Auth — Financial data is handled exclusively by Stripe using PCI DSS Level 1 compliant infrastructure — Access to production databases is restricted to authorized personnel — We conduct regular security reviews

No method of transmission over the internet is 100% secure. While we strive to protect your information we cannot guarantee absolute security.

6. Data Retention

We retain your account information for as long as your account is active. If you delete your account we will delete your personal information within 30 days except where we are required to retain it for legal or compliance purposes.

Deal records and payment history may be retained for up to 7 years for tax and legal compliance purposes.

Photos and media you upload are deleted from our storage within 30 days of account deletion.

7. Your Rights

You have the following rights regarding your personal information:

Access: You can view and update your profile information at any time from your account settings.

Correction: You can correct inaccurate information through your account settings or by contacting us.

Deletion: You can request deletion of your account and associated data by contacting support@nextsigned.com. We will process deletion requests within 30 days.

Portability: You can request a copy of your personal data by contacting us.

California residents have additional rights under the California Consumer Privacy Act (CCPA) including the right to know what personal information is collected, the right to deletion, and the right to opt out of sale (we do not sell personal information).

8. Cookies

NextSigned uses cookies and similar technologies to:

— Maintain your login session — Remember your preferences — Analyze platform usage through analytics

You can control cookies through your browser settings. Disabling cookies may affect your ability to use certain features of the platform including staying logged in.

9. Children's Privacy

NextSigned is not directed to children under 13. We do not knowingly collect personal information from children under 13. High school athletes between 13 and 18 may use the platform with parental consent. If you believe we have inadvertently collected information from a child under 13 please contact us at support@nextsigned.com.

10. NIL Compliance

NextSigned facilitates Name, Image, and Likeness transactions between athletes and brands. All deals must comply with applicable NCAA rules, state NIL laws, and the federal NIL framework effective August 1, 2026.

Athletes are responsible for reporting NIL income to their institution's compliance office where required by their school's policies. NextSigned does not provide tax or legal advice.

Stripe issues 1099-K tax forms to athletes who receive more than $600 in payments through the platform in a calendar year.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email and by posting the updated policy on this page with a new "Last updated" date. Your continued use of NextSigned after changes become effective constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or how we handle your information please contact us:

Email: support@nextsigned.com Website: nextsigned.com